You are almost done. The only thing left is the capstone project — one piece of work that shows what you have learned, applied to a problem you chose.
Written output · 4.2
Capstone Project
The workspace holds your draft as you go and exports it as Markdown. Coming from the bank, open a brief there and it arrives with you.
Open the capstone workspaceThere is no assigned task. Two ways to pick one:
- Choose from the capstone bank. The full bank is below — every brief with the numbers that decide whether you can take it on — and the bank page has the same briefs with search and filters.
- Suggest your own capstone idea. It has to be relevant to technical AI governance and aimed at an AI-safety-related theme.
Either way, put your name on the sign-up sheet, so your facilitator knows what you are working on and can read your proposal.
Sign-up sheet
Your facilitator reads this sheet — the brief you committed to, or the idea you proposed.
The sheet is tied to an account, so your capstone and your progress are the same person.
Sign in to sign upRedraw the AI-vs-Human Capability Chart
The best-known chart of AI against human performance stops in 2023. Rebuild it at today's date and say what a threshold can honestly attach to.
Fits this course: Lands on 1.1 — a pause agreement has to name a covered capability, and this is the measurement that claim would rest on.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableReproducible chart and dataset, a methods note, and a two-page brief on what a capability threshold can be written against
A Cloud KYC Regime That Is Not Just Paperwork
Module 2.2 warns that self-reporting alone is a paperwork regime. Design the cloud reporting rules for one provider so that at least one claim in them is actually checkable.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableReporting-rule spec with a per-claim checkability rating and the evasion routes it leaves open
A Minimum Viable Compute-Accounting Audit
What should a commercial AI audit prove about how each GPU was used? Claims, logs, retention, auditor access — and what happens when logs are missing.
1–2 people · 12–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableDraft auditing standard, 2–3 pages
A Reporting Channel an Insider Would Actually Use
Module 2.4 says the human layer reveals what hardware and intelligence cannot — if evidence reaches a verifier. Design the channel, against the NDAs and equity that stop it.
1–2 people · 12–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableChannel design — who receives, what protects the reporter, and the evidence standard on arrival
A Security Case for One Sensor
Power, temperature and timing telemetry cannot classify workloads reliably. Build the security case for using one sensor feed anyway.
1–2 people · 12–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableA verification security case for one telemetry mechanism
A Verification Package You Could Ship in a Year
Twelve months, no new chips. Assemble the verification package that could actually be deployed, and state plainly what it still cannot see.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverablePrioritized implementation roadmap with residual gaps stated
Build the US–China AI Incident Hotline
The hotline has been proposed for years and never specified. Design it — what counts as an incident, who picks up, what is said, and why either side would believe it.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableHotline design — incident taxonomy, escalation ladder, and the credibility problem addressed
Can You Prove This Model Came From That Run?
Proof-of-learning is in Module 2.1 as fragile and spoofed; model-heritage inference is an open problem next door. Assess what either can support and what a regime could rest on them.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableFeasibility assessment of training-provenance claims, with the claims each method can and cannot carry
Cut the Interconnect, Keep the Inference
Disconnect part of the optical links between racks and training stops while inference survives — allegedly. Work out what remains possible and who checks the cables.
1–2 people · 10–14 hrs · 2 weeks · ≈6 hrs/wk
DeliverableShort protocol design plus a red-team pass on it
Does Switching Off the Cooling Switch Off the Training?
An inspector confirms the cooling is off. Under what conditions does that actually rule out a large training run — and how would an operator get around it?
1–2 people · 12–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableThreat model with a claim → observable → evasion → countermeasure table
Hardware Chokepoint Dossier
Trace one node of the compute supply chain end to end and rank it as a verification chokepoint — who sees what, and who would have to agree.
1 solo · 10–14 hrs · 2 weeks · ≈6 hrs/wk
DeliverableSix-to-eight page dossier with a chokepoint ranking table
How Much Hidden Compute Breaks the Deal?
How much concealed compute must a state retain before a pause agreement stops being worth signing? Three scenarios, priced for capability and strategic effect.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableScenario analysis with a sensitivity table
Is the Model in Production the Model That Passed?
Evals passed on one model. Millions of requests run against another — would anyone notice? Design the chain that lets an auditor say deployed equals evaluated.
