Research atlas / October 2026

The evidence beneath
the confidence.

What can we verify about AI compute? Follow a claim to its mechanisms, inspect the evidence, and find the assumptions holding the argument together.

Mechanisms
25
Implementations
17
Verification claims
10
Published sources
290

42 of 42 records

I-0011 / implementationIsolation & architecture

AI 2040 inference-only verification stack

A proposed retrofit that isolates data-centre inference units, taps their front-end traffic and recomputes random samples to check that only declared inference runs.

Assessed use: showing that retrofitted data centres run only inference

R1 Proposedmedium confidence7 sources
I-0013 / implementationOn-chip & hardware

Apple Private Cloud Compute

Apple's cloud AI inference service, in which user devices send requests only to servers that attest to running software published in a public transparency log.

Assessed use: showing users which software serves their AI requests, not which model

R3 In productionmedium confidence9 sources
I-0007 / implementationOn-chip & hardware

Attestable Audits

A research prototype that runs AI safety benchmarks inside a trusted execution environment and publishes attestations binding the model, the audit and the results.

Assessed use: showing users that the model answering them is the audited one

R2 Demonstratedlow confidence2 sources
I-0005 / implementationCryptography & computation

Attestable zero-knowledge inference prover

Attestable's zero-knowledge prover, which the company reports proves large language model outputs came from committed weights at tens of tokens per second.

Assessed use: proving an output came from committed weights

R1 Proposedlow confidence3 sources
M-0014 / mechanismIsolation & architecture

Bandwidth limits and compartmentalization

Capping or removing network links between groups of accelerators, so that serving within each group still works but large training across groups becomes far slower.

Assessed use: monitoring inter-node traffic with operator-run software on four GPUs

R2 Demonstratedlow confidence11 sources
I-0016 / implementationCryptography & computation

Batch-invariant inference kernels (Thinking Machines)

Open-source kernels from Thinking Machines Lab that make LLM outputs independent of batch size, adopted in vLLM and SGLang to give reproducible inference.

Assessed use: exact recomputation of served outputs by a verifier, with a cooperating provider

R2 Demonstratedlow confidence8 sources
M-0024 / mechanismIsolation & architecture

Bounding unexplained information in outputs

Limits the hidden information a facility's outputs can carry by measuring how much of those outputs the declared computation fails to predict.

Assessed use: bounding how much hidden information can leave in checked inference outputs

R2 Demonstratedlow confidence7 sources
M-0018 / mechanismAccounting & provenance

Chip location verification

Timing a chip's signed replies to trusted servers at known places, so that the speed of light bounds how far away the chip can be.

Assessed use: bounding how far a chip is from trusted landmark servers when checked

R1 Proposedmedium confidence10 sources
M-0019 / mechanismAccounting & provenance

Chip registries and manufacturing records

Recording each AI chip's identity and owner from the fab onwards, and cryptographically fixing manufacturing records, so that chips can be accounted for later.

Assessed use: a checkable record of which chips were made and who declared owning them

R1 Proposedmedium confidence10 sources
M-0025 / mechanismCryptography & computation

Confidential multi-party verification

Lets mutually distrusting parties run an agreed check over private models or records inside attested enclaves or zero-knowledge proofs, revealing only the result.

Assessed use: audits or evaluations of a private model that reveal neither party's inputs

R2 Demonstratedmedium confidence17 sources
M-0002 / mechanismCryptography & computation

Deterministic and bit-exact inference

Making model inference reproducible bit for bit, so that a verifier's re-run must match the provider's output exactly rather than approximately.

Assessed use: reproducing open-model inference from receipts in Gensyn's information-market service

R3 In productionlow confidence24 sources
I-0002 / implementationCryptography & computation

DiFR (Divergence From Reference)

DiFR checks that an inference provider ran its declared model by comparing output tokens or activations with a trusted re-run using the same random seed.

Assessed use: checking that outputs match the declared model, precision and sampling settings

R2 Demonstratedmedium confidence9 sources
I-0014 / implementationCryptography & computation

EZKL

EZKL is a library from Zkonduit that turns neural networks into zero-knowledge circuits, so a prover can show an output came from a committed model.

Assessed use: proving a language model's output follows from committed weights, against a cheating prover

R2 Demonstratedmedium confidence3 sources
M-0011 / mechanismOn-chip & hardware

Hardware performance throttling and licensing

On-chip mechanisms that cut an AI accelerator's performance when a license expires or a trusted trigger fires, bounding what the hardware can do.

