01 / The mechanism and its boundary
What the technique establishes
Attestable, a company, reports a zero-knowledge prover for transformer inference that would let an AI developer prove that an output came from a committed model, input and random seed without revealing the weights. On one NVIDIA H100 GPU, Attestable reports proving a 31-billion-parameter model at 53 tokens per second for one 16,000-token sequence, and 77 tokens per second across four 4,000-token sequences. It reports proofs of a few megabytes that a CPU verifies in under a second. It also proposes using such proofs to support verifiable limits on AI development. All evidence comes from the company's blog, and no paper, protocol specification or code is public, so the results cannot be independently checked. The company lists its own limits: a 16,000-token context, 8-bit integer matrix multiplications, and proofs that cover only the computation they are about.
- Threat model
- Adversarial prover
- Adversarial evaluation
- None
- Hardware needed
- None
- Prover cooperation
- Required
- Confidentiality
- Preserving
- Category
- Cryptography & computation
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
The declared model is the one being served
Attestable reports proving y = F(W, x, r) for committed weights W.
This compute runs inference, not training
Proposed use: showing an accounted workload used an approved, unchanged model.
Declared safeguards were applied during inference
Proposed use: showing an agreed input classifier was applied.
Readiness for a stated use
Assessed use: proving an output came from committed weights
low confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
Attestable states the claim, its security basis and its limits, but has published no code, protocol description or artifact.
- R1 met: Attestable publicly states the claim proven (an output y = F(W, x, r) for committed weights W, input x and seed r), its security basis (hash functions only, 100-bit security) and its limits S-1101. It also states the verification uses it proposes S-1102 S-1103.
- R2 not met. The rubric excludes results that are claimed but not public or not reproducible, and Attestable's figures are published without code, a protocol description or an artifact S-1101.
Evidence needed for the next level
A public working implementation, or reproducible published end-to-end results, such as a paper with a protocol specification and benchmarks others can rerun.
Any independent security analysis of the proof system.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / open question
Proves an 8-bit quantised variant of the model
Attestable reports that matrix multiplications are dynamically quantised to 8-bit integers, while non-linear operations are proven in floating point. It reports that its IFEval result "shows where the current quantization still needs improvement" S-1101. The proven model is therefore a quantised variant, which a verifier must accept as the declared model.
significant / open / theoretical argument
A proof covers only the computation it is about
Attestable states that "a proof of some computation is not a proof of all computation" and that a proof "cannot discover a datacenter that was never declared" S-1102.
What still blocks use or stronger assurance
- S-1101
No paper, protocol specification or code is public, so the reported results cannot be reproduced.
- S-1101
Attestable reports a context window limited to 16K tokens.
Covering computation that is not proven relies on proof-of-work accounting, which Attestable has only proposed.
Dependency: Proofs of useful work for capacity accounting
S-1102
Connections in the research map
Mechanisms implemented
Organizations and developers
Sources and provenance
- S-1101 / Tier C
Proving LLMs at Scale ↗
Attestable · 2026 · Attestable blog
Supports: statement proven, security basis, performance figures, limitations (provider-reported)
Version and catalogue details - S-1102 / Tier C
Pacing AI Requires Proof ↗
Attestable · 2026 · Attestable blog
Supports: proposed verification uses and proof-of-work accounting; coverage argument (provider-reported)
Version and catalogue details - S-1103 / Tier C
From Verifiability to Model-Weight Security ↗
Attestable · 2026 · Attestable blog
Supports: verification-firewall proposal with random sampling of outputs; stated threats (provider-reported)
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review