Skip to content
The Story

Why trust in AI has to be rebuilt

The current shift

We Have Entered the Machine-to-Machine Era.

01 · Human → Human

Trust ran on relationships, institutions, and reputation. A person stood behind every action.

02 · Human → Machine

The era of digital transformation. Our current governance, software, and architecture is built for this stage.

03 · Now · Machine → Machine

Agents initiate, at machine scale and speed that humans cannot keep up with. Soon, agents and bots will outnumber human beings on the internet.

HUMAN → HUMAN

HUMAN →
MACHINE

MACHINE →
MACHINE

NOW

SHARE OF INTERACTIONS

TIME

The crossing

We’ve Crossed the Line: Human Oversight Cannot Keep Up with Machines.

Machine capabilities are compounding exponentially while human oversight over machines scales linearly. We have reached The Crossover—the inflection point where autonomous systems act faster and perform tasks more complex than real-time human oversight can track. The tools we rely on to monitor machines are outdated—manual reviews, reactive policy, and static dashboards. The expanding wedge above this threshold is the Verifiability Gap: an unmonitored operational void where machines act without verifiable evidence, giving attackers a compounding structural advantage.

“We’re potentially looking at a singularity event for cyber attackers.”

BRUCE SCHNEIER, HEATHER ADKINS AND GADI EVRON, “AUTONOMOUS AI HACKING AND THE FUTURE OF CYBERSECURITY,” ORIGINALLY IN CSO, 10 OCTOBER 2025

The Verifiability Gap in AI: when machine capability outpaces human oversight

CROSSOVER

VERIFIABILITY
GAP

HUMAN OVERSIGHT

MACHINE CAPABILITY

CAPABILITY

TIME

The Problem

The Verifiability Gap Is Widening.

The Verifiability Gap is the widening distance between what AI agents do and anyone’s ability to openly verify that they stayed within the controls they were given.

Because an agent’s path is unpredictable, static vendor logs and annual audit reports reduce true verification to “someone’s word.” Traditional software follows fixed, predictable code paths, making static logging easy.

THE CROSSING, ABOVE

WHAT AGENTS DO

WHAT ANYONE CAN OPENLY VERIFY

VERIFIABILITY GAP

WIDENS AS CAPABILITY COMPOUNDS

What agents do: actions taken, decisions made, data touched—continuous, non-deterministic execution at machine speed.

What anyone can openly verify: operator logs, vendor policies, and static audit reports. All of it someone’s word.

Closing the Verifiability Gap requires open verification at machine speed. Trust can no longer move at human speed.

The stakes

Unverifiable Agent Controls Are an Existential Risk and a Business Liability.

On the surface, insurers are already declining to cover AI risk. What that points to is much bigger, and it sits below the waterline.

VISIBLE

ISO added a generative-AI exclusion to standard general-liability forms · Jan 2026
Verisk is weighing agentic-AI exclusions · Jul 2026

INVISIBLE

EXISTENTIAL RISK

Loss of control
Black-swan agent failures
Unattributable harm
Uncorrectable error at machine speed

BUSINESS LIABILITY

Lack of customer protection
Uninsurable deployments
Compliance that cannot be demonstrated

When things go wrong (and even when they go right), how do we verify agent controls were put into place?

Non-deterministic by nature

Static Logs Fail in an Agentic World.

Unlike traditional software, which follows fixed, predictable code paths, agents are intelligent and act with intent. That makes them non-deterministic by nature: given a goal, an agent chooses its own route to point B, picking tools, reasoning chains, and execution routes on the fly. No two runs need look alike.

AB
A latent market

The Technology to Solve the Verifiability Gap at Machine Speed Is Here, but the Security Solutions Are Scattered.

Verifiable AI is a latent category waiting for structural unification.

The tech to make agentic orchestration secure exists in a range of cryptographic and decentralized services: from trusted execution environments and hardware attestation to zero-knowledge proofs.

The market forming

Verifiable AI Sits at the Intersection of the Fastest-Growing Categories in AI.

