Engineers (hardware or software)
You want to know which verification mechanisms are ready to deploy, which are still prototypes, and how an adversary would attack each one.What is ready to deploy, and how it breaks.
Compute Verification Track · Course 2 of 2
How mature hardware verification really is, what cloud records prove, and how a determined actor evades it all. The advanced second half of the compute verification track.
Compute Verification 1 argued that an AI slowdown agreement must be checkable, and worked out what it would say and whom it would bind. This course is about the checking itself: what cloud records, satellites, insiders, and inspections can honestly establish, and what a determined evader does to each of them.
The first three units each take one stream of evidence: hardware and cloud records, intelligence, and the human layer of insiders, whistleblowers, and audits. The last two put the picture under adversarial pressure. You’ll read a published low-trust architecture for verifying compute use closely, then work a taxonomy of evasion routes into a red team review of what that architecture can enforce.
This course assumes Compute Verification 1 and starts from its results. The capstone, where you rank the mechanisms by feasibility and design a verification regime of your own, is a separate course that follows.
You want to know which verification mechanisms are ready to deploy, which are still prototypes, and how an adversary would attack each one.What is ready to deploy, and how it breaks.
You want to find where a verification architecture's conclusion outruns its evidence, and which gaps are worth a research project.Find the gaps worth researching.
You work on AI governance, intelligence, or arms control and want to know what each evidence stream can prove before a treaty relies on it.Know what evidence can prove before a treaty relies on it.
You build communities, programs, or organizations and want to see where verification work is still missing and who could do it.See where verification work is still missing.
All source material is online. Each unit combines close reading, interactive exercises, and written assessments with a group discussion.
Separate where hardware verification actually stands from where a demo suggests it stands, and write a hardware assurance brief for a delegation weighing a three-month pause. Then turn to the cloud: what billing, identity, and workload records can prove about a training run, and how know-your-customer rules moved from finance to compute.
Find where cloud oversight runs out, and practise stopping at what a record proves. Then take up intelligence: the signatures of an undeclared training run, who has found undeclared facilities in the past, how a signal becomes an assessment, and treaty text that protects sensors but obliges nobody to share. You red-line that text yourself.
The cheapest verification tools to deploy, and the easiest to fool. Examine insiders and source credibility, whistleblower protections and the route a report must survive, audits and inspections and the limits on what they can find, and who finds, who judges, and who enforces.
Take apart a worked evasion, where the aim is to make operations inconclusive rather than invisible. Then read a published proposal for verifying AI compute use between parties who do not trust each other: reconstruct its argument, trace evidence from chip to verdict, and find where the conclusion outruns the proof.
Learn why defining cheating comes before detecting it, and why layered defences only work when the layers fail differently. Work through ten routes around an agreement, then write an expert review of which treaty obligations the architecture can carry and which it cannot touch.
Separate demonstrated hardware verification from proposals and prototypes, and brief decision-makers on what they can rely on today.
State exactly what billing, identity, and workload records and know-your-customer schemes prove about a training run, and what they leave open.
Explain which signatures could reveal an undeclared training run, how a signal becomes an assessment, and what treaty text does and does not require states to share.
Judge insider reports, whistleblower channels, audits, and inspections by what they can establish and how they can be fooled.
Trace a proposed low-trust system from chip to verdict, and find the step where its conclusion outruns its evidence.
Map evasion routes against a draft treaty, and write a review of which obligations can be verified and which cannot.
5h/day · 1 week
5h/week · 3 weeks
Not sure it’s for you? Come to the first session. If it’s not the right fit, we’ll help you find something that is.
Compute Verification 2