Skip to content
The Proof-of-Control v1.0 working draft is open for public comment through October 30, 2026.Read and comment →

Proof-of-Control v1.0 is open for live commentary through October 30, 2026.

The question everyone deploying agents has to answer (and most cannot today):Can I deploy this agent and still account for what it does?How do I know the controls held?

More than 80 security leaders, along with the founders of the companies building verifiable AI, have come together to create Proof-of-Control: an open standard for tamper-evident evidence, openly verifiable by anyone, that an AI agent stayed within the controls it was given.

Become a founding contributor → (Google sign-in required)


The enterprise reality of agentic AI

Agents are being deployed on faith.

Agents are already reprogramming their own environments, poisoning their own memory, and minting identities for other agents, at a speed beyond human oversight.

01 The system writes its own record.

Logs are generated by the same system they are meant to account for. The entity being watched is writing its own report card, and a compromised step can rewrite it afterward. Your logs are written by the thing you are investigating.

02 A policy states intent, not behavior.

A governance policy says what should happen. It produces no record of what did.

03 A contract assigns liability after the fact.

It creates a consequence for a violation. It does not produce evidence of what occurred, and it is a right you cannot exercise without the cooperation of the party you would be exercising it against.


Seeing what your agents achieved does not tell you what they actually did

Security leaders cannot bound an incident they cannot reconstruct.

Enterprises cannot show a board what their agents did last quarter.

Regulators cannot confirm that a high-risk system stayed within authorized parameters.

Insurers cannot underwrite what they cannot audit.

Procurement teams have no way to compare vendors on the one question that matters: can you show me what your system did, and can I check it myself.

Nobody owns the action. A delegation chain runs three agents deep and no one can name who authorized the last step.


The solution

We need to be able to openly verify agent controls.

Proof-of-Control is an open standard for tamper-evident evidence, openly verifiable by anyone, that an AI agent stayed within the controls it was given. It is the anchoring standard of the third-party open verification ecosystem that Advanced AI Society is building with its member organizations and founding contributors in the security industry.

Electrical safety has Underwriters Laboratories. Steam has ASME’s boiler code. Cloud software has SOC 2. The certificate authorities that secure the web have WebTrust audits. The Agentic Age needs Proof-of-Control.

Charles Iheagwara

“We’re running on a broken trust model, vendor assertions instead of evidence. That doesn’t work when patient safety and our intellectual property are on the line. We need open verification: an independent, inspectable way to know what these agents actually did. That’s the gap Proof-of-Control closes, and it’s why I’ve joined this effort at Advanced AI Society.”

Charles IheagwaraGlobal Head, AI & Cybersecurity, AstraZeneca
Distinguished Review Board, Proof-of-Control
More than 80

security leaders have signed on to develop Proof-of-Control with our members.

See everyone who has joined ↓

Meet our Distinguished Review Board

Michelle DennedyMichelle DennedyPrivacy expert
Bruce SchneierBruce SchneierSecurity technologist
Charles IheagwaraCharles IheagwaraGlobal Head, AI & Cybersecurity, AstraZeneca

The Verifiability Gap

As machine capabilities compound exponentially and human oversight of machines scales linearly, the Verifiability Gap is the widening distance between what AI agents do and anyone’s ability to openly verify that they stayed within the controls they were given.

The Verifiability Gap in AI: when machine capability outpaces human oversight

CROSSOVER

VERIFIABILITY
GAP

HUMAN OVERSIGHT

MACHINE CAPABILITY

CAPABILITY

TIME

What the gap actually looks like

A record only the operator can vouch for

A support agent reads a customer record, calls three internal tools, and issues a refund. It reports success. Did it open only the records it was allowed to, or pull more while it was there? Was its goal quietly redirected by a crafted input? An agent reporting that it stayed in bounds is not evidence that it did.

Every incident review begins with evidence the suspect produced.

You would never let a vendor audit itself and yet that is exactly what’s happening right now with your agents.


The third-party open verification ecosystem

One open standard, and the same evidence travels.

Today, every party demanding assurance invents their own process. Your buyer sends a questionnaire, your insurer sends its own assessment, your regulator requests a filing, your certifier asks for access, and none of those records talk to each other. Under one open standard, the evidence your system produces at execution is the same evidence all of them can verify, without any of them trusting you or each other. That is what open buys you that independent never could.