155%

CAGR · AI DATA

The fastest-growing AI spending category

74%

CAGR · AI SECURITY

The second fastest-growing

141%

agentic AI spending increase

50%+

enterprises deploying agents by 2028

#1

cybersecurity trend: agentic AI security

GARTNER, FORECAST ANALYSIS: AI SPENDING, 4Q25, 17 DECEMBER 2025

AI SECURITYAI DATAAGENTIC AIVERIFIABLEAI
The paradigm shift

From Claims-Based AI to Verifiable AI.

Claims-based AI asks you to trust corporate assertions. Verifiable AI produces tamper-evident evidence that anyone can verify without privileged access or operator self-attestation.

CLAIMS-BASED AI
where most AI is at now
VERIFIABLE AI
at minimum does the following:
Who is the actor?
Inferred from credentials.
The actor is attested.
What were they allowed to do?
Asserted in policy.
Authority documented & signed.
What did they actually do?
Reconstructed from logs.
Each action carries evidence.
What is the agent made of?
Undocumented, changes silently.
Composition documented.
Who can verify?
Only the vendor.
Someone other than the vendor.
The macroeconomics of scarcity

Verification Is the New Moat.

As compute costs collapse, automated execution becomes abundant. This shift creates dual realities: an explosion of positive capability—infinite potential in science, medicine, and productivity—alongside an equal collapse in the cost of generating automated harm and systemic exploits.

Whether an agent is generating breakthroughs or executing attacks, the sheer volume and velocity of machine execution create a hard physical reality: human verification breaks at scale. The burden of verification must fall on machines.

“In a sea of infinite synthetic production, provenance becomes the scarcity anchor.”

CHRISTIAN CATALINI, XIANG HUI, JANE WU, ARXIV, FEBRUARY 2026

COST TO VERIFY — BOUNDED

COST TO AUTOMATE — HEADING TO ZERO

COST

TIME

Unlocking verifiable AI across society

Machine-Speed Open Verification for Society.

When the burden of open verification is handed to machines, we can more easily trust autonomous agents can safely tackle challenges too complex for human timelines. To translate this technical capability into societal progress, every sector requires a dedicated mechanism of trust.

THE MARKET CASE

Verifiable execution turns internal agent capability into Intelligence Capital—allowing firms to safely rent, share, and deploy agents across organizational boundaries without incurring unpriceable liability.

DAVID L. SHRIER, “THE INTELLIGENCE CAPITAL MANIFESTO,” IMPERIAL COLLEGE LONDON, 2026

The Firm: Intelligence Compounding

RENTED

SHARED

DEPLOYED

THE POLICY CASE

Regulation is arriving faster than the tools to enforce it: the EU AI Act already demands logging, transparency, and human oversight of high-risk systems, but paper obligations need machine-speed evidence. Open verification gives policymakers deterministic auditability they can write directly into law and procurement—and gives governments deploying their own agents in public services the same accountable footing they demand of the market.

THE CIVIL SOCIETY CASE

Journalists get records that stand up to denial: tamper-evident evidence of what an agency’s or company’s agent actually did. Human-rights advocates get both sides of it— they can demand verifiable records from the systems that act on vulnerable people, and verify that their own tools kept sources and identities inside the boundaries they were given. Citizens get the receipt: when an agent denies a claim, a loan, or a benefit, anyone they trust can verify the decision stayed within its published controls—without taking the operator’s word.

The market case

Solving the enterprise dilemma.

CISOs and business leaders are deploying agentic workflows blind. Enterprises are trapped between constraining agents into uselessness or unleashing them with unmanaged liability— leading to insurance exclusions, regulatory non-compliance, and unpriced liability.

79%

of organizations deploying agentic AI can’t observe what their systems actually did. They’re stuck between constraining agents and losing value, or unleashing them and accepting unmanaged risk.

SOURCE: AKTO, STATE OF AGENTIC AI SECURITY, 2025

The Agent Risk-to-Bind Matrix

RISK

HIGH

LOW

FAILED

RISK ↑↑ · VALUE −

Agents operate unchecked with nothing to show for it.

UNLEASHED

RISK ↑↑ · VALUE ↑↑

High output, but no way to verify agent actions.

CONSTRAINED

RISK ↓↓ · VALUE ↓↓

Authority restricted, preventing agents from performing their core tasks.

CONTROLLED

RISK ↓↓ · VALUE ↑↑

Agents operate autonomously with machine-speed verifiable evidence. The only quadrant that works.

