Why verify
The case for verification
Agreements about AI are easier to make and to keep when each party can check what the others are doing. Verification technology provides that check, so the parties need to rely less on each other's word.
The trust problem
Verification mechanisms are "processes or tools that give one party greater confidence that another is following the agreed-upon rules, typically by detecting violations" 1.
States are weighing international agreements to manage AI, and "the political feasibility of such agreements can hinge on their verifiability" 2. Without verification, "states may find that otherwise desirable deals are unavailable" 2. Wasil and colleagues suggest that nations "might be much more likely to form international agreements around rules that they can reliably verify", and see such agreements as a way to avoid or mitigate a race between nations 3.
What verification enables
- Verification can make deals possible. "Effective verification mechanisms can transform strategic deadlocks into viable compromises" 2.
- Even rivals could check each other. A RAND working paper by Baker and colleagues asks whether the United States and China could verify each other's compliance with AI guardrails. It concludes that nations "could eventually verify compliance via six largely independent approaches", although technical research and protections against overreach are needed 4.
- Compute is a workable place to check. Sastry and colleagues call computing power "a particularly effective point of intervention" compared with data and algorithms: it is "detectable, excludable, and quantifiable, and is produced via an extremely concentrated supply chain" 5.
- Checks could keep secrets. States limit transparency to protect national security, but "a verification mechanism that could demonstrate compliance without revealing any extraneous information may face no transparency-security tradeoff at all" 2. Zero-knowledge proofs and trusted execution environments aim at that.
- Evidence serves both peace and markets. Harack argues that "preventing war might require credible evidence that civilian AI resources are not being militarized", and that "individuals, companies, and countries are less likely to buy products that they cannot trust" 6. The same approaches could also serve domestic regulation of companies 1.
Verification has costs and limits. Sastry and colleagues warn that "naive or poorly scoped approaches" to governing compute "carry significant risks in areas like privacy, economic impacts, and centralization of power" 5. Scher and Thiergart note that "many of the ideal solutions for verification are not yet technologically feasible" 1.
Nuclear precedents
Nuclear arms control faced the same problem and built tools for it. Baker's study of that history finds that, "with certain preparations, the main foreseeable challenges of hardware-based AI treaty verification would be ones that were manageable in nuclear arms control" 7.
- Satellites came first. The 1972 SALT I interim agreement and ABM Treaty relied only on "national technical means", state-owned technologies such as satellites that check compliance from a distance 7. Each side undertook not to interfere with the other's means 8. The AI counterpart is remote detection of data centres.
- On-site inspection followed. At the signing of the 1987 INF Treaty, Reagan quoted the Russian maxim "trust, but verify" and described inspection teams "actually residing in each other's territory" 9. New ways to verify missiles "expanded the set of realistic political options for arms control" and helped make that treaty possible 2.
- Safeguards count and seal. IAEA safeguards rest largely on "nuclear material accountancy, complemented by containment and surveillance techniques, such as tamper-proof seals and cameras" 10. The AI counterparts are chip registries and tamper evidence for verifier devices.
- Test-ban monitoring listens from afar. The International Monitoring System for the Comprehensive Nuclear-Test-Ban Treaty will have 337 facilities using seismic, hydroacoustic, infrasound and radionuclide sensors. It detected all six nuclear tests North Korea declared between 2006 and 2017 11. Workload classification from side channels applies the same idea at closer range, inferring what a chip is doing from indirect signals such as its power draw.
- Warhead checks could keep designs secret. Warhead inspectors need "high confidence in the authenticity of submitted items while learning nothing about them". Glaser, Barak and Goldston proposed a zero-knowledge protocol for this, based on neutron measurements 12. Zero-knowledge proofs of training constraints pursue the same goal for AI.
The analogy has limits. Baker expects that "states are likely less willing to accept costly verification for AI treaties, as AI security currently tends to be a relatively low priority" 7.
Other precedents
- Under the Chemical Weapons Convention, the OPCW had verified the destruction of 72,304 tonnes of declared chemical weapons by July 2023, covering every stockpile declared up to then 13.
