01 / The mechanism and its boundary
What is being described
RAND describes itself as a nonprofit, nonpartisan research organization that provides leaders with the information they need to make evidence-based decisions S-3607. Its reports on verification include:
- Six layers of verification. Baker et al. set out six layers of verification for rules on large-scale AI development and deployment S-0002. They describe an AI chip registry with sampled chain-of-custody checks (Chip registries and manufacturing records), and list satellite imagery among supplementary mechanisms that they call "less robust" than their main layers (Remote detection of data centres) S-0002.
- Hardware-enabled governance mechanisms. Kulp et al. define such mechanisms as controls built into AI hardware that enable "enforcement and compliance verification" S-0057. They analyse offline licensing, which lets a GPU run a set amount of work before it refuses or slows further work, and a "fixed set" that limits high-bandwidth links to a pod of pre-authorized chips S-0057. See Hardware performance throttling and licensing, Hardware-enabled guarantees (flexHEG) and guarantee processors and On-chip telemetry from timing, memory and performance counters.
- Secure inference data centres. A report by RAND's Center on AI, Security, and Technology designs a highly secure, vertically integrated inference data centre S-1510; see RAND secure inference data center (SIDC) design.
- Model-weight security. Nevo et al. identify 38 attack vectors against model weights and define five security levels, for defending against actors up to well-resourced nation-states S-1610; see Model weights have not left the facility.
- Field listing. The AI Futures Project's verification page lists RAND's Center on AI, Security, and Technology as doing "foundational technical and policy research on AI verification" S-1511.
Connections in the research map
Related research
Sources and provenance
- S-3607 / Tier B
About RAND ↗
· 2026 · RAND
Supports: nonprofit nonpartisan research organization and evidence-based decisions
Version and catalogue details - S-0002 / Tier B
Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗
M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation
Supports: six layers of verification; AI chip registry; satellite imagery as a supplementary mechanism
Version and catalogue details - S-0057 / Tier B
Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 ↗
G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman · 2024 · RAND Corporation
Supports: hardware-enabled governance mechanisms: offline licensing and fixed set
Version and catalogue details - S-1510 / Tier B
Highly Secure Inference Data Centers: A Vertically Integrated Strategy for Security Engineering ↗
S. F. Comer, H. Pavela, V. Gandhi, K. Siler-Evans, E. Devendorf, B. Kelley, J. Gimbi, J. Aguirre, G. Kulp, M. Stalczynski, M. J. Malone · 2026 · RAND Corporation (Research Report RR-A4827-1)
Supports: secure inference data center design by the Center on AI, Security, and Technology
Version and catalogue details - S-1610 / Tier B
Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models ↗
S. Nevo, D. Lahav, A. Karpur, Y. Bar-On, H. A. Bradley, J. Alstott · 2024 · RAND Corporation
Supports: attack vectors and security levels for model weights
Version and catalogue details - S-1511 / Tier C
Get Involved in Verification ↗
AI Futures Project · 2026 · AI 2040
Supports: RAND CAST listed as doing research on AI verification
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review