Map
Map
Every mechanism and implementation, placed by the claim it addresses and its category. The code before each name is its readiness level. Entries in grey italics play a supporting role rather than a primary one. ⚠ marks an open critical flaw.
| Claim ↓ · Where the mechanism sits → | On-chip | Off-chip devices | Crypto / compute | Isolation & architecture | Accounting | Sensing |
|---|---|---|---|---|---|---|
| Compute stock is at most a declared amount A party holds no more AI-relevant compute, counted in chips or equivalent capacity, than the total it has declared. | — | — | — | |||
| Chips are where they are declared to be Specific AI chips are physically located at the sites a party has declared, throughout the declared period. | — | — | — | |||
| Declared hardware is idle or shut down Specified AI chips or facilities are not performing computation, or are powered off, throughout a declared period. | — | — | — | — | ||
| This compute runs inference, not training A declared cluster is used only to run existing models to produce outputs, and not to train new or more capable models. |
| — | ||||
| The declared model is the one being served Outputs delivered to users or auditors come from the specific model, weights and configuration the provider declared, not from a substitute. |
| — | — | |||
| Declared safeguards were applied during inference Specified safety measures, such as input filters, output checks or monitoring, actually ran on the requests a deployed model served. | — | — | — | |||
| A training run stayed within declared limits A declared training run used no more compute than permitted and had its declared properties, such as data, hyperparameters and resulting weights. | — | — | ||||
| Communication between compute groups is bounded Data flowing between specified groups of chips, or out of a facility, stays below a declared rate, so the groups cannot jointly run large workloads. | — | — | — | |||
| Model weights or data have not left the facility No copy of specified model weights or sensitive data has left a designated facility through networks, physical media or other channels. | — | — | — | |||
| There is no undeclared relevant compute A party controls no AI-relevant computing hardware or facilities, above an agreed threshold, beyond those it has declared. | — |