Open core · verifiable AI agents

Human Control Plane for Verifiable AI Agents

EvidenceBound is an early-stage AI Safety infrastructure project for binding agent actions to evidence, provenance, executable policy, deterministic verification, bounded blast radius and recoverable human control.

EvidenceBound Core · Apache-2.0Early-stage research / no production customers claimedFail-closed control semanticsPublic tests and evidence
Public OSS coreHuman approval boundaryTyped negative statesReproducible receipts
Canonical control contract

Evidence before authority.

The core pattern is deliberately narrow: an AI system may propose or reason, but authority is bounded by verifiable state outside the model process.

Claim → Evidence → Policy → Verification → Blast Radius → Recovery

Evidence binding

Bind an exact claim or action to exact source identity, provenance and retained artifacts.

Policy binding

Version the operator-owned obligations that decide what is allowed, blocked or requires human approval.

Verification

Keep deterministic checks and typed outcomes outside probabilistic model self-evaluation.

Blast radius

Scope what a verified task may affect instead of treating verification as universal deployment authority.

Recovery

Interrupt, correct and resume with lineage rather than silently mutating history after a failure.

Human authority

Preserve explicit review, approval and kill boundaries when the operator remains accountable.

AI Safety Assurance

Technical evidence for governance, not compliance theater.

EvidenceBound is being developed to make control evidence inspectable: which policy applied, what evidence was available, which deterministic checks ran, what failed, what was approved, and how recovery changed state.

NIST AI RMF support mapping

Evidence artifacts can support selected GOVERN, MAP, MEASURE and MANAGE activities, especially traceability, TEVV evidence, decision records, incident response and recovery. The NIST AI RMF is voluntary and broader than this technical runtime.

ISO/IEC 42001 evidence support

Policy lineage, verification receipts, human approvals and corrective-action evidence can support an organization's AI management-system records. EvidenceBound is not ISO certification and cannot certify an organization.

EU AI Act technical evidence

Where legally relevant, retained logs, traceability, human-control evidence and bounded risk controls may support organizational work around high-risk AI obligations. Applicability depends on role, system classification and legal context.

Claim boundary

EvidenceBound does not guarantee safety, legal compliance, model truthfulness, regulatory approval or fitness for a domain. It verifies bounded technical statements against declared evidence and controls.

Agent Safety

The model is a proposer, not the final control authority.

Prompt rules and model self-critique can assist review, but they do not create a deterministic runtime boundary. EvidenceBound keeps executable policy, typed failure states and approval outside the model's ability to rewrite its own verdict.

A VERIFIED result is deliberately narrow: the exact candidate satisfied the exact declared contract under the retained evidence and execution policy. It is not a universal statement that the model, system or future deployment is safe.
Assurance evidence

Make the decision chain reproducible before an incident.

Governance becomes inspectable when request identity, policy version, candidate identity, execution evidence, verdict and approval are bound at decision time instead of reconstructed from disconnected logs later.

operator-owned policy + exact evidence + bounded execution ↓ deterministic verification ↓ VERIFIED / REFUTED / BLOCKED / UNKNOWN ↓ retained receipt ↓ accountable human decision
Public proof surface

Receipts, negative paths and reproducible claims.

The public OSS core contains executable conformance tests, signing and persistence paths, adversarial cases, graph recovery and correction evidence. Public demonstrations are evidence of implemented properties, not evidence of customer adoption.

Typed negative states

Unsupported, blocked, stale or incomplete evidence must not be promoted into a successful result.

Content identity

Cryptographic digests make changed artifacts and stale receipts detectable instead of silently reusable.

Correction lineage

Recovery produces explicit lineage so operators can distinguish the original state from a corrected successor.

RAB-1 · NVIDIA OpenShell

Runtime authority at the pre-effect boundary.

A frozen reproducible agent-safety benchmark tested EvidenceBound recovery-authority semantics on stock NVIDIA OpenShell v0.1.2 as an independent runtime enforcement substrate. The same runtime and non-idempotent target were exercised first as a negative control and then under fail-closed authority enforcement.

EvidenceBound Runtime Authority Benchmark on NVIDIA OpenShell

The negative control reproduced two consequences after an uncertain outcome and retry. Under frozen controlled conditions the benchmark returned FULL_PASS: 12/12 hard gates, 8/8 frozen scenarios, and no middleware-denied request ID appeared in target-contact evidence.

Exact execution tag frozenExact-tag regeneration73 retained files0 evidence hash failures

Claim boundary

EvidenceBound demonstrated outcome-aware recovery authority and trusted operation-lineage enforcement at the OpenShell pre-effect HTTP boundary under the tested benchmark conditions.

Bounded result. This is not universal agent safety, not superiority over OpenShell, and not NVIDIA validation or endorsement. Independent blinded practitioner review is in progress and is separate from the frozen benchmark verdict.
Research Atlas

Technical notes around verifiable agent control.

Reference implementation

SignalReview: production sports intelligence as a bounded case study.

SignalReview is a separate sports-intelligence product that exercises provenance visibility, deterministic evidence, explicit missing-data states and bounded AI reasoning. It is useful as an applied EvidenceBound case study without making EvidenceBound part of the sports product's commercial identity.

Maintainer

Ruslan Vrublevskyi

Creator and maintainer of EvidenceBound. Product and systems work focuses on verifiable agent behavior, evidence-bound decisions, deterministic control boundaries, human corrigibility, recovery semantics and production AI infrastructure.

Current work

EvidenceBound Core, human-control research, open conformance evidence, and applied reference implementations. Claims remain evidence-scoped: working code is not the same as a security certification or a production customer deployment.

Technical orientation

Python, TypeScript, agent orchestration, policy-as-code, provenance, cryptographic receipts, cloud delivery, production QA and commercialization of trustworthy AI systems.

Assurance boundary. EvidenceBound is early-stage research and open-source infrastructure. It is not a certification, not legal advice, not a conformity assessment, and not a guarantee of safety or regulatory compliance. Domain validation, organizational governance, security review and accountable deployment remain external obligations.