Notes from the frontier.
How we think about governing what AI agents do — and proving it to someone who doesn’t trust you. Short, technical, and opinionated.
What we’re thinking about
Identity proves who. What proves what?
The whole industry rushed to verify an agent’s identity. The unguarded question is what it actually did at runtime — and why that is the harder, more valuable problem.
Proof a company can’t forge about itself
Why self-anchored logs aren’t evidence, and how a neutral chain, a diverse witness mesh, and a public verifier turn "trust us" into "verify it yourself."
"Cryptographically verifiable" still means trust someone
The distinction that decides a regulated deployment: trusted-vendor proof versus proof that survives assuming both vendor and operator are hostile.
Auditable without being slow
Mapping Articles 12 / 14 / 15 / 26 to concrete runtime controls — and why the Digital Omnibus extension is runway, not a reprieve.
A promise, not a probability
Why a second model guarding the first is the wrong shape for enforcement, and what deterministic, fail-closed policy buys an auditor.
The network is the moat
How privacy-preserving, cross-deployment threat signatures compound into a defense a single company can never self-build.
We publish deliberately, not on a content-marketing cadence. Full posts are in progress — in the meantime, the sharpest version of our argument lives on Why NOCTRYS.