Research gaps

Recorded blockers and gaps to the next readiness level, for each mechanism and implementation’s assessed verification use.

50 of 50 records with gaps shown

ImplementationR1Proposedfor showing that retrofitted data centres run only inference

Assessment and limits · Assessment sources

Related organizations: Amodo Design, AI Futures Project

ImplementationR3In productionfor showing users which software serves their AI requests, not which model

  • Published binaries cannot be rebuilt from source and carry no symbols, so checking what the attested software does needs reverse engineering.

  • Outside developers can use PCC only with an entitlement from Apple, which is limited to small developers.

  • An independent public evaluation of the attestation and transparency-log chain, including what attestation covers at runtime, that leaves no critical flaw open.

    Next readiness level
  • Evidence that the Google Cloud deployment's attestation resists attackers with physical access to TDX and NVIDIA hardware.

    Next readiness level
  • Reproducible builds, so that published binaries can be checked against published source.

    Next readiness level

Assessment and limits · Assessment sources

ImplementationR2Demonstratedfor showing users that the model answering them is the audited one

Assessment and limits · Assessment sources

Related organizations: University of Cambridge

ImplementationR1Proposedfor proving an output came from committed weights

Assessment and limits · Assessment sources

Related organizations: Attestable

MechanismR2Demonstratedfor monitoring inter-node traffic with operator-run software on four GPUs

Assessment and limits · Assessment sources

Related organizations: Amodo Design, Lucid Computing, AI Futures Project, Machine Intelligence Research Institute

ImplementationR2Demonstratedfor exact recomputation of served outputs by a verifier, with a cooperating provider

  • Batch invariance costs throughput: on Qwen3-8B the improved deterministic build took 42 s against 26 s for vLLM's default, and SGLang reports an average slowdown of 34.35% on its FlashInfer and FlashAttention 3 backends.

  • Outputs are identical only while the model, inference implementation and device stay fixed, so provider and verifier must run the same stack.

  • A production-grade verification stack that uses these kernels for exact-match checks, or a party other than the developers relying on such checks for a verification decision.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Thinking Machines Lab

MechanismR2Demonstratedfor bounding how much hidden information can leave in checked inference outputs

Assessment and limits · Assessment sources

MechanismR1Proposedfor bounding how far a chip is from trusted landmark servers when checked

  • No public code or reproducible end-to-end location results are available for the reported H100 prototype.

  • Per-chip keys must be provisioned and protected against extraction; hardware-integrated, tamper-resistant versions still need R&D.

  • The time limit forces a trade-off: a limit at the speed of light in fibre can be beaten by faster links, while one at the vacuum speed of light makes honest chips fail often.

  • A trusted landmark network must be built and secured, and who should operate it, under what oversight, is unsettled.

  • A public implementation, or reproducible end-to-end results, on data-centre accelerators with a real landmark network.

    Next readiness level
  • Published measurements of false-positive and false-negative rates under realistic internet routing.

    Next readiness level
  • An evaluation against a stated adversary covering delay manipulation, faster network paths, landmark compromise and key extraction.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Lucid Computing, Institute for AI Policy and Strategy, Center for a New American Security, NVIDIA

MechanismR1Proposedfor a checkable record of which chips were made and who declared owning them

Assessment and limits · Assessment sources

Related organizations: RAND, AI Futures Project, Institute for AI Policy and Strategy

MechanismR2Demonstratedfor audits or evaluations of a private model that reveal neither party's inputs

Assessment and limits · Assessment sources

Related organizations: University of Cambridge, Machine Intelligence Research Institute, Tinfoil, OpenMined

Cove

Draft

ImplementationR2Demonstratedfor composing owner-approved confidential workflow stages on Intel TDX

  • Docker policy cannot prove that arbitrary guest workloads cannot generate quotes when quote channels are globally exposed.

  • The production workflow depends on owners reviewing manifests, allow rules and provisioning code.

  • A production-grade, available confidential evaluation workflow, or another party's documented reliance on its results.

    Next readiness level

Assessment and limits · Assessment sources

ImplementationR1Proposedfor confirming data presence and bounding free memory across data-centre servers

Assessment and limits · Assessment sources

Related organizations: Machine Intelligence Research Institute

MechanismR3In productionfor reproducing open-model inference from receipts in Gensyn's information-market service

Assessment and limits · Assessment sources

ImplementationR2Demonstratedfor checking that outputs match the declared model, precision and sampling settings

  • The verifier needs the model weights, so outsiders cannot use the method to verify providers of closed-weights models.

  • The verifier must know and match the provider's sampling procedure, and in one prototype a sampling mismatch in a newer vLLM version produced large spurious logit differences.

