Lucid Computing

Lucid Computing builds provable trust infrastructure for frontier AI: privacy-preserving compute clusters whose operation can be cryptographically verified rather than contractually promised. Fellows in this stream will work on hardware security, hardware verification, and the governance questions that verifiable compute makes tractable.

Stream overview

Lucid Computing works on verifiable compute for frontier AI: confidential-computing clusters that produce cryptographic evidence about how and where an AI workload actually ran, so that claims about data residency, model provenance and execution integrity can be checked instead of trusted. Lucid also contributes to the Sovereignty Certificates effort (sovcert.org), an open industry standard for proving the physical jurisdiction a CPU or GPU is operating in using physics-based bounds on processing location.

The stream is open to projects anywhere in hardware security, hardware verification, and the associated policy questions, and welcomes project proposals from applicants. Example directions:

  • Verification of AI workloads in hardware: designing and stress-testing schemes that let a third party confirm which model ran, on what hardware, under what conditions, without exposing weights or inputs.
  • Attacking and hardening confidential compute: red-teaming the trust assumptions behind secure enclaves and attestation chains, including what an adversary with physical access to a machine can actually achieve.
  • Location and identity proofs for compute: extending the Sovereignty Certificates approach, including its threat model, its failure modes, and which guarantees survive real network conditions.
  • Policy work on verifiable compute: which compute-governance and export-control regimes become enforceable once hardware verification exists, and what evidence a regulator would need in practice.

Mentors

Greg Kollmer
Lucid Computing
,
Co-Founder
AI Systems Security
Technical AI Governance

Greg Kollmer is a co-founder of Lucid Computing, which develops secure, verifiable AI infrastructure. As a Columbia engineering graduate student Kollmer co-developed Palmos, a wireless sensor network for early landslide detection.

Read more

Mentorship style

Fellows we are looking for

Project selection

Streams

The Winter 2026 cohort offers a wide range of research streams led by experts across AI alignment, interpretability, governance, and safety. Each stream provides its own research agenda, methodology, and mentorship focus.

SF Bay Area
Dangerous Capability Evals
Boston
Policy and Governance
Adversarial Robustness, Policy & Governance, Red-Teaming, Safeguards
New York City
Control, Scalable Oversight, Red-Teaming, Model Organisms, Monitoring
SF Bay Area
Policy and Governance
Policy & Governance
SF Bay Area
Control, Monitoring, Dangerous Capability Evals
SF Bay Area
Security, Compute Infrastructure
London
Theory
Interpretability
London
Scheming & Deception, Dangerous Capability Evals, Control, Red-Teaming
SF Bay Area
Dangerous Capability Evals, Red-Teaming, Model Organisms, Control, Monitoring
Toronto
Interpretability
London
Control, Monitoring, Safeguards, Dangerous Capability Evals, Scheming & Deception
Chicago
Biorisk, Security, Safeguards
SF Bay Area
Interpretability, Agent Foundations
London
Empirical
Interpretability
London
Interpretability, Red-Teaming, Monitoring
London
Monitoring, Adversarial Robustness, Control, Model Organisms, Red-Teaming, Dangerous Capability Evals, Safeguards
New York City
Policy and Governance
Dangerous Capability Evals, Control, Strategy & Forecasting, Policy & Governance, Scalable Oversight, Agent Foundations
SF Bay Area
Empirical
Theory
Dangerous Capability Evals, Adversarial Robustness, Security, Red-Teaming, Scalable Oversight
London
Control, Scheming & Deception, Dangerous Capability Evals, Monitoring
Washington, D.C.
Policy and Governance
Policy & Governance, Strategy & Forecasting