Every model evaluation, deployment monitor, and governance regime quietly assumes that chips compute faithfully. When that assumption fails, safety checks still pass while the system is corrupted. AICS makes the assumption explicit, measurable, and testable.
Compute is the most physically governable input to advanced AI. It is also the layer almost nobody is verifying. Four things make this a gap rather than a preference.
No easy way exists for a third party to confirm that a chip is what it claims to be, was made as specified, or reached its owner unaltered. Downstream, as inference spreads to private servers, consumer GPUs, and open-weight deployments, hardware-originating faults can degrade safety-relevant behaviour with nothing watching for it.
Leading firms already run rigorous pre-silicon validation and Design-for-Test flows — for their own reliability, privately. What is missing is an independent, affordable, publicly legible layer of assurance. Today, third parties and states must simply trust vendor self-attestation.
The compute supply-chain debate stays long on ambition and short on practical enforcement. Many proposals are technically weak or effectively unenforceable. Clear threat models and prioritisation frameworks are scarce, and there is no playbook for post-incident response.
Serious technical compute-security work is concentrated in the US and UK. Europe hosts the most critical chokepoint in the supply chain, yet has almost no dedicated organisational capacity on this question. Our advantage is credibility and chokepoint proximity — not market leverage, and we do not pretend otherwise.
Rather than one undifferentiated end-to-end domain, the work narrows into four focused streams — from design and fabrication, through datacenter operation, to deployment on heterogeneous hardware.
The funnel is simultaneously our research methodology and our cost-control mechanism. Each tier has distinct infrastructure, distinct unit costs, and distinct exit criteria — so the expensive, hardware-dependent work concentrates only on threats that survive scrutiny.
We map the entire threat space of the AI compute stack and hold nothing out. Also home to the standing watching brief on next-generation substrates — photonic, analog, quantum.
Only a prioritised shortlist enters simulation: open-source EDA flows, emulation, fault injection, and adversarial workload testing against representative designs.
Only the narrow subset whose results justify the cost of real hardware: FPGA and development-board demonstrations, small-scale bare-metal tests on commercial silicon.
Every project has a stated problem, deliverables, milestones with go/pivot/stop gates, success criteria, and an effort estimate. Several are framed so that a well-evidenced negative result is a genuine deliverable rather than a failure.
We would rather a funder learn our uncertainties from us than discover them unaided. Each question below is load-bearing for some part of the agenda, each has a stated way of being resolved, and in several cases a negative answer would be a publishable result that redirects the field. Being able to say clearly which parts of an agenda are not yet known to work is a marker of technical seriousness, not a weakness in the proposal.
A small but growing set of organisations works at the hardware layer. This work is valuable and we expect to collaborate with much of it — our differentiation is a matter of layer and posture, not a claim that others are doing it wrong.
Investigates how oversight and verification can be embedded at the hardware layer, with an emphasis on design profiles. Our founder authored its inaugural paper on verifiable semiconductor manufacturing. We differentiate by moving from design research into empirical engineering — building and testing the artefacts.
Runs fellowships and programmes, including a dedicated hardware assurance track, that move engineers into assurance and compute-governance work. AICS is a natural downstream home for that talent and a collaborator on programming; our output is research and hardware rather than training.
Builds cryptographic attestation and compute-tracking software oriented to export-control compliance and data residency, operating primarily at the software and orchestration layer. Complementary to us: their work, like most verification efforts, verifies what runs inside the system. We work on the layer beneath.
Designs and builds hardware for AI verification on a project basis for startups, universities, and funders. The closest neighbour to our technical programme and a natural collaborator. We differ in being an institution that owns a sustained, end-to-end research agenda rather than executing discrete builds.
Credible upstream verification cannot be built without the people who make the hardware. Both founders come directly out of the core semiconductor chokepoints.
Combines technical, industrial, and policy experience across the domains this work must bridge: electronics and AI; technology-policy work at NATO Headquarters; semiconductor and lithography-adjacent work at ASML across Europe and the US; and AI-governance research on verifiable semiconductor manufacturing — he authored the inaugural paper of Oxford's Hardware & AI Governance group.
Leads the technical research programme overall: testbed architecture and experimental design, technical hiring and supervision, and representation in technical and standards venues. Oversees the four technical programs and the fellowship programme.
A tiered, risk-mitigated structure over 24 months. The core base funds the institute and its research programme; the additive stretch funds the physical lab and modern accelerator hardware that make bare-metal work possible at all.
Figures are indicative and subject to change. AICS is being established as a Netherlands Stichting and intends to pursue ANBI public-benefit status, which supports both philanthropic giving and access to non-profit research licensing for EDA tooling.
We are talking with philanthropic funders, semiconductor partners, and researchers who want to work at this layer. If you are interested in the space — whether to fund it, build with it, or join it — we would like to hear from you.