C-0008

Communication between compute groups is bounded

Data flowing between specified groups of chips, or out of a facility, stays below a declared rate.

Source reviewed 2026-09-23

01 / The mechanism and its boundary

What is being described

The claim is that data flowing between specified groups of chips, or out of a facility, stays below a declared rate. Restricting communication between compute groups could limit joint training while allowing existing models to keep serving users S-0005. A bound on a facility's external links also limits how much weights or data could leave it S-1508. The claim covers every channel, including paths outside the monitored network.

Proposed designs cap the external bandwidth of small groups of chips, called pods, or restrict chip networking in hardware. A pod design aims to allow inference tokens while restricting training gradients if the served model and routing fit within each pod S-0005 S-3565. Network taps observe the links. The hard parts are finding every path, including physical side channels; choosing bounds that stay meaningful as training methods improve; and monitoring high-speed accelerator fabrics that are difficult to tap.

State of verification

Editorial synthesis from the AI Verification Tech Map.

A software bandwidth monitor has been demonstrated (R2). It runs on the operator's nodes, and its authors say the measurements are trivially spoofable S-3220. No bandwidth cap that a verifier can check has been demonstrated publicly.

Bandwidth limits and compartmentalization (R2 for software monitoring) proposes to cap or remove links between accelerator groups. Its pod-cap design aims to allow inference tokens while restricting training gradients, provided the served model and routing fit within each pod S-0005 S-3565. It needs no access to a facility's code S-0005. Hardware versions include RAND's fixed-set design S-0057 and guarantee processors (R1), and the AI 2040 stack (R1) removes back-end networking S-0067. Side-channel suppression (R1) addresses paths outside the network S-0038. Tamper evidence (R2 for probing detection on servers and protected electronics) would protect the enforcing devices, and bounding unexplained information (R2) limits what the permitted bandwidth can carry.

Lucid Computing's pod-cap design is "not yet implemented or red-teamed" S-1301, and Amodo's rate limiting on 400G links was for weight security with a cooperating operator S-1313.

Copper scale-up links and encrypted interconnects are hard to observe S-0031, and the designs aim to cut side channels to low rates, not to eliminate them S-0018 S-0038. Sastry and colleagues note that decentralised training, if it becomes more viable, might undermine the detectability of training runs S-0053, and training methods that need less communication could likewise erode a bound that separates training from inference today.

Connections in the research map

Concepts used

Techniques addressing this claim

Sources and provenance

  1. S-0005 / Tier B

    Mechanisms to Verify International Agreements About AI Development ↗

    A. Scher, L. Thiergart · 2025 · arXiv

    Supports: pods with high internal and very low external bandwidth; enough for inference tokens not training gradients; implementable with modest changes, physical access and monitoring, without code access

    Locator: Interconnect bandwidth limits

    Version and catalogue details
  2. S-0053 / Tier B

    Computing Power and the Governance of Artificial Intelligence ↗

    G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle · 2024 · arXiv

    Supports: compute caps via physical limits on chip-to-chip networking; decentralised training could undermine detectability

    Locator: enforcement; §3.B.1 Detectability

    Version and catalogue details
  3. S-1314 / Tier B

    DiLoCo: Distributed Low-Communication Training of Language Models ↗

    A. Douillard, Q. Feng, A. A. Rusu, R. Chhaparia, Y. Donchev, A. Kuncoro, M. Ranzato, A. Szlam, J. Shen · 2024 · ICML 2024 Workshop on Advancing Neural Network Training (WANT)

    Supports: DiLoCo on 8 workers matched fully synchronous training while communicating 500 times less

    Locator: abstract

    Version and catalogue details
  4. S-0057 / Tier B

    Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 ↗

    G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman · 2024 · RAND Corporation

    Supports: fixed-set HEM restricting networking of small GPU sets

    Locator: p. viii

    Version and catalogue details
  5. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: front-end vs back-end bandwidth; inference bandwidth assumption; covert side-channel target in kilobits per second; egress explainable by ingress

    Locator: inference vs training; open problems

    Version and catalogue details
  6. S-0031 / Tier C

    The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use ↗

    N. Cankaya · 2026 · The Datacenter Lie Detector

    Supports: front-end vs back-end tapping costs and feasibility; copper links and scale-up domains; encrypted interconnect

    Locator: frontend vs backend; open problems

    Version and catalogue details
  7. S-0038 / Tier C

    Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses ↗

    N. Cankaya · 2026 · MIRI Technical Governance Team

    Supports: physical side channels can bypass network monitoring; defences; tolerable low rate

    Locator: channels of concern; defences

    Version and catalogue details
  8. S-0029 / Tier B

    What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗

    Y. Shavit · 2023 · arXiv

    Supports: retroactively confirming data-centre topology is beyond scope

    Locator: open problems

    Version and catalogue details
  9. S-0002 / Tier B

    Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗

    M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation

    Supports: network taps intercepting inter-chip data

    Locator: §4.2

    Version and catalogue details
  10. S-0067 / Tier C

    Verification Plan ↗

    R. Dean · 2026 · AI 2040

    Supports: removing back-end networking to create isolated inference units

    Locator: verification mechanisms

    Version and catalogue details
  11. S-1301 / Tier C

    Traffic Shaping for Workload Classification ↗

    Lucid Computing · 2026 · Lucid Computing (Substack)

    Supports: pod-level traffic cap design; not yet implemented or red-teamed

    Locator: summary; status

    Version and catalogue details
  12. S-1313 / Tier C

    The Tray as a Bandwidth Boundary ↗

    Amodo Design · 2026 · Amodo Design

    Supports: DPU-enforced rate limiting on 400G links for weight security, with the limits set by a trusted operator's controller

    Locator: whole note

    Version and catalogue details
  13. S-3220 / Tier C

    De-risking Interconnect Limits for AI Verification ↗

    A. Scher, D. Sarbakysh, A. Moskvin · 2026 · MIRI Technical Governance Team

    Supports: software bandwidth-monitor prototype on AI GPUs; authors say operator-controlled measurements are trivially spoofable

    Locator: Abstract; Pros and Cons analysis

    Version and catalogue details
  14. S-1508 / Tier B

    Haiku to Opus in Just 10 bits: LLMs Unlock Large Compression Gains ↗

    R. Rinberg, A. M. Carrell, S. Henniger, N. Carlini, K. Warr · 2026 · arXiv

    Supports: egress limits cap what can be stolen

    Locator: §5.1

    Version and catalogue details
  15. S-3565 / Tier A

    Shortcut-connected Expert Parallelism for Accelerating Mixture of Experts ↗

    W. Cai, J. Jiang, L. Qin, J. Cui, S. Kim, J. Huang · 2025 · ICML 2025, Proceedings of Machine Learning Research 267

    Supports: expert-parallel MoE inference can require cross-device all-to-all communication

    Locator: abstract

    Version and catalogue details
Source review date
2026-09-23
Drafted by (source map)
ai
Review handles (source map)
codex-review