How it works
- Choose a scenario: how far the prover can be trusted, what the verifier may do on site, whether new chips are allowed and whether secrets must stay hidden.
- Choose one or more goals. Each goal needs commitments, and each commitment rests on claims from this map.
- Pick mechanisms for each claim. The report lists coverage, strengths, gaps and possible additions, each linked to its record and sources.
Every proposal has its own link. The report offers prompts that pair that link with a task for an AI assistant.
Published designs
Start from one of the whole-system designs on this map.
- AI 2040 inference-only verification stack R1
A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs.
- Low-trust AI compute verification system overview R1
A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records.
- RAND secure inference data center (SIDC) design R1
A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.