RAND
A nonprofit, nonpartisan research organization; its reports cover verification of international AI agreements, hardware-enabled governance mechanisms and secure inference data centres.
RAND describes itself as a nonprofit, nonpartisan research organization that provides leaders with the information they need to make evidence-based decisions 1. Its reports on verification include:
- Six layers of verification. Baker et al. set out six layers of verification for rules on large-scale AI development and deployment 2. They describe an AI chip registry with sampled chain-of-custody checks (Chip registries and manufacturing records), and list satellite imagery among supplementary mechanisms that they call "less robust" than their main layers (Remote detection of data centres) 2.
- Hardware-enabled governance mechanisms. Kulp et al. define such mechanisms as controls built into AI hardware that enable "enforcement and compliance verification" 3. They analyse offline licensing, which lets a GPU run a set amount of work before it refuses or slows further work, and a "fixed set" that limits high-bandwidth links to a pod of pre-authorized chips 3. See Hardware performance throttling and licensing, Hardware-enabled guarantees (flexHEG) and guarantee processors and On-chip telemetry from timing, memory and performance counters.
- Secure inference data centres. A report by RAND's Center on AI, Security, and Technology designs a highly secure, vertically integrated inference data centre 4; see RAND secure inference data center (SIDC) design.
- Model-weight security. Nevo et al. identify 38 attack vectors against model weights and define five security levels, for defending against actors up to well-resourced nation-states 5; see Model weights have not left the facility.
- Field listing. The AI Futures Project's verification page lists RAND's Center on AI, Security, and Technology as doing "foundational technical and policy research on AI verification" 6.
On this page
Implementations
Implementations this organization develops.
- A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.
Related records
Mechanisms and implementations whose records cite or describe this organization's work.
- Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.
- On-chip mechanisms that cut an AI accelerator's performance when a license expires or a trusted trigger fires, bounding what the hardware can do.
- Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used.
Publications
Sources this organization authored or published.
- BAbout RAND. RAND. Source recordCited by RAND
- BS. F. Comer et al. (2026). Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering. RAND Corporation (Research Report RR-A4827-1). Source recordCited by RAND secure inference data center (SIDC) design; Model weights have not left the facility; Intelligence Security Laboratories; RAND
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordCited by Chip registries and manufacturing records; Remote detection of data centres; Communication between compute groups is bounded; Compute stock is at most a declared amount; Declared hardware is idle or shut down; The declared model is the one being served; This compute runs inference, not training; There is no undeclared relevant compute; Declared safeguards were applied during inference; A training run stayed within declared limits; Model weights have not left the facility; Compartmentalization; FLOP accounting; Inference and training workloads; Network tap; Positive and negative claims; Prover; Undeclared compute; Verifier; RAND
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordCited by Hardware-enabled guarantees (flexHEG) and guarantee processors; Hardware performance throttling and licensing; On-chip telemetry from timing, memory and performance counters; TEE remote attestation for AI workloads; Communication between compute groups is bounded; Compute stock is at most a declared amount; Declared hardware is idle or shut down; A training run stayed within declared limits; Compartmentalization; FLOP accounting; Hardware-enabled mechanism (HEM); RAND
- BS. Nevo et al. (2024). Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models. RAND Corporation. Source recordCited by Model weights have not left the facility; Weight exfiltration; RAND
Sources
- BAbout RAND. RAND. Source recordSupports: nonprofit nonpartisan research organization and evidence-based decisions
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: six layers of verification; AI chip registry; satellite imagery as a supplementary mechanism
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: hardware-enabled governance mechanisms: offline licensing and fixed set
- BS. F. Comer et al. (2026). Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering. RAND Corporation (Research Report RR-A4827-1). Source recordSupports: secure inference data center design by the Center on AI, Security, and Technology
- BS. Nevo et al. (2024). Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models. RAND Corporation. Source recordSupports: attack vectors and security levels for model weights
- CAI Futures Project (2026). Get Involved in Verification. AI 2040. Source recordSupports: RAND CAST listed as doing research on AI verification