A map of AI verification technologies
This site maps the technical side of AI verification: the claims one party might want to check about another party's AI hardware or software, the mechanisms that could check them, the implementations that exist, and the organizations doing the work. Every fact cites a public source. Each mechanism has a readiness rating and a list of what blocks it.
10 claims · 25 mechanisms · 12 implementations · 20 organizations · 171 sources
Claims and mechanisms
Each number counts the mechanisms and implementations in a category that address a claim. Hover over a number to see them and their readiness; click it to open them in Browse.
- Compute stock is at most a declared amount
- Chips are where they are declared to be
- Declared hardware is idle or shut down
- This compute runs inference, not training
- The declared model is the one being served
- Declared safeguards were applied during inference
- A training run stayed within declared limits
- Communication between compute groups is bounded
- Model weights or data have not left the facility
- There is no undeclared relevant compute
Categories
Mechanisms are grouped by where they act: on the chip, next to it, in cryptography, in the system architecture, in accounting, or from a distance.
- On-chip & hardware-enabled
- Mechanisms built into accelerators or their firmware: trusted execution, attestation, hardware-enabled governance, on-chip telemetry and limits.4 mechanisms · 1 implementation
- Off-chip devices & sensors
- Retrofittable devices outside the accelerator: network taps and certifiers, power and analog sensors, tamper-evident enclosures.3 mechanisms · 1 implementation
- Cryptographic & computational
- Protocols that check computation itself: recomputation, zero-knowledge proofs, proofs of learning, proofs of work, challenge-response.10 mechanisms · 6 implementations
- Isolation & system architectures
- Ways of arranging or constraining a facility so that other checks become possible: bandwidth limits, compartmentalization, memory wiping, secure facilities, whole verification stacks.4 mechanisms · 3 implementations
- Compute accounting & provenance
- Establishing what compute exists, where it is and what it can do: chip registries, manufacturing records, location verification, capacity bounds.2 mechanisms · 1 implementation
- Remote & side-channel sensing
- Inferring activity from outside or from physical signals: detecting data centres, classifying workloads from power or other emissions.2 mechanisms
Readiness runs from R0 (idea) to R3 (deployment-ready). It is an editorial judgment under a published rubric, shown apart from the facts. About this site.