Organization · Research organization
RAND
A nonprofit, nonpartisan research organization; its reports cover verification of international AI agreements, hardware-enabled governance mechanisms and secure inference data centres.
RAND describes itself as a nonprofit, nonpartisan research organization that provides leaders with the information they need to make evidence-based decisions. Its reports on verification include:
- Six layers of verification. Baker et al. set out six layers of verification for rules on large-scale AI development 1. They describe an AI chip registry with sampled chain-of-custody checks (Chip registries and manufacturing records), and list satellite imagery among supplementary mechanisms that they call "less robust" than their main layers (Remote detection of data centres) 1.
- Hardware-enabled governance mechanisms. Kulp et al. define such mechanisms as controls built into AI hardware that enable "enforcement and compliance verification" 2. They analyse offline licensing, which lets a GPU run a set amount of work before it refuses or slows further work, and a "fixed set" that limits high-bandwidth links to a pod of pre-authorized chips 2. See Hardware performance throttling and licensing, Hardware-enabled guarantees (flexHEG) and guarantee processors and On-chip telemetry from timing, memory and performance counters.
- Secure inference data centres. A report by RAND's Center on AI, Security, and Technology designs a highly secure, vertically integrated inference data centre 3; see RAND secure inference data center (SIDC) design.
- Model-weight security. Nevo et al. identify 38 attack vectors against model weights and define five security levels, for defending against actors up to well-resourced nation-states 4; see Model weights or data have not left the facility.
- Field listing. The AI Futures Project's verification page lists RAND's Center on AI, Security, and Technology as doing "foundational technical and policy research on AI verification" 5.
Implementations
- A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.
Mechanisms
Mechanisms this organization has designed, built, evaluated or supplied.
- Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.
- On-chip mechanisms that cut an AI accelerator's performance when a license expires or a trusted trigger fires, bounding what the hardware can do.
- Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used.
Publications
Sources this organization authored or published.
- BS. F. Comer et al. (2026). Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering. RAND Corporation (Research Report RR-A4827-1). RecordCited by RAND secure inference data center (SIDC) design; Model weights or data have not left the facility; Intelligence Security Laboratories; RAND
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. RecordCited by Chip registries and manufacturing records; Remote detection of data centres; Communication between compute groups is bounded; Compute stock is at most a declared amount; Declared hardware is idle or shut down; The declared model is the one being served; This compute runs inference, not training; There is no undeclared relevant compute; Declared safeguards were applied during inference; A training run stayed within declared limits; Model weights or data have not left the facility; Compartmentalization; FLOP accounting; Inference and training workloads; Network tap; Positive and negative claims; Prover; Undeclared compute; Verifier; RAND
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. RecordCited by Hardware-enabled guarantees (flexHEG) and guarantee processors; Hardware performance throttling and licensing; On-chip telemetry from timing, memory and performance counters; TEE remote attestation for AI workloads; Communication between compute groups is bounded; Compute stock is at most a declared amount; Declared hardware is idle or shut down; A training run stayed within declared limits; Compartmentalization; FLOP accounting; Hardware-enabled mechanism (HEM); RAND
- BS. Nevo et al. (2024). Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models. RAND Corporation. RecordCited by Model weights or data have not left the facility; Weight exfiltration; RAND
Sources
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source recordSupports: six layers of verification; AI chip registry; satellite imagery as a supplementary mechanism
- BG. Kulp et al. (2024). Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090. RAND Corporation. Source recordSupports: hardware-enabled governance mechanisms: offline licensing and fixed set
- BS. F. Comer et al. (2026). Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering. RAND Corporation (Research Report RR-A4827-1). Source recordSupports: secure inference data center design by the Center on AI, Security, and Technology
- BS. Nevo et al. (2024). Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models. RAND Corporation. Source recordSupports: attack vectors and security levels for model weights
- CAI Futures Project (2026). Get Involved in Verification. AI 2040. Source recordSupports: RAND CAST listed as doing research on AI verification