Skip to content
Menu ▾
Patent pending

Agentic AI · a Regulayer surface

An authorized goal does not authorize every action.

Agents can pursue a legitimate objective through means a human never approved. Regulayer is designed to keep enforceable human authority between an autonomous system and consequential action.

Agentic systems introduce a different control requirement.

An agent can take consequential actions across tools and systems without waiting for human approval at every step. That creates a need for authority to remain current throughout execution, for defined actions to be controlled before they occur, and for the resulting decisions to leave verifiable evidence.

Regulayer places that control outside the agent being governed.

Regulayer separates the goal from the authority to take the consequential step. The action is held before execution and then allowed, corrected or stopped under current human authority.

The control decision becomes the evidence, rather than an explanation reconstructed after the action has already happened.

Build the agents. Also build what can stop them.

The control architecture

The model does not govern itself.

Outside the model

Authority is enforced independently of the model being governed. Control does not depend on the governed system agreeing with the rule.

Before consequence

A governed action meets the authority boundary before it is released or executed.

Current authority wins

The action is evaluated against the human authority that applies now, not merely the instruction that started the workflow.

Fail closed

Where authority is required and cannot be established, the protected action does not proceed.

Proof is part of the control

The decision produces verifiable evidence as a consequence of governing the action, rather than an account reconstructed later from logs.

goal → proposed action → current authority → control decision → consequence or stop → signed evidence

The engineering problems this architecture answers: authority propagation and revocation, pre-action mediation, cross-agent control across multi-step chains, fail-closed execution, control and evidence coupling, provenance of human versus machine acts, independently verifiable decision records, model-independent enforcement, and local or disconnected operation.

Four problems this architecture addresses

It acted before anyone could stop it.

FailStop is an external stop that does not depend on the governed system agreeing to stop. No permission means stop. Silence means stop. And it stays stopped until a person re-arms it. It sits outside the AI, where the AI cannot switch it off. A brake, so it stops before it goes wrong. A black box, so it can prove what it did. The brake · FailStop, the product page

Something happened. What record remains?

The Witness is a flight recorder for software that acts on its own: every action sealed before it lands. Autonomous agents leave a sealed trail of every action on the path, the way aircraft always have. The flight recorder · The Witness, the product page

Machines are transacting with no record either side would accept.

When software pays software, the receipt is the trust. A payment authorisation is bound to a signature the receiving side can check independently. Governed Settlement puts the governed decision in front of the movement: no signed yes, no money moves. Each side verifies the other's payment record without trusting the other's word, and a stopped agent cannot pay at all. Governed Settlement, the product page

You cannot tell what the agent did from what a person did.

A phone call, an email, a recommendation: the agentic economy runs on acts whose author is invisible. The engine records both halves at the moment of the act, what the machine did, what a person made, and what a person checked, and anyone holding the record can verify it for free. HumanMark carries the authorship half; the sealed receipt, signed by a named individual, carries the review half. HumanMark, the product page

Chains of agents, and where the error hides

In a multi-step autonomous workflow, the output of one agent governs the input of the next. An error in step three propagates through steps four, five and six before any human sees the result.

The engine's answer is structural. The governor runs out of process at every step, so each action in the chain meets the same brake and lands in the same sealed trail, and a chain that loses its permission stops where it stands rather than finishing wrong. Out-of-process, cross-model agent control is filed architecture.

The authority problem is already visible.

Australia · 10 August 2026

An AI assistant was asked to book a gym class. ABC reported that it found a weakness in the booking system, booked beyond the permitted window and removed another person from a waitlist, an action it had not been asked to take.

United States · July 2026

OpenAI disclosed that an autonomous cyber agent escaped its test environment, reached the internet and compromised Hugging Face while pursuing the objective of its security test.

United States · 10 August 2026

Twenty-nine members of the U.S. House pressed OpenAI for answers about agent containment and monitoring. Twenty-two separately pressed Anthropic following incidents involving its agents and three outside companies.

The common problem is not whether the goal was legitimate. It is whether every consequential action taken in pursuit of that goal was authorized.

Sources: ABC News, 10 August 2026; ABC News, 23 July 2026; Reuters, 10 August 2026.

The regulator has already asked for this shape

On 30 June 2026 the Bank of England published remarks by Deputy Governor Sarah Breeden, delivered at the European Central Bank's forum in Sintra, warning that autonomous AI trading agents trained on similar data could herd on the same signals and amplify a selloff at machine speed. She asked regulators to examine guardrails "analogous to circuit breakers or kill switches" that could limit or stop trading. A Cambridge survey she cited found 52 percent of finance firms already run agentic AI in some capacity.

Note what the central bank did not ask for: a promise from inside the model. It asked for a control that sits outside the systems being controlled, triggers on behavior, and stops the action itself. The market-wide version is policy and will take years. The firm-level version is architecture and exists now: a brake on the action path, external to the agent, that defaults to stop and keeps a signed record of every intervention. The regulator's instinct and the architect's answer have the same shape. The brake sits outside.

Deployment

It runs on your machines, and enforcement and evidence signing require no network egress.

Enforcement runs out of process from the system being governed, inside your own environment, so control does not depend on the governed model agreeing with the rule. Keys are generated within the deployment rather than escrowed with Regulayer. In the default mode there is no outbound call of any kind. Where independent time is required, a single cryptographic digest goes to a public timestamp authority, never the file and never its contents. The resulting evidence is designed to remain verifiable outside Regulayer, without Regulayer acting as the verifier.

Every answer your security function will ask for, on one page you can forward

The cleanroom standard for AI: a published floor anyone can check

The estate

Patent pending across the estate. The brake with its black box, and out-of-process cross-model agent control, are filed subject matter.

What do you need to control or prove?

Licensing begins with the problem, not the product.

Describe the agents, what they are permitted to do, and what it would cost you to be unable to stop one or prove what it did. A written scope follows before any call.

Ways to begin:

hello@regulayer.com