Geoffrey Irving Outlines Three-Layer Approach for AI Treaty Verification

Geoffrey Irving suggests that AI treaty verification technology could become indispensable under two scenarios: an international agreement to slow or pause AI development, or a highly "fragile state" induced by the expansion of superintelligence. He categorizes the verification approach into three tiers and calls on experts in hardware, security, and cryptography to collaborate on this engineering challenge.

Confirmed

Irving explicitly divides AI treaty verification technology into three tiers:

1. **Pragmatic**: Real-world methods that do not directly inspect running code. Specific measures include data center inspections, hardware location tracking, chip controls and constraints, and chip designs that make training more difficult than inference.

2. **Enclaves**: Verification using secure enclave technology. However, this approach has clear limitations, as most computations remain unencrypted. It is vulnerable to side-channel attacks (such as timing analysis) and strong physical attacks (like high-magnification microscopy), potentially leading to the leakage of keys or model weights.

3. **Math**: Verification methods based on mathematical and cryptographic principles.

Why it matters

The author emphasizes that AI treaty verification is transitioning from a purely theoretical discussion to an engineering problem that must be solved in the near future. As AI capabilities continue to surge, establishing practical verification mechanisms is a critical prerequisite for ensuring the implementation of safety protocols.

2026-07-25 ~ 2026-07-25 · 5 related posts

Primary sources