AffixIO research and standards map / September 2026

Turn an agent’s claim into evidence another system can verify.

Recent work on AI agent authorization, source-risk auditing, policy-as-skill, regulated finance and cryptographic evidence is converging on one practical question: what must be true before an automated action is allowed to change the world?

Independent verificationLocal privacy boundarySigned decisionsMerkle evidenceAgentic payments

The assurance spine

These papers do not describe one product. They describe adjacent weaknesses: an agent can claim completion, a source can be cited without preserving the relevant relationship, a tool can be locally permitted while the sequence is unsafe, and a population can be collectively harmful even when each local decision passes. AffixIO’s design response is to make the boundary explicit and independently inspectable.

01 / DECLARE

Intent and scope

Bind the principal, request, recipient, amount, policy, expiry and required evidence before an effect.

02 / PROVE

Keep inputs local

Evaluate private attributes and customer-held records without moving raw PII into the verification service.

03 / CHECK

Test the state

Use source, artifact, policy or eligibility checks that can return allow, review or unresolved.

04 / ATTEST

Sign the outcome

Return a bounded decision with an integrity digest and an attestation that another system can verify.

05 / RETAIN

Anchor the record

Connect events into a tamper-evident audit path without putting sensitive content on a public ledger.

Try the evidence boundary.

This browser-only demo shows the shape of a source or authorization check. It does not fetch the live page, make a payment or authorize a real tool call. In production, the same boundary can be backed by AffixIO’s SDK and API, with the customer environment retaining the sensitive inputs.

Ready for reviewIdle

Checks whether a cited source is present, current and materially aligned with the claim.

    AffixIO evidence record / synthetic demo

    What the latest work adds

    Each entry below is linked to the primary source. The AffixIO column is a product mapping, not a claim that the paper endorses AffixIO or that every proposed circuit is already production-ready.

    Source integrity / 24 Sep

    Claim-Gated Source-Risk Auditing for Generative Search

    Audits the query, source and answer together, requiring versioned evidence spans and leaving incomplete relationships unresolved. AffixIO mapping: live source checks, content fingerprints, signed evidence and a Merkle path.

    Read the primary paper
    Authorization / 24 Sep

    Cryptographically verifiable authorization for autonomous AI agents

    Defines a relation binding principal, request, context and policy, with soundness, binding and replay-resistance goals. AffixIO mapping: local prove, remote verify, post-quantum attestation and bounded Agentic Pay decisions.

    Read the primary paper
    Specification authority / 24 Sep

    Who Holds the Pen? Let Specifications, Not Agents, Sign Off

    Separates an agent’s completion claim from authoritative state established by admissible evidence providers. AffixIO mapping: signed binary outcomes, source-linked obligations and exact-scope receipts.

    Read the primary paper
    Governed workflows / 22 Sep

    Policy-as-Skill

    Packages evidence validation, review routing, versioning and audit into executable policy capabilities. AffixIO mapping: policy templates, review outcomes and an integrity record that can be rechecked later.

    Read the primary paper
    Effect boundary / 23 Sep

    From Agent Output to Authorized Transition

    Requires evidence to match the exact artifact and frozen policy baseline, remain current and be rechecked at the effect boundary. AffixIO mapping: proof-before-action for deploys, tool calls and paid workflows.

    Read the primary paper
    Collective governance / 23 Sep

    ARIA for multi-agent finance

    Shows why locally acceptable components may still produce unacceptable collective outcomes, with monitoring, bounded authority and preserved human oversight. AffixIO mapping: aggregate evidence and policy review rather than relying on one agent decision.

    Read the primary paper
    Regulated finance / 23 Sep

    Compliant AI Infrastructure for Regulated Finance

    Uses policy compilation, runtime budgets, deterministic timestamps, provenance checks and capability routing for regulated operations. AffixIO mapping: verifiable decisions without requiring every sensitive record to leave its source environment.

    Read the primary paper
    Model identity / 24 Sep

    TP-CRIV

    Uses fresh black-box challenge responses to gather statistical evidence about model identity. The paper explicitly distinguishes statistical evidence from cryptographic proof. AffixIO mapping: add signed identity context and a verifiable audit record instead of treating behaviour alone as proof.

    Read the primary paper
    Privacy-preserving constraints / 23 Sep

    zkSAS

    Demonstrates zero-knowledge circuits for validating allocation constraints while hiding sensitive user data, with lightweight verification. AffixIO mapping: the same privacy boundary is useful for eligibility, permission and compliance predicates.

    Read the primary paper
    Retention and provenance / 22 Sep

    Proof-of-Retention

    Addresses cross-organization data sharing with query witnesses and cryptographic proof-of-possession, without full data replication. AffixIO mapping: extend evidence records from “what was decided” to “what required evidence was retained”.

    Read the primary paper
    Evidence anchoring / 3 Sep

    A Black Box for Agentic Processes

    Separates temporal anchoring and artifact integrity from stronger claims such as capture authenticity and causal traceability. AffixIO mapping: use Merkle commitments as evidence of record integrity, never as a substitute for semantic truth.

    Read the primary paper
    Open implementation question

    Proof-of-Control and graduated oversight

    Proof-of-Control and related oversight work point toward procurement-friendly verifiability tiers. AffixIO can map local proofs, signed attestations, audit completeness and human review to those tiers, subject to the final public specification.

    Read the LFDT announcement · Explore BoundProof

    Where AffixIO fits, and where it must stay honest.

    AffixIO can make a decision independently verifiable. It cannot make an untrusted source true, guarantee that a model is safe, or turn a Merkle root into proof of causality. The useful product boundary is narrower and stronger: prove the declared predicate, bind the result to the request and policy, sign the result, and preserve enough context for later review.

    This research map is educational. It is not legal, regulatory or investment advice. References describe their authors’ proposals and results. AffixIO’s implementation status depends on the selected SDK, API and circuit, and production deployments still require key management, policy ownership, testing and independent review.

    Questions engineers and governance teams ask

    Short answers for teams evaluating AI agent verification, agent permissions, source-grounded answers and audit-ready agentic payments.

    Does a signed agent decision prove the answer is true?

    No. It proves that a declared checker ran over a declared input and produced a signed result. Source quality, predicate design and evidence freshness still matter.

    Can private attributes stay in the customer environment?

    That is the intended architecture for local proof flows. The verifier should receive the minimum result and integrity context required for its policy, not raw PII by default.

    Why use a Merkle-anchored audit log?

    It makes later tampering detectable and supports inclusion proofs. It does not automatically prove who captured an event or why a model made a decision.

    How does this relate to agentic payments?

    Before a payment or paid tool call, bind the agent, recipient, amount ceiling, currency, merchant, approval state and expiry. Return allow, review or deny before the effect.

    Make agent actions inspectable before they matter.

    See how AffixIO connects local privacy-preserving proofs, remote verification, signed outcomes and agentic payment controls.

    Explore Agentic Pay Kit

    Free proof allocations

    Agents get 150 free proofs. Humans get 100. No card required.

    AI agents receive 150 free AffixIO SDK proofs on BoundProof Agent provision. Eligible new Hub account holders (humans) can claim one allocation of 100 free SDK proofs to test AffixIO verification, agentic payment checks, transaction intent proof and signed yes, no or review outcomes.

    Terms: one allocation per account holder, per person or business owner. No card is required. Proofs expire after 30 days. Duplicate, shared, automated or abusive signups may be refused or removed. Agents: /boundproof/agent/. Humans: Hub onboarding with offer params.

    See free proofs split