Can the US and China verify an AI deal? Start-ups are starting to build the tools

Posted on

Researchers are developing technology to monitor AI development without relying on trust between Washington and Beijing

There are growing calls for Washington and Beijing to agree to slow down development of artificial intelligence. But even if they wanted to do so, how could they verify that the other side would do the same?

A group of researchers and start-ups is developing technology intended to make this a possibility, without relying on trust alone. Their proposed tools would allow third parties and governments to check some claims about how AI models are being trained or used – possibly without needing access to the AI models and infrastructure themselves.

This work is drawing attention ahead of Thursday’s meeting in Washington between US President Donald Trump and Chinese President Xi Jinping, at which AI is expected to be a topic of discussion. Still, advocates of the technology, known as “AI verification”, acknowledge that much work still needs to be done before the technology could be relied upon to monitor the vast computing facilities used to develop advanced AI.

Do you have questions about the biggest topics and trends from around the world? Get the answers with SCMP Knowledge, our new platform of curated content with explainers, FAQs, analyses and infographics brought to you by our award-winning team.

Nonetheless, they argue that a recent surge in interest from both policymakers and industry is likely to rapidly accelerate progress in the field.

“The level of interest has just kind of exploded in the last few weeks and months,” said Connor Dunlop, head of policy and strategy at San Francisco-based Lucid Computing, a leading AI verification start-up.

On Monday, leaders and representatives from 20 countries including Canadian Prime Minister Mark Carney and Singaporean Prime Minister Lawrence Wong issued a public letter that called for greater controls on frontier AI systems. The letter cited recent incidents in which cutting-edge AI systems from the likes of OpenAI and Anthropic circumvented safeguards and conducted cyberattacks.

The call to action proposed the creation of an international governance institution that could perform AI verification, without specifying how this should be done.

According to Tom Milton, co-founder of UK-based AI verification consultancy Amodo Design, there are two main claims that Washington and Beijing would likely want to be able to verify as part of any future international AI treaty: whether a data centre in the other country is training a new AI model or merely serving an existing one, and whether an AI model being served is the one it is purported to be.

The reason is that data centres only serving existing AI models – a process called inference – rather than training new ones would mean that the country is not advancing AI capabilities. Meanwhile, the governments might also want to verify that a data centre in the other country is running a model known to be safe instead of an unsafe one.

One proposed verification mechanism is called “recomputation”, in which an AI system’s outputs are checked by running the same calculation again on a different system, with the same inputs and settings, to see if the same result is achieved.

According to a report from the Machine Intelligence Research Institute, equipping data centres with such verification technology could only cost a small percentage of the facility’s upfront costs, given that the recomputation process would rely on commodity hardware. Compute costs arising from the verification process could also be kept low by only testing a small random sample of all AI activity in the facility.

Both Amodo and Lucid Computing have begun testing such solutions in real-world settings. Earlier this month, Lucid began 18 months of “adversarial” testing of its recomputation solution on a cluster of 16 Nvidia H100 semiconductor chips in Sweden, provided by the government-funded research institute RISE.

Amodo is also in talks to scale up its testing to a cluster of 128 graphics processing units (GPUs), said Milton. He acknowledged, however, that the field is still in its infancy, with the need to validate such solutions at the scale of cutting-edge data centres, which have hundreds of thousands of GPUs installed.

Political and commercial barriers also present a real challenge, with both China and the US pouring trillions of dollars into advancing their AI capabilities amid their fierce tech rivalry.

Chinese state media in recent weeks have dismissed US industry giants’ calls to “pace” the development of AI as efforts to entrench their industry-leading positions and suppress China’s AI development.

Bad blood between the two countries has affected proposed technical solutions to AI governance issues before. Beijing last year rebuffed suggestions that US chipmaking giant Nvidia could install technology in its chips to verify their location as part of efforts to comply with US export controls. Chinese officials feared the technology could be used by Washington to sabotage the country’s AI infrastructure.

Still, the first step would be to let politicians know that technical solutions to verify AI development are there if they want them, rather than have them wrongly believe that verification is impossible on a technical level, said Milton.

He pointed to US-Soviet nuclear arms control agreements in the 20th century, when the two countries overcame high levels of mutual distrust by using multiple verification mechanisms, including satellites and unique identifiers.

“Obviously the technology is not perfect yet … but it doesn’t have to be to help build early confidence that an agreement is possible,” said Milton.

Amid growing signals from industry and policymakers that such technology is needed, investors are also showing signs of interest. Last month, Israeli AI verification start-up Attestable raised US$20 million in seed funding with major investors including Silicon Valley hedge fund Altimeter Capital.

The firm is applying a cryptographic technique called “zero-knowledge proof” (ZKP) to its proposed verification solution, using mathematics instead of recomputation to allow parties to verify that a response to a query was provided by the exact AI model specified.

The technique, already used in blockchain technologies, is called “zero knowledge” because it does not reveal information about the underlying model or data. This could help allay the fears of governments and companies about leakage of sensitive information, said Miro Pluckebaum, founder of the Singapore AI Safety Hub (SASH).

“The sentiment within the research community is that something workable can be built within six to 12 months,” he said. “The myth as we see it is that verification would be impossible.”

SASH, a non-profit organisation based in the Asian city state, is trying to promote international collaboration on AI verification as early as possible to ensure that the field is not viewed as the exclusive tool of any country, said Pluckebaum.

While Beijing’s stance on AI verification remains unclear, Pluckebaum said that the open-source nature of the field’s early results would allow Chinese researchers to also test the underlying cryptographic techniques and contribute to their hardening.

Amodo, Lucid and SASH have all committed to open sourcing their research findings.

Growing signals from politicians that this technology is needed will also help with one of the field’s main bottlenecks today, which is a lack of talent, said Lucid’s Dunlop. He estimates that there are only around 50 people working on AI verification technology globally.

“I think there should probably be 100 times more people working on this, given what’s at stake,” he said.

Government support could also spur greater participation among leading tech giants. To underpin a global AI treaty, AI verification would require compatibility with the wide range of chip and model configurations available in the market today, covering not just US but also Chinese chips and frontier AI models from the likes of Huawei Technologies and DeepSeek.

“Ideally we would see many teams working on verification, both inside and outside frontier AI companies, trying out their solutions on as many different ‘stacks’ as possible,” said Dunlop.

Dunlop, Milton and Pluckebaum are all in New York this week at the United Nations General Assembly to explain their work to politicians and experts.

“There’s already been a lot of progress with an extremely small number of people working on this,” said Dunlop. “Let’s ramp that up and see how much more progress we can make.”

More Articles from SCMP

Donald Trump built a US$5 million White House helipad. Don’t expect Xi Jinping to use it

Paraguay’s president urges UN to let Taiwan in, calls island’s exclusion ‘a stain’

Marco Rubio defends Xi Jinping’s US visit as essential despite deep disagreements

Xi’s US visit begins with rare airport welcome from Trump, trade truce extension

This article originally appeared on the South China Morning Post (www.scmp.com), the leading news media reporting on China and Asia.

Copyright (c) 2026. South China Morning Post Publishers Ltd. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *