01 / The mechanism and its boundary
What the technique establishes
The AI 2040 verification plan proposes that every AI workload in a monitored facility be organized into discrete, reproducible "packets" that a verifier's recomputation server can see. The verifier re-runs a random sample of packets to check that they were computed as declared. The plan states that smaller packets raise the chance of catching a rogue workload. As of September 2026, no implementation of whole-workload packets has been published. The nearest prototypes recompute single inference requests or, in proof-of-learning, selected training steps. The main obstacles are that workloads and network traffic are not reproducible by default, that the recomputation server must be secured, and that compute outside declared packets is not covered. The plan itself does not verify that spare compute is unused, and notes that non-compliant work might be hidden inside compliant-looking workloads.
- Threat model
- Adversarial prover
- Adversarial evaluation
- None
- Hardware needed
- Retrofit device
- Prover cooperation
- Required
- Confidentiality
- Partial
- Category
- Isolation & architecture
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
This compute runs inference, not training
Proposed as the correctness check for an inference-only retrofit (S-0067).
A training run stayed within declared limits
Proposed for later R&D verification by treating training steps as packets (S-0067, S-0017).
Readiness for a stated use
Assessed use: recomputing whole workloads to show a cluster runs only declared inference
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
The design, its claim and its assumptions are public, but no implementation of whole-workload packets has been built.
- R1 met: the AI 2040 verification plan describes the design (discrete, reproducible packets visible to a recomputation server, with random partial recomputation), the claim it serves (correct outputs in an inference-only regime, later R&D verification) and its assumptions (reproducibility, an intact recomputation server, physical security) S-0067. Amodo gives a comparable written design at the level of single training steps S-0017. The plan is the only Implementation record for this mechanism (AI 2040 inference-only verification stack, assessed R1).
- R2 not met: no public implementation or end-to-end result organizes whole workloads into reproducible packets. The nearest demonstrations recompute single inference requests S-1006 or, in proof-of-learning, selected training steps (Training-transcript verification (proof-of-learning)) S-0027. The plan's companion page lists a reproducible inference stack and network reproducibility as not started S-1511, and Amodo rates network reproducibility "not on track" S-1008.
Confidence is medium. The design is described only at a high level, but the plan's authors and Amodo both list the reproducible inference stack it needs as not started S-1511 S-1008.
Evidence needed for the next level
A public implementation, or reproducible end-to-end results, of packet-based recomputation beyond single inference requests, under realistic model scale, hardware or a stated adversary.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / theoretical argument
Spare compute is outside the scheme
The plan states that it does not verify that spare compute is not used for unapproved workloads, because this seems very challenging S-0067. Recomputation checks the correctness of declared work, not its completeness S-0017.
significant / open / theoretical argument
Non-compliant work could be encoded inside compliant-looking packets
The plan notes that an AI company might try to encode a non-compliant workload inside a workload that looks compliant on the surface S-0067.
What still blocks use or stronger assurance
Workloads are not reproducible by default, and achieving reproducibility may cost performance.
Dependency: Deterministic and bit-exact inference
S-0067- S-1008
Network packets are not individually reproducible by default; making them so may need considerable software, firmware and hardware work. Amodo rates this 'not on track'.
All traffic must reach the recomputation server via network taps, and the server's integrity is critical.
Dependency: Network taps and certifiers
S-0067S-1008- S-0017
Recomputing training steps needs checkpoints: writing one at every step would cost more than 100% overhead, so Amodo's design needs a spare data-parallel replica that tracks the weights instead.
Connections in the research map
Depends on
- Deterministic and bit-exact inference
Packets must be reproducible, which needs deterministic execution.
- Network taps and certifiers
Network taps copy traffic to the recomputation server.
Complementary techniques
Concepts used
Organizations and developers
Implementations
Sources and provenance
- S-0067 / Tier C
Verification Plan ↗
R. Dean · 2026 · AI 2040
Supports: packet design, hierarchy of workload steps, recomputation budget example, assumptions and stated gaps
Locator: 2027: Concrete inference-only retrofitting proposal; Feb 2029; Early 2030: Workload Approval, Workload Verification (2034 chart)
Version and catalogue details - S-0017 / Tier C
Example Schemes for Verifying High-Stakes AI Agreements ↗
Amodo Design · 2026 · Amodo Design
Supports: step-level recomputation design for pre-training; shadow replica instead of per-step checkpoint writes; commitments before audit selection; tolerance comparison; audit rate; correctness vs completeness
Locator: pre-training scheme; introduction
Version and catalogue details - S-1006 / Tier C
Scaling Recomputation Inference Verification ↗
Amodo Design · 2026 · Amodo Design
Supports: single-request inference recomputation prototype
Locator: whole note
Version and catalogue details - S-1008 / Tier C
AI 2040 Plan A — Verification SITREP ↗
Amodo Design · 2026 · Amodo Design
Supports: status of reproducible inference stack and network reproducibility
Locator: status items
Version and catalogue details - S-1511 / Tier C
Get Involved in Verification ↗
AI Futures Project · 2026 · AI 2040
Supports: plan authors' status of a reproducible inference stack and network reproducibility, July 2026
Locator: reproducible packets
Version and catalogue details - S-0027 / Tier A
Proof-of-Learning is Currently More Broken Than You Think ↗
C. Fang, H. Jia, A. Thudi, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, V. Chandrasekaran, N. Papernot · 2023 · 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023)
Supports: proof-of-learning verifiers reproduce a subset of updates within a noise threshold; spoofs exploit the noise tolerance
Locator: §4.1; §4.2; §6.1
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review