Skip to content
Article reader Listen + reading controls
LISTEN + READ YOUR WAY

Article reader

Preparing the reader…

0:00 0:00
Reading settings
Text size
100%

Independent evaluation needs a secure place to work

The Center for Artificial Intelligence Standards and Innovation (CAISI) at the National Institute of Standards and Technology (NIST) has entered a cooperative research and development agreement with OpenMined. The collaboration is intended to advance secure methods for evaluating artificial intelligence systems.

The agreement points at a recurring barrier to credible assurance: evaluators need access to meaningful systems and evidence, while model developers, customers, and government organizations need to protect intellectual property, personal information, security-sensitive data, and operational methods.

Transparency is not the same as public disclosure

Artificial intelligence (AI) assurance is often framed as a choice between openness and secrecy. The real design space is larger. A system can be opaque to everyone, fully public, or selectively inspectable within a controlled environment under defined rules.

Selective access is common in other high-consequence fields. Auditors inspect financial records without publishing every transaction. Security researchers examine vulnerabilities under coordinated-disclosure processes. Cleared personnel work with classified systems inside controlled facilities. The purpose is not to avoid scrutiny. It is to make scrutiny possible without creating a second harm.

AI evaluation needs similar institutional machinery.

Access shapes what can be known

An evaluator limited to a public chat interface can observe outputs but may not be able to inspect system prompts, tool traces, model versions, safeguards, or representative protected data. A developer running its own tests has deeper access but also an interest in the outcome. Neither position alone provides complete assurance.

A secure evaluation environment can support a more useful middle ground: approved evaluators, scoped questions, protected artifacts, reproducible procedures, and reports that communicate findings without disclosing exploitable details.

The challenge is socio-technical. Identity, encryption, isolation, logging, and privacy-enhancing technologies matter. So do contracts, conflict-of-interest rules, reporting thresholds, challenge procedures, and authority to remediate. A secure enclave with weak governance can protect data while producing little trust.

Design the evidence exchange

Organizations commissioning an independent evaluation should define the exchange before testing begins:

  • Which claims is the evaluator being asked to assess?
  • Which system versions, data, and operational conditions are in scope?
  • What access is necessary to make those claims credible?
  • Which artifacts may leave the environment, and in what form?
  • How will serious findings be escalated and contested?
  • What evidence will remain available for replication or later review?

This resembles the concept of an assurance case: claims are connected to arguments and supporting evidence. Kelly's work on goal-structuring notation gives safety-critical engineering a way to make those connections visible. AI programs need the same discipline even when some of the evidence cannot be broadly distributed.

The National Institute of Standards and Technology's Privacy Framework is also relevant. Data protection should be built into the processing environment and governance decisions, not added after evaluators have copied sensitive information into ad hoc tools.

Independence requires capacity

Independent evaluation will fail if only model developers have the compute, expertise, tooling, and access required to perform serious tests. Building evaluator capacity is therefore part of the assurance ecosystem. Shared secure infrastructure can reduce the cost of participation and let academic, public-interest, and government teams contribute specialized knowledge.

The objective is not unlimited access. It is sufficient access for a qualified evaluator to make a defensible claim—and enough transparency about the process for others to understand the claim's limits.

Trustworthy AI will require organizations to share more evidence across boundaries. Secure evaluation gives them a way to do that deliberately. The strongest assurance may come neither from keeping everything secret nor from making everything public, but from designing a place where sensitive systems can be challenged by people empowered to look closely.

Sources and research trail

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.