AI agent verification

AI agent verification: an independent verdict on whether the claims about an agent are true.

AI agent verification is the independent determination of whether the governance claims made about an AI agent hold against evidence, issued before a counterparty relies on the agent. Certisyn issues that determination as a sealed, policy-versioned, revocable record against the AI Governance Verified standard (AIGVS), published at the IETF as an individual Internet-Draft and open for review. Every verdict resolves publicly at registry.certisyn.com.

3 questions about an agent

A counterparty deciding whether to transact with an AI agent asks 3 different questions. The market answers the first 2 well. Certisyn answers the third.

QuestionLayerWhat answers it
Who is the agent?IdentityAgent name services, agent passports and on-chain agent registries establish who an agent is and who stands behind it.
What did the agent do?Runtime evidenceExecution traces and hardware attestation record what an agent did and where it ran.
Are the claims about how the agent is governed true?Governance verdictCertisyn: an independent, sealed, revocable determination, issued before the transaction.

What a Certisyn verdict contains

Every determination is a record another party can replay. It is bound to the exact policy version it was made under, anchored so its time of issue is fixed, and it names its own gaps.

FieldWhat it gives the reader
Policy versionThe exact rule set in force at issuance, so a later reader can tell whether the standard moved after the verdict.
Derivation rootA hash chain over the evidence and the reasoning, independently recomputable from the record.
Public anchorThe root committed to a public chain, so the time of issue is fixed by a party with no interest in the outcome.
Maturity levelDocumented, Operational or Adversarial-ready. A level is earned against evidence.
Could not determineEvery claim the evidence did not reach, stated plainly, with the count out of the total claims assessed.
Revocation stateLive. Monitoring withdraws the seal on drift.

The 8 control areas AIGVS assesses

AIGVS verifies how an organisation governs its use of AI. The 8 control areas are:

  • AI inventory: what is deployed, where, and under whose authority.
  • Risk assessment: assessed before deployment and revisited on change.
  • Model provenance: what the system is built on and where it came from.
  • Application controls: the limits the agent operates inside.
  • Prompt and output governance: what goes in and what is allowed out.
  • Identity and access: who and what may direct the agent.
  • Logging: a record that survives the incident it documents.
  • Incident response: what happens when the agent is wrong.

How a verdict is issued

  • Submit. The subject names the agent, its purpose and where it runs.
  • Connect. The subject connects the agent's runtime through an MCP endpoint or an existing identity or trace record. Access is scoped, read-only and revocable by the subject at any time.
  • Independent review and seal. An accredited Issuing Partner reconciles the evidence against AIGVS and seals the determination.
  • Listed and monitored. The verdict receives a registry code and a portable badge, and monitoring revokes the seal on drift.

Independence is a structural property

The platform that builds an agent cannot credibly verify it. The marketplace that lists an agent and the operator that profits from it carry the same limit. Certisyn issues determinations and accredits the partners who issue under its standard, and separation of duties between those 2 functions is enforced in the pipeline. The conflict-of-interest gate runs at the point of sale and at issuance, and it refuses where a conflict exists.

The test of an independent verdict
A verdict a subject could mint for itself carries no information. Review is deliberate and human-supervised for that reason.

Check a verdict yourself

These public endpoints need no account. They return the state of a determination, the anchor check, the open registry search and the coverage report.

# Resolve a determination: state, policy version, claims summary, derivation root, anchor
curl https://certisyn.com/api/v1/public/scorecard/{vro_code}

# Check the anchor for a root
curl https://certisyn.com/api/v1/anchor/verify/{root}

# Search the open registry
curl 'https://certisyn.com/api/v1/registry/search?q=acme'

# Read what the engine covers, with denominators
curl https://certisyn.com/api/v1/verification/capability

Coverage is published with its gaps. The capability endpoint reports what the engine covers, with denominators, and names every register no domain has claimed. Read it before relying on a verdict for a claim type.

What AIGVS scopes

AIGVS verifies governance of the use of AI. A determination describes a subject at a point in time under a stated policy version, which is why monitoring is part of the product. A verdict is evidence a decision-maker weighs, and it sits alongside model evaluation and regulatory approval as a separate input.

Frequently asked

What is AI agent verification?

AI agent verification is the independent determination of whether the governance claims made about an AI agent are true, issued before a counterparty relies on the agent. Certisyn issues it as a sealed, policy-versioned record against the AI Governance Verified standard (AIGVS).

How does agent verification relate to agent identity and runtime evidence?

Identity establishes who an agent is. Runtime evidence records what an agent did. Verification determines whether the claims about how the agent is governed are true. A counterparty deciding whether to transact with an agent needs all 3 answers.

What does an AIGVS verdict contain?

The policy version in force at issuance, a derivation root that anyone can recompute from the record, a public anchor that fixes the time of issue, a maturity level, the claims the evidence did not reach, and the current revocation state.

Who issues a verdict?

An accredited Issuing Partner reconciles the evidence against AIGVS and seals the determination. A conflict-of-interest gate runs at the point of sale and at issuance, so a party with a hand in building or operating an agent cannot issue its verdict.

Can a verdict be revoked?

Yes. Monitoring withdraws the seal when the subject drifts from the evidence, and the public registry reflects the change immediately.

How does a counterparty check a verdict?

Every determination resolves over a public endpoint with no account, key or signup. The record carries what a reader needs to recompute the derivation root and to check the anchor without asking Certisyn.

Where is the AIGVS standard published?

AI Governance Verified is published at the IETF as an individual Internet-Draft, draft-hillier-certisyn-ai-governance-verified, and is open for review.

Related