The model owner and evaluator keep separate secrets

The pilot places a proprietary model and confidential benchmark prompts inside a secure computing enclave. Cryptographic verification is intended to show that the evaluator cannot inspect the weights and the provider cannot inspect the hidden questions.

That separation addresses a structural conflict in frontier testing: independent experts need meaningful access while providers need to protect intellectual property and evaluators need to prevent test leakage.

A sealed test can still ask the wrong question

Preventing prompt exposure improves integrity, especially for cybersecurity or government tests whose reuse could create risk. It can also make external testing more repeatable without forcing either party to surrender protected material.

The cryptographic box does not validate the benchmark, eliminate implementation bugs, or guarantee that reported results reflect deployment behavior. Independent methodology review and broader replication remain necessary.

Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

Google DeepMind — Double-blind AI evaluation pilot