  • No independent red-team of DiFR's consistency check has been published, Amodo rates recomputation red-teaming 'not started', and the one independent attack study targets an exfiltration detector built on the same statistic.

  • Reliance by a party other than the developers on DiFR for a verification decision, or a production-grade release.

    Next readiness level
  • An independent public security evaluation (audit, red-team or peer-reviewed analysis) against adaptive adversaries.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Amodo Design

ImplementationR2Demonstratedfor proving a language model's output follows from committed weights, against a cheating prover

  • Proving cost grows steeply with model size: a 250,000-parameter nanoGPT took 2,781 s to prove and needed a 219 GB proving key, which South et al. name as the main limit on model size.

  • A production-grade release that proves language models at the scale verification claims concern, or reliance by another party on such proofs for a verification decision.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Zkonduit

ImplementationR2Demonstratedfor detecting another workload running on the same GPU

  • Continuous probes add power draw, occupy GPU memory and reduce inference throughput.

  • No thresholds or statistical tests define when a timing shift counts as a detection.

  • Production-grade probe tooling, or use by a party other than the authors for a verification decision.

    Next readiness level
  • Detection thresholds with measured false-positive and false-negative rates.

    Next readiness level
  • Results on multi-GPU servers and against an operator who tries to hide a workload.

    Next readiness level

Assessment and limits · Assessment sources

MechanismR1Proposedfor performance limits a verifier can rely on, against an operator trying to bypass them

Assessment and limits · Assessment sources

Related organizations: RAND, Center for a New American Security

MechanismR1Proposedfor checking and enforcing training-compute limits on chips, against adversaries up to states

  • Integrated flexHEG needs substantial help from the accelerator manufacturer, and the authors estimate 3.7–7.9 years, from when the manufacturer starts work, for such hardware to displace other accelerators in frontier development.

  • State-level attackers who hold the hardware can likely compromise the best current secure enclosures.

  • Rival states would need to trust the design and manufacture of guarantee processors and enclosures, for example through open design, redundant processors from each side or oversight of production.

  • Restricting future rule updates would need a formal language for rules, which the authors judge most likely infeasible for early flexHEG versions.

  • Governing all relevant chips depends on knowing where they are, through chip registries and detection of undeclared facilities.

  • A public prototype of a guarantee processor or Interlock on a real accelerator data path, with published end-to-end results.

    Next readiness level
  • A secure enclosure evaluated against invasive physical attacks, with published cost-to-circumvent estimates.

    Next readiness level
  • A specified ruleset language and a multi-party update protocol implemented and analysed.

    Next readiness level
  • Chipmaker engagement, needed for integrated designs.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: RAND, Center for a New American Security

ImplementationR1Proposedfor screening challenged records to show declared inference compute is not training

Assessment and limits · Assessment sources

Related organizations: Machine Intelligence Research Institute

ImplementationR1Proposedfor certifying the region where an attested workload ran at a given time

Assessment and limits · Assessment sources

Related organizations: Lucid Computing

MechanismR1Proposedfor showing that no data from earlier work persists in memory the wipe reaches

Assessment and limits · Assessment sources

Related organizations: Amodo Design, AI Futures Project, Machine Intelligence Research Institute

MechanismR3In productionfor showing users that a service runs the declared model weights

Assessment and limits · Assessment sources

Related organizations: Tinfoil, University of Cambridge, Machine Intelligence Research Institute

MechanismR1Proposedfor committing a complete record of cluster traffic, so declared inference can be checked

Assessment and limits · Assessment sources

Related organizations: Amodo Design, Singapore AI Safety Hub (SASH), AI Futures Project, Machine Intelligence Research Institute, Hardware AI Governance Lab

MechanismR2Demonstratedfor workload evidence from GPU counters and timing, assuming authentic measurements

Assessment and limits · Assessment sources

Related organizations: Machine Intelligence Research Institute

PAL*M

Draft

ImplementationR2Demonstratedfor attesting declared model operations on a confidential CPU–GPU prototype

Assessment and limits · Assessment sources

Related organizations: University of Waterloo

ImplementationR3In productionfor checking matrix-multiplication work proofs for blockchain consensus

Assessment and limits · Assessment sources

Related organizations: Pearl Research Labs

MechanismR1Proposedfor bounding the spare capacity of declared hardware that could run training

  • Bounding spare capacity needs a credible estimate of the compute available to the actor, including third-party access 6.

  • Proofs of work cannot find facilities that were never declared 6.

  • As of September 2026 no implementation, demonstration or independent evaluation of proofs of work for capacity bounding has been published.

