{
  "schema_version": "1.0.0",
  "rubric_version": "1.0",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "O-0200",
    "slug": "rand",
    "title": "RAND",
    "aliases": [],
    "status": "draft",
    "last_reviewed": "2026-09-23",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "kind": "research-org",
    "homepage": "https://www.rand.org/",
    "one_liner": "A nonprofit, nonpartisan research organization; its reports cover verification of international AI agreements, hardware-enabled governance mechanisms and secure inference data centres.",
    "sources": [
      {
        "source": "S-0002",
        "supports": "six layers of verification; AI chip registry; satellite imagery as a supplementary mechanism"
      },
      {
        "source": "S-0057",
        "supports": "hardware-enabled governance mechanisms: offline licensing and fixed set"
      },
      {
        "source": "S-1510",
        "supports": "secure inference data center design by the Center on AI, Security, and Technology"
      },
      {
        "source": "S-1610",
        "supports": "attack vectors and security levels for model weights"
      },
      {
        "source": "S-1511",
        "supports": "RAND CAST listed as doing research on AI verification"
      }
    ],
    "type": "organization",
    "url": "https://trustbutveri.fyi/organizations/rand/",
    "source_file": "content/organizations/rand.md",
    "flags_all": [
      "ai-drafted"
    ],
    "body_markdown": "RAND describes itself as a nonprofit, nonpartisan research organization that provides leaders with the information they need to make evidence-based decisions. Its reports on verification include:\n\n- **Six layers of verification.** Baker et al. set out six layers of verification for rules on large-scale AI development [[S-0002]]. They describe an AI chip registry with sampled chain-of-custody checks ([[M-0019]]), and list satellite imagery among supplementary mechanisms that they call \"less robust\" than their main layers ([[M-0020]]) [[S-0002]].\n- **Hardware-enabled governance mechanisms.** Kulp et al. define such mechanisms as controls built into AI hardware that enable \"enforcement and compliance verification\" [[S-0057]]. They analyse offline licensing, which lets a GPU run a set amount of work before it refuses or slows further work, and a \"fixed set\" that limits high-bandwidth links to a pod of pre-authorized chips [[S-0057]]. See [[M-0011]], [[M-0009]] and [[M-0010]].\n- **Secure inference data centres.** A report by RAND's Center on AI, Security, and Technology designs a highly secure, vertically integrated inference data centre [[S-1510]]; see [[I-0010]].\n- **Model-weight security.** Nevo et al. identify 38 attack vectors against model weights and define five security levels, for defending against actors up to well-resourced nation-states [[S-1610]]; see [[C-0009]].\n- **Field listing.** The AI Futures Project's verification page lists RAND's Center on AI, Security, and Technology as doing \"foundational technical and policy research on AI verification\" [[S-1511]].",
    "body_text": "RAND describes itself as a nonprofit, nonpartisan research organization that provides leaders with the information they need to make evidence-based decisions. Its reports on verification include: - Six layers of verification. Baker et al. set out six layers of verification for rules on large-scale AI development [S-0002]. They describe an AI chip registry with sampled chain-of-custody checks (Chip registries and manufacturing records), and list satellite imagery among supplementary mechanisms that they call \"less robust\" than their main layers (Remote detection of data centres) [S-0002]. - Hardware-enabled governance mechanisms. Kulp et al. define such mechanisms as controls built into AI hardware that enable \"enforcement and compliance verification\" [S-0057]. They analyse offline licensing, which lets a GPU run a set amount of work before it refuses or slows further work, and a \"fixed set\" that limits high-bandwidth links to a pod of pre-authorized chips [S-0057]. See Hardware performance throttling and licensing, Hardware-enabled guarantees (flexHEG) and guarantee processors and On-chip telemetry from timing, memory and performance counters. - Secure inference data centres. A report by RAND's Center on AI, Security, and Technology designs a highly secure, vertically integrated inference data centre [S-1510]; see RAND secure inference data center (SIDC) design. - Model-weight security. Nevo et al. identify 38 attack vectors against model weights and define five security levels, for defending against actors up to well-resourced nation-states [S-1610]; see Model weights or data have not left the facility. - Field listing. The AI Futures Project's verification page lists RAND's Center on AI, Security, and Technology as doing \"foundational technical and policy research on AI verification\" [S-1511].",
    "referenced_by": [
      {
        "id": "M-0019",
        "title": "Chip registries and manufacturing records",
        "url": "https://trustbutveri.fyi/mechanisms/chip-registries-and-manufacturing-records/"
      },
      {
        "id": "M-0009",
        "title": "Hardware-enabled guarantees (flexHEG) and guarantee processors",
        "url": "https://trustbutveri.fyi/mechanisms/flexheg-guarantee-processors/"
      },
      {
        "id": "M-0011",
        "title": "Hardware performance throttling and licensing",
        "url": "https://trustbutveri.fyi/mechanisms/hardware-performance-throttling/"
      },
      {
        "id": "I-0010",
        "title": "RAND secure inference data center (SIDC) design",
        "url": "https://trustbutveri.fyi/implementations/rand-secure-inference-data-centers/"
      },
      {
        "id": "S-0002",
        "title": "Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment",
        "url": "https://trustbutveri.fyi/sources/baker-verifying-international-agreements-ai/"
      },
      {
        "id": "S-1510",
        "title": "Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering",
        "url": "https://trustbutveri.fyi/sources/comer-highly-secure-inference-data-centers/"
      },
      {
        "id": "S-0057",
        "title": "Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090",
        "url": "https://trustbutveri.fyi/sources/kulp-hardware-enabled-governance-mechanisms/"
      },
      {
        "id": "S-1610",
        "title": "Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models",
        "url": "https://trustbutveri.fyi/sources/nevo-securing-ai-model-weights/"
      }
    ]
  }
}