A FlexHEG is a small, tamper-resistant coprocessor sitting alongside an AI accelerator. Its only job is to make cryptographic attestations about what the accelerator is doing. Which model weights are loaded. Which workload class is running. How much compute has been consumed against which quota. Which policies were in force when a training run started. It does not itself perform inference or training. It is the accountant, not the worker.
The paper's central design bet is that governance needs are unpredictable. Today a regulator might care about a compute threshold above which a training run must be reported. Tomorrow it might care about a country-of-use restriction, or a specific eval a model must pass. A rigid hardware root of trust ossifies whichever policy was current when the chip shipped. FlexHEG is designed as a policy-carrying substrate: the coprocessor exposes a small, well-audited attestation and licensing API, and the policy sits above it in updatable, revocable form. Same silicon, different governance regimes over the chip's lifetime.
The paper was commissioned by ARIA, the UK Advanced Research and Invention Agency, whose Safeguarded AI programme has been quietly funding the substrate-level end of AI safety research since 2024. The framing throughout the paper is not "a kill switch for AI"; it is "the enforcement layer any credible international agreement on compute would need to bind to". A treaty that cannot be verified cannot be enforced. FlexHEG is a candidate verification instrument, and the paper is explicit that the alternative (trust-based enforcement) has not worked historically for dual-use technologies.
In the ARC/Eden convergence register, FlexHEG is classified CONCURRENT with the April 30 2025 manuscript. That manuscript names the general architecture ("The Eden Protocol") and its enforcement primitives at the substrate level. FlexHEG names the specific hardware artefact required to make the enforcement primitives actually bind. They arrive at overlapping conclusions in the same month from independent starting points, ARIA-commissioned safety research on one side, an interfaith-flavoured AI-safety manuscript on the other. Priority on the specific FlexHEG artefact is credited to Petrie, Aarne, Ammann and Dalrymple. The convergence claim is structural.
Two things. First, a guarantee processor is only as trustworthy as the certifying authority that issues its licences; if a single government controls the key, FlexHEG becomes precisely the foreign kill-switch that European policymakers have publicly said they will not accept. Second, FlexHEG assumes attestations are honest at the point of manufacture; it does not solve the supply-chain problem, though it does make substitution attacks much more expensive.
Open the arXiv link. Read the threat-model section first: it is short and it is the honest bit. The rest of the paper is engineering detail that is easier to follow if you already know which threat the authors are trying to price out.
From the book Infinite Architects: Intelligence, Recursion, and the Creation of Everything by Michael Darius Eastwood.