A common-knowledge machine for AI.
Make a coordinated AI slowdown credible.
So labs can accelerate without flying blind.
A platform that makes a coordinated AI slowdown credible: verifiable to participants, legible to the world, and cheap to switch on.
the platform sits in the middle
above
Enforcement
export controls · sanctions · treaty
the platform
Legibility
compliance & defection, made seen
below
Raw compute
the chips and datacenters
Not an enforcement mechanism. A defector is not blocked, a defector is seen.
Why this exists · Effective Equilibrium
VCC is a denominator move, not a pause.
VCC is the flagship proposal of The Acceleration Paradox by AK. The book reads safety as two clocks: a clock of capability (how fast we can act) and a clock of control (how fast we can understand, detect, and correct). The danger is the gap between them.
That gap is the control ratio, R = L / H: decision latency (L) over the oversight half-life (H). Keep R below 1 and oversight stays ahead of change. VCC holds R below 1 by making a credible slowdown switchable. That is a denominator move: it grows our capacity to correct, which is exactly what lets us go fast safely. This is velocity with vigilance, not a brake.
Frontier labs make the same point: a real slowdown needs verifiable coordination (for third-party context, see Anthropic on recursive self-improvement). VCC is that verification.
01Thesis
Rivals don't race because they want to. They race because each fears the other won't stop. The only thing that flips that is verifiable common knowledge.
Everyone knowing that everyone knows that everyone is in compliance. The VCC's product is therefore not a brake and not a lock. It is a common-knowledge machine.
Everything downstream is engineering in service of that one epistemic good, produced at the minimum possible disclosure of anyone's secrets.
02Principles
Five commitments the architecture is held to.
non-negotiable
Open source is the trust substrate
A competitor or foreign government will never trust a black-box verifier built by a rival. They trust code and math they can read. All verification logic is open and auditable.
Privacy-preserving by construction
Verification reveals that a claim holds, never what the party is doing, via TEEs, zero-knowledge proofs where tractable, and compute-accounting that proves bounds, not contents.
Neutrality is existential
If any one lab or state controls the platform, adoption dies. Governance, hosting, and rule-change authority are multi-stakeholder and capture-resistant from commit #1.
Peacetime-first, dormant gear
The slowdown capability is a latent feature of a system already adopted for everyday, independently valuable reasons. A pause button invented during the crisis arrives too late.
Ratchet, never weaken
Update rules permit increasing transparency and tightening verification. Weakening either requires a supermajority of mutually-distrusting parties.
03Architecture
A layered stack. Each layer is independently useful.
That independent usefulness is what makes incremental, peacetime adoption possible.
Policy
Machine-readable commitments: FLOP ceilings, architecture/dataset restrictions, deployment conditions, plus the three things a credible pause must specify: what triggers it, what lifts it, who adjudicates.
Attestation
How each participant emits evidence about its own compute. TEE/TPM attestation on hardware that exists today → proof-of-training-transcript → flexHEG-class hardware guarantees later.
Verification
Checks attestations against policy. The hard problem is the negative claim, proving “I did not run anything above N FLOPs.” Logic ships open; inputs stay private.
Adjudication
Anomaly detection and discrepancy handling. When attestations are inconsistent, or a declared fleet doesn't reconcile with independent signals, it flags and routes to a neutral body.
Transparency
Lets non-signatories (the public, other states, civil society) see that participants are in compliance without seeing secrets. This is what makes a slowdown politically real.
Reciprocal reveal escrow
Symmetric disclosure. Encrypted compliance evidence sits in a neutral escrow no one can read in peacetime, decryptable to all only when a trigger fires. No party reveals first.
The reciprocal reveal escrow is the cryptographic answer to the oldest problem in arms control: who disarms first. Nobody reveals first; everyone's compliance becomes checkable at the same instant.
The verification commons
One engine. A portfolio of verifiable claims.
Compute is vertical #1. The same engine, signed evidence checked against a machine-readable commitment, extends to other safety claims about a model. Compute is the load-bearing guarantee; the behavioral verticals are legibility layered on top, never sold as equivalent.
