· AI Assurance · Rob Murtha · 4 min read
Cryptographic Accountability for Autonomous AI
Third-party AI audits are arriving through legislation and industry agreements. These audits require systems to maintain signed, immutable action records.
The following outlines eighteen months of infrastructure development for cryptographic logging across software agents and physical systems.
Audits rely on verifiable system proofs. Absent cryptographic evidence, audits devolve into interviews. Over the past eighteen months, our team has built infrastructure to address this requirement, which has recently evolved into formal policy. In July, Illinois mandated annual independent audits for large frontier AI developers beginning in 2028. California directed the creation of an AI Auditor Registry by 2029. At the federal level, a bipartisan bill proposes independent audits for foundational models, and leading AI executives recently signed a White House accord committing to external auditor verification of internal controls. Furthermore, Anthropic proposed integrating outside auditors directly into frontier labs with publication rights.
External oversight addresses the expanding autonomy of these systems. AI models currently execute financial transactions and modify codebases. Stakeholders require concrete evidence of compliance. Independent auditing provides necessary verification of these activities.
What the auditor finds when they arrive
Researchers highlighted several structural auditing challenges in Scientific American. Excessive unstructured documentation obstructs effective evaluation. Embedded auditors risk institutional capture. Additionally, regulatory implementation timelines lag significantly behind rapid model deployment cycles.
Current regulations primarily target foundational model developers, leaving enterprise deployments unaddressed. Organizations deploying internal autonomous agents retain full responsibility for investigating and verifying system actions.
Why AI audits turn into interviews
Standard AI system logs are designed for debugging purposes. Operators maintain full control over these records, enabling unrestricted modification or deletion. Consequently, external audits frequently rely on ad-hoc reconstructions using internal tickets and staff interviews, forcing auditors to depend entirely on operator testimony.
Effective audits require systemic, real-time evidence generation. Systems must create immutable records of their own actions concurrently with execution. Retroactive documentation is impossible, leaving organizations unable to provide requisite proof to regulators or insurers during an inquiry.
Systems that prove their own trust
A self-proving system generates cryptographically signed, tamper-evident action logs during execution. External parties can independently verify this evidence using a public key.
Our development of this architecture began eighteen months ago. We introduced the Software Bill of Function in May 2025 to attest to software execution. Subsequent releases included the Evidence-Sealed Authorization framework for machine-generated compliance evidence and research on verifiable restraint. The production sealing layer deployed in July 2026. Defense and federal sector requirements drove this development timeline. These environments mandate rigorous technical verification over procedural trust.
The mechanism relies on cryptographic binding. Each action generates a signed envelope containing a payload hash, action classification, timestamp, and signer identity. A policy gate validates the signature against execution rules and cryptographically signs its authorization. These envelopes enter an append-only ledger where unauthorized alterations immediately invalidate the signature. Verification requires only a 32-byte public key and local compute resources. This signing authority enforces the operational boundaries of the Ultimus harness.
Digital and physical AI systems
Software agent actions include tool calls, shell commands, commits, and repository deployments. The resulting record documents the agent’s decision context and the authorizing entity. Finished workflows compile into portable proofs for offline replay, establishing provable software provenance for AI-generated code. The open-source engine available on Labs automatically signs all outputs.
Physical systems utilize identical cryptographic envelopes. The signature mechanism accommodates software tool calls, sensor readings, and hardware commands equally. Two distinct engineering challenges remain in physical deployments.
Connectivity presents the first challenge. Edge systems frequently operate within air-gapped enclaves. The sealing layer functions independently of databases or hardware security modules. Envelopes exist as plain files, allowing signatures generated offline to verify on standard hardware. This architecture supports deployments in national security research institutions requiring secure data transmission across network boundaries.
Device identity poses the second challenge. Hardware design must root cryptographic identity directly in silicon using uncontrollable manufacturing variations. Device inspection selection relies on public randomness to prevent operator manipulation. This hardware implementation remains in the design phase.
What changes for the auditor
Structured evidence streamlines auditor access. Auditors receive queryable, cryptographically signed records. Zero-knowledge patterns enable organizations to verify compliance claims while retaining full control over proprietary source code and model weights.
Remote cryptographic verification mitigates institutional capture. Multiple independent auditors can execute identical checks and achieve mathematically guaranteed consensus using only a public key.
Evidence generation begins at system initialization, eliminating dependencies on delayed regulatory timelines.
Cryptographic signatures guarantee record integrity. They confirm data immutability. Verifying underlying model safety remains a separate engineering and regulatory discipline. With tamper-evident logs, auditors transition from reconstructing historical events to evaluating the appropriateness of verified system actions.
Organizations operating existing agent deployments can integrate this logging layer via the Impact & Governance API. Regulatory audit requirements are approaching rapidly, with state mandates taking effect between 2028 and 2029. Auditors will examine historical system logs. Because cryptographic records cannot be backdated, organizations must implement these logging mechanisms immediately.