01 / The mechanism and its boundary
What is being described
The claim is that data flowing between specified groups of chips, or out of a facility, stays below a declared rate. Restricting communication between compute groups could limit joint training while allowing existing models to keep serving users S-0005. A bound on a facility's external links also limits how much weights or data could leave it S-1508. The claim covers every channel, including paths outside the monitored network.
Proposed designs cap the external bandwidth of small groups of chips, called pods, or restrict chip networking in hardware. A pod design aims to allow inference tokens while restricting training gradients if the served model and routing fit within each pod S-0005 S-3565. Network taps observe the links. The hard parts are finding every path, including physical side channels; choosing bounds that stay meaningful as training methods improve; and monitoring high-speed accelerator fabrics that are difficult to tap.
State of verification
Editorial synthesis from the AI Verification Tech Map.
A software bandwidth monitor has been demonstrated (R2). It runs on the operator's nodes, and its authors say the measurements are trivially spoofable S-3220. No bandwidth cap that a verifier can check has been demonstrated publicly.
Bandwidth limits and compartmentalization (R2 for software monitoring) proposes to cap or remove links between accelerator groups. Its pod-cap design aims to allow inference tokens while restricting training gradients, provided the served model and routing fit within each pod S-0005 S-3565. It needs no access to a facility's code S-0005. Hardware versions include RAND's fixed-set design S-0057 and guarantee processors (R1), and the AI 2040 stack (R1) removes back-end networking S-0067. Side-channel suppression (R1) addresses paths outside the network S-0038. Tamper evidence (R2 for probing detection on servers and protected electronics) would protect the enforcing devices, and bounding unexplained information (R2) limits what the permitted bandwidth can carry.
Lucid Computing's pod-cap design is "not yet implemented or red-teamed" S-1301, and Amodo's rate limiting on 400G links was for weight security with a cooperating operator S-1313.
Copper scale-up links and encrypted interconnects are hard to observe S-0031, and the designs aim to cut side channels to low rates, not to eliminate them S-0018 S-0038. Sastry and colleagues note that decentralised training, if it becomes more viable, might undermine the detectability of training runs S-0053, and training methods that need less communication could likewise erode a bound that separates training from inference today.
Connections in the research map
Techniques addressing this claim
Sources and provenance
- S-0005 / Tier B
Mechanisms to Verify International Agreements About AI Development ↗
A. Scher, L. Thiergart · 2025 · arXiv
Supports: pods with high internal and very low external bandwidth; enough for inference tokens not training gradients; implementable with modest changes, physical access and monitoring, without code access
Locator: Interconnect bandwidth limits
Version and catalogue details - S-0053 / Tier B
Computing Power and the Governance of Artificial Intelligence ↗
G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle · 2024 · arXiv
Supports: compute caps via physical limits on chip-to-chip networking; decentralised training could undermine detectability
Locator: enforcement; §3.B.1 Detectability
Version and catalogue details - S-1314 / Tier B
DiLoCo: Distributed Low-Communication Training of Language Models ↗
A. Douillard, Q. Feng, A. A. Rusu, R. Chhaparia, Y. Donchev, A. Kuncoro, M. Ranzato, A. Szlam, J. Shen · 2024 · ICML 2024 Workshop on Advancing Neural Network Training (WANT)
Supports: DiLoCo on 8 workers matched fully synchronous training while communicating 500 times less
Locator: abstract
Version and catalogue details - S-0057 / Tier B
Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 ↗
G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman · 2024 · RAND Corporation
Supports: fixed-set HEM restricting networking of small GPU sets
Locator: p. viii
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: front-end vs back-end bandwidth; inference bandwidth assumption; covert side-channel target in kilobits per second; egress explainable by ingress
Locator: inference vs training; open problems
Version and catalogue details - S-0031 / Tier C
The Fundamentals and Feasibility of Secure Network Taps for Verifying AI Datacenter Use ↗
N. Cankaya · 2026 · The Datacenter Lie Detector
Supports: front-end vs back-end tapping costs and feasibility; copper links and scale-up domains; encrypted interconnect
Locator: frontend vs backend; open problems
Version and catalogue details - S-0038 / Tier C
Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses ↗
N. Cankaya · 2026 · MIRI Technical Governance Team
Supports: physical side channels can bypass network monitoring; defences; tolerable low rate
Locator: channels of concern; defences
Version and catalogue details - S-0029 / Tier B
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗
Y. Shavit · 2023 · arXiv
Supports: retroactively confirming data-centre topology is beyond scope
Locator: open problems
Version and catalogue details - S-0002 / Tier B
Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗
M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation
Supports: network taps intercepting inter-chip data
Locator: §4.2
Version and catalogue details - S-0067 / Tier C
Verification Plan ↗
R. Dean · 2026 · AI 2040
Supports: removing back-end networking to create isolated inference units
Locator: verification mechanisms
Version and catalogue details - S-1301 / Tier C
Traffic Shaping for Workload Classification ↗
Lucid Computing · 2026 · Lucid Computing (Substack)
Supports: pod-level traffic cap design; not yet implemented or red-teamed
Locator: summary; status
Version and catalogue details - S-1313 / Tier C
The Tray as a Bandwidth Boundary ↗
Amodo Design · 2026 · Amodo Design
Supports: DPU-enforced rate limiting on 400G links for weight security, with the limits set by a trusted operator's controller
Locator: whole note
Version and catalogue details - S-3220 / Tier C
De-risking Interconnect Limits for AI Verification ↗
A. Scher, D. Sarbakysh, A. Moskvin · 2026 · MIRI Technical Governance Team
Supports: software bandwidth-monitor prototype on AI GPUs; authors say operator-controlled measurements are trivially spoofable
Locator: Abstract; Pros and Cons analysis
Version and catalogue details - S-1508 / Tier B
Haiku to Opus in Just 10 bits: LLMs Unlock Large Compression Gains ↗
R. Rinberg, A. M. Carrell, S. Henniger, N. Carlini, K. Warr · 2026 · arXiv
Supports: egress limits cap what can be stolen
Locator: §5.1
Version and catalogue details - S-3565 / Tier A
Shortcut-connected Expert Parallelism for Accelerating Mixture of Experts ↗
W. Cai, J. Jiang, L. Qin, J. Cui, S. Kim, J. Huang · 2025 · ICML 2025, Proceedings of Machine Learning Research 267
Supports: expert-parallel MoE inference can require cross-device all-to-all communication
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-23
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review