The People Building a Way to Slow Down the AI Race

Wait 5 sec.

Amodo Design engineer Carl Heimann stands before a rack of Nvidia chips at an Amodo facility in Sheffield, England. —Courtesy of Tom Milton—AmodoIn the corner of a nondescript office in Sheffield, a city in the north of England, a compact server full of Nvidia chips is whirring away.It’s a microcosm of the huge data centers springing up all over the globe: town-sized, energy-guzzling computers that are the worldly manifestations of frontier AI models.Here in Sheffield, on these eight chips, engineers from the consultancy Amodo Design are piloting a monitoring system that they hope, one day, might find its way into every data center, allaying the fears of AI researchers who are concerned that the technology they are building may destroy the world.In late July, more than 1,300 employees of frontier AI companies signed an open letter warning that their AI is quickly becoming so powerful that humans may soon no longer be able to control it. Slowing the pace of AI development, they warned, may become vital in order to allow more time for safety research, and thus avert catastrophe. But slowing down, they wrote, is essentially impossible, due to intense competition between companies and countries. The AI race is stuck in an arms-race dynamic, these top scientists say, in which one team slowing down would only hand victory to rivals that don’t.The letter’s main request—one so important to 1,300 of the world’s top AI researchers that they called publicly for it—was for the U.S. government to support an international effort to build tools that would enable all sides to slow down the AI race. So far, only a small group of people are working on this effort. There are fewer than 50 engineers in the world working full-time on building so-called “AI verification” tools, Amodo CEO Tom Milton estimates—nine of them at Amodo—plus a few dozen more policy researchers scattered among a handful of companies and research institutes. Meanwhile, trillions of dollars, and the combined might of the world’s biggest tech companies, are now dedicated to making AI systems more powerful as quickly as possible. Efforts to build slowdown tools are funded mostly by academia and philanthropy. (Amodo’s work in this area is funded by the Survival and Flourishing Fund and Longview Philanthropy, two grantmakers that have donated heavily toward reducing AI-related risks.) “It is surprising that very few people are doing it,” says Milton, a 28-year-old who fell into the field almost by accident several years ago, when Amodo was commissioned to do some work in the area. In Sheffield, three workers are huddled around their compute cluster, under an air conditioning unit that is running on full-blast. Their small-scale prototype may be running hot, but it isn’t ready yet. Many technical obstacles remain in its way, plus a bigger political one: it won’t be useful unless the U.S. and China come to the table and agree on an AI slowdown treaty, Milton says.For now at least, such an agreement looks unlikely. But Amodo’s engineers are keenly aware that political choices are downstream from what is possible. Treaties that curtailed the Cold War arms race were only possible because new technologies, like satellites and seismometers, allowed each side to verify the other’s compliance. Milton expects a similar moment to arrive for AI. When that moment comes, he wants to be ready. Read More: Can the Cold War Teach Us How to Slow Down AI?Halfdan Holm, an Amodo staffer, adjusts the server rack that is running Amodo's recomputation algorithm in Sheffield, England —Courtesy of Tom Milton—AmodoHow AI verification might workNobody knows how an AI slowdown treaty might look, but Amodo’s engineers believe it will probably require monitoring data centers, given that these are the places where AI physically lives. The current prototype that Amodo is building could make it possible to gain two assurances about a data center that might be helpful in the years to come, Milton says. First, that a data center is only being used for inference. That means the running of existing AI models, rather than the training of new, more powerful ones. Second, that a data center is running a particular, agreed-upon model—for example, one that has passed certain safety tests, perhaps ones that have been set down in law.To demonstrate how this might work, an Amodo engineer logs into the whirring server rack, where he spins up two separate systems, each containing an open-source AI model made by OpenAI. Think of the first system, he says, as an AI model that a company would normally run in a data center. The second system is the “verifier,” he explains. Its job is to sample snippets of data from this data center and rerun them on its own version of the model, thus confirming that the model is the one the data center operator claims it to be.When he demonstrates it, the system works—at least on its own terms. The verifier performs some calculations on the outputs of the original AI model, and spits out a high certainty score that this model is GPT-OSS-120B, which is exactly correct.A rack of Nvidia chips at an Amodo facility in Sheffield, England —Courtesy of Tom Milton—AmodoThe limitationsThere are several significant problems that point to Amodo’s solution not yet being ready for prime time. For now, it only works with unencrypted data, which makes it unfeasible for the most sensitive workloads, which are routinely encrypted. (Milton says the next version of Amodo’s prototype will utilize “zero-knowledge” cryptography, which would significantly reduce the amount of unencrypted data needed.)A second limitation is that a system like this would require data centers to be retrofitted, including a process ominously named “network tapping,” which involves copying data from working chips onto other verification systems within the same building. Given that these are some of the highest-security buildings on earth, housing trillion-dollar intellectual property and masses of private data, that’s access that no leading AI company is likely to be willing to grant, at least today. But it doesn’t have to be as scary as it sounds, Milton says. There are precedents in the history of arms control—including nuclear and chemical weapons—for international bodies to carry out inspections of sensitive facilities. These inspections can guarantee that a facility is compliant with international law, without revealing the secrets of how it works to adversaries. Amodo hopes to build on these principles, aiming to build a system that would only send low-information signals like “passed” or “failed” outside of the data center’s secure walls.