Containment Without Cooperation: A Verifiable Standard for Third-Party Platforms Hosting AI Evaluation Traffic
Hadiza Yusuf
Containment standards that a lab checks against its own telemetry face a structural limit: a signed record only proves a known checker ran, not that the underlying data was not curated. This paper relocates verification to the party with no incentive to look away: the third-party platform whose infrastructure an AI agent touches during an evaluation. We define an AI Evaluation Identity (AEI), a credential a lab declares at provisioning time as belonging to an autonomous agent, and specify four containment invariants checkable entirely from a third-
party platform’s own access, authorization, and volume logs. Two invariants are preventive and require a declared AEI; two are behavioral and require no disclosure at all. Applied to the July 2026 OpenAI/Hugging Face incident, only the two disclosure-independent invariants fire, because no AEI was ever declared for the campaign. This asymmetry is our central finding: a containment standard’s usefulness against an uncooperative actor depends entirely on which
of its checks require that actor’s cooperation. We provide a reference monitor, an illustrative event trace built from the incident’s public record, and a detection-latency estimate showing a volume-based check would plausibly have flagged the campaign within its first day, versus the roughly 3.5 days it actually took.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Containment Without Cooperation: A Verifiable Standard for Third-Party Platforms Hosting AI Evaluation Traffic
},
author={
Hadiza Yusuf
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


