Implementation · AI 2040 inference-only verification stack
Evidence & limits
On this page
R1Proposed for showing that retrofitted data centres run only inference
The six-layer design, its claim and its assumptions are published, but the integrated stack has not been built.
Assessed use: showing that retrofitted data centres run only inference
Rubric assessment
- R1 met: the plan publishes the design of the stack, the claim it would verify (only inference runs on retrofitted compute) and its key assumptions, including a trusted recomputation server and strong physical security 1.
- R2 not met: there is no public implementation or end-to-end result for the integrated stack. The plan's companion page lists a reproducible inference stack as not started and gives no plan yet for scaling side-channel defences 2. A team working on the components says that nothing is past a proof-of-principle prototype 3. Some components are further along: passive optical taps work at 400G, and recomputation schemes such as TOPLOC and DiFR are being tested on relevant hardware 2; see Sampled inference recomputation. Amodo reports a lab prototype that feeds a passive tap on a 1 Gbps link into DiFR recomputation, which covers two of the six layers 5.
Confidence is medium: the design is clearly published, but component status comes from pages that are updated over time 2 4.
- A public working implementation or reproducible end-to-end results for the integrated stack (isolated inference unit, taps, packetization and recomputation) at realistic scale or against a stated adversary.
- A hardened recomputation server and a method for checking that taps are correctly installed and remain in place.
- Red-teaming of recomputation and of the completeness measures (side channels, memory wiping).
Assessed 2026-09-25 against rubric v1.1.
Evidence
The plan's companion page, updated in July 2026, and a practitioner status page report the state of each component 2 4:
- Taps. The companion page says passive optical taps work at 400G, while 800G and 1600G remain undemonstrated 2. This is component readiness; the published tapped inference-verification prototype used a 1 Gbps lab link 5. Capturing all front-end traffic still needs infrastructure and work on network topologies and sampling 2.
- Recomputation. TOPLOC and DiFR are well described and are being tested on relevant hardware and models 2. Both status pages list recomputation red-teaming as not started 2 4.
- Tapped prototype. In September 2026 Amodo reported fitting a passive fibre tap to a 1 Gbps lab link of its DiFR-based recomputation prototype 5. All 800 test inferences were tapped and verified while the link was flooded with non-whitelisted traffic 5. Amodo concludes that the passive tap must become active to close the side channels that remain 5. See Network taps and certifiers.
- Reproducibility. Demonstrations work around non-determinism, but work on a fully reproducible inference stack has not started 2.
- Completeness. Early hardware testing of memory wiping is under way 2. For side-channel mitigation, only early theoretical pieces exist 2.
- Overall. The Amodo team reports that the core components are being de-risked, but that nothing is past a proof-of-principle prototype 3.
Limitations
- Trusted recomputation server. The assurance argument assumes that the server's computations and outputs can be trusted 1. Amodo rates recomputation-server security as not on track 4.
- Spare compute. Idle or spare compute is not directly verified 1.
- Tap installation. Checking that taps are correctly installed and stay in place is not yet solved 2.
- Network reproducibility. Making individual packets reproducible across the network may need considerable software, firmware and possibly hardware work 2.
- Recomputation attacks. When the adversary controls the prompts, Gumbel-based inference verification, the family that includes Token-DiFR 6, leaks roughly twice as many bits per token as under benign prompts 7. See Bounding unexplained information in outputs.
- Side-channel defence. There is no plan yet for scaling side-channel defences quickly on a frontier cluster 2.
Known flaws
Blockers
A fully reproducible inference stack needs substantial software and tooling, and per-packet network reproducibility may need considerable software, firmware and possibly hardware work.
Passive optical taps work at 400G, but the 800G and 1600G line rates now arriving in data centres are undemonstrated.
Checking that taps are correctly installed and stay in place at scale is not a solved problem, and hardening the recomputation server inside the prover's facility needs significant research.
There is no plan yet for quickly scaling side-channel defences on a frontier cluster; only early theoretical pieces exist.
Memory wiping may use existing algorithms, but hardware testing is at an early stage.
Robust red-teaming of recomputation schemes has not started, and most algorithm development remains academic.