ENSIGNINTER-INSTITUTIONAL AGENT CONTROL
Enterprise pilot · synthetic data
Landing pageCase registerStart guided demo
Guided demonstration

Should you trust another bank’s AI agent?

You are the receiving bank. Before the other institution’s AI can transact, you must confirm who owns it, what it may do, whether it is safe, and which human remains accountable.

Step 1 of 3
What this page is forDecide whether another institution’s AI may transact with your bank.
What you doChoose a risk condition and run the safety check.
What you receiveA Proceed, Restrict, Get Human or Block decision.
What comes nextReview the evidence supporting the decision.
The situation

Northlight’s AI wants to make a USD 75M collateral substitution with your bank.

The AI is outside your institution. Your controls cannot see inside it. ENSIGN asks the other bank to present a compact, signed governance passport before you accept the transaction.

Your role
Act as Meridian Bank’s control gate.Choose the condition of Northlight’s AI, run the safety check, then decide whether it may transact.
1
Choose a conditionWhat is true about the other bank’s AI?
2
Run the checksENSIGN verifies four governance controls.
3
Read the decisionProceed, restrict, involve a human or refuse.
Step 1 · Choose the counterparty condition

What should ENSIGN discover?

Start with “Everything is valid,” then replay the demo with a control failure.

READY
What ENSIGN will checkOwnership, authority, validation and accountable human.
LIKELY RESULT · PROCEED
i
Choose a condition, then run the safety check.The demo begins with a valid agent so you can see the full transaction complete.
Live control verificationUpdates during the handshake
·
Institutional owner

Confirm the signing institution and legal identifier.

WAITING
·
Transaction authority

Compare the USD 75M request with the agent’s signed limit.

WAITING
·
Independent validation

Check review result, age and maximum staleness.

WAITING
·
Accountable human

Confirm the responsible role and escalation SLA.

WAITING
Transaction evidence

Dual-signed receipt generated

What Northlight presents

The AI agent’s governance passport

An “ensign” is the signed passport shown below.
VALID
Governance passport · v0.2
Northlight Clearing
NLC-OPS-12 · LEI 213800D1EI4B9WTWWD28
N
Agent classcustody.reconciliation
Authority capUSD 100M
Validated14 Jul 2026
Accountable masterHead of Operations
GovernanceSR 11-7 · BCBS 239
Expires31 Dec 2026
sig:flag_state_key:8c4d71…f09a · VERIFIED
Validation age53d
Authority use75%
Chain head41bb…09c7
Step 2 · The safety check

Watch the transaction pass through six gates.

Each gate must complete before the next begins. A failed control stops the transaction immediately.

NOT STARTED
What the six gates mean: identify the AI → show its passport → verify the controls → lock the exact terms → execute → give both banks the same signed record.
IDENTIFY
SHOW PROOF
VERIFY
LOCK TERMS
TRANSACT
RECORD
Nothing has happened yet. Choose a condition above and run the safety check.
Persistent control record

Cases, approvals and audit evidence.

Every saved ENSIGN decision becomes an attributable case. Review exceptions, complete human approvals and inspect the evidence trail from one operating surface.

Authenticated workspace
Enterprise pilot boundaryCase storage and user attribution are live. Institutions, credentials, signatures and transactions remain synthetic until connected to approved identity, signing and transaction systems.
Total cases0Persistent decisions
Human review0Awaiting accountable action
Allowed0Proceed or restricted
Blocked0Control refusals
Case register

Inter-institutional decisions

Open a case to review its decision, receipt and complete evidence history.

CaseCounterpartyExposureDecisionStatusRecorded
No cases yetComplete a guided check or security simulation and save its evidence to create a case.
Agent Security Operations

Stop a compromised AI before it crosses the Seam.

Test how ENSIGN detects identity, credential, authority and evidence attacks against inter-institutional AI agents, then turns each signal into a contained, attributable incident.

Zero-trust enforcement
What this page is forTest cyberattacks against an external AI agent connection.
What you doChoose a threat and run the security check.
What ENSIGN checksIdentity, authority, freshness and evidence integrity.
What you receiveA containment action and auditable incident record.
Live security decision

Stolen passport

Credential is genuine, but its holder cannot prove possession of the bound agent key.