  • A public implementation or reproducible end-to-end result that uses proofs of work to bound the spare capacity of declared hardware against a stated adversary.

    Next readiness level
  • A method for the verifier to obtain a credible estimate of the prover's available compute.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Attestable, Pearl Research Labs, Machine Intelligence Research Institute

ImplementationR2Demonstratedfor evaluating a private model on private prompts, neither party seeing the other's inputs

  • The pilot could not inspect or allowlist all model code, and the guest operating system builds were not independently reproducible.

  • The pilot ran on one H100; the authors name many-node confidential GPU clusters as the next scale target.

  • A generally available production workflow, or documented reliance by another party on its result for a verification decision.

    Next readiness level
  • An independent public security evaluation that leaves no critical flaw open.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: OpenMined

ImplementationR1Proposedfor the operator's own weight security, with no outside verification described

  • No prototype exists; RAND recommends prototyping key security features and integration now.

  • The report describes internal integrity checks, audit logging and accreditation, but no way for a party outside the operator to verify the facility's properties.

  • Human review of every prompt and response makes each request take three to five minutes, with the review steps as the rate-limiting factor.

  • Detailed design information is withheld from the public report and is to be evaluated privately with stakeholders, which limits independent public scrutiny.

  • A public working prototype, or reproducible published results, for key features such as the diode-gated realm topology and cross-realm protocols.

    Next readiness level
  • A published way for a party other than the operator to verify the facility's claims, for example weight confidentiality or which model is served.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: RAND

MechanismR1Proposedfor finding undeclared data centres above an agreed compute threshold

Assessment and limits · Assessment sources

Related organizations: Planet Labs, AI Futures Project, Epoch AI

MechanismR2Demonstratedfor attesting that a declared safeguard mediated a service's responses

Assessment and limits · Assessment sources

Related organizations: University of Cambridge, Machine Intelligence Research Institute, Tinfoil

SAGE

Draft

ImplementationR2Demonstratedfor attesting code execution on a GPU that lacks hardware trusted-execution support

  • The verifier must know the exact hardware configuration of the GPU.

  • The verifier runs in an SGX enclave on the same host as the GPU, so the scheme inherits trust in that enclave.

  • A production-grade release, or use by a party other than the authors for a verification decision.

    Next readiness level
  • Evaluation on current AI accelerators and with AI inference or training workloads.

    Next readiness level
  • An independent security evaluation of the timing margin against proxy and optimisation attacks.

    Next readiness level

Assessment and limits · Assessment sources

MechanismR3In productionfor checking untrusted workers' activations against the declared model, prompt and precision

Assessment and limits · Assessment sources

Related organizations: Prime Intellect, Amodo Design, AI Futures Project, Machine Intelligence Research Institute

ImplementationR1Proposedfor telling inference from training on a mutually inspected cluster

Assessment and limits · Assessment sources

Related organizations: Singapore AI Safety Hub (SASH), Future of Life Institute

MechanismR1Proposedfor bounding physical covert channels out of a verified enclosure

  • No prototype or red-team exists; the design is a first-pass viability study.

  • Volume costs of TEMPEST-grade power-line filters are uncertain, because existing products are mostly made to order.

  • A prototype enclosure for at least one AI rack or scalable unit, with measured attenuation for each channel class.

    Next readiness level
  • A red-team exercise against the prototype by a stated adversary.

    Next readiness level
  • Validated costs for filters, jamming and optical conversion at production scale.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Machine Intelligence Research Institute

MechanismR2Demonstratedfor detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence

  • No tamper-evident enclosure has been designed for AI verifier hardware at retrofit scale.

  • Battery-backed designs add bulk, limit operating temperature (+10 °C to +35 °C for the IBM 4765) and complicate transport.

  • Active monitoring needs power, and visual inspection of large enclosures faces access limits.

  • No evaluation has been published in the AI verification setting.

  • An enclosure or sensing design built for AI verifier devices (taps, gateways, recomputation servers) and deployable at data-centre scale.

    Next readiness level
  • An independent public evaluation (red team or certification) of such an enclosure in the AI verification setting.

    Next readiness level
  • Inspection protocols suited to host-controlled AI facilities.

    Next readiness level

Assessment and limits · Assessment sources

MechanismR3In productionfor showing which software ran to a party that distrusts the operator holding the hardware

Assessment and limits · Assessment sources

Related organizations: NVIDIA, Tinfoil, University of Cambridge, Machine Intelligence Research Institute, Future of Life Institute

MechanismR2Demonstratedfor detecting whether a GPU is doing other work

  • No network-level memory challenge across data-centre servers has been demonstrated.