(Amodo says it plans to open-source all of its work on AI verification, so that all sides can interrogate it, understand exactly how it works, and be confident it lacks security vulnerabilities.) Another limitation is that the verifier system requires computing power in order to run. That could substantially reduce the total capacity, and thus profitability, of any data center that hosts it. The system witnessed by TIME required computing power equal to between one-third and one-fifth of the AI model it was monitoring. Amodo’s engineers say they expect to find substantial further efficiency gains, in particular because the system could theoretically be set to monitor only random samples of a data center’s computation, rather than every single calculation, in order to achieve its intended result. Milton acknowledges that for now at least, Amodo’s tech isn’t perfect. The idea, he says, is for it to improve significantly over time, ultimately reaching a point where it becomes minimally invasive and maximally privacy-preserving. “We tend to be of the mind that verification mechanisms will ladder up, and they won't be perfectly trustable and perfectly secure on day one,” he says. “Over time, we can get to systems that can be verified in much more detail.”There are many individual AI researchers, Milton says, who are paid more than the single-digit-million dollar budget for his entire project. A full-scale effort, of the kind that AI workers asked for in the open letter, might quickly result in more sophisticated tools. “It is insane for us to think that we are even a noteworthy participant in this,” Milton says. “Let alone one of the largest projects.”Sam Reynolds, an Amodo engineer, adjusts a server in Sheffield, England —Courtesy of Tom Milton—AmodoIs it politically possible?While AI verification tech remains nascent, the acceleration of AI capabilities in recent months has led to a surge of interest in the field.The Institute for Progress, a think-tank, recommended in August that the U.S. government collaborate with frontier AI labs, chipmakers, and hyperscale data center builders, plus other governments, to accelerate the development of AI verification tools. “If the nuclear arms control precedent is any indication, the ability to verify that agreements are being upheld is often necessary for parties to enter into them in the first place,” it wrote. “Better verification technology would unlock a broader space of possible agreements.”It is a view shared by the authors of AI 2040, a follow-up to the widely-read essay AI 2027. Their so-called “Plan A” for humanity to navigate the arrival of superintelligent AI safely makes heavy use of data center monitoring technologies. And Anthropic recently announced it would devote resources to “help build the systems that a credible slowdown or pause would require.” Those systems, it said in a June blog post, “would enable frontier AI developers to verify that others globally have actually stopped or slowed, and that a bad actor could not use the auspices of a coordinated slowdown to jump ahead in secret.”Milton says Amodo has held some preliminary discussions with governments about its work, although he declines to say which governments, or to share specifics.For now, at least, it seems clear the U.S. government does not share the enthusiasm.“We totally reject global governance of AI,” the director of the White House office of science and technology policy, Michael Kratsios, said in February. “We believe AI adoption cannot lead to a brighter future if it is subject to bureaucracies and centralized control.”It’s true that since that speech in February, the White House has slightly moderated its approach to AI regulation, having been spooked by the cyber-warfare capabilities of recent models into testing some frontier models before their release. But White House officials remain highly skeptical of heavy-handed interventions in the AI industry, especially ones that might be perceived as allowing for ground to be lost to China. “We refuse to stifle [AI] innovation with overly burdensome regulation,” President Trump wrote in the introduction to a June executive order.China, meanwhile, appears to still be pursuing its strategy of releasing open-weight models in an attempt to catch up to the U.S. frontier. In other words: neither great power is exactly clamoring to agree on an AI treaty. Officials from the U.S. and China are planning to meet in September to discuss the growing risks of AI, Reuters reported, though that meeting is more likely to focus on immediate security issues.Milton is unfazed by what appears, for the moment, to be the political unfeasibility of putting this technology to use. He expects that more powerful AI models will soon arrive, with scarier capabilities. At that point, he expects, both the U.S. and Chinese governments will be “sufficiently scared”—and might come to the table. That possibility, he says, is likely enough “that money should be spent on building the optionality for it.”