Assessed use: performance limits a verifier can rely on, against an operator trying to bypass them

R1 Proposedmedium confidence9 sources
M-0009 / mechanismOn-chip & hardware

Hardware-enabled guarantees (flexHEG) and guarantee processors

Proposed chip add-ons, a guarantee processor inside a tamper-protected enclosure, that would check and enforce agreed rules on how AI accelerators are used.

Assessed use: checking and enforcing training-compute limits on chips, against adversaries up to states

R1 Proposedmedium confidence8 sources
I-0012 / implementationIsolation & architecture

Low-trust AI compute verification system overview

A retrofittable reference design in which network taps commit to all facility traffic, and air-gapped, independently sourced checkers later re-run randomly challenged records.

Assessed use: screening challenged records to show declared inference compute is not training

R1 Proposedmedium confidence2 sources
I-0009 / implementationAccounting & provenance

Lucid sovereignty (location) certificates

A draft specification, hosted by Lucid Computing, for short-lived certificates that bound where a workload runs by timing signed exchanges with fixed anchors.

Assessed use: certifying the region where an attested workload ran at a given time

R1 Proposedmedium confidence6 sources
M-0015 / mechanismIsolation & architecture

Memory wiping and proofs of secure erasure

Overwriting a device's memory in a way a verifier can check, so that data from earlier, undeclared work cannot persist in memory the wipe reaches.

Assessed use: showing that no data from earlier work persists in memory the wipe reaches

R1 Proposedmedium confidence8 sources
M-0012 / mechanismCryptography & computation

Model identity attestation

Establishes that responses come from a specific, committed set of model weights, using enclave measurements or recomputation of sampled outputs.

Assessed use: showing users that a service runs the declared model weights

Open critical flaw in source assessment
R3 In productionmedium confidence19 sources
M-0013 / mechanismOff-chip devices & sensors

Network taps and certifiers

Devices on a cluster's network links that copy and hash all traffic, so a verifier can later check sampled records against declared work.

Assessed use: committing a complete record of cluster traffic, so declared inference can be checked

R1 Proposedmedium confidence13 sources
M-0010 / mechanismOn-chip & hardware

On-chip telemetry from timing, memory and performance counters

Uses timing, memory-residency and performance-counter signals measured on AI accelerators as evidence about which workloads they are running.

Assessed use: workload evidence from GPU counters and timing, assuming authentic measurements

Open critical flaw in source assessment
R2 Demonstratedmedium confidence9 sources
I-0004 / implementationCryptography & computation

Pearl proof-of-useful-work blockchain

A blockchain whose mining is designed to be a by-product of GPU matrix multiplications in AI workloads, with public node and miner code.

Assessed use: checking matrix-multiplication work proofs for blockchain consensus

R3 In productionlow confidence8 sources
M-0007 / mechanismCryptography & computation

Proofs of useful work for capacity accounting

Cryptographic evidence that a given amount of matrix-multiplication work was completed, proposed as one input to accounting for spare capacity on declared hardware.

Assessed use: bounding the spare capacity of declared hardware that could run training

R1 Proposedlow confidence11 sources
I-0017 / implementationCryptography & computation

PySyft double-blind evaluations

PySyft coordinates an attested enclave where a model owner and evaluator run tests without sharing weights or private prompts.

Assessed use: evaluating a private model on private prompts, neither party seeing the other's inputs

R2 Demonstratedmedium confidence4 sources
I-0010 / implementationIsolation & architecture

RAND secure inference data center (SIDC) design

A RAND design for a purpose-built facility that serves already-trained AI models while protecting weights and inference data against state-level attackers.

Assessed use: the operator's own weight security, with no outside verification described

R1 Proposedlow confidence3 sources
M-0020 / mechanismRemote & side-channel sensing

Remote detection of data centres

Remote detection locates large data centres and estimates their power capacity without site access, using satellite imagery, heat signatures and public records such as permits.

Assessed use: finding undeclared data centres above an agreed compute threshold

R1 Proposedmedium confidence7 sources
M-0023 / mechanismCryptography & computation

Safeguard attestation

Hardware-signed evidence that an AI service ran its declared safeguards, such as a guardrail classifier or monitor, when producing a given response.

Assessed use: attesting that a declared safeguard mediated a service's responses

R2 Demonstratedlow confidence17 sources
M-0001 / mechanismCryptography & computation

Sampled inference recomputation

A verifier re-runs a random sample of an AI provider's logged queries on a trusted copy of the declared model and checks the outputs match.

