Geoffrey Irving Outlines Three-Layer Approach to AI Treaty Verification
Geoffrey Irving suggests that AI treaty verification is evolving from a theoretical concept into a pressing engineering challenge for the near future. He identifies two scenarios where this tech becomes indispensable: an international treaty to slow or pause AI, or a superintelligence bringing the world into a highly "vulnerable state." He calls on experts in hardware, security, and cryptography to collaborate.
Confirmed
Irving categorizes AI treaty verification into three distinct layers, noting their current status and limitations:
- Pragmatic: Real-world methods that do not directly inspect running code. This includes data center inspections, hardware location tracking, chip controls, and chip designs that make training harder than inference. Irving views this as the actionable direction for the present.
- Enclaves: Verification using secure enclaves. However, this approach has clear limitations: most computations remain unencrypted, and the system is vulnerable to side-channel attacks (like timing analysis) and strong physical attacks (such as high-magnification microscopes), potentially leaking keys or model weights.
- Math: Verification based on mathematical and cryptographic principles. The goal is to use circuit obfuscation to render microscope attacks irrelevant, proposing the use of Fully Homomorphic Encryption (FHE) for non-linear parts and custom techniques for matrix multiplication. Irving admits this route still suffers from performance overheads several orders of magnitude too high to be practical.
Unconfirmed
There are differing estimates regarding the ultimate performance overhead of the purely cryptographic route. Irving cites cryptographers suggesting that even a thousand years from now, the speed penalty for optimally obfuscated neural network inference might only be 2 to 10 times. While acceptable if superintelligence drives collaboration, this contrasts sharply with current pessimistic industry expectations.
Why it matters
As AI capabilities surge, establishing practical verification mechanisms is a prerequisite for enforcing safety agreements. Defining the engineering boundaries and bottlenecks of different verification routes helps guide targeted, cross-disciplinary collaboration.
2026-07-25 ~ 2026-07-25 · 7 related posts
Primary sources
- AI treaty verification is becoming an engineering problem with pragmatic, enclave, and math layers — geoffreyirving ·
- AI treaty verification may need pragmatic hardware checks before “math” solutions — geoffreyirving ·
- Pragmatic AI verification can rely on datacenter checks, chip controls, and tracking — geoffreyirving ·
- [source] AI treaty verification may need pragmatic hardware checks before “math” solutions — geoffreyirving · 2026-07-25
- [source] Pragmatic AI verification can rely on datacenter checks, chip controls, and tracking — geoffreyirving · 2026-07-25
- [source] AI treaty verification is becoming an engineering problem with pragmatic, enclave, and math layers — geoffreyirving · 2026-07-25
- Secure enclaves may still leak keys and weights through side channels or microscopy — geoffreyirving · 2026-07-25
- Pure cryptographic obfuscation for AI verification still costs multiple orders of magnitude — geoffreyirving · 2026-07-25
- Cryptographers think obfuscated neural nets may only cost 2–10× even in the long run — geoffreyirving · 2026-07-25
- AI treaty verification may need three layers: pragmatic checks, enclaves, and math — geoffreyirving · 2026-07-25