Compute Verification Track · Course 2 of 2

Compute Verification 2

How mature hardware verification really is, what cloud records prove, and how a determined actor evades it all. The advanced second half of the compute verification track.

Next cohortDates TBA
Intensive
1 week, Mon–Fri
Part-time
3 weeks
Workload
25 hours, 5 per module
Format
Online, facilitated groups
Included
Lens AI Coach

About this course

Compute Verification 1 argued that an AI slowdown agreement must be checkable, and worked out what it would say and whom it would bind. This course is about the checking itself: what cloud records, satellites, insiders, and inspections can honestly establish, and what a determined evader does to each of them.

The first three units each take one stream of evidence: hardware and cloud records, intelligence, and the human layer of insiders, whistleblowers, and audits. The last two put the picture under adversarial pressure. You’ll read a published low-trust architecture for verifying compute use closely, then work a taxonomy of evasion routes into a red team review of what that architecture can enforce.

This course assumes Compute Verification 1 and starts from its results. The capstone, where you rank the mechanisms by feasibility and design a verification regime of your own, is a separate course that follows.

Who is it for:

Engineers (hardware or software)

You want to know which verification mechanisms are ready to deploy, which are still prototypes, and how an adversary would attack each one.What is ready to deploy, and how it breaks.

Researchers

You want to find where a verification architecture's conclusion outruns its evidence, and which gaps are worth a research project.Find the gaps worth researching.

Policy people

You work on AI governance, intelligence, or arms control and want to know what each evidence stream can prove before a treaty relies on it.Know what evidence can prove before a treaty relies on it.

Fieldbuilders

You build communities, programs, or organizations and want to see where verification work is still missing and who could do it.See where verification work is still missing.

Curriculum

5 UNITS · ~5H EACH

All source material is online. Each unit combines close reading, interactive exercises, and written assessments with a group discussion.

01

Hardware judgment and cloud records

Separate where hardware verification actually stands from where a demo suggests it stands, and write a hardware assurance brief for a delegation weighing a three-month pause. Then turn to the cloud: what billing, identity, and workload records can prove about a training run, and how know-your-customer rules moved from finance to compute.

02

Cloud limits and intelligence

Find where cloud oversight runs out, and practise stopping at what a record proves. Then take up intelligence: the signatures of an undeclared training run, who has found undeclared facilities in the past, how a signal becomes an assessment, and treaty text that protects sensors but obliges nobody to share. You red-line that text yourself.

03

The human layer

The cheapest verification tools to deploy, and the easiest to fool. Examine insiders and source credibility, whistleblower protections and the route a report must survive, audits and inspections and the limits on what they can find, and who finds, who judges, and who enforces.

04

Covert development and the low-trust architecture

Take apart a worked evasion, where the aim is to make operations inconclusive rather than invisible. Then read a published proposal for verifying AI compute use between parties who do not trust each other: reconstruct its argument, trace evidence from chip to verdict, and find where the conclusion outruns the proof.

05

Evasion routes and the red team review

Learn why defining cheating comes before detecting it, and why layered defences only work when the layers fail differently. Work through ten routes around an agreement, then write an expert review of which treaty obligations the architecture can carry and which it cannot touch.

Course Outcomes

Judge hardware maturity

Separate demonstrated hardware verification from proposals and prototypes, and brief decision-makers on what they can rely on today.

Read cloud records precisely

State exactly what billing, identity, and workload records and know-your-customer schemes prove about a training run, and what they leave open.

Assess intelligence evidence

Explain which signatures could reveal an undeclared training run, how a signal becomes an assessment, and what treaty text does and does not require states to share.

Weigh human sources and inspections

Judge insider reports, whistleblower channels, audits, and inspections by what they can establish and how they can be fooled.

Critique a verification architecture

Trace a proposed low-trust system from chip to verdict, and find the step where its conclusion outruns its evidence.

Red-team an agreement

Map evasion routes against a draft treaty, and write a review of which obligations can be verified and which cannot.

Upcoming cohorts

INTENSIVE

5h/day · 1 week

Dates to be announcedWe’ll publish the next intensive cohort here.

PART-TIME

5h/week · 3 weeks

Dates to be announcedWe’ll publish the next part-time cohort here.

Common questions

Not sure it’s for you? Come to the first session. If it’s not the right fit, we’ll help you find something that is.

Don’t wait 3 months for a 5% acceptance rate.

Upskill now

Compute Verification 2

Apply