Evidence, Audit and Replay
Evidence ledgers, tamper-evident records, decision replay, provenance and runtime observability for AI execution.
Scope
We investigate how the work an AI system performs can be recorded as tamper-evident evidence, replayed deterministically, and traced to its inputs and policies — so decisions can be audited after the fact rather than taken on trust.
Programmes in this area
- Status: Active researchGoverned Agent Systems
A single controlled execution boundary for AI agents, with human approval for irreversible actions and policy-based access to tools.
- Status: Active researchEvidence and Workstate
Store-untrusting, fail-closed design where verdicts are captured as evidence, contracts are pinned, and work state is replayable and tamper-evident.
- Status: ExperimentalGraph Reasoning Runtime
An experimental reasoning runtime separating a planner, a transaction log and an evidence ledger, with constraint enforcement over structured domain knowledge.
Open questions
Publications
- A governed ReAct agent on a real local quantized model: benign tools run, injected side-effects are denied, memory is tenant-isolated
- Governed multi-sub-agent orchestration: plan, route, execute, verify, merge, audit, recover — with per-sub-agent isolation
- A scenario-aware routing policy with co-resident dense-small backends: the model bake-off as automatic runtime behavior
- A governed agent runtime: clarify the input, gate the outcome, compound the skill
- The sovereign product layer: integrating research engines into a coherent capability set
- Safe convergence for an experience-reuse product loop: belief provenance, a confirmation state machine, and adversarial design punch-throughs
- Risk classification cannot be static: from a Memory System to a Commitment System
- Commitment System: stands or falls — an adversarial integration of four punch-throughs
- The Commitment Decision Is Undecidable; the Commit Action Is Not
- Authority Is Not Liability: The Solvent-Backstop-Aware Runtime
- Capstone: the sovereign runtime is a fold of refused collapses terminating in stipulation by fiat
- Clarify Runtime: the model-free floor of the input gate
- Composing a model-free clarify-execute-verify loop into one sovereign orchestration module
- Skill Runtime: activation beats re-derivation, acquisition stays sovereign
- State Runtime: the agent's world is an event-sourced belief log
- Skill Factory: acquisition where the judge, not the teacher, is authority
- The epistemic guard: a hard gate against confident-wrong answers
- A sovereign ReAct agent harness under in-loop governance
- A sovereign decentralized bidding network (Ed25519 + a hash-chained ledger)
- A Single Execution Boundary for Governed AI Agents: A Technical Report
