Security risks from AI have motivated calls for international agreements that guardrail the technology. However, even if states could agree on what rules to set on AI, the problem of verifying compliance might make these agreements infeasible. To help clarify the difficulty of verifying agreements on AI$\unicode{x2013}$and identify actions that might reduce this difficulty$\unicode{x2013}$this report examines the case study of verification in nuclear arms control. We review the implementation, track records, and politics of verification across three types of nuclear arms control agreements. Then, we consider implications for the case of AI, especially AI development that relies on thousands of highly specialized chips. In this context, the case study suggests that, with certain preparations, the foreseeable challenges of verification would be reduced to levels that were successfully managed in nuclear arms control. To avoid even worse challenges, substantial preparations are needed: (1) developing privacy-preserving, secure, and acceptably priced methods for verifying the compliance of hardware, given inspection access; and (2) building an initial, incomplete verification system, with authorities and precedents that allow its gaps to be quickly closed if and when the political will arises.
翻译:人工智能带来的安全风险催生了通过国际协定为该项技术设立防护栏的呼声。然而,即便各国能够就人工智能的规则达成共识,履约核查难题仍可能使这些协定难以付诸实施。为阐明人工智能协定核查的难度,并识别可能降低难度的行动,本报告以核军控核查作为案例研究。我们梳理了三类核军控协定的实施过程、执行记录及政治因素,继而探讨其对人工智能领域的启示——尤其针对依赖成千上万枚高度专业化芯片的人工智能研发。案例研究表明:若能做好特定准备,核军控中已成功管控的核查挑战水平同样可适用于人工智能领域。为避免更严峻的挑战,需要开展实质性准备工作:(1)在允许现场检查的前提下,开发保护隐私、安全且价格合理的硬件合规核查方法;(2)构建初始的不完全核查体系,使其具有相应的权威性和先例依据,以便在政治意愿出现时能够迅速填补漏洞。