01 / The mechanism and its boundary
What is being described
The Hardware AI Governance Lab (HAIGL) is an interdisciplinary initiative at the University of Oxford, hosted by the Oxford Martin AI Governance Initiative (AIGI) S-1703. Its co-directors are Amro Awad and Robert Trager, and Ben Harack is its co-founder and research lead S-1703.
The lab lists two 2026 papers among its publications S-1703:
- A design for fingerprinting all of an AI cluster's I/O without processors that both parties must trust. It aims to make it infeasible to covertly exfiltrate the results of undisclosed workloads through the tapped links S-1300. Its first author lists the lab as an affiliation S-1300. See Network taps and certifiers and Low-trust AI compute verification system overview.
- A survey of verifiable semiconductor manufacturing that develops a threat model spanning chip design through manufacturing. It argues that defence in depth is required, with assurance tiered by chip criticality, and that neutral third-party verification authorities can help overcome industry opacity S-1704. Two of its four authors list the lab as an affiliation S-1704.
The lab states that it treats hardware architecture as a foundational layer for embedding oversight, verification and control mechanisms S-1703. Its stated aims are:
- It aims to turn high-level governance concepts into hardware design proposals, and then into early-stage feasibility prototypes S-1703.
- It explores ways to verify how AI systems behave, and whether some governance constraints can be enforced directly in hardware S-1703.
- It studies how agreements between states could be structured and implemented when the parties have limited trust in each other S-1703.
The lab expects to release its first hardware governance design profile in late 2026 S-1703.
Connections in the research map
Related research
Sources and provenance
- S-1703 / Tier B
Hardware AI Governance Lab ↗
· 2026 · Oxford Martin AI Governance Initiative
Supports: hosted by AIGI; co-directors and research lead; research focus and aims; first design profile expected in late 2026; lists S-1300 and S-1704 among its publications
Version and catalogue details - S-1300 / Tier B
Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors ↗
N. Cankaya, J. Kryś, J. Ng, L. Marks, F. Krückel · 2026 · arXiv
Supports: cluster I/O fingerprinting design and its aim; first author affiliated with the lab
Version and catalogue details - S-1704 / Tier B
Verifiable Semiconductor Manufacturing ↗
A. Ilhan, C. Withers, H. Gietz, B. Harack · 2026 · Oxford Martin AI Governance Initiative
Supports: chip manufacturing threat model, defence in depth and tiered assurance; two authors affiliated with the lab
Version and catalogue details
- Source review date
- 2026-10-08
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review