Implementation · AI 2040 inference-only verification stack

Evidence & limits

On this page

R1Proposed for showing that retrofitted data centres run only inference

The six-layer design, its claim and its assumptions are published, but the integrated stack has not been built.

Assessed use: showing that retrofitted data centres run only inference

Rubric assessment

  • R1 met: the plan publishes the design of the stack, the claim it would verify (only inference runs on retrofitted compute) and its key assumptions, including a trusted recomputation server and strong physical security 1.
  • R2 not met: there is no public implementation or end-to-end result for the integrated stack. The plan's companion page lists a reproducible inference stack as not started and gives no plan yet for scaling side-channel defences 2. A team working on the components says that nothing is past a proof-of-principle prototype 3. Some components are further along: passive optical taps work at 400G, and recomputation schemes such as TOPLOC and DiFR are being tested on relevant hardware 2; see Sampled inference recomputation. Amodo reports a lab prototype that feeds a passive tap on a 1 Gbps link into DiFR recomputation, which covers two of the six layers 5.

Confidence is medium: the design is clearly published, but component status comes from pages that are updated over time 2 4.

Gaps to the next level
  • A public working implementation or reproducible end-to-end results for the integrated stack (isolated inference unit, taps, packetization and recomputation) at realistic scale or against a stated adversary.
  • A hardened recomputation server and a method for checking that taps are correctly installed and remain in place.
  • Red-teaming of recomputation and of the completeness measures (side channels, memory wiping).

Assessed 2026-09-25 against rubric v1.1.

Evidence

The plan's companion page, updated in July 2026, and a practitioner status page report the state of each component 2 4:

  • Taps. The companion page says passive optical taps work at 400G, while 800G and 1600G remain undemonstrated 2. This is component readiness; the published tapped inference-verification prototype used a 1 Gbps lab link 5. Capturing all front-end traffic still needs infrastructure and work on network topologies and sampling 2.
  • Recomputation. TOPLOC and DiFR are well described and are being tested on relevant hardware and models 2. Both status pages list recomputation red-teaming as not started 2 4.
  • Tapped prototype. In September 2026 Amodo reported fitting a passive fibre tap to a 1 Gbps lab link of its DiFR-based recomputation prototype 5. All 800 test inferences were tapped and verified while the link was flooded with non-whitelisted traffic 5. Amodo concludes that the passive tap must become active to close the side channels that remain 5. See Network taps and certifiers.
  • Reproducibility. Demonstrations work around non-determinism, but work on a fully reproducible inference stack has not started 2.
  • Completeness. Early hardware testing of memory wiping is under way 2. For side-channel mitigation, only early theoretical pieces exist 2.
  • Overall. The Amodo team reports that the core components are being de-risked, but that nothing is past a proof-of-principle prototype 3.

Limitations

  • Trusted recomputation server. The assurance argument assumes that the server's computations and outputs can be trusted 1. Amodo rates recomputation-server security as not on track 4.
  • Spare compute. Idle or spare compute is not directly verified 1.
  • Tap installation. Checking that taps are correctly installed and stay in place is not yet solved 2.
  • Network reproducibility. Making individual packets reproducible across the network may need considerable software, firmware and possibly hardware work 2.
  • Recomputation attacks. When the adversary controls the prompts, Gumbel-based inference verification, the family that includes Token-DiFR 6, leaks roughly twice as many bits per token as under benign prompts 7. See Bounding unexplained information in outputs.
  • Side-channel defence. There is no plan yet for scaling side-channel defences quickly on a frontier cluster 2.

Known flaws

Blockers

Search

Full search page