BUYER

INSURER

REGULATOR

CERTIFIER

VENDOR

PRIVATE EVIDENCE — STUCK WHERE IT WAS MADE

BUYER

INSURER

REGULATOR

CERTIFIER

VENDOR

EVERY PARTY REACHES THE SAME ANSWER FROM THE SAME RECORD. THAT IS WHAT LETS ONE BODY OF EVIDENCE SERVE ALL OF THEM.

What Proof-of-Control does differently

What the evidence is

What your agent did, not what it can do

Formal verification says what a system is bounded to do. Evaluations say how it behaved in a test. Proof-of-Control shows what your agent did in your deployment.

Binary, not scored

Maturity scores and risk ratings are subjective judgments. Proof-of-Control produces binary evidence: an action either occurred and stayed within assigned controls, or it did not. There are no gradients to negotiate and no weightings to dispute.

Deterministic, not probabilistic

AI models produce probabilistic outputs, but the verification record must be deterministic. Every verifier reaches the exact same conclusion from the same record, regardless of who asks or when. The model stays probabilistic; the verification of what it executed does not.

Machine verification, not human sampling

SOC 2 relies on human sampling, and no amount of sampling keeps up with agents that act a thousand times a week. Proof-of-Control evidence is verified by machine, so a million of your agent’s actions cost close to what one costs.

What you do not have to trust, or buy

Open mechanisms, not trusted third parties

An independent auditor is still a party you have to trust. Open verification removes the party altogether and anchors verification in mechanisms anyone can inspect, with their assumptions stated, while your data, your prompts, and your models stay private. One question sorts any vendor: can I verify it without trusting you?

An open standard, not a proprietary product

Proof-of-Control specifies what the evidence must be, not the tool that produces it, so you assemble the mechanisms you already run, per domain, against the tier your risk calls for. A mechanism invented five years from now can still conform.

Tamper-evident records, not self-reported enforcement logs

Runtime gateways enforce policy, and the operator controls the logs. A gateway that was misconfigured, bypassed, or disabled still produces a clean log. Proof-of-Control requires evidence written where the agent cannot reach it, and tamper-evident, so anyone holding the record can detect a change to it.

One verifiable record, not fragmented reporting

Your auditor, your insurer, your regulator, and your counterparty each ask a version of the same question, and today each answer is produced separately, on its own schedule. Evidence anyone can verify answers all four at once, and none of them has to take it on your word.


The Verifiability Tiers:
The Anchoring Framework of Proof-of-Control

Claims-based AI: where most AI is today
Proof-of-Control: achieved at tiers 3–4 · open verification

TIER 01

Assertion

their word

TIER 02

Attestation

a third party vouches

TIER 03

Trust-minimized

anyone can verify

TIER 04

Self-enforcing

it cannot run otherwise

Who you must trust
The operator
A third party or qualified auditor
The verification mechanism itself, open to anyone (mathematical or distributed assumptions)
The protocol itself: continuous constraints, anchored in external hardware roots of trust
How it is verified
Not verified; asserted
An auditor verifies, with privileged access
Anyone can verify, no privileged access
Execution is gated by cryptographic proofs; verification is continuous and automated
When it is verified
Never, or only when questioned
After the fact, sampled
After the fact, but by anyone
Before every execution interval: no proof, no write
On integrity break
Nothing: the system runs regardless
Detected in audit, after the fact
Detected by anyone, but the system can still run
MUST NOT execute until the integrity condition holds again
Accountability
Operator, self-attested
Named human + institution, bound to policy
Same authority, externally verifiable without trusting the operator or their auditors
Accountable person whose authorization is un-bypassable

THE BINARY THRESHOLD: Graded by who you must trust, not by whether cryptography is used. It indicates the phase change from human verification to mechanical verification, from a party’s word to a mechanism anyone can verify.

Verifiability Tiers in Practice.

Tier 1 · Assertion

“Show me your system prompt and your policy settings.”

If the operator’s own records are your only evidence, you have an assertion, not control. Treat it as unverified.

Trust required: total.

Tier 2 · Attestation

“Show me your SOC 2 or ISO 42001 report.”

Good hygiene, but static and retrospective, and it cannot stop a live action. Necessary, not sufficient.

Trust required: the auditor.

