This compute runs inference, not training
On this page
Sources
- BA. Scher et al. (2025). An International Agreement to Prevent the Premature Creation of Artificial Superintelligence. Machine Intelligence Research Institute. Source recordSupports: restricting the scale of training; chip use verification distinguishing inference on existing systems from training · abstract; Article VII (as summarised)
- CR. Dean (2026). Verification Plan. AI 2040. Source recordSupports: data centres converted to inference-only operation; network taps, recomputation and reproducible packets · phases; verification mechanisms
- BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source recordSupports: majority of AI compute used for inference; decentralised training could undermine detectability · training vs inference; limitations
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: declared inference (1.A.2) as a distinct subgoal; deterministic replication of inference as an R&D problem · §3.2; Appendix A.9
- BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: distinguishing inference from training; token-level front-end evidence; back-end harder to tap; egress explainable by ingress as open question; memory wiping; side channels · verification goals; inference vs training; open problems
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source recordSupports: inference-specialised chips repurposable for training; pods with limited external bandwidth · Verifying that known compute is not being used for a large training run
- BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: no straightforward way to tell whether a chip is running training or another job · open problems
- BR. Rahman & S. Tajdari (2026). Detecting Hidden ML Training With Zero-Overhead Telemetry. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: telemetry classifier accuracy overall and on adversarially disguised workloads; required telemetry protections · abstract; §5.2; deployment requirements
- AA. Reuel et al. (2025). Open Problems in Technical AI Governance. Transactions on Machine Learning Research. Source recordSupports: workload classification; adversarial customers may obfuscate by adding noise · §3.2.2 / §5.2.2 open problems
- CN. Cankaya (2026). The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use. The Datacenter Lie Detector. Source recordSupports: front-end tapping most viable; back-end requires sampling · frontend vs backend
- BA. Karvonen et al. (2025). DiFR: Inference Verification Despite Nondeterminism. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: recomputation despite benign numerical noise on 8–30B open-weight models · abstract; §5
- BN. Cankaya (2026). Bit-Exact AI Inference Verification Without Performance Tradeoffs. ICML 2026 Workshop on Technical AI Governance Research. Source recordSupports: bit-exact inference verification across GPU variants · abstract
- CT. Milton et al. (2026). Verifying international AI deals: Plan A, the state-of-play, and what you can do to help. Amodo (Substack). Source recordSupports: no verification component past a proof-of-principle prototype · introduction
- BS. K. Monfared et al. (2026). Timing and Memory Telemetry on GPUs for AI Governance. arXiv. Source recordSupports: current GPUs expose limited trusted telemetry · abstract
- CAttestable (2026). Pacing AI Requires Proof. Attestable blog. Source recordSupports: spare capacity could run an unauthorised training job; approved inference plus protocol-defined work fills a required work budget (provider proposal) · blog post
- Cjoshc (2026). Can governments quickly and cheaply slow AI training?. AI Alignment Forum. Source recordSupports: public analysis of covert reinforcement-learning rollouts on declared inference servers and updates on hidden compute; share of computation that must be accounted for (scenario estimate) · §2.5; §3.4; §4
- BSingapore AI Safety Hub (SASH) (2026). inference-verification: Inference Verification Prototype. GitHub. Source recordSupports: SASH prototype re-runs every request through a logger on a separate cluster, with Gemma 3 270M and a demo switch as the only adversary · README.md; implementation
- BN. Cankaya et al. (2026). Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors. arXiv. Source recordSupports: a tap on external links does not prevent covert workloads, only the exfiltration of their results