A common-knowledge machine for AI.
So labs can accelerate without flying blind.
A platform that makes a coordinated AI slowdown credible: verifiable to participants, legible to the world, and cheap to switch on.
Why this exists · Effective Equilibrium
VCC is the flagship proposal of The Acceleration Paradox by AK. The book reads safety as two clocks: a clock of capability (how fast we can act) and a clock of control (how fast we can understand, detect, and correct). The danger is the gap between them.
That gap is the control ratio, R = L / H: decision latency (L) over the oversight half-life (H). Keep R below 1 and oversight stays ahead of change. VCC holds R below 1 by making a credible slowdown switchable. That is a denominator move: it grows our capacity to correct, which is exactly what lets us go fast safely. This is velocity with vigilance, not a brake.
Frontier labs make the same point: a real slowdown needs verifiable coordination (for third-party context, see Anthropic on recursive self-improvement). VCC is that verification.
Rivals don't race because they want to. They race because each fears the other won't stop. The only thing that flips that is verifiable common knowledge.
Everyone knowing that everyone knows that everyone is in compliance. The VCC's product is therefore not a brake and not a lock. It is a common-knowledge machine.
Everything downstream is engineering in service of that one epistemic good, produced at the minimum possible disclosure of anyone's secrets.
non-negotiable
A competitor or foreign government will never trust a black-box verifier built by a rival. They trust code and math they can read. All verification logic is open and auditable.
Verification reveals that a claim holds, never what the party is doing, via TEEs, zero-knowledge proofs where tractable, and compute-accounting that proves bounds, not contents.
If any one lab or state controls the platform, adoption dies. Governance, hosting, and rule-change authority are multi-stakeholder and capture-resistant from commit #1.
The slowdown capability is a latent feature of a system already adopted for everyday, independently valuable reasons. A pause button invented during the crisis arrives too late.
Update rules permit increasing transparency and tightening verification. Weakening either requires a supermajority of mutually-distrusting parties.
That independent usefulness is what makes incremental, peacetime adoption possible.
Machine-readable commitments: FLOP ceilings, architecture/dataset restrictions, deployment conditions, plus the three things a credible pause must specify: what triggers it, what lifts it, who adjudicates.
How each participant emits evidence about its own compute. TEE/TPM attestation on hardware that exists today → proof-of-training-transcript → flexHEG-class hardware guarantees later.
Checks attestations against policy. The hard problem is the negative claim, proving “I did not run anything above N FLOPs.” Logic ships open; inputs stay private.
Anomaly detection and discrepancy handling. When attestations are inconsistent, or a declared fleet doesn't reconcile with independent signals, it flags and routes to a neutral body.
Lets non-signatories (the public, other states, civil society) see that participants are in compliance without seeing secrets. This is what makes a slowdown politically real.
Symmetric disclosure. Encrypted compliance evidence sits in a neutral escrow no one can read in peacetime, decryptable to all only when a trigger fires. No party reveals first.
The reciprocal reveal escrow is the cryptographic answer to the oldest problem in arms control: who disarms first. Nobody reveals first; everyone's compliance becomes checkable at the same instant.
Phase 0
months 0–6
Stand up the legal entity, recruit an adversarial board, publish charter + threat model + architecture, choose jurisdiction and license.
Phase 1
months 3–12
Ship open TEE/TPM training-provenance attestation on hardware that exists today. Publish v0 of the adversarial verification test suite.
Phase 2
months 9–24
≥2 mutually-distrusting orgs emitting heartbeats and cross-checking. Stand up the public-legibility view. First real common knowledge.
Phase 3
months 18–36
Implement policy-layer triggers/lift/adjudication and the reciprocal reveal escrow. The pause becomes a tested but un-invoked capability.
Phase 4
months 30+
Consume flexHEG-class hardware attestations as they mature, hardening coverage against the off-the-books hole.
Attestation governs only the equipped frontier, and falling FLOP thresholds erode coverage. Mitigation: pair attestation with independent signals so un-attested large-scale compute is itself anomalous. The absence of a heartbeat becomes the alarm.
Proof-of-Learning, as published, can be forged. No primitive is endorsed until it survives an open, reproducible adversarial test suite (a Pwn2Own of compute verification) under coordinated disclosure.
A single state or lab gaining control of hosting, funding, or rule-updates. Mitigations: adversarial board, the ratchet, diversified funding, a multi-jurisdictional seat.
A slowdown that merely lets the least cautious catch up makes everyone less safe. The platform must be valuable even if a slowdown never triggers, and never framed as unilateral disarmament.
The five gears are the levers that grow the denominator, our capacity to correct: Governance, Equity, Aligned incentives, Resilience, Steering. VCC turns three of them.
A neutral platform with machine-readable commitments and no single lab or state in control. Capture resistance is built in from commit #1.
A dormant slowdown you can actually switch on, adopted in peacetime for independently useful reasons, so the capability exists before the crisis, not after it.
Verification that proves bounds, not contents. A defector is seen, not blocked, so the system degrades visibly instead of failing silently.
Equilibrium Scorecard · VCC
verdict: accelerate / proceedGovernance
green
neutral, machine-readable commitments
Equity
n/a
not VCC's lever
Aligned incentives
n/a
not VCC's lever
Resilience
green
proves bounds, not contents
Steering
green
a slowdown you can switch on
phase 2
Once mutually-distrusting organizations are emitting compliance heartbeats, this section will show (to the public, without revealing any secrets) that participants are in compliance. A slowdown nobody can confirm has no deterrent or reassurance value.
Participant A
no heartbeat yet
Participant B
no heartbeat yet
Participant C
no heartbeat yet
Verification logic is permissively licensed for maximum auditability. The adversarial test suite ships under coordinated disclosure. Both are open to scrutiny, and that scrutiny is the point.