The TEE remote-attestation chain of trust, stepped through: silicon root, CPU TDX quote, H100 attestation, on-chain DCAP verifier, signed inferences. Flip to the TEE.fail forged-quote path and watch the verifier still return valid — the crypto checks out, the premise is false.
zkML costs 1000x, optimistic schemes cost a challenge window. Hardware attestation verifies AI inference at under 7% overhead and ~$0.26 on-chain — if you're willing to trust Intel. Part 3 weighs the third leg of verifiable inference.