Verification
Can states reliably observe major training runs, compute clusters, model transfers, dangerous capabilities, or prohibited deployments?
Compute's physical footprint — power draw, cooling, supply chains — makes AI more verifiable than most software. Layered verification schemes, including on-chip mechanisms, are the frontier proposals.
View on the map → · Open in Browse →
What changed
01
Verification research produced both its most promising primitive and its sharpest doubt: a zero-knowledge architecture that could let a verifier confirm a training run's compute without seeing weights or data; satellite imagery demonstrated as a national-technical-means layer for corroborating data-center claims — and an analysis showing distributed training could move frontier runs outside the registrable facilities all of this assumes.
Recent thinking
Pierre Peigné, Ky Nguyen & Paul Wang · arXiv · 3 Jun 2026 paper
Zero knowledge verification for frontier AI training is possibleenforcement rests on self-reporting because no technical verification primitive for training exists.
Proposes the missing technical primitive for treaty verification: a zkVM-based architecture combining pre-committed training specs, network observations, and Merkle commitments, letting a verifier confirm a training run's compute without seeing weights or data.
Christina Krawec · Federation of American Scientists · 12 May 2026 report
Tracking Hyperscale AI Data Center Growth with Satellite Imageryserve as one complementary layer to independently verify commitments under future AI-related agreements
Empirical demonstration that compute's physical footprint is observable from orbit: satellite imagery can independently corroborate data-center build-out claims, adding a national-technical-means layer to layered verification schemes.
Robi Rahman · arXiv · 28 May 2026 paper
Does Distributed Training Undermine Compute Governance?Developers who prefer not to be constrained by regulations may structure their hardware in a manner that evades the registration and monitoring requirements associated with compute governance.
The strongest recent stress test of datacenter-centric verification: algorithmic advances in distributed training could let frontier runs happen on agglomerated hardware outside registrable facilities, eroding the physical-footprint assumption verification schemes rely on.
Samar Ansari · arXiv · 6 Apr 2026 paper
Hardware-Level Governance of AI Compute: A Feasibility Taxonomythe hardware-level mechanisms invoked by policy proposals remain largely unexamined from an engineering perspective.
An engineering reality-check on hardware-enabled governance: taxonomizes 20 on-chip mechanisms by feasibility and finds the ones treaty verification most needs — compute metering, proof-of-training — are the least mature, while the fabrication window to deploy them is closing.
Foundational reading (2)
Verification Methods for International AI AgreementsWasil et al. · 2024Verifying International Agreements on AIBaker, Brundage, Heim et al. · 2025