Tier 3 → 4 · Trust-minimized, into Self-enforcing

“Show me the signed, openly verifiable evidence for this specific action, and show that policy runs in a trusted execution environment that halts on violation.”

Now you verify the mechanism, not the vendor. This is the bar.

Trust required: the mechanism and the parties it rests on, all named in the disclosure.


The six domains of verification

Provenance

Lineage & origin

Verified at the boundary

Where an artifact, model, or piece of data came from, that it matches what it claims to be, and the custody chain linking origin to the action record.

Privacy

Confidentiality

Verified at the boundary

What data was touched, and that the purpose matched the grant — evidenced without exposing the data being protected.

Portability

Cross-context control

Verified at the boundary

That evidence and control move across vendors, platforms, and environments as claimed.

Authorization

Granted authority

Verified at the boundary

That each action stayed within the authority granted, and what happened when it did not.

Identity

Attribution

Verified at the boundary

Whose agent acted, who delegated the authority, and that the operator authorized it.

Security

Environment integrity

Verified at the boundary

That the code ran unmodified, in the environment claimed, with access controls enforced.


The market forcing function

Built for insurance adoption

Priced risk turns verification into a business mandate.

Carriers pricing AI risk today are flying blind on questionnaires, vendor self-claims, and static security reviews, none of which produce evidence an outside underwriter can actually verify. Proof-of-Control replaces self-claims with tamper-evident evidence generated at the moment of execution.

Carriers cannot underwrite what they cannot audit. Adjusters can be deposed, underwriters can testify, and actuaries can defend reserves in court. An AI agent can do none of these, and “the model did it” is not a defense any regulator or court accepts. Proof-of-Control supplies the record. Who testifies to it under oath is one of the questions this working group takes up.

The Proof-of-Control Insurance Working Group, convened by Vidur Nayyar, brings carriers, reinsurers, and underwriters together to convert runtime verification into priceable risk models, claims-evidence frameworks, and a clear insurability classification.

Learn more →Sign up for the working group →

What changes for insurers
Today With Proof-of-Control
Self-reported questionnairesEvidence produced at execution
Vendor compliance claimsOpenly verifiable; no party vouches for the evidence
Logs that can be fabricatedTamper-evident by design
No standardized taxonomyStandardized shared taxonomy
No post-deployment evidenceMachine-verifiable at scale

Open verification

From Proof-of-Control to open verification

Bringing open source’s core principles into the agentic era.

Open source verified the code you ship. But as non-deterministic AI agents take autonomous action, code transparency is no longer enough. Open verification is a new category of standards of verifiable AI where trust does not rely on a central gatekeeper, but on evidence anyone can openly verify.

Claims-based

You are given a report

You have to accept it

It requires a relationship with the operator

It stops at your own boundary

When it is contested, you have their word

Open verification

You are given evidence

You can confirm it yourself

It requires no relationship at all

It crosses every boundary your agents do

When it is contested, you have the record

VERIFIABLE AI

OPEN VERIFICATION


FAQ about Proof-of-Control

Each answer ends with links to the matching sections on GitHub.

The standard’s own FAQ answers sixteen questions, including whether the evidence is post-quantum safe, when someone will require this of you, whether this is a real certification, and who owns it. Read all sixteen on GitHub →


Founding Contributors

Distinguished Review Board

Michelle Dennedy

Michelle Dennedy

LinkedIn ↗

Privacy expert

Charles Iheagwara

Charles Iheagwara

LinkedIn ↗

Global Head, AI & Cybersecurity, AstraZeneca

Bruce Schneier

Bruce Schneier

Website ↗

Security technologist

Leadership Team

Bob Blessing-Hartley

Bob Blessing-Hartley

LinkedIn ↗

CTO, Shielded Technology

Patrick Duffy

Patrick Duffy

LinkedIn ↗

CEO, Solv Labs

Cristin Flynn Goodwin

Cristin Flynn Goodwin

LinkedIn ↗

Managing Partner, Advanced Cyber Law

Drummond Reed

Drummond Reed

LinkedIn ↗

Director, First Person Cooperative

Mo Sadek

Mo Sadek

LinkedIn ↗
Ed Sewell

Ed Sewell

LinkedIn ↗

Founder and Chair

Founding Contributors

Alice Albl

Alice Albl

LinkedIn ↗

Emergent Technology Researcher, Mueller Consulting

Abdelhamid Bakhta

Abdelhamid Bakhta

LinkedIn ↗

Head of Applied AI & Verifiable Intelligence

Tim Bansemer

Tim Bansemer

LinkedIn ↗

CEO inblock.io assets GmbH

Joe Braidwood

Joe Braidwood

LinkedIn ↗

Co-founder & CEO, Glacis Technologies, Inc.