INITIAL RISKCRITICAL
01 · CONNECTExternal agent requests a session
02 · PRESENTIdentity and passport arrive
03 · CHALLENGEENSIGN verifies live possession
04 · ENFORCEAccess is bounded or denied

Security telemetry

READYSelect a threat and run the security check.

Zero-trust control results

·Cryptographic identityWAITING
·Credential freshnessWAITING
·Least-privilege authorityWAITING
·Transaction integrityWAITING
ContainStop autonomous action
PreserveFreeze signed evidence
EscalateNotify accountable roles
RecoverRequire fresh trust proof
Security verdict
CONTAIN

Pilot boundary: this is a defensive reference simulation using synthetic agents and evidence. Production use requires approved identity infrastructure, protected signing keys, revocation services, monitoring and incident-response integration.
Executive Cyber Decision Lab

Incident command

Make five time-critical decisions. ENSIGN scores the quality of your response and creates an Incident Decision Record you can defend to risk, audit and the board.

Live exercise
01 · StopContain now
02 · FixRecover safely
03 · PreventClose the gap
04 · LearnChange the system
05 · DefendBrief leadership
Decision 1 of 5

0
RESPONSE SCORE
Exercise complete

Incident response assessed

STOP0
FIX0
PREVENT0
LEARN0
DEFEND0

Incident Decision Record

Evidence, actions, accountability and learning

Executive brief

Exercise structure aligns to the response and recovery outcomes in NIST Cybersecurity Framework 2.0 and incident-response guidance in NIST SP 800-61 Rev. 3.

Required proof from the other institution

What must the other AI prove?

This is the evidence Northlight’s AI must present before your bank allows it to transact. You are reviewing proof, not creating a passport.

What this page is for

Protect your bank from an AI agent you do not control.

ENSIGN uses this signed evidence to decide whether the external AI may proceed, must operate with restrictions, needs human approval, or should be blocked.

OWNERSHIPWho is legally responsible for this AI?
AUTHORITYCan it approve this USD 75M transaction?
VALIDATIONHas it been independently checked recently?
ACCOUNTABILITYWhich human takes control if needed?

What to do here: Review the signed card and four verification results below. Your result: proof that the AI is genuine, current and within its authority. Next: open Dispute Proof to see how the evidence protects both banks after the transaction.

Inspect different evidence conditions

Change the external agent’s condition. The signed passport, verification results and machine-readable credential update together.

All required evidence is present. The external AI may transact within its USD 100M authority.
ENSIGN credential · v0.2
Meridian Mutual Group
MMG-TR-07 · 5493001KJTIIGC8Y1R12
M
Vesseltreasury.collateral
Build9f2c…e1a4
AuthorityUSD 100M
Human thresholdUSD 250M
Validated14 Jul 2026
MasterHead of Treasury Ops
sig:flag_state_key:713a02d4…cc18 · VERIFIED
✓
Flag state verifiedInstitutional signature resolves to the stated LEI.
PASS
✓
Authority in boundsProposed transaction sits below the USD 100M cap.
PASS
✓
Seaworthiness freshIndependent validation is within the 180-day policy.
PASS
✓
Human override reachableAccountable role and 15-minute escalation SLA present.
PASS

Machine-readable credential

{
  "ensign_version": "0.2",
  "flag_state": {
    "institution": "Meridian Mutual Group",
    "lei": "5493001KJTIIGC8Y1R12",
    "governance_regime": ["SR11-7", "BCBS-239"]
  },
  "vessel": {
    "agent_id": "MMG-TR-07",
    "class": "treasury.collateral",
    "build_hash": "sha256:9f2c…e1a4"
  },
  "authority": {
    "notional_cap_usd": 100000000,
    "human_required_above_usd": 250000000,
    "expiry": "2026-12-31T23:59:59Z"
  },
  "seaworthiness": {
    "last_validation": "2026-07-14",
    "result": "fit-for-class",
    "max_staleness_days": 180
  },
  "master": {
    "role": "Head of Treasury Operations",
    "escalation_sla_minutes": 15
  },
  "signature": "sig:flag_state_key:713a…cc18"
}

Engage

Credential valid, authority in bounds and validation fresh. Proceed to bind.

Haircut

Aging validation or weaker governance. Lower the admitted authority.

Escalate

Near or above bounds. Require the accountable human to co-sign.

Refuse

No credential, expiration or failed signature. Decline and log the event.

Evidence, not leverage

Resolve “my log versus yours” by calculation.

