From 3117a33107f306f46239b1ec7c82b1c2c4b4491b Mon Sep 17 00:00:00 2001 From: Aere Network Date: Tue, 29 Sep 2026 22:01:33 +0300 Subject: [PATCH] AIP-23: a sixteenth proof kind, agent-decision (an AI agent's action judged against a policy named by its hash, allowed or refused and why), with its conformance envelope; its actionHash is the SHA-256 of the canonical JSON of the action, so anyone can recompute it. Produced by the agents component published in aere-quantum the same day. All sixteen envelopes VALID with verify-proof.mjs offline. --- aips/AIP-23.md | 6 +++++ aips/aip23-kinds/KINDS.json | 36 ++++++++++++++++++++++++++++ aips/aip23-kinds/README.md | 1 + aips/aip23-kinds/agent-decision.json | 14 +++++++++++ 4 files changed, 57 insertions(+) create mode 100644 aips/aip23-kinds/agent-decision.json diff --git a/aips/AIP-23.md b/aips/AIP-23.md index d53da57..b9f2153 100644 --- a/aips/AIP-23.md +++ b/aips/AIP-23.md @@ -171,6 +171,10 @@ covering anchor post-quantum from the presence of a certificate; it is replaced identity, compliance, runtime, location, device, payment, ownership, time, block, authorization, settlement, provenance, AI; the last three before AI were added on 2026-09-28), each with its required fields in `KINDS.json` and one envelope. A `settlement` carries its transaction and block as 32-byte hashes as they are, never re-hashed; a `provenance` names a non-empty list of parents. +- Later on 2026-09-29, a sixteenth kind in the same folder: `agent-decision` (`aere-proof-of-agent-decision`), an AI agent's action + judged against a policy named by its hash, allowed or refused and why. Its `actionHash` is the SHA-256 of the canonical JSON of the + action (keys sorted at every level), so anyone can recompute it from the action. It is produced by the agents component published + the same day in `aere-quantum/agents/`. ### Measured status (2026-09-27) @@ -194,6 +198,8 @@ covering anchor post-quantum from the presence of a certificate; it is replaced - Each of the fifteen envelopes in `aere-research/aips/aip23-kinds/` is `VALID` with the reference verifier offline (form and integrity pass; signature and finality are `ABSENT`). The folder is written from one source, and a copy altered, a foreign file, a kind without its description or a vector whose statement no longer hashes to its `statementHash` stops the publication. +- With `agent-decision` added later that day, the folder holds sixteen envelopes, each `VALID` with the reference verifier offline + (measured with `verify-proof.mjs` on each of the sixteen files, 16 of 16). ### Adoption path diff --git a/aips/aip23-kinds/KINDS.json b/aips/aip23-kinds/KINDS.json index d41b847..cce6464 100644 --- a/aips/aip23-kinds/KINDS.json +++ b/aips/aip23-kinds/KINDS.json @@ -515,6 +515,42 @@ ], "attests": "an AI action: which model and version, which prompt, input and output (digests), which tools, which agent, who asked", "vector": "ai.json" + }, + { + "kind": "agent-decision", + "statementKind": "aere-proof-of-agent-decision", + "envelopeKind": "aere-proof-of-agent-decision-attestation", + "fields": [ + { + "name": "policyHash", + "type": "hash", + "note": "the hash of the agent policy in its normal form (0x + 64 hex)" + }, + { + "name": "actionHash", + "type": "digest", + "note": "SHA-256 of the canonical JSON of the action (keys sorted at every level), 0x + 64 hex" + }, + { + "name": "allowed", + "type": "plain", + "note": "boolean" + }, + { + "name": "reason", + "type": "plain", + "note": "why the policy allowed or refused it, in English" + } + ], + "required": [ + "policyHash", + "action", + "decision", + "createdAt" + ], + "attests": "an AI agent action was judged against a policy (by its hash): allowed or refused, and why; the action by the digest of its canonical JSON", + "added": "2026-09-29", + "vector": "agent-decision.json" } ] } diff --git a/aips/aip23-kinds/README.md b/aips/aip23-kinds/README.md index fbe856f..266eda8 100644 --- a/aips/aip23-kinds/README.md +++ b/aips/aip23-kinds/README.md @@ -41,6 +41,7 @@ ABSENT). Change one field of a statement and it is INVALID at the integrity leve | settlement (added 2026-09-28) | `aere-proof-of-settlement` | `chainId`, `txHash`, `blockHash`, `amount`, `asset`, `createdAt` | a settlement on a chain: its transaction and block (32-byte hashes carried as they are, never re-hashed), amount and asset | | provenance (added 2026-09-28) | `aere-proof-of-provenance` | `subjectHash`, `parents`, `createdAt` | an artifact (digest) was produced from a non-empty list of parents (digests), by a process (digest), by an actor | | ai | `aere-proof-of-ai` | `model.name`, `createdAt` | an AI action: which model and version, which prompt, input and output (digests), which tools, which agent, who asked | +| agent-decision (added 2026-09-29) | `aere-proof-of-agent-decision` | `policyHash`, `action`, `decision`, `createdAt` | an AI agent action was judged against a policy (by its hash): allowed or refused, and why; the action by the digest of its canonical JSON | Field types in `KINDS.json`: `digest` is the SHA-256 of some content (0x + 64 hex), so nothing sensitive enters the statement in the clear; `hash` is a value that is already a 32-byte hash (a transaction or block hash) and is refused if it has another form; diff --git a/aips/aip23-kinds/agent-decision.json b/aips/aip23-kinds/agent-decision.json new file mode 100644 index 0000000..9067f82 --- /dev/null +++ b/aips/aip23-kinds/agent-decision.json @@ -0,0 +1,14 @@ +{ + "v": 1, + "kind": "aere-proof-of-agent-decision-attestation", + "statement": { + "v": 1, + "kind": "aere-proof-of-agent-decision", + "policyHash": "0xc7d983a9886a0899bd6f3f09fde526514b0075f8f6abe77a1886405d86048c27", + "actionHash": "0x4ed27941710465e1431097592d2426f029306343d7e1172aa581b56b2fcf7cd4", + "allowed": true, + "reason": "under the limit", + "createdAt": "2026-09-26T00:00:00Z" + }, + "statementHash": "0x80e2d43344c4b23aea1700f9230d5162a7a8768036e5ed4cd5303856fcd5632a" +}