Middle Powers Should Invest in AI Verification

Summary
- Call for action: World leaders are calling for ways to verify frontier AI models and for the US and China to strike an AI deal.
- Small field: The technology required to verify an international AI agreement is still young, with only about 50 people globally working in the field.
- Win-win: The same tools that could one day enable an AI treaty could more immediately help middle powers gain visibility into AI models running in their jurisdictions.
- Recommendations: Middle powers should fund verification research, run government pilots, and write verification requirements into data centre licensing rules.
On 21 September, leaders and ministers from over 25 countries and the European Union signed an open letter calling for control of frontier AI models. One of its asks was for “an international institution, able to set standards, enable verification, and convene states when capability thresholds are crossed”. Days earlier, Australian Prime Minister Albanese called for the US and China to strike an AI deal “in the interests of humanity”.
For middle powers, verification technology could serve two key objectives. First, it could help them retain oversight of AI models running in their territories. Second, it could lay the groundwork for a future agreement between the US and China to slow down AI development.
However, the technology is still nascent and the field developing it is greatly understaffed. Middle powers should start investing in it now.
How AI verification works
AI verification is about gathering enough evidence to determine whether another party is complying with an agreement, while revealing as little other sensitive information as possible.
One verification mechanism involves using the AI chips themselves to generate evidence. For example, modern AI chips can run a workload inside Trusted Execution Environments (TEEs) – a sealed-off part of the chip that even the machine's owner cannot see into. The chip can provide a signed statement saying exactly what code and model weights were loaded into that sealed region.
Other tools involve retrofitting equipment onto data centres or using specialised software to monitor their activity. For example, power metering tools or privacy-preserving mathematical proof tools can detect whether a data centre is being used to train a new model or serve an existing one to users, without exposing the model weights or user prompts.
More investment will be needed to make these tools secure enough to verify international agreements on AI development. For example, TEEs can be reliably compromised through physical attacks on the chips. However, verifying that a commercial operator is following local rules is a lower bar and can be met with modest improvements on existing tools.
Domestic benefits
Verification tools can strengthen oversight of foreign AI systems, benefiting both domestic companies and governments.
For example, if a hospital adopts a foreign AI model, it may consent to the AI company monitoring its queries for malicious use, while also wanting assurance that the company won’t have access to sensitive clinical data. By running the model and safeguard checks inside a TEE, the hospital could get technical evidence that queries were checked for agreed safeguards without exposing the clinical data to the AI company.
AI verification tools can also give middle powers the visibility they need to enforce AI regulations. For example, governments may require that foreign AI models deployed in sensitive settings pass an evaluation by their AI Safety Institutes or other agencies. They can then use verification tools to confirm that the system serving requests in deployment is the one they evaluated.
Governments may even use hardware-based verification tools to automate compliance processes – reducing reliance on labour-intensive checks. This can help enable oversight even when state capacity to regulate is limited.
International benefits
International AI agreements will likely require answering the same question facing domestic oversight: how can a country demonstrate what is happening inside a data centre without exposing proprietary information?
Data centre verification tools could help both sides detect when the other is training a next-generation AI model. Such tools could underpin a coordinated slowdown of frontier AI development.
Any agreement between the US and China will require verification mechanisms that are technically mature and trusted by actors on both sides. Yet almost all research and development into these mechanisms is happening inside a handful of institutions in the US, UK, and Sweden.
This presents a real opportunity for countries without frontier AI companies to contribute to international AI governance, since their experts can independently assess whether AI verification tools are secure and reliable.
Policy recommendations
- Contribute talent and funding.
With only around 50 people currently working in the field, relatively small amounts of investment in research and development could yield real improvements. Additionally, this research is seriously in need of skillsets that many middle powers are world leaders in, such as cryptography and hardware design. Competition-style grantmaking programs – like the US Defense Advanced Research Projects Agency Grand Challenge – have historically been effective catalysts for nascent technologies and could apply well to verification.
- Run pilots and workshops to build awareness of new use cases.
In July and August 2026, a coalition of AI verification companies ran a pilot with Google DeepMind and Singapore’s AI Safety Institute. The pilot demonstrated a mechanism for AI evaluations which preserved the privacy of both the evaluation dataset and model weights. Government involvement in these projects can confer legitimacy that technical progress alone cannot.
- Incorporate verification rules into data centre agreements.
This could involve writing verification requirements into data centre construction licensing rules, and designating AI data centres critical national infrastructure to give regulators expanded remit to oversee and enforce local regulations. These methods are best suited to countries like Australia and Canada that are already top destinations for data centre buildouts.
As a concrete example of what this could look like, Australia’s Systems of National Significance designation enables the government to require companies to report certain system information – such as data centre telemetry – to enable real-time threat monitoring.
The investment is worth the cost
While investing in verification technology could unlock new policy levers for middle power governments, it is not costless.
One concern might be that a country’s verification requirements could deter AI companies from building data centres there. However, the same tools also serve the companies’ own interests. Cryptographic techniques, like zero-knowledge proofs, could be used to verifiably demonstrate to AI companies that security controls aimed at protecting model weights have been deployed as specified, making their models safe to deploy in the host country.
Another concern is first-mover risk: the first country to request that AI companies comply with verification mechanisms will face scrutiny over the security and privacy of the technology. This highlights the importance of early pilots to validate verification mechanisms before deployment.
For countries that take sovereignty and AI safety seriously, these costs are worth paying. The same technology that helps protect middle power sovereignty today could build the evidence base for treaty-grade verification tomorrow.

