Next, we'll pivot from voluntary reporting channels to mandatory audits and inspections. Read the below three excerpts to learn about on-site audits, routine vs. challenge inspections, and levels of assurance, drawing from both contemporary AI inspection regimes and the Chemical Weapons Convention precedent. As you read, keep the following questions in mind:
- Who conducts the audit or inspection, and what access are they actually granted — to sites, to systems, to people?
- What can routine, continuous, and challenge inspections each actually observe, and what does that access still not let the inspector conclude?
- How does the regime protect information unrelated to compliance (managed access), and what does that protection cost in assurance?
- What level of assurance does each arrangement produce, and what errors or deception can it still miss?
Access-dependent verification methods
Read On-site Inspections of Data Centers, On-site Inspections of AI Developers, and Key Takeaways.
Wasil et al. (2024) | 4–5 min
Challenge inspections: general rules and managed access
Read paragraphs 38–50.
OPCW | Chemical Weapons Convention, Verification Annex, Part X | 4 min

