AgentLaw

Blog

Notes on securing AI agents with deterministic policy: signed manifests, enforcement, and tamper-evident audit.

4 min read

A model can be persuaded. A signed policy cannot.

Why prompt-level rules are not a security boundary for AI agents, and what a deterministic, signed policy changes about the problem.

securitypolicyprompt-injection
3 min read

What a hash-chained audit log actually proves

Tamper-evident is not tamper-proof. A precise look at the guarantees of AgentLaw's audit chain — and at the claims it deliberately does not make.

auditintegrityspec