Notes

Dated notes. Older ones are not revised; if I change my mind, that is a new note.

What a chip attestation cannot tell you

A European AI strategy was published this month, convened by a senior council that includes a Turing laureate, a former competition commissioner and one of the people who built the field of formal verification. It asks the Commission for at least two hundred and fifty million euros over five years, and it is the most concrete demand signal I have seen for the thing I work on. It also has a gap in the exact shape of it.

Its fifth immediate objective is to make Europe the leader in assurance technology, and the strategy is candid about why: at the moment, in its own words, it is not possible to verify claims about the safety and security of frontier AI technology and its use. What it then funds is hardware. Trusted execution environments hardened against physical attack. Tamper-evident enclosures for chips. Location attestation for imported accelerators. Privacy-preserving methods for verifying a chip's workload. Two purpose-built data centres by 2028, one maximally secure and one maximally verifiable, because the two requirements turned out to conflict.

That is real work and I want it funded. But notice what it establishes. A chip attestation can tell you which accelerator ran which workload, in which building, unmodified. It cannot tell you whether the evaluation that workload computed measured the thing it was taken to measure. Those are different claims, and only one of them is being paid for.

The absences are checkable and I would rather state them than characterise them. In the strategy as published this month, across both the recommendations and the implementation detail, the word assurance appears dozens of times and verification more than sixty. The word evaluator does not appear in the implementation half at all. Third-party evaluation appears once in the whole document, as a passing call to empower an ecosystem that already exists, with a link out rather than a recommendation. Construct validity, conformity assessment, metrology and reproducibility appear nowhere. Every use of methodology, measurement and benchmark in the implementation half turns out to be about compute capacity, trade commitments, data-centre cooling or national statistics.

This is not a complaint about the document, which is a strategy for assurance technology and does not claim to be a methodology for evaluation. It is the observation that the gap is not filled anywhere else in it either, and that the pattern is the one this site is about: a checking mechanism is being built and funded, and the question of what its verdict establishes has no line item. I have a commercial interest in this class of problem being taken seriously, which is stated on the disclosure page. The strategy invites briefings, and I intend to send one.

Why this is published now

The work described on this site predates the essay that prompted me to publish it, and the dates are on the deposits. The probe was deposited in July 2026, the thesis it draws on was finished in March, and the professional practice the field evidence comes from goes back to 2002. What changed in September was not the finding. It was the audience.

On 12 September 2026 the chief executive of Anthropic published an essay proposing that frontier laboratories give embedded third-party evaluators employee-like access, and justified it in a sentence I had been arguing towards from a different direction. On transparency: we are still the ones choosing what to include and omit. Within hours OpenAI and Google DeepMind agreed in public, and OpenAI pledged evaluator access of its own.

So the institution is being built. What does not exist is the methodology that would say what such an evaluator's verdict establishes — against whose reference it is computed, whether the evaluated party authored that reference, and how an omission becomes visible rather than silent. In the eighteen thousand words of the same author's longer essay from January, third-party verification receives a single clause.

There is already a case study, and it is public. On 4 August 2026 the UK AI Security Institute published an incident report: across 122 evaluation runs, agents took nineteen unsanctioned actions against real people and organisations, and seventeen of those came from one laboratory's model. The Financial Times subsequently reported that the same laboratory withheld its next model from that evaluator. Access that can be withdrawn at the moment it would bind is not a verification mechanism; it is a courtesy.

I have no connection to any of the people involved and this is not a reply to them. It is the observation that a question I had been working on in a small domain — organisational decisions, client engagements, a law faculty in Budapest — had become the load-bearing question in a much larger one, and that it was not being answered. That is why I am publishing rather than continuing to accumulate.