C-0007

A training run stayed within declared limits

A declared training run used no more compute than permitted and had its declared properties, such as training data, settings and resulting weights.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

The claim is that a declared training run used no more compute than permitted and had its declared properties, such as its training data, settings and resulting weights. Many proposed rules on frontier AI limit training, often through a threshold on total training compute measured in floating-point operations, sometimes combined with limits on data or methods. Verifying that a run stayed within them would let a regulator or treaty partner rely on something other than self-reporting. It is hard because training is long, distributed and expensive to repeat. Exact replay is complicated by numerical noise, the data and weights are sensitive, and work could be split across declared and undeclared hardware. Proposals include on-chip logging of weight snapshots with sampled recomputation of training segments, proof-of-learning protocols, zero-knowledge proofs and telemetry-based accounting. Published attacks show that the original proof-of-learning protocol can be spoofed.

State of verification

Editorial synthesis from the AI Verification Tech Map.

Proof-based checks of training remain far below frontier-scale runs. Proof-of-learning and zero-knowledge proofs of training are both demonstrated (R2); hardware enforcement remains proposed (R1).

Proof-of-learning and transcript verification (R2) re-runs sampled training segments between logged weight snapshots S-0029, and zero-knowledge proofs of training (R2) prove that training followed a committed specification without revealing data or weights S-1110. Guarantee processors such as flexHEG and licensing (both R1) could enforce compute limits in hardware S-0035 S-0057.

Choi and colleagues report proof-of-training-data experiments on language models of up to 1 billion parameters S-0030, and Kaizen proves training iterations of a 10-million-parameter image model at about 15 minutes of proving per iteration S-1110. VeriLoRA proves individual low-rank fine-tuning steps on language models of up to 13 billion parameters S-3080.

Published attacks spoof the original proof-of-learning protocol, and the attack's authors argue that a provably robust version needs a better understanding of deep-learning optimisation S-0027. Governance analyses have judged zero-knowledge proofs impractical at frontier scale, and one 2026 proposal argues this is a limit of current approaches, not a fundamental one S-0025. A compute limit bounds a run only if all the chips used are known, so this claim depends on Compute stock is at most a declared amount and There is no undeclared relevant compute.

Connections in the research map

Concepts used

Techniques addressing this claim

Sources and provenance

  1. S-0029 / Tier B

    What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗

    Y. Shavit · 2023 · arXiv

    Supports: goal and example rules; weight snapshots; sampled segment recomputation; reasons full re-run is infeasible; PoTT harder than PoL; open problems (online RL, thresholds)

    Locator: abstract; §2–§3; open problems

    Version and catalogue details
  2. S-0053 / Tier B

    Computing Power and the Governance of Artificial Intelligence ↗

    G. Sastry, L. Heim, H. Belfield, M. Anderljung, M. Brundage, J. Hazell, C. O'Keefe, G. K. Hadfield, R. Ngo, K. Pilz, G. Gor, E. Bluemke, S. Shoker, J. Egan, R. F. Trager, S. Avin, A. Weller, Y. Bengio, D. Coyle · 2024 · arXiv

    Supports: EO 14110 threshold; compute as a high-level proxy; thresholds must change with progress

    Locator: thresholds; limitations

    Version and catalogue details
  3. S-0069 / Tier A

    Executive Order 14148: Initial Rescissions of Harmful Executive Orders and Actions ↗

    Executive Office of the President · 2025 · Federal Register, 90 FR 8237 (document 2025-01901, published 2025-01-28)

    Supports: revocation of EO 14110 on 20 January 2025

    Locator: Sec. 2(ggg)

    Version and catalogue details
  4. S-0063 / Tier B

    An International Agreement to Prevent the Premature Creation of Artificial Superintelligence ↗

    A. Scher, D. Abecassis, P. Barnett, B. Abeyta · 2025 · Machine Intelligence Research Institute

    Supports: training above 10^24 FLOP prohibited; runs above 10^22 FLOP approved and monitored

    Locator: §4

    Version and catalogue details
  5. S-0062 / Tier B

    Verification methods for international AI agreements ↗

    A. R. Wasil, T. Reed, J. W. Miller, P. Barnett · 2024 · arXiv

    Supports: unauthorised training above a FLOP threshold as a violation type

    Locator: What to verify

    Version and catalogue details
  6. S-0002 / Tier B

    Verifying International Agreements on AI: Six Layers of Verification for Rules on Large-Scale AI Development and Deployment ↗

    M. Baker, G. Kulp, O. Marks, M. Brundage, L. Heim · 2025 · RAND Corporation

    Supports: Subgoal 1.A.1 verifying declared training

    Locator: §3.2

    Version and catalogue details
  7. S-0025 / Tier B

    Zero knowledge verification for frontier AI training is possible ↗

    P. Peigné, K. Nguyen, P. Wang · 2026 · arXiv

    Supports: enforcement rests on self-reporting; governance analyses judge ZKPs impractical at frontier scale, which the authors argue is paradigm-bound; proposed architecture; ~36-month estimate

    Locator: abstract

    Version and catalogue details
  8. S-0027 / Tier A

    Proof-of-Learning is Currently More Broken Than You Think ↗

    C. Fang, H. Jia, A. Thudi, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, V. Chandrasekaran, N. Papernot · 2023 · 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023)

    Supports: reproducible PoL spoofing at a fraction of prior cost; provably robust PoL requires advances in understanding deep-learning optimisation

    Locator: abstract

    Version and catalogue details
  9. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: monitoring training needs larger perimeters or compute-fabric taps; back-end traffic harder to capture

    Locator: §5.1.1; inference vs training

    Version and catalogue details
  10. S-0035 / Tier B

    Flexible Hardware-Enabled Guarantees for AI Compute ↗

    J. Petrie, O. Aarne, N. Ammann, D. Dalrymple · 2025 · arXiv

    Supports: flexHEG compute limits for training

    Locator: abstract; Executive Summary

    Version and catalogue details
  11. S-0057 / Tier B

    Hardware-Enabled Governance Mechanisms: Developing Technical Solutions to Exempt Items Otherwise Classified Under Export Control Classification Numbers 3A090 and 4A090 ↗

    G. Kulp, D. Gonzales, E. Smith, L. Heim, P. Puri, M. J. D. Vermeer, Z. Winkelman · 2024 · RAND Corporation

    Supports: offline licensing with a compute budget

    Locator: p. viii

    Version and catalogue details
  12. S-0030 / Tier A

    Tools for Verifying Neural Models' Training Data ↗

    D. Choi, Y. Shavit, D. K. Duvenaud · 2023 · Advances in Neural Information Processing Systems 36 (NeurIPS 2023)

    Supports: training-data verification experiments on GPT-2 and Pythia models up to 1B parameters

    Locator: §4

    Version and catalogue details
  13. S-1110 / Tier A

    Zero-Knowledge Proofs of Training for Deep Neural Networks ↗

    K. Abbaszadeh, C. Pappas, J. Katz, D. Papadopoulos · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330

    Supports: Kaizen zero-knowledge proofs of training; VGG-11 (10M parameters) at about 15 minutes per iteration

    Locator: abstract; evaluation

    Version and catalogue details
  14. S-3080 / Tier A

    VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs ↗

    G. Liao, T. Wang, S. Zhang, J. Zhang, L. Shi, D. Tao · 2026 · NDSS Symposium 2026

    Supports: VeriLoRA proofs of individual LoRA fine-tuning steps on language models up to 13B parameters

    Locator: §VI-B–VI-D

    Version and catalogue details
  15. S-3542 / Tier A

    Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) ↗

    European Parliament, Council of the European Union · 2024 · Official Journal of the European Union, OJ L, 2024/1689

    Supports: Art. 51(2) presumption of high-impact capabilities above 10^25 FLOP; Art. 52(1) notification within two weeks; Art. 113(b) Chapter V applies from 2 August 2025

    Locator: Arts 51, 52, 113

    Version and catalogue details
  16. S-3543 / Tier A

    Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act) ↗

    European Commission · 2025 · European Commission, Communication C(2025) 5045 final

    Supports: 10^25 FLOP presumption and two-week notification; entry into application on 2 August 2025

    Locator: §2.3.1–2.3.2; landing page

    Version and catalogue details
  17. S-3544 / Tier A

    California Senate Bill 53 (2025): Transparency in Frontier Artificial Intelligence Act ↗

    California State Legislature · 2025 · Statutes of 2025, Chapter 138 (Business and Professions Code §22757.10 et seq.)

    Supports: frontier model defined by more than 10^26 integer or floating-point operations including fine-tuning; transparency duties

    Locator: §22757.11(i); §22757.12

    Version and catalogue details
  18. S-0059 / Tier A

    Detecting Compute Structuring in AI Governance Is Likely Feasible ↗

    E. Seferis, T. Fist · 2026 · Proceedings of the AAAI Conference on Artificial Intelligence 40(44), pp. 37904–37912 (AAAI-26, Special Track on AI Alignment)

    Supports: compute structuring: splitting or modifying workloads to avoid regulation

    Locator: abstract

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review