KTH Royal Institute of Technology
- Martin Monperrus — Professor, project leader
- Carmine Cesarano — Postdoctoral researcher
- Julien Malka — Postdoctoral researcher
A2I
Swedish industry is moving AI workloads onto shared datacenter infrastructure. A tenant running a compound AI system on that infrastructure cannot verify that what executes matches what was declared and approved.
Compound AI systems span datasets, base models, fine-tuning steps, embedding indexes, prompt templates and orchestration logic, assembled across organizations that do not trust each other. Traditional supply chain attestation assumes reproducible builds. Training is not reproducible, so recompute-and-compare has no purchase on a model checkpoint.
A2I builds an integrity layer for the datacenter AI control plane. The project delivers a formal model of what integrity means for these systems, cryptographic binding of artifacts to the environment and recipe that produced them, and verification techniques that test an artifact against its declared recipe when no proof came with it. Everything is released open source.
A2I is funded by Vinnova.
Nothing published yet. The first outputs are due in 2027, and all publications will be open access.
All code is developed in the open at github.com/a2i-project.
No posts yet. Technical write-ups will appear here as the work lands.
KTH Royal Institute of Technology
Nothing scheduled yet. Talks and programme events will be listed here.