  • Challenges that fill memory displace workloads; filling a pod's volatile memory takes tens of minutes and SSDs take hours.

  • Outside help, such as remote memory, must be excluded during challenges.

  • Production-grade challenge tooling, or use by a party other than the developers for a verification decision.

    Next readiness level
  • A network-level challenge that bounds free memory across accelerator servers, with public code or measurements described in enough detail to repeat.

    Next readiness level
  • Quantified false-positive and false-negative rates under adversarial conditions.

    Next readiness level
  • Evaluation against known attack classes on timed attestation, such as compression and relocation.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Amodo Design, Machine Intelligence Research Institute

ImplementationR3In productionfor showing clients that the served weights match a committed hash

  • The underlying TEE attestation does not resist attackers with physical access to the host.

  • No independent evaluation of the model-identity chain has been published.

  • An independent security evaluation of Modelwrap and the attestation chain that leaves no critical flaw open.

    Next readiness level
  • A supported tool for audit-time verification from transparency records.

    Next readiness level
  • A way for third parties to learn something about private models beyond consistency across requests.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Tinfoil

ImplementationR3In productionfor checking that untrusted providers used the claimed model, prompt and precision

  • No independent security evaluation has been published, and Amodo Design rates red-teaming of recomputation schemes as 'not started'.

  • The verifier must run the model itself, which suits the paper's setting of providers serving open-weights models.

  • An independent public security evaluation, such as an audit, red-team or peer-reviewed analysis, that tests adaptive attacks like the spoofing and speculative-decoding cases the TOPLOC authors list.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Prime Intellect

MechanismR2Demonstratedfor checking from its transcript that a training run followed declared rules

Assessment and limits · Assessment sources

ImplementationR3In productionfor reproducing declared-model inference from receipts in Gensyn's information-market service

  • Reproducibility costs throughput: RepOps added 98% to Llama-8B inference time on an A100 in the paper, and Gensyn reports a threefold cut in REE's reproducible-mode overhead without absolute figures.

  • The providers who re-run a job and the referee need the model and data, and the guarantee holds only if at least one provider is honest.

  • An independent public security evaluation of the Verde dispute protocol and of RepOps reproducibility across hardware, which the paper asserts but does not test.

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: Gensyn

ImplementationR2Demonstratedfor proving single-sample LoRA fine-tuning steps for 3–13-billion-parameter language models

  • Each single-sample step took 121.93–249.38 seconds to prove, with commitment generation taking another 156–554 seconds in the reported experiments.

  • A production-grade, available LoRA proving implementation, or another party's documented reliance on its proofs.

    Next readiness level

Assessment and limits · Assessment sources

ImplementationR2Demonstratedfor detecting whether verifier-supplied data remains in a single GPU's memory

  • The challenge data occupies a large part of GPU memory for as long as the test runs.

  • No test across servers has been reported, and the MIRI overview lists network-level probing of memory contents as undemonstrated.

  • Production-grade tooling, or use by a party other than the authors for a verification decision.

    Next readiness level
  • Detection thresholds with measured false-positive and false-negative rates.

    Next readiness level
  • A test across servers, where the verifier is not on the same host as the GPU.

    Next readiness level

Assessment and limits · Assessment sources

MechanismR1Proposedfor recomputing whole workloads to show a cluster runs only declared inference

Assessment and limits · Assessment sources

Related organizations: Amodo Design, AI Futures Project

MechanismR2Demonstratedfor telling training from inference and other work using genuine telemetry, including disguised workloads

Assessment and limits · Assessment sources

Related organizations: Machine Intelligence Research Institute, Intelligence Security Laboratories, Amodo Design

MechanismR2Demonstratedfor proving a language model's output follows from committed weights, against a cheating prover

Assessment and limits · Assessment sources

Related organizations: Attestable, University of Waterloo

MechanismR2Demonstratedfor proving a training run followed a committed specification and data

Assessment and limits · Assessment sources

ImplementationR2Demonstratedfor proving an output came from committed weights, against a prover who cheats

  • Proving takes about 13 minutes (803 seconds) of A100 time per 2,048-token forward pass at 13B parameters, plus a one-time weight commitment of 16 to 21 minutes.

  • The repository was archived on 10 July 2025 and the author states there is no plan for upgrades or maintenance.

  • No security audit of the code has been carried out.

  • A production-grade implementation, with prover and verifier separated and non-interactive proofs, or reliance by a third party for a verification decision.

    Next readiness level
  • An independent public security evaluation (audit, red-team or third-party peer-reviewed analysis).

    Next readiness level

Assessment and limits · Assessment sources

Related organizations: University of Waterloo

Search

Full search page