Assessed use: checking untrusted workers' activations against the declared model, prompt and precision

R3 In productionlow confidence16 sources
I-0008 / implementationOff-chip devices & sensors

SASH confidential network logger

An open-source prototype that routes a facility's inference traffic through a logger and re-runs requests on a separate cluster to check it serves inference.

Assessed use: telling inference from training on a mutually inspected cluster

R1 Proposedmedium confidence3 sources
M-0022 / mechanismOff-chip devices & sensors

Side-channel suppression for isolated facilities

Shielding, filtering, jamming and inspecting an AI facility to limit hidden physical communication around monitored network links.

Assessed use: bounding physical covert channels out of a verified enclosure

R1 Proposedmedium confidence7 sources
M-0017 / mechanismOff-chip devices & sensors

Tamper evidence for verifier devices

Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating.

Assessed use: detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence

R2 Demonstratedmedium confidence14 sources
M-0008 / mechanismOn-chip & hardware

TEE remote attestation for AI workloads

Trusted execution environments (TEEs) in CPUs and GPUs sign reports of loaded software, so a remote party can check which code ran an AI workload.

Assessed use: showing which software ran to a party that distrusts the operator holding the hardware

Open critical flaw in source assessment
R3 In productionmedium confidence38 sources
M-0016 / mechanismCryptography & computation

Timed challenge-response and memory-occupation challenges

A verifier sends unpredictable questions that a device can answer in time only if it holds specified data, or dedicates specified resources, locally.

Assessed use: detecting whether a GPU is doing other work

R2 Demonstratedmedium confidence11 sources
I-0006 / implementationCryptography & computation

Tinfoil model identity (Modelwrap)

Tinfoil's method for proving which model weights its enclave-hosted inference service runs, by binding a dm-verity hash of the weights into remote attestation.

Assessed use: showing clients that the served weights match a committed hash

Open critical flaw in source assessment
R3 In productionmedium confidence9 sources
I-0001 / implementationCryptography & computation

TOPLOC

TOPLOC is a hashing scheme from Prime Intellect that lets a verifier check whether an inference provider ran the model, prompt and precision it claims.

Assessed use: checking that untrusted providers used the claimed model, prompt and precision

R3 In productionlow confidence10 sources
M-0006 / mechanismCryptography & computation

Training-transcript verification (proof-of-learning)

A trainer logs checkpoints, data order and settings, so a verifier can re-run sampled training segments and check that the claimed training happened.

Assessed use: checking from its transcript that a training run followed declared rules

Open critical flaw in source assessment
R2 Demonstratedmedium confidence10 sources
I-0015 / implementationCryptography & computation

Verde and RepOps (Gensyn)

Gensyn's system for checking delegated machine-learning jobs, which settles disagreements between providers by re-running a single operation with bitwise-reproducible operators.

Assessed use: reproducing declared-model inference from receipts in Gensyn's information-market service

R3 In productionlow confidence7 sources
M-0003 / mechanismIsolation & architecture

Whole-workload recomputation (reproducible packets)

Organizing all AI workloads in a facility into discrete, reproducible units, so that a verifier can recompute a random sample and check each one.

Assessed use: recomputing whole workloads to show a cluster runs only declared inference

R1 Proposedmedium confidence6 sources
M-0021 / mechanismRemote & side-channel sensing

Workload classification from telemetry and side channels

Telling whether chips are training, serving or doing non-AI work from GPU counters or power draw, signals that do not read weights or data.

Assessed use: telling training from inference and other work using genuine telemetry, including disguised workloads

R2 Demonstratedmedium confidence11 sources
M-0004 / mechanismCryptography & computation

Zero-knowledge proofs of inference

A prover produces a cryptographic proof that an output came from running a committed model on a given input, without revealing the weights.

Assessed use: proving a language model's output follows from committed weights, against a cheating prover

R2 Demonstratedmedium confidence15 sources
M-0005 / mechanismCryptography & computation

Zero-knowledge proofs of training constraints

Cryptographic proofs that a training run followed a committed dataset, procedure and rules, checkable without revealing the model or the data.

Assessed use: proving a training run followed a committed specification and data

R2 Demonstratedmedium confidence6 sources
I-0003 / implementationCryptography & computation

zkLLM

zkLLM is a GPU-accelerated zero-knowledge proof system that proves a large language model's output came from committed weights without revealing those weights.

Assessed use: proving an output came from committed weights, against a prover who cheats

R2 Demonstratedmedium confidence4 sources