1–2 people · 12–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableProtocol diagram from evaluation to deployment, plus an attack tree
Make an Eval Result Believable to a Stranger
A lab says its model scored below the danger threshold. Specify what a third party would have to observe to believe that — and what it costs to provide.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableAttestation spec — the observation chain, the residual trust, and the cost to the lab
Minimal Verification Regime for an Emergency Pause
Design the smallest verification regime that could make a three-month emergency pause credible to a party that expects to be cheated.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableTwo-page regime spec plus a one-page evasion annex
Permit Inference, Prohibit Training
An agreement permits inference and prohibits training. Define permitted inference so the boundary survives fine-tuning, distillation and synthetic-data generation.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableDraft rule, five edge cases, and the revisions they force
Prove Compliance Without Handing Over the Model
Module 2.0's whole problem in one artifact — pick one claim a developer must prove, and specify how to prove it without disclosing weights, data, or a trusted enclave.
1–2 people · 16–22 hrs · 3 weeks · ≈6 hrs/wk
DeliverableProtocol sketch for one claim, with the trust assumptions and the residual disclosure named
Red-Team a Verification Stack
Take a published verification proposal and break it — a structured evasion report with detection probabilities and the patch each route demands.
2–3 people · 16–22 hrs · 3 weeks · ≈6 hrs/wk
DeliverableEvasion report with an attack tree and a patch list
Spot a Training Run Without Looking Inside It
Could a verifier tell a large training run from utilisation signatures alone — no workload access, no code? Work out what the signature is and how cheaply it is faked.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableSignature analysis with a detection-rule sketch and the spoofing cost for each signal
Steal a Chain of Custody From Another Industry
Other industries already track dangerous things through many hands. Take one working custody regime apart and report what transfers to compute — and what does not.
1–2 people · 14–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableCase study of one custody regime plus a transfer analysis for the compute supply chain
Stock and Flow Accounting Case Studies
Case studies of regimes that track dual-use physical objects — registration, transfer penalties, measured loss rates — as building blocks for compute stock-and-flow accounting.
1–2 people · 10–14 hrs · 2 weeks · ≈6 hrs/wk
DeliverableTwo case studies on the source's own template — methods, penalties, and the measured loss rate
The Security Baseline That Would Have Stopped It
Weight exfiltration is the evasion route that voids the compute regime. Write the infrastructure-security baseline a regime would require in advance, and price it.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableSecurity baseline by threat tier, with the audit evidence for each control and its cost
Train It in Pieces, Under Every Threshold
Evasion scenario 8 says a run can be fragmented below the line. Work out how far that actually goes today, what it costs, and which threshold designs survive it.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableFeasibility assessment of fragmented training plus a threshold-design recommendation that survives it
Treaty Clause Redraft
Take the verification articles of a real arms-control treaty and redraft them for frontier AI — clause by clause, with the disanalogies marked.
1–2 people · 12–16 hrs · 2 weeks · ≈7 hrs/wk
DeliverableRedrafted clause set with a facing-page commentary
What Assurance Costs in Secrets
Every verification mechanism buys confidence by spending the operator's secrets. Price the exchange rate across inspections, taps, telemetry, trusted hardware and recomputation.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverableAssurance × disclosure × intrusiveness matrix
What Would Compute Monitoring Actually Cost?
The compute-monitoring literature has the mechanisms, the timing, even a first-pass inspector headcount. It has no penalties and no price. Produce the costing a budget office would need.
1–2 people · 16–22 hrs · 3 weeks · ≈6 hrs/wk
DeliverableCosted monitoring plan — headcount, inspection cadence, penalty schedule, hardware dependencies
When Does a Secret Datacenter Earn an Inspection?
Power draw, cooling, procurement, satellite imagery — when does a stack of maybes justify an inspection? Build the rubric that turns signals into a decision.
1–2 people · 12–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableEvidentiary rubric plus a decision memo
When Is Tamper-Evidence Enough?
Tamper-proof hardware is expensive and unsolved; tamper-evident is neither. In which institutional settings is finding out afterwards actually sufficient?
1–2 people · 10–14 hrs · 2 weeks · ≈6 hrs/wk
DeliverableDecision framework
When the Weights Are Already Out
Module 3 rates weight exfiltration as the evasion route that bypasses the compute regime entirely. Specify what a verification regime does the day after it happens.
1–2 people · 14–20 hrs · 3 weeks · ≈6 hrs/wk
DeliverablePost-exfiltration regime annex — what is still verifiable, what is not, and what the agreement should have said
Where Should the Supply Chain Keep Logs?
Manufacturing logs are cheap to demand and easy to drown in. Find the point in the semiconductor chain where credible logs buy the most information for the least trust.
1–2 people · 12–18 hrs · 3 weeks · ≈5 hrs/wk
DeliverableRanked chokepoint matrix
Open the bank — all 80 briefs across the program, with filters, prerequisites and sources →Sign up for a capstone, or propose your own →

