Get your free personalized podcast brief

We scan new podcasts and send you the top 5 insights daily.

Emerging technologies like confidential computing offer a novel path to building trust between rivals. They could allow for mutual verification of AI systems or even sensitive government documents, with an AI providing trusted attestations (e.g., "no backdoor found") without exposing the underlying secret data.

Related Insights

The US and USSR, despite being adversaries, collaborated to prevent nuclear proliferation to rogue actors. A similar model can be applied to AI. The US and China share an interest in preventing powerful open-weight models from being used for cyber-attacks or bio-terrorism by third parties, creating a foundation for a safety dialogue.

Chinese AI models are largely open source not for ideological reasons, but as a pragmatic branding strategy. Open-sourcing their models was necessary to build trust and credibility with Western developers who might otherwise be skeptical of closed, proprietary Chinese technology.

While Apple's long-term strategy is on-device AI, it must still use cloud providers like Google for the most powerful models. To reconcile this with its privacy-first brand, Apple is leveraging NVIDIA's confidential compute, which encrypts data and models even during active processing, thus maintaining its privacy guarantee off-device.

As sovereign AI initiatives grow, the risk of an unchecked capabilities race increases. A shared language of evaluations could provide a "trust but verify" mechanism, akin to nuclear arms verification treaties. This allows nations to audit each other's AI for risks like runaway RSI, creating a basis for international policy.

The same governments pushing AI competition for a strategic edge may be forced into cooperation. As AI democratizes access to catastrophic weapons (CBRN), the national security risk will become so great that even rival superpowers will have a mutual incentive to create verifiable safety treaties.

Technologies like Intel TDX and NVIDIA's Confidential Compute encrypt AI workloads directly on hardware. This guarantees that even the physical server owner cannot access the data, allowing anyone to contribute hardware to a decentralized network without needing to be vetted or trusted.

Despite intense technological competition, both the U.S. and China face a common threat from non-state actors like terrorist or criminal groups acquiring powerful AI models. This shared vulnerability presents a potential opportunity for cooperation on AI regulation and safeguards, even amid broader strategic rivalry.

A pragmatic starting point for U.S.-China AI cooperation is to agree on verifiable red lines for proliferating dangerous dual-use capabilities, such as advanced cyberattack tools. This addresses a mutual security interest and builds the institutional trust and processes needed for more ambitious agreements on superintelligence.

Claims that AI treaties are unverifiable lack imagination. During the Cold War, the US and USSR agreed to saw bombers in half on runways, allowing spy planes to visually confirm disarmament. Similar 'outside-the-box' physical verification methods, like publicly escrowing or destroying GPUs, could work for AI.

The goal for trustworthy AI isn't simply open-source code, but verifiability. This means having mathematical proof, like attestations from secure enclaves, that the code running on a server exactly matches the public, auditable code, ensuring no hidden manipulation.