Lessons from Source Code Inspection Facilities for AI Verification
← Back to the Research Library
FIG Fellows: Thomas Van Damme
Authors: Thomas Van Damme
Abstract:
For well over a decade, a secure facility jointly operated by Huawei and British intelligence services has given the UK government unparalleled access to Huawei source code and telecom hardware for cyber security testing. The Huawei Cyber Security Evaluation Centre (HCSEC) was born out of necessity; to maintain access to the UK’s lucrative telecom market, Huawei had to offer the British government strong assurances that its telecom products wouldn’t facilitate Chinese espionage and compromise UK national security.
Today, governments face a similar challenge in verifying the safety of increasingly powerful artificial intelligence systems. To address this issue, AI policy researchers have proposed trusted compute clusters: secure, government-operated facilities where AI companies could submit their models for independent verification and evaluation, without exposing their intellectual property to theft or misuse. The precedent set by HCSEC suggests that such facilities are technically feasible, and can provide credible security assurances — even in high-stakes, low-trust contexts.
Below, we'll first take a deep dive into everything we've managed to learn about this little-known facility. We then compare HCSEC's “embedded assurance” model for source code inspections to the “visitor access” model used at Transparency Centers operated by Microsoft, Cisco, Kaspersky, Huawei, and ZTE. We conclude by discussing the main lessons from these case studies for AI verification.
While many insights are drawn from publicly available sources, we also interviewed industry experts such as John Frieslaar, who helped negotiate and set up HCSEC on behalf of Huawei, and who served as HCSEC's first managing director.