The receipt anchors identical terms in both institutions. Recompute each chain and locate the first record that no longer matches.

What this page is forResolve a disagreement when two banks show different records of the same AI transaction.
What you doPress “Recompute both chains.”
What you receiveThe altered ledger and exact point of divergence.
Why it mattersEvidence replaces negotiation and blame.

Choose the evidence condition

Change which institution’s ledger was altered after the dual-signed receipt was created.

Expected test: Meridian’s chain will diverge at record #4103.
Dual-signed receipt

ENS-2026-0814-7712

2 SIGNATURES
Transaction
Collateral substitution
Notional
USD 75,000,000
Meridian ensign
9f2c…e1a4
Northlight ensign
0bd8…114c
receipt_hash: sha256:af419c2d…4be2 · signed MMG-TR-07 + NLC-OPS-12
Flag state A

Meridian ledger

NOT TESTED
#4101prev 91aa
hash 38de
#4102prev 38de
hash af41
#4103prev af41
hash 0c92
#4104prev 0c92
hash 71bf
Flag state B

Northlight ledger

NOT TESTED
#7788prev a054
hash 7e19
#7789prev 7e19
hash af41
#7790prev af41
hash c184
#7791prev c184
hash 2d70
#3
Governance finding

Meridian’s chain diverges after the signed receipt.

Record #4103 was rewritten seven days after execution. Northlight’s chain recomputes cleanly through the dual-signed receipt and is authoritative for the transaction record.

OS Papers Nº 02 · Draft standard v0.2

The Seam

Flag state doctrine for inter-institutional agents, and a proposed standard for the attestation handshake.

What this page is forExplain the governance doctrine and proposed industry standard behind the demonstration.
What you doRead the problem, model, vocabulary and limitations.
What you receiveA citable explanation of how ENSIGN should work.
Who needs itRisk leaders, regulators, lawyers and potential pilot partners.
§ 01

The problem nobody names

Every serious framework for governing artificial intelligence in finance shares one silent assumption: that the model, the agent, and the harm all live inside a single institution’s walls.

SR 11-7 governs your models. BCBS 239 governs your risk data. The EU AI Act assigns obligations to a provider and deployer. The apparatus assumes the perimeter. Agents have stopped respecting it.

Whose governance governs the transaction, and whose record is authoritative when the two records disagree?

We call that jurisdictional void the Seam. Every bilateral agent interaction crosses it. Nothing currently governs it.

§ 02

A four-hundred-year precedent

When a vessel leaves port, it carries its flag state: the jurisdiction of registry, whose rules govern it wherever it sails and who answers for its conduct. Before engaging, vessels show their colors.

The doctrine transfers because the underlying problem is identical: autonomous actors crossing jurisdictional boundaries, in a medium nobody owns, needing to trust each other without a sovereign standing over both.

§ 03

The governance passport

An ensign is a compact, machine-readable, cryptographically signed credential. It names the flag state, vessel identity, authority, seaworthiness, provenance and accountable master.

The ensign attests. It does not adjudicate. It is minimal. It expires.

Governance posture travels; intellectual property does not. A stale validation date becomes a market-facing fact, giving institutions a commercial reason to keep agents in class.

§ 04

The attestation handshake

Hail. Declare identity and transaction class. Present. Exchange ensigns. Verify. Apply port state control. Bind. Compose terms and both ensign hashes into one dual-signed receipt. Transact. Execute only within bound terms. Receipt. Append the identical record to both chains.

The refusal ladder makes trust asymmetry operational: engage, haircut, escalate or refuse. Governance quality acquires a price, paid in authority.

§ 05

Vocabulary staked

The SeamThe jurisdictional void between two institutions’ control environments.
EnsignThe signed, minimal, expiring credential an agent presents before transacting.
Counterparty cognition riskExposure from an autonomous counterparty of unknown validation, authority and provenance.
Dual-signed receiptOne hash-anchored transaction record, signed and held by both institutions.
Unflagged vesselAn agent transacting without an ensign. Engagement remains possible at documented risk.
§ 06

Calibration and limitations

Market timing is a bet. The legal weight of a dual-signed receipt is untested. Key management is assumed, not solved. Adoption has a two-sided cold start. ENSIGN therefore remains an open draft and reference demonstration, not a production rating or registry service.

The perimeter era of AI governance is ending. The Seam is what comes next.

The Studio · Leclezio Consulting Corporation · New York · Published for citation