Why trust in AI has to be rebuilt
We Have Entered the Machine-to-Machine Era.
01 · Human → Human
Trust ran on relationships, institutions, and reputation. A person stood behind every action.
02 · Human → Machine
The era of digital transformation. Our current governance, software, and architecture is built for this stage.
03 · Now · Machine → Machine
Agents initiate, at machine scale and speed that humans cannot keep up with. Soon, agents and bots will outnumber human beings on the internet.
HUMAN → HUMAN
HUMAN →
MACHINE
MACHINE →
MACHINE
NOW
SHARE OF INTERACTIONS
TIME
We’ve Crossed the Line: Human Oversight Cannot Keep Up with Machines.
Machine capabilities are compounding exponentially while human oversight over machines scales linearly. We have reached The Crossover—the inflection point where autonomous systems act faster and perform tasks more complex than real-time human oversight can track. The tools we rely on to monitor machines are outdated—manual reviews, reactive policy, and static dashboards. The expanding wedge above this threshold is the Verifiability Gap: an unmonitored operational void where machines act without verifiable evidence, giving attackers a compounding structural advantage.
“We’re potentially looking at a singularity event for cyber attackers.”
BRUCE SCHNEIER, HEATHER ADKINS AND GADI EVRON, “AUTONOMOUS AI HACKING AND THE FUTURE OF CYBERSECURITY,” ORIGINALLY IN CSO, 10 OCTOBER 2025
The Verifiability Gap in AI: when machine capability outpaces human oversight
CROSSOVER
VERIFIABILITY
GAP
HUMAN OVERSIGHT
MACHINE CAPABILITY
CAPABILITY
TIME
The Verifiability Gap Is Widening.
The Verifiability Gap is the widening distance between what AI agents do and anyone’s ability to openly verify that they stayed within the controls they were given.
Because an agent’s path is unpredictable, static vendor logs and annual audit reports reduce true verification to “someone’s word.” Traditional software follows fixed, predictable code paths, making static logging easy.
THE CROSSING, ABOVE
WHAT AGENTS DO
WHAT ANYONE CAN OPENLY VERIFY
VERIFIABILITY GAP
WIDENS AS CAPABILITY COMPOUNDS
What agents do: actions taken, decisions made, data touched—continuous, non-deterministic execution at machine speed.
What anyone can openly verify: operator logs, vendor policies, and static audit reports. All of it someone’s word.
Closing the Verifiability Gap requires open verification at machine speed. Trust can no longer move at human speed.
Unverifiable Agent Controls Are an Existential Risk and a Business Liability.
On the surface, insurers are already declining to cover AI risk. What that points to is much bigger, and it sits below the waterline.
VISIBLE
INVISIBLE
EXISTENTIAL RISK
BUSINESS LIABILITY
When things go wrong (and even when they go right), how do we verify agent controls were put into place?
Static Logs Fail in an Agentic World.
Unlike traditional software, which follows fixed, predictable code paths, agents are intelligent and act with intent. That makes them non-deterministic by nature: given a goal, an agent chooses its own route to point B, picking tools, reasoning chains, and execution routes on the fly. No two runs need look alike.
The Technology to Solve the Verifiability Gap at Machine Speed Is Here, but the Security Solutions Are Scattered.
Verifiable AI is a latent category waiting for structural unification.
The tech to make agentic orchestration secure exists in a range of cryptographic and decentralized services: from trusted execution environments and hardware attestation to zero-knowledge proofs.
Verifiable AI Sits at the Intersection of the Fastest-Growing Categories in AI.
155%
CAGR · AI DATA
The fastest-growing AI spending category
74%
CAGR · AI SECURITY
The second fastest-growing
141%
agentic AI spending increase
50%+
enterprises deploying agents by 2028
#1
cybersecurity trend: agentic AI security
GARTNER, FORECAST ANALYSIS: AI SPENDING, 4Q25, 17 DECEMBER 2025
From Claims-Based AI to Verifiable AI.
Claims-based AI asks you to trust corporate assertions. Verifiable AI produces tamper-evident evidence that anyone can verify without privileged access or operator self-attestation.
where most AI is at now
at minimum does the following:
Verification Is the New Moat.
As compute costs collapse, automated execution becomes abundant. This shift creates dual realities: an explosion of positive capability—infinite potential in science, medicine, and productivity—alongside an equal collapse in the cost of generating automated harm and systemic exploits.
Whether an agent is generating breakthroughs or executing attacks, the sheer volume and velocity of machine execution create a hard physical reality: human verification breaks at scale. The burden of verification must fall on machines.
“In a sea of infinite synthetic production, provenance becomes the scarcity anchor.”
CHRISTIAN CATALINI, XIANG HUI, JANE WU, ARXIV, FEBRUARY 2026
COST TO VERIFY — BOUNDED
COST TO AUTOMATE — HEADING TO ZERO
COST
TIME
Machine-Speed Open Verification for Society.
When the burden of open verification is handed to machines, we can more easily trust autonomous agents can safely tackle challenges too complex for human timelines. To translate this technical capability into societal progress, every sector requires a dedicated mechanism of trust.
THE MARKET CASE
Verifiable execution turns internal agent capability into Intelligence Capital—allowing firms to safely rent, share, and deploy agents across organizational boundaries without incurring unpriceable liability.
DAVID L. SHRIER, “THE INTELLIGENCE CAPITAL MANIFESTO,” IMPERIAL COLLEGE LONDON, 2026
The Firm: Intelligence Compounding
RENTED
SHARED
DEPLOYED
THE POLICY CASE
Regulation is arriving faster than the tools to enforce it: the EU AI Act already demands logging, transparency, and human oversight of high-risk systems, but paper obligations need machine-speed evidence. Open verification gives policymakers deterministic auditability they can write directly into law and procurement—and gives governments deploying their own agents in public services the same accountable footing they demand of the market.
THE CIVIL SOCIETY CASE
Journalists get records that stand up to denial: tamper-evident evidence of what an agency’s or company’s agent actually did. Human-rights advocates get both sides of it— they can demand verifiable records from the systems that act on vulnerable people, and verify that their own tools kept sources and identities inside the boundaries they were given. Citizens get the receipt: when an agent denies a claim, a loan, or a benefit, anyone they trust can verify the decision stayed within its published controls—without taking the operator’s word.
Solving the enterprise dilemma.
CISOs and business leaders are deploying agentic workflows blind. Enterprises are trapped between constraining agents into uselessness or unleashing them with unmanaged liability— leading to insurance exclusions, regulatory non-compliance, and unpriced liability.
79%
of organizations deploying agentic AI can’t observe what their systems actually did. They’re stuck between constraining agents and losing value, or unleashing them and accepting unmanaged risk.
SOURCE: AKTO, STATE OF AGENTIC AI SECURITY, 2025
The Agent Risk-to-Bind Matrix
RISK
HIGH
LOW
FAILED
RISK ↑↑ · VALUE −
Agents operate unchecked with nothing to show for it.
UNLEASHED
RISK ↑↑ · VALUE ↑↑
High output, but no way to verify agent actions.
CONSTRAINED
RISK ↓↓ · VALUE ↓↓
Authority restricted, preventing agents from performing their core tasks.
CONTROLLED
RISK ↓↓ · VALUE ↑↑
Agents operate autonomously with machine-speed verifiable evidence. The only quadrant that works.
LOW
VALUE
HIGH
Introducing Open Verification: Purpose-Built for the Agentic Age.
Open verification carries open source’s principle into the agentic age. It is a type of verification where what you must trust is a mechanism anyone can verify, not a party.
The test is where the root of trust sits: mathematics, a distributed protocol, or, at its strongest, execution that cannot run unless its integrity holds. What open verification removes is the need to trust a single gatekeeper.
VERIFIABLE AI — THE CATEGORY
OPEN VERIFICATION
A mode of verification where no single party must be trusted
A Trustable AI Stack Needs Open Verification.
Whatever sits beneath your deployment, an open-source model, a closed frontier model, or local inference on infrastructure you control, the actions your agents take still need evidence anyone can openly verify, without privileged access and without trusting the operator.
Open weights* alone verify nothing about behavior, and a closed model can still be openly verified. The new kind of open the agentic era demands is open verification.
*Open weights are not necessarily open source.
Open verification
Open Verification does not replace existing assurance tools. A Tier 2 audit rests on the operator’s own record. Anchoring it in Tier 3 evidence gives the auditor something they did not have to take on anyone’s word.
Pick one per row.
Proof-of-Control: A Foundational Anchor of Open Verification.
Advanced AI Society is introducing Proof-of-Control, an industry-led open standard that allows anyone to openly verify that an agent stayed within the controls it was given.
Why it matters: it converts AI governance from assurances into evidence. A security leader can green-light agents at scale because every action carries a tamper-evident record that satisfies the auditor, the insurer, and the regulator at the speed the agents run. Think of it as a public notary for your agents’ actions, except no one has to trust the notary.
Verifying control first makes enterprise liability measurable, and therefore priceable and defensible for business, while establishing the essential containment layer required for society.
It does not judge whether those controls were the right ones; that judgement stays with the people who set them.
VERIFIABLE AI — THE CATEGORY
OPEN VERIFICATION
PROOF-OF-CONTROL
verifying agent controls
= THERE ARE MANY WAYS TO OPEN VERIFICATION
WHAT GETS VERIFIED: THE SIX DOMAINS OF VERIFICATION
PROVENANCE
The chain of custody from origin to output.
PRIVACY
Data handling stayed within its privacy bounds.
PORTABILITY
Evidence holds across system boundaries.
AUTHORIZATION
The agent acted within granted permissions.
IDENTITY
Who acted: human, agent, or a chain of both.
SECURITY
The execution environment and controls held.
Our Three-Point Agenda.
Advanced AI Society builds the open verification infrastructure with our partners.
Build the Public Infrastructure for the Open Verification Ecosystem.
Open verification runs on public goods. The standards, tools, research, and services of the ecosystem need to be built out, in the open, to give the field the neutral foundation a verifiable AI market requires.
Design the Open Verification Ecosystem with Cybersecurity Leaders.
Cybersecurity leaders are the ones responsible for implementing agentic AI, which makes them the people who matter most to get this right. Our agenda is to design the ecosystem with them from the start.
Spread Adoption of Verifiable AI to Scale Low-Cost Defense.
Verifying an agent’s actions costs far less than executing them, which is what makes defense affordable at scale. Member builders create the open tooling that makes verification cheap and fast; buyers adopt verifiable AI directly into their stack.
We Have a Small Window to Build the Open Verification Ecosystem for Verifiable AI.
Join the industry association
Join as an organizational member if you’re a founder and buyer of verifiable AI. Open to start-ups, enterprises, universities, and key players in the open verification ecosystem.
Join the open verification movement
Join as an individual. Free and open to any individual who wants to advance verifiable AI and open verification.
Join Proof-of-Control
If you’re a cybersecurity practitioner or CISO, we invite you to join as a Founding Contributor to Proof-of-Control.
Become a founding contributor →(Gmail sign-in required)
Join the Open Verification Lab
Contribute or lead research, build tools that advance Proof-of-Control and the larger open verification category.