Compute
load-bearingFLOP ceilings, fleet coverage, off-the-books detection. Physical and hardest to fake.
Evaluations
Proof a safety or capability eval was actually run, on a named model, with an approved pinned harness, within score ceilings and floors.
Structured access
An independent evaluator's sign-off, cryptographically bound to the exact audited session. No weight handover.
Runtime monitoring, coverage, and response signals for deployed agents. Built as a separate platform.
Weights custody
Proof the weights stayed in an approved enclave and did not leave above a bound. The non-exfiltration negative claim.
Disclosure
An append-only, tamper-evident, signed registry of system cards, incidents, and evaluator sign-offs.
Not a manifesto: running code
Open source
Apache-2.0
Attestation
Real TPM 2.0 quotes
Test suite
91 passing
Run it
7-command CLI + 5 demos
Attacked in the open
36
attacks
30
defended
6
gaps published
In security, only what survives public attack is trusted. An open suite attacks the real verifier on every commit: the 30 defended attacks are regression-gated in CI, so the verifier cannot be silently weakened. The 6 gaps that get through are published on purpose and mapped to the threat model. A verifier nobody has attacked is not evidence of anything.
04Threat model
Designed against its own failure modes.
Off-the-books compute
Attestation governs only the equipped frontier, and falling FLOP thresholds erode coverage. Mitigation: pair attestation with independent signals so un-attested large-scale compute is itself anomalous. The absence of a heartbeat becomes the alarm.
Spoofing existing schemes
Proof-of-Learning, as published, can be forged. No primitive is endorsed until it survives an open, reproducible adversarial test suite (a Pwn2Own of compute verification) under coordinated disclosure.
Neutrality capture
A single state or lab gaining control of hosting, funding, or rule-updates. Mitigations: adversarial board, the ratchet, diversified funding, a multi-jurisdictional seat.
The legitimacy trap
A slowdown that merely lets the least cautious catch up makes everyone less safe. The platform must be valuable even if a slowdown never triggers, and never framed as unilateral disarmament.
05Effective Equilibrium
How VCC maps to the five gears.
The five gears are the levers that grow the denominator, our capacity to correct: Governance, Equity, Aligned incentives, Resilience, Steering. VCC turns three of them.
Governance
A neutral platform with machine-readable commitments and no single lab or state in control. Capture resistance is built in from commit #1.
Steering
A dormant slowdown you can actually switch on, adopted in peacetime for independently useful reasons, so the capability exists before the crisis, not after it.
Resilience
Verification that proves bounds, not contents. A defector is seen, not blocked, so the system degrades visibly instead of failing silently.
Equilibrium Scorecard · VCC
verdict: accelerate / proceedGovernance
green
neutral, machine-readable commitments
Equity
n/a
not VCC's lever
Aligned incentives
n/a
not VCC's lever
Resilience
green
proves bounds, not contents
Steering
green
a slowdown you can switch on
06Transparency
The public-legibility view.
This is what non-signatories see: whether every expected participant is reporting, and whether the cohort spans genuinely mutually-distrusting blocs. It reveals no fleet, no runs, no utilization. A slowdown nobody can confirm has no deterrent or reassurance value.
Cohort · 2026-Q2
common knowledge establishedLab A
lab
compliant
Lab B
lab
compliant
State Auditor
government
compliant
blocs reporting: lab, government · policy 07476ce429370819…
Demonstration cohort with synthetic participants. This view is generated by the open verifier (verifier/scripts/transparency-demo.ts), not hand-drawn, but it is not a claim that any organization is participating. Real heartbeats begin when mutually-distrusting organizations join.
Build the common-knowledge machine.
Verification logic is permissively licensed for maximum auditability. The adversarial test suite ships under coordinated disclosure. Both are open to scrutiny, and that scrutiny is the point.
Get involved
The adversarial mix of early participants is the whole game.
Whether anyone trusts the regime depends on who shows up first: mutually-distrusting labs, governments across blocs, academic cryptographers, funders, and red-teamers. If that is you, start a conversation.
Security disclosures: security@vc-common.org