- The Biological Weapons Convention has no verification mechanism, unlike the Non-Proliferation Treaty and the Chemical Weapons Convention. Revelations in the early 1990s of non-compliance by Iraq and the former Soviet Union exposed that gap 14. NTI noted in 2024 that the convention still "lacks mechanisms to monitor and enforce compliance or verify adherence" 15.
- Computer security supplies the rest of the toolkit. Remote attestation lets one end of a network exchange check "whether the other end is in an intended operating state" 16, and attestation for AI workloads builds on it.
Lead times
- Monitoring can be built before a treaty takes effect. The Comprehensive Nuclear-Test-Ban Treaty opened for signature in 1996 and has not yet entered into force 17. About 90 percent of its 337 planned monitoring facilities are already running 11.
- Baker argues for preparing before the political will arrives. That means "developing privacy-preserving, secure, and acceptably priced methods for verifying the compliance of hardware, given inspection access", and "building an initial, incomplete verification system" whose gaps can be closed quickly 7.
- Harack and colleagues judge that if key states get serious, combined efforts "should be sufficient to enable the creation of a robust verification system within a few years" 2. Harack argues that if society wants the benefits of verification, "serious efforts need to begin now" 6.
Further reading
- Nuclear Arms Control Verification and Lessons for AI Treaties (Baker, 2023) compares three kinds of nuclear agreement and draws lessons for AI.
- Verification for International AI Governance (Harack et al., 2025) covers what verification needs, technically and politically.
- Verification methods for international AI agreements (Wasil et al., 2024) sets out ten methods, each with historical precedents and ways to evade it.
- Verifying International Agreements on AI: Six Layers of Verification (Baker et al., 2025) describes how rival states could check each other's compliance.
- Mechanisms to Verify International Agreements About AI Development (Scher and Thiergart, 2025) works through verification for three example policy goals.
- Open Problems in Technical AI Governance (Reuel et al., 2025) maps the open research questions, verification among them.
On this site, Claims lists what one party might want to check about another. Mechanisms shows how each claim could be checked, and each mechanism's readiness level says how far it has got.
Sources
- BA. Scher & L. Thiergart (2025). Mechanisms to Verify International Agreements About AI Development. arXiv. Source record
- BB. Harack et al. (2025). Verification for International AI Governance. Oxford Martin AI Governance Initiative. Source record
- BA. R. Wasil et al. (2024). Verification methods for international AI agreements. arXiv. Source record
- BM. Baker et al. (2025). Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment. RAND Corporation. Source record
- BG. Sastry et al. (2024). Computing Power and the Governance of Artificial Intelligence. arXiv. Source record
- CB. Harack (2026). AI Verification: Infrastructure for Prosperity, Governance, and Peace. Lawfare. Source record
- BM. Baker (2023). Nuclear Arms Control Verification and Lessons for AI Treaties. arXiv. Source record
- AUnited States of America & Union of Soviet Socialist Republics (1972). Treaty between the United States of America and the Union of Soviet Socialist Republics on the Limitation of Anti-Ballistic Missile Systems. United Nations Treaty Series, vol. 944, No. 13446. Source record
- AR. Reagan (1987). Remarks on Signing the Intermediate-Range Nuclear Forces Treaty. Ronald Reagan Presidential Library and Museum. Source record
- AInternational Atomic Energy Agency (2026). IAEA Safeguards Overview: Comprehensive Safeguards Agreements and Additional Protocols. IAEA fact sheet. Source record
- ACTBTO Preparatory Commission (2026). The International Monitoring System. CTBTO. Source record
- AA. Glaser et al. (2014). A zero-knowledge protocol for nuclear warhead verification. Nature 510, 497โ502. Source record
- AOrganisation for the Prohibition of Chemical Weapons (2023). OPCW confirms: All declared chemical weapons stockpiles verified as irreversibly destroyed. OPCW. Source record
- BNuclear Threat Initiative (2003). The Biological Weapons Convention. NTI. Source record
- CG. Essix (2024). BWC at 50: Taking Bold Steps to Secure the Future. NTI. Source record
- BH. Birkholz et al. (2023). Remote ATtestation procedureS (RATS) Architecture (RFC 9334). Internet Engineering Task Force (RATS Working Group). Source record
- ACTBTO Preparatory Commission (2026). The Comprehensive Nuclear-Test-Ban Treaty (CTBT). CTBTO. Source record