Stichting in formation · Eindhoven, NL

Everyone verifies what runs
inside the system.
We verify the hardware itself.

Every model evaluation, deployment monitor, and governance regime quietly assumes that chips compute faithfully. When that assumption fails, safety checks still pass while the system is corrupted. AICS makes the assumption explicit, measurable, and testable.

Fig. 01 — Scan chain through observation points
€5.90M
Total ask / 24 months
4
Research streams
16
Scoped projects
22FTE
Headcount at year 2
The gap

The least examined layer of AI safety

Compute is the most physically governable input to advanced AI. It is also the layer almost nobody is verifying. Four things make this a gap rather than a preference.

01

Trust across the whole lifecycle

No easy way exists for a third party to confirm that a chip is what it claims to be, was made as specified, or reached its owner unaltered. Downstream, as inference spreads to private servers, consumer GPUs, and open-weight deployments, hardware-originating faults can degrade safety-relevant behaviour with nothing watching for it.

02

Verification is unaffordable and opaque

Leading firms already run rigorous pre-silicon validation and Design-for-Test flows — for their own reliability, privately. What is missing is an independent, affordable, publicly legible layer of assurance. Today, third parties and states must simply trust vendor self-attestation.

03

Governance without enforcement

The compute supply-chain debate stays long on ambition and short on practical enforcement. Many proposals are technically weak or effectively unenforceable. Clear threat models and prioritisation frameworks are scarce, and there is no playbook for post-incident response.

04

Geographically neglected

Serious technical compute-security work is concentrated in the US and UK. Europe hosts the most critical chokepoint in the supply chain, yet has almost no dedicated organisational capacity on this question. Our advantage is credibility and chokepoint proximity — not market leverage, and we do not pretend otherwise.

Research streams

Four programs, mapped to the compute lifecycle

Rather than one undifferentiated end-to-end domain, the work narrows into four focused streams — from design and fabrication, through datacenter operation, to deployment on heterogeneous hardware.

Method

A three-tier funnel, broad at the top

The funnel is simultaneously our research methodology and our cost-control mechanism. Each tier has distinct infrastructure, distinct unit costs, and distinct exit criteria — so the expensive, hardware-dependent work concentrates only on threats that survive scrutiny.

Tier 1 · Comprehensive

Taxonomy, mapping & prioritisation

We map the entire threat space of the AI compute stack and hold nothing out. Also home to the standing watching brief on next-generation substrates — photonic, analog, quantum.

Exits when: a threat is safety-relevant, has a credible technical mechanism, and a possible defense pathway.
Tier 2 · Shortlisted

Simulation & verification

Only a prioritised shortlist enters simulation: open-source EDA flows, emulation, fault injection, and adversarial workload testing against representative designs.

Exits when: simulation shows measurable impact and a plausible mitigation. Useful negative results exit as published findings.
Tier 3 · Narrow

Prototype demonstration

Only the narrow subset whose results justify the cost of real hardware: FPGA and development-board demonstrations, small-scale bare-metal tests on commercial silicon.

Exits when: a defense is demonstrated concretely enough to be adopted by someone else.
Portfolio

Sixteen scoped projects

Every project has a stated problem, deliverables, milestones with go/pivot/stop gates, success criteria, and an effort estimate. Several are framed so that a well-evidenced negative result is a genuine deliverable rather than a failure.

Intellectual honesty

What we don't yet know

We would rather a funder learn our uncertainties from us than discover them unaided. Each question below is load-bearing for some part of the agenda, each has a stated way of being resolved, and in several cases a negative answer would be a publishable result that redirects the field. Being able to say clearly which parts of an agenda are not yet known to work is a marker of technical seriousness, not a weakness in the proposal.

Landscape

Where we sit, and who we work with

A small but growing set of organisations works at the hardware layer. This work is valuable and we expect to collaborate with much of it — our differentiation is a matter of layer and posture, not a claim that others are doing it wrong.

Oxford HAIGL

Academic & policy translation

Investigates how oversight and verification can be embedded at the hardware layer, with an emphasis on design profiles. Our founder authored its inaugural paper on verifiable semiconductor manufacturing. We differentiate by moving from design research into empirical engineering — building and testing the artefacts.

Cambridge AI Safety Hub

Talent & field-building

Runs fellowships and programmes, including a dedicated hardware assurance track, that move engineers into assurance and compute-governance work. AICS is a natural downstream home for that talent and a collaborator on programming; our output is research and hardware rather than training.

Lucid Computing

Commercial verification vendor

Builds cryptographic attestation and compute-tracking software oriented to export-control compliance and data residency, operating primarily at the software and orchestration layer. Complementary to us: their work, like most verification efforts, verifies what runs inside the system. We work on the layer beneath.

Amodo Design

Hardware engineering consultancy

Designs and builds hardware for AI verification on a project basis for startups, universities, and funders. The closest neighbour to our technical programme and a natural collaborator. We differ in being an institution that owns a sustained, end-to-end research agenda rather than executing discrete builds.

Team

Founder–market fit at the chokepoint

Credible upstream verification cannot be built without the people who make the hardware. Both founders come directly out of the core semiconductor chokepoints.

Aytunc Ilhan

Founder & Executive Director

Combines technical, industrial, and policy experience across the domains this work must bridge: electronics and AI; technology-policy work at NATO Headquarters; semiconductor and lithography-adjacent work at ASML across Europe and the US; and AI-governance research on verifiable semiconductor manufacturing — he authored the inaugural paper of Oxford's Hardware & AI Governance group.

Mert Koc

Co-founder & Head of Research

Leads the technical research programme overall: testbed architecture and experimental design, technical hiring and supervision, and representation in technical and standards venues. Oversees the four technical programs and the fellowship programme.

Funding

What the ask buys

A tiered, risk-mitigated structure over 24 months. The core base funds the institute and its research programme; the additive stretch funds the physical lab and modern accelerator hardware that make bare-metal work possible at all.

  • A micro-scale datacenter pod built for physical fidelity rather than throughput — 4–16 contemporary GPUs and 4–10 high-RAM CPU nodes. We are not trying to out-build commercial clouds; we are trying to make findings transfer to the silicon frontier models actually run on.
  • Air-gapped infrastructure because discovering hardware vulnerabilities generates real dual-use infohazards, and because standard cloud terms of service prohibit the physical fault injection this research requires.
  • CPU-heavy EDA simulation — RTL and gate-level co-simulation is bound by single-thread performance and memory, not GPUs, so it needs dedicated provisioning.
  • Phased headcount — core technical staff in Year 1 at roughly 16 FTE lines, expanding to 22 in late Year 2 once foundational simulation research is stable.
  • Salaries benchmarked against industry, not against NGOs. Recruiting semiconductor engineers away from ASML, NXP, and frontier labs is the whole staffing thesis.
Core base €4.48M
Additive stretch — lab & accelerators €1.42M
Total over 24 months €5.90M

Figures are indicative and subject to change. AICS is being established as a Netherlands Stichting and intends to pursue ANBI public-benefit status, which supports both philanthropic giving and access to non-profit research licensing for EDA tooling.

Get involved

The hardware layer needs an institution

We are talking with philanthropic funders, semiconductor partners, and researchers who want to work at this layer. If you are interested in the space — whether to fund it, build with it, or join it — we would like to hear from you.