David Campbell

David Campbell

LinkedIn ↗

Head of AI Security, Scale AI

David Cass

David Cass

LinkedIn ↗

CISO and Enterprise Technology Leader, Harvard (HES) Faculty

Sharath Chandra

Sharath Chandra

LinkedIn ↗

Founder & Architect

Vinod Choyi

Vinod Choyi

LinkedIn ↗

Distinguished Engineer - Security Architect, Verizon

Ben Christensen

Ben Christensen

LinkedIn ↗

Head of Partnerships, AI 2030 | Senior Fellow, AEGIXInstitute.org | VP Innovation and Impact, Cultural Infusion's Atlas | Advisor, Advanced AI Society | Fellow AIandFaith.org | Startup Mentor, Quay Acceleration | Steering Committee, IEEE Global AI Systems Flourishing Initiative

Eugene Coffie

Eugene Coffie

LinkedIn ↗

CEO & Founder of Predict AI

Crystal Coindreau

Crystal Coindreau

LinkedIn ↗

A.V.P., Sr. Security Architect - AI

Rosalyn Curato

Rosalyn Curato

LinkedIn ↗

Chief Innovation Officer & GM, Agentic Security

Danny Davis

Danny Davis

Founder, Loqal

Andrew Davis

Andrew Davis

LinkedIn ↗

Founder, Living Code

Brijesh Deo

Brijesh Deo

LinkedIn ↗

Director of Software Development

Fraser Edwards

Fraser Edwards

LinkedIn ↗

CEO, cheqd; Board member, Ayra

Craig Ellrod

Craig Ellrod

LinkedIn ↗

Founder, CEO of the HACKERverse®

David Goecke

David Goecke

LinkedIn ↗

Founder, gotech.ai

Shiva Kumar Gosula

LinkedIn ↗

Information Security Engineer, FinMkt

Matt Grasser

Matt Grasser

LinkedIn ↗

CTO and Co-Founder, Digital Transformation Solutions

Dazza Greenwood

Dazza Greenwood

LinkedIn ↗

Founder, CIVICS.com and Interlateral.com

Nas Hajia

Nas Hajia

LinkedIn ↗

Security Architecture, Lam Research

Dylan Hobbs

Dylan Hobbs

LinkedIn ↗

Principal Founding Engineer, Vouched. KYA-OS Author, Decentralized Identity Foundation (DIF).

Sai Honig

Sai Honig

LinkedIn ↗

Responsible AI & CyberSecurity Leader | International Speaker on Security, AI Ethics & Women in Tech | Senior Security Consultant, Novera Consulting

Ahmer Inam

Ahmer Inam

LinkedIn ↗

Founder and CEO, Cognisee PBC

John Jiang

John Jiang

LinkedIn ↗

Cloud and Security Architect

JP

JP

LinkedIn ↗

CEO, Blue Cycle LLC

Rajesh Kanungo

Rajesh Kanungo

LinkedIn ↗

CEO of TalaSeure, Inc. CSA member

Ali Khan

Ali Khan

LinkedIn ↗

CEO, SHAPE, Visiting Professor

Mahesh Kukreja

Mahesh Kukreja

LinkedIn ↗

Security Engineer, Zipline International

Markus Lam

Markus Lam

LinkedIn ↗

Co-founder, Angainor BD @Axal, in-coming president,NYU blockchain labs

Chris Marzilli

Chris Marzilli

LinkedIn ↗
Lain McNeill

Lain McNeill

LinkedIn ↗

Founder, Hybrid Intelligent Systems Design & Integration (HISDI)

