As a user
- Know which AI answered you
- See what your agent may do
- Receipts anyone can check
Research prototype
Proofs can show which model answered, and would show how chips were used.
Compute limits hold only if use is checked.
Customers could check which model answered them.
No enclaves or chip-maker keys, just rented GPUs.
How it works
Every GPU is listed; the list caps compute.
The list sets the ceiling in step 6. Nobody inspects the hall, so a complete list is a premise, not a check.
The checker fingerprints the approved weights. Every proof must match.
Proofs are checked against the checker's own fingerprint; that it fingerprinted the real published checkpoint is a premise. The proof covers an integer version of the model; how closely it matches the released model is not measured yet. A verifier flaw found on 29 Sep is fixed (reviewed), and earlier proofs are being re-checked with the fixed verifier; until then they count .
A recorder seals every exchange in order, so none can be removed later.
Each entry seals the one before it, so an edit breaks every later seal. Today the log and its signed checkpoints stay inside the recorder: outside witnesses are built but not tested yet. Traffic that skips the recorder isn't covered.
After sealing, random answers are picked and proven.
Picking after sealing means the operator can't know which answers get checked. Our zero-knowledge proof of a 7B model took on an 8-core cloud CPU.
| Answers proven | Fake answers it takes |
|---|---|
| 1 in 100 | 459 |
| 1 in 1,000 | 4,603 |
| 1 in 10,000 | 46,050 |
A nearby landmark would time each reply. Light is only so fast, so a quick reply means nearby work.
Light covers per millisecond of round trip, so a deadline allows at most . No landmark exists yet: these are sizing numbers, and the landmark's position would be trusted.
Proven work is weighed against capacity. The gap would be published.
The bound holds only if its premises hold: a complete GPU list, the recorder as the only way in, and work and capacity counted in the same units. Publishing to outside witnesses is built but not tested yet.
A scripted replay. Every answer carries a sample receipt.
Every answer carries a sample receipt. Tap one to see what it would check.
Usually not. A fixed-term lease normally locks the rent until it ends, unless the lease itself has a clause that allows increases during the term.
Check your lease for a rent review or escalation clause. If there isn't one, you can reply in writing that the current rent stands until March, and ask them to point to the clause they rely on.
Here's a reply. I'll send it from your email once you approve it.
Dear [landlord's name], Thank you for your letter of 20 September. My lease runs until March and doesn't include a clause allowing rent changes during the term, so I'll keep paying the current rent until then. If you believe a clause allows the increase, please point me to it. Kind regards, [your name]
Nothing was sent: this is a scripted demo.
Not sent. You chose not to send it.
This sample would read
Answered 14:02 · proof checked 14:54 (sample)
A sample receipt shows what a live one would carry. Nothing was proven for this answer: Mistral-7B-v0.1, the model our proof covers, did not write these scripted answers.
3 checks: 3 partly built.
What it would check
Limited: At least one check rests on a premise, has no evidence yet, or is not built.
A verifier flaw found on 29 Sep is fixed (reviewed); until earlier proofs are re-checked with the fixed verifier, they count . The target is or more.
A zero-knowledge proof of a 7B model took on an 8-core CPU, so answers are proven at random, and a picked answer's proof would reach its receipt later. The receipt would still read Limited: model identity rests on the premise that admission fingerprinted the real model.
The proof covers an integer version of the model; how closely it matches the released model is not measured yet.
What a receipt can't tell you:
This sample would read
Approved 14:07 · sent 14:07 · proof checked 14:58 (sample)
A sample receipt shows what a live one would carry. Nothing was proven for this answer: Mistral-7B-v0.1, the model our proof covers, did not write these scripted answers.
10 checks: 4 partly built, 6 preview only.
What it would check
Limited: At least one check rests on a premise, has no evidence yet, or is not built.
A verifier flaw found on 29 Sep is fixed (reviewed); until earlier proofs are re-checked with the fixed verifier, they count . The target is or more.
A zero-knowledge proof of a 7B model took on an 8-core CPU, so answers are proven at random, and a picked answer's proof would reach its receipt later. The receipt would still read Limited: model identity rests on the premise that admission fingerprinted the real model.
The proof covers an integer version of the model; how closely it matches the released model is not measured yet.
What a receipt can't tell you:
Against published provers
One planned cluster, as it would be checked hour by hour. Sample data.
of capacity could have gone to unexplained work, if the premises hold.
Last 14 hours
Deadline , so work stays within . GPU 4 missed one deadline, so it earns no credit this hour.
Why it matters for existential risk
Frontier AI built out of sight cannot be paced. Checkable compute could let rivals slow down together, and know it.
The pathway this is meant to cut. When no party can check another's restraint, each has a reason to keep racing, and a race leaves less time to build and test safeguards against the most severe risks from advanced AI, including losing control of it (Armstrong, Bostrom and Shulman 2016; Wasil, Reed, Miller and Barnett 2024).
This is an argument, not a result: whether checkable compute slows frontier progress is a question this system cannot answer. Compute-focused governance: Shavit 2023, arXiv 2303.11341.
The bound can't tell customer traffic from the operator's own. Inference on the admitted model counts as explained, even if it feeds capability work such as generating training data. It bounds other uses of the chips, such as undeclared training.
The proofs run. A verifier flaw found on 29 Sep is fixed (reviewed), and earlier proofs are being re-checked with the fixed verifier; until then they count . We would call or more production strength.
Light covers per millisecond of round trip, so a deadline allows at most . No landmark has been built, so the timings here are sample values.
We hid extra useful work in the unused rows of one GPU kernel. The timing check never caught it, and never raised a false alarm. Caught: 0 of 60 trials, at each of 4 amounts.
So timing alone is not evidence of how chips were used: the site bounds unexplained work with proofs and names what the bound assumes. What didn't work
A demo check run by Lucid; in practice an independent verifier would run it. In this demo Lucid would run every role: the cluster, the recorder, the landmark, the verifier and the log witnesses. Today only the recorder and verifier software exist, and Lucid runs both. The proofs show what was computed; they can't show that separate parties agree. An outside witness or landmark operator would change that.