Regulayer Enterprise licensing

Agentic AI · the engine applied

If agents are the new software, the off switch is the new firewall.

The agents are coming, and they will not stay in the chat window. They will take actions at machine speed: payments, code, records, handoffs. Every action is a new way to go wrong, and most agents ship with no external way to stop one mid-step.

The situation

Most agents ship with no way to stop them. An autonomous agent acts, and then you find out. Guardrails built inside the model can be talked around, and a log written afterward is a postmortem, not a stop.

The industry built a gas pedal. The brake is the open problem. When safety is added, it is usually built inside the model, where the same system being governed can switch it off, or be talked around it. A brake that works has to sit somewhere the model cannot reach. It cannot be switched off by the system it governs. It fails toward stop, so failure or silence halts the action rather than letting it through. And it keeps a signed record anyone can verify.

Every aircraft carries a black box, so that whatever happens, there is a record no one can argue with. Regulayer puts one inside your AI.

Build the agents. Also build what can stop them.

Four problems the agentic economy cannot answer for itself

It acted before anyone could stop it.

FailStop is the brake that cannot be talked out of stopping. No permission means stop. Silence means stop. And it stays stopped until a person re-arms it. It sits outside the AI, where the AI cannot switch it off. A brake, so it stops before it goes wrong. A black box, so it can prove what it did. The brake · FailStop, the product page

Something happened and nobody can prove what.

The Witness is a flight recorder for software that acts on its own: every action sealed before it lands. Autonomous agents leave a sealed trail of every action on the path, the way aircraft always have. The flight recorder · The Witness, the product page

Machines are transacting with no record either side would accept.

When software pays software, the receipt is the trust. An AI can be talked out of its rules. A payment cannot be talked out of its signature. Governed Settlement puts the governed decision in front of the movement: no signed yes, no money moves. Each side verifies the other's payment record without trusting the other's word, and a stopped agent cannot pay at all. Governed Settlement, the product page

You cannot tell what the agent did from what a person did.

A phone call, an email, a recommendation: the agentic economy runs on acts whose author is invisible. The engine records both halves at the moment of the act, what the machine did, what a person made, and what a person checked, and anyone holding the record can verify it for free. HumanMark carries the authorship half; the sealed receipt, signed by a named individual, carries the review half. HumanMark, the product page

Chains of agents, and where the error hides

In a multi-step autonomous workflow, the output of one agent governs the input of the next. An error in step three propagates through steps four, five and six before any human sees the result.

The engine's answer is structural. The governor runs out of process at every step, so each action in the chain meets the same brake and lands in the same sealed trail, and a chain that loses its permission stops where it stands rather than finishing wrong. Out-of-process, cross-model agent governance is filed architecture.

The regulator has already asked for this shape

On 30 June 2026 the Bank of England published remarks by Deputy Governor Sarah Breeden, delivered at the European Central Bank's forum in Sintra, warning that autonomous AI trading agents trained on similar data could herd on the same signals and amplify a selloff at machine speed. She asked regulators to examine guardrails "analogous to circuit breakers or kill switches" that could limit or stop trading. A Cambridge survey she cited found 52 percent of finance firms already run agentic AI in some capacity.

Note what the central bank did not ask for: a promise from inside the model. It asked for a control that sits outside the systems being controlled, triggers on behaviour, and stops the action itself. The market-wide version is policy and will take years. The firm-level version is architecture and exists now: a brake on the action path, external to the agent, that defaults to stop and keeps a signed record of every intervention. The regulator's instinct and the architect's answer have the same shape. The brake sits outside.

Deployment

It runs on your machines, and nothing of the work leaves the building.

The kernel binds the loopback interface and refuses any client that is not local. The signing key is generated on your own machine on first run and never leaves it. In the default mode there is no outbound call of any kind. Where independent time is required, a single cryptographic digest goes to a public timestamp authority, never the file and never its contents. The source ships readable, so your own security function can satisfy itself line by line.

Every answer your security function will ask for, on one page you can forward

The estate

Part of the filed estate: eighteen patent filings and a PCT. Patent pending across the estate. The brake with its black box, and out-of-process cross-model agent governance, are filed subject matter.

Licensing begins with the problem, not the product.

Describe the agents, what they are permitted to do, and what it would cost you to be unable to stop one or prove what it did. A written scope follows before any call.

Ways to begin:

hello@regulayer.com