Mihaly

Mihaly

LinkedIn ↗

Security Manager, Deutsche Telekom Security

Atsushi Mizushima

Atsushi Mizushima

LinkedIn ↗

Partner, Nishimura and Asahi

Dilip Mohapatra

Dilip Mohapatra

LinkedIn ↗

CEO

Rezza Moieni

Rezza Moieni

LinkedIn ↗

CTO and CyberSecurity Adjunct Lecturer

Paul Oakes

Paul Oakes

LinkedIn ↗
Pushpendra Pal

Pushpendra Pal

LinkedIn ↗

CEO, DapplePot

Govindaraj Palanisamy

Govindaraj Palanisamy

LinkedIn ↗

Principal Architect, Global Payments

Satnam Purewal

Satnam Purewal

LinkedIn ↗

ISACA Puget Sound, Board Member, AI Safety WG (Cloud Security Alliance)

Arvind Raja

Arvind Raja

LinkedIn ↗

Founder & CEO, Kurral

Marianna Richardson

Marianna Richardson

LinkedIn ↗

Director of Communication, G20 Interfaith Forum Assoc.

Kristian Ronn

Kristian Ronn

CEO, Lucid Computing

Nelson Rosario

Nelson Rosario

LinkedIn ↗

Partner @ Rosario Tech Law | Board @ Illinois Blockchain Association | AI Steering Committee @ ISBA | Advisor @ Advanced AI Society

Andrew Rubinger

Andrew Rubinger

LinkedIn ↗

Founder, withaileron.ai

Aman Sardana

Aman Sardana

LinkedIn ↗
Udbhav Saxena

Udbhav Saxena

LinkedIn ↗

Software Intern at Vouched

Amy Steagall

Amy Steagall

LinkedIn ↗

Stanford University Chief Information Security Officer

Mikayla Stewart

Mikayla Stewart

LinkedIn ↗

Cofounder, Coldstart AI, Founder @ Atono, CTO & Cofounder @ Athena Collective

Dan Stocker

Dan Stocker

LinkedIn ↗

Executive Director, AI Security, JPMorganChase

Nowa Sutaka

Nowa Sutaka

LinkedIn ↗

CEO & Founder, Puddin AI

Ravi Tanguturi

Ravi Tanguturi

LinkedIn ↗

Chief AI Security Architect, Director - Solutions Engineering, PointGuardAI

Ramesh Thiagarajan

Ramesh Thiagarajan

LinkedIn ↗

Security Architect, Amazon

David Thomson

David Thomson

LinkedIn ↗

Co-founder and Chief Ecosystem Architect

Yogesh Trivedi

Yogesh Trivedi

LinkedIn ↗

Founder and CEO, CognitivTrust

Julie Tsai

Julie Tsai

LinkedIn ↗

Board Member, Bay Area CSO Council; CISO-in-Residence Ballistic Ventures; Founder Polaris Collective; Cyber Co-Lead AI Insiders; IANS Faculty

John V

John V

LinkedIn ↗

AI red team SME at the Institute of Security and Technology (NC3)

Samuel Vance-Law

Samuel Vance-Law

Head of Research

Joshua Waldrep

Joshua Waldrep

LinkedIn ↗

Founder, Pipelock (open-source agent firewall). Pipelab

Lindsay Walker

Lindsay Walker

LinkedIn ↗

Product Manager, Hedera AI Studio

Aydan Wang

Aydan Wang

LinkedIn ↗

RNA Biology Researcher, University of Manitoba; Co-Founder, Angainor; Undergraduate Researcher, University of Pennsylvania

Caroline Wong

Caroline Wong

LinkedIn ↗

Chief Strategy Officer, Axari; Author, The AI Cybersecurity Handbook (Wiley, 2026)

Seref Yarar

Seref Yarar

LinkedIn ↗

Co-founder, Index Network


Join them

The standard is still being written. Contributors shape what it says before v1.0.

Become a founding contributor →(Google sign-in required)


How to Get Involved

Join the alliance

Join as an organizational member if you’re a founder and buyer of verifiable AI. Open to start-ups, enterprises, universities, and key players in the open verification ecosystem.

Learn more

Join the open verification movement

Join as an individual. Free and open to any individual who wants to advance verifiable AI and open verification.

Sign up

Join Proof-of-Control

If you’re a cybersecurity practitioner or CISO, we invite you to join as a Founding Contributor to Proof-of-Control.

Become a founding contributor →(Google sign-in required)

Join the Open Verification Lab

Contribute to or lead research, and build tools that advance Proof-of-Control and the larger open verification category.

Join the Lab