# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-09. Interactive version: https://trustbutveri.fyi/explorer/?claims=C-0008&goal=G-0005

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's development status, security evidence and findings. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and findings) and https://trustbutveri.fyi/about/readiness/ (development status).

## Goal

The proposal is for the goal "Prevent weight theft" (https://trustbutveri.fyi/goals/prevent-weight-theft/): Keep the weights of capable AI models from being copied out of the facilities that hold them. The links from the goal to claims are the editors' judgment. Direct: The claim states part of what the goal requires. The goal cannot be verified without it. Supporting: Verifying the claim makes a direct claim easier to check or a violation less useful. The goal could be verified without it.

- Direct: Model weights have not left the facility (not in this proposal). This claim is the goal in a form a verifier can check: no copy of the specified weights has left the facility. (Sources: S. Nevo et al. 2024; A. Scher & L. Thiergart 2025.)
- Supporting: Communication between compute groups is bounded. If only a set amount of data can leave a data centre, an adversary cannot steal more than that amount. (Sources: R. Rinberg et al. 2026.)

Outside this map, the goal also needs:

- Insider and physical security. Nevo and colleagues group their 38 attack vectors into nine categories, which include unauthorised physical access, supply chain attacks and human intelligence. Access controls, insider threat programmes and physical security are outside this map's records. (Sources: S. Nevo et al. 2024.)

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Claims

### 1. Communication between compute groups is bounded

Data flowing between specified groups of chips, or out of a facility, stays below a declared rate. ([Communication between compute groups is bounded](https://trustbutveri.fyi/claims/bandwidth-is-bounded/))

Status: unaddressed. No mechanism in the proposal addresses it.


## Mechanisms

No mechanisms chosen.

## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open failure or a dependency. Pointers, not recommendations: each brings its own readiness level and findings, and none is claimed to close a failure.

- **Bandwidth limits and compartmentalization** (Research demonstration (legacy code R2), assessed for monitoring inter-node traffic with operator-run software on four GPUs)
  - Aimed at the claim "Communication between compute groups is bounded", which is unaddressed.
- **Side-channel suppression for isolated facilities** (Proposed (legacy code R1), assessed for bounding physical covert channels out of a verified enclosure)
  - Aimed at the claim "Communication between compute groups is bounded", which is unaddressed.

