Implementation · RAND secure inference data center (SIDC) design

Evidence & limits

On this page

R1Proposed for the operator's own weight security, with no outside verification described

The design is detailed and costed but has no prototype. Its stated objectives are security properties for the operator, not claims an outside party could check.

Assessed use: the operator's own weight security, with no outside verification described

Rubric assessment

  • R1 met for the security design: the report states its protection objectives and the further claim that each inference response is verifiable given valid weights, architecture and retrieved context. It also states its threat model and assumptions, such as a trusted setup and likely supply-chain compromise of commodity hardware 1.
  • R2 not met: no facility or prototype has been published, and RAND recommends prototyping key security features now 1.

Confidence is low because the stated verification use is only partly addressed. The report describes internal integrity checks and audit logging, but no way for a party outside the operator to verify the facility's properties, and it omits architectural blueprints and detailed implementations from the public version 1.

Gaps to the next level
  • A public working prototype, or reproducible published results, for key features such as the diode-gated realm topology and cross-realm protocols.
  • A published way for a party other than the operator to verify the facility's claims, for example weight confidentiality or which model is served.

Assessed 2026-09-25 against rubric v1.1.

Evidence

  • Design and cost study. RAND estimates $37–50 million for a proof-of-concept facility and $277–345 million for an enterprise-scale version 1. It reports that an SIDC can be built today with proven, off-the-shelf compute hardware, and that no fundamental research breakthroughs are required 1.
  • Schedule. Construction and deployment could take as few as 14 months under emergency or national-priority conditions, and two to two and a half years otherwise, plus time for accreditation 1.
  • No prototype yet. RAND recommends prototyping key security features and integration now, and notes that FPGA-based channel control with formally verified protocols and optical diodes can be tested immediately 1. Its other recommendations are to begin procurement, engage a system integrator and select a site early 1. Intelligence Security Laboratories, a nonprofit led by one of the report's co-authors, states that it aims to develop and demonstrate the security that critical AI deployments need, applies the same STPA-Sec method, and points to the report for details 2 3.

Limitations

  • Trusted setup. The facility cannot detect compromise that happened before ingestion if the trusted setup itself was compromised 1.
  • No external check. The public report omits architectural blueprints, detailed technical implementations and deployment procedures, and says these must be evaluated privately with stakeholders 1. It describes internal checks, audit logging and accreditation, but no verification path for outside parties 1.
  • Scope. The facility does not defend against undetected biases or latent model behaviours 1.
  • Latency. Human review makes a full request–response cycle take three to five minutes; automating some human-mediated steps could bring the overhead under a minute 1.
  • Time horizon. The security claims are framed over a five-year operational period, and the authors expect resistance to long OC5 campaigns to weaken the longer the facility operates 1.

Known flaws

Blockers

  • No prototype exists; RAND recommends prototyping key security features and integration now.

  • The report describes internal integrity checks, audit logging and accreditation, but no way for a party outside the operator to verify the facility's properties.

  • Human review of every prompt and response makes each request take three to five minutes, with the review steps as the rate-limiting factor.

  • Detailed design information is withheld from the public report and is to be evaluated privately with stakeholders, which limits independent public scrutiny.

Search

Full search page