The missing control layer for inter-institutional AI

Your AI is governed. Theirs is unknown.

ENSIGN makes autonomous agents prove who owns them, what they may do, whether they are validated, and which human remains accountable before they transact across institutions.

Zero-trust admissionSix cyber scenariosAuditable response
Listen to the introductionVoice narration · 60 seconds
One transaction crossing two control environments
Your institution

Meridian Bank

Receiving control environment
AI
● GOVERNED INTERNALLY
OwnerKnown
AuthorityKnown
HumanKnown
ENSIGN
GATE
Counterparty

Northlight Clearing

External control environment
AI
? GOVERNANCE UNKNOWN
OwnerProve it
AuthorityProve it
HumanProve it
ENSIGN verifies the other agent before either system becomes bound.
Designed to extend, not replace, existing controls
Zero-trust
security
Model risk
governance
Institutional
PKI
Incident
response
The control gap

Governance stops at the wall. Agents do not.

As AI agents begin acting across firms, each institution can govern its own system, but cannot see the validation, authority or human accountability behind the counterparty’s agent.

INSIDE YOUR PERIMETER

Your AI agent

Your policies, validation, controls and accountable executives travel through your internal governance.

Identity and ownerKNOWN
Transaction authorityKNOWN
Independent validationKNOWN
ACROSS THE COUNTERPARTY

Their AI agent

The name of the institution is familiar. The system acting in its name may not be.

Identity and ownerUNPROVEN
Transaction authorityUNPROVEN
Independent validationUNPROVEN
ENSIGN turns “we assumed they controlled it” into evidence both institutions can verify.THE SEAM · WHERE TWO CONTROL ENVIRONMENTS MEETTest the control gap →
The ENSIGN handshake

Proof before permission.

Every bilateral agent transaction passes through four understandable control moments. The protocol completes before either institution is bound.

01 · PRESENT

Show the passport

The external AI presents a signed credential naming its institution, identity, authority, validation and accountable human.

Question answered · Who are you?
Inspect the passport →
02 · VERIFY

Check the controls

Your institution verifies the signature, expiry, transaction limit and validation freshness against its own policy.

Question answered · May you act?
Verify the controls →
03 · DECIDE

Set the boundary

Proceed, restrict the authority, require a human co-signature or block the transaction completely.

Question answered · On what terms?
Run the decision →
04 · BIND

Share one record

Both agents sign the exact transaction terms. Each institution stores the same receipt in its own tamper-evident chain.

Question answered · What happened?
Test the shared record →
One control model

Four decisions. No false binary.

ENSIGN does more than accept or reject. It lets institutions price governance differences operationally by changing how much autonomous authority they accept.

Proceed

Identity verified, authority in bounds and validation current. Complete and record the transaction.

CONTROL RESPONSE · FULL AUTHORITYTest Proceed →

Restrict

The credential is valid but a control is aging. Lower the transaction authority until it is refreshed.

CONTROL RESPONSE · REDUCED AUTHORITYTest Restrict →

Get human

The transaction exceeds autonomous authority or presents an anomaly. Require accountable human approval.

CONTROL RESPONSE · CO-SIGNATURETest Get Human →

Block

No passport, an expired credential or a failed signature. Stop and record the refusal.

CONTROL RESPONSE · NO ADMISSIONTest Block →
Agent Security Operations

Zero trust for AI agents crossing institutional boundaries.

Run six defensive simulations covering stolen credentials, impersonation, privilege escalation, replay, instruction tampering and signing-key compromise.

Detect

Challenge every agent

Verify live key possession, credential status, signed authority and transaction hashes before admission.

Contain

Stop autonomous action

Block the session, freeze evidence and prevent a suspect request from becoming an institutional obligation.

The evidence layer

When records disagree, stop negotiating. Recompute.

ENSIGN gives both institutions an identical, dual-signed receipt. If one ledger later changes, the other side can locate the precise break.

✓
Exact terms frozen at the moment of agreementNo reconstruction from emails or independent system logs.
✓
Both governance passports anchored to the tradeAuthority can be proven as it existed when the action occurred.
✓
Two signatures, held by two institutionsNeither party can silently rewrite the shared evidence.
Run the dispute demonstration →
Dual-signed transaction receipt

ENS-2026-0814-7712

VERIFIED
2 SIGNATURES
TransactionCollateral substitution
NotionalUSD 75,000,000
Meridian agentMMG-TR-07
Northlight agentNLC-OPS-12
DecisionPROCEED
Recorded14 Aug 2026 · 14:31 UTC
receipt_hash: sha256:af419c2de8871a9f61b83d1bc4e20f379914be2
Meridian Mutual Groupsig:mmg:713a…cc18
Northlight Clearingsig:nlc:0bd8…114c
Who needs this

The standard is written for both sides of the Seam.

ENSIGN is a reference proposal for the institutions, infrastructure providers and oversight functions that will have to govern cross-firm autonomous action.

Financial institutions

Control the counterparty agent

Extend existing governance to AI-mediated bilateral activity.

  • Bank and asset-manager AI teams
  • Model risk and operational risk
  • Treasury, markets and post-trade
Market infrastructure

Standardize the handshake

Create one interoperable credential and receipt pattern across participants.

  • Clearing and settlement venues
  • Custodians and market utilities
  • Identity and trust providers
Oversight

Make accountability portable

Inspect who authorized an agent and which human remained responsible.

  • Regulators and supervisors
  • Internal audit and compliance
  • Legal and industry working groups
OS Papers Nº 02 · Draft standard v0.2

The Seam has a vocabulary now.

ENSIGN ports the logic of maritime flag-state doctrine to autonomous AI: an actor crossing jurisdictions carries its issuing institution’s governance, shows verifiable colors before engagement, and leaves a contemporaneous shared log.

The credential uses existing signing and hash-chain technology. ENSIGN proposes the governance content, verification duties, decision ladder and dispute doctrine, not a new cryptographic protocol.

The SeamThe control gap between institutions.
EnsignThe signed governance passport.
Flag stateThe institution accountable for the AI.
Port-state controlThe receiver’s right to verify or refuse.
Trust asymmetryThe difference between governance postures.
Dual-signed receiptThe shared authoritative record.
Reference demonstration

Do not trust the agent. Verify the institution behind it.

Take the role of the receiving bank, test five governance conditions, and see exactly when ENSIGN proceeds, restricts, escalates or blocks.

No sign-up required · Synthetic institutions · Draft standard v0.2