Hand the work to AI. Still be able to show what it did.
Attach proof to the reasons behind an AI's decision and to what it actually executed, and both can be shown to an auditor or a third party as genuine records. The work of explaining afterwards drops sharply.
is running now
Every quarter more work runs through AI — and more often, someone asks why a particular decision came out the way it did. What gets tested is less the substance of the decision than whether the record of it is genuine. Narrowing permissions is not enough on its own, because the routes that deceive an agent run inside its legitimate authority. What is missing is a layer that establishes whose request this is before anything executes.
What gets tested isn't how smart the AI is.
It's where the record came from.
What the AI decided, and what it based that on, both carry a proof — so you can still show afterwards that they are genuine.
Every record you submit carries proof that it has not changed since issuance, so it can go to the auditor as-is.
The scope of what an agent may do is configured from the admin screen. Outside that scope, nothing runs.
Three cases from this area, drawn from the Lemma Critical Briefs. In each one an AI acted on something nobody had independently verified.
The work you handed to AI —
how do you account for it?
We work through with you what needs to be on the record, and identify where proof should be attached. It starts with a 30-minute call.