LOW

VALUE

HIGH

Open verification

Introducing Open Verification: Purpose-Built for the Agentic Age.

Open verification carries open source’s principle into the agentic age. It is a type of verification where what you must trust is a mechanism anyone can verify, not a party.

The test is where the root of trust sits: mathematics, a distributed protocol, or, at its strongest, execution that cannot run unless its integrity holds. What open verification removes is the need to trust a single gatekeeper.

VERIFIABLE AI — THE CATEGORY

OPEN VERIFICATION
A mode of verification where no single party must be trusted

Open verification

A Trustable AI Stack Needs Open Verification.

Whatever sits beneath your deployment, an open-source model, a closed frontier model, or local inference on infrastructure you control, the actions your agents take still need evidence anyone can openly verify, without privileged access and without trusting the operator.

Open weights* alone verify nothing about behavior, and a closed model can still be openly verified. The new kind of open the agentic era demands is open verification.

*Open weights are not necessarily open source.

Deploymentthe actions

Open verification

Open Verification does not replace existing assurance tools. A Tier 2 audit rests on the operator’s own record. Anchoring it in Tier 3 evidence gives the auditor something they did not have to take on anyone’s word.

What variesbefore the agent acts
Runtime
Weights
Model code
Training data

Pick one per row.

Proof-of-Control Standard

Proof-of-Control: A Foundational Anchor of Open Verification.

Advanced AI Society is introducing Proof-of-Control, an industry-led open standard that allows anyone to openly verify that an agent stayed within the controls it was given.

Why it matters: it converts AI governance from assurances into evidence. A security leader can green-light agents at scale because every action carries a tamper-evident record that satisfies the auditor, the insurer, and the regulator at the speed the agents run. Think of it as a public notary for your agents’ actions, except no one has to trust the notary.

Verifying control first makes enterprise liability measurable, and therefore priceable and defensible for business, while establishing the essential containment layer required for society.

It does not judge whether those controls were the right ones; that judgement stays with the people who set them.

VERIFIABLE AI — THE CATEGORY

OPEN VERIFICATION

PROOF-OF-CONTROL
verifying agent controls

= THERE ARE MANY WAYS TO OPEN VERIFICATION

WHAT GETS VERIFIED: THE SIX DOMAINS OF VERIFICATION

PROVENANCE

The chain of custody from origin to output.

PRIVACY

Data handling stayed within its privacy bounds.

PORTABILITY

Evidence holds across system boundaries.

AUTHORIZATION

The agent acted within granted permissions.

IDENTITY

Who acted: human, agent, or a chain of both.

SECURITY

The execution environment and controls held.

The agenda

Our Three-Point Agenda.

Advanced AI Society builds the open verification infrastructure with our partners.

Build the Public Infrastructure for the Open Verification Ecosystem.

Open verification runs on public goods. The standards, tools, research, and services of the ecosystem need to be built out, in the open, to give the field the neutral foundation a verifiable AI market requires.

Design the Open Verification Ecosystem with Cybersecurity Leaders.

Cybersecurity leaders are the ones responsible for implementing agentic AI, which makes them the people who matter most to get this right. Our agenda is to design the ecosystem with them from the start.

Spread Adoption of Verifiable AI to Scale Low-Cost Defense.

Verifying an agent’s actions costs far less than executing them, which is what makes defense affordable at scale. Member builders create the open tooling that makes verification cheap and fast; buyers adopt verifiable AI directly into their stack.

How to participate

We Have a Small Window to Build the Open Verification Ecosystem for Verifiable AI.

Join the industry association

Join as an organizational member if you’re a founder and buyer of verifiable AI. Open to start-ups, enterprises, universities, and key players in the open verification ecosystem.

Learn more

Join the open verification movement

Join as an individual. Free and open to any individual who wants to advance verifiable AI and open verification.

Sign up

Join Proof-of-Control

If you’re a cybersecurity practitioner or CISO, we invite you to join as a Founding Contributor to Proof-of-Control.

Become a founding contributor →(Gmail sign-in required)

Join the Open Verification Lab

Contribute or lead research, build tools that advance Proof-of-Control and the larger open verification category.

Join the Lab