Published July 11, 2026 | Version 2.2.0

Dual-Gate Evidence Rails for Attested Agentic AI: Deny-Before-Inference and Permit-Before-Commit Control of External Effects

Authors/Creators

Description

Attestation can establish where and how an AI runtime executed. It does not, by itself, authorize every later inference request or external effect.

This technical report defines Dual-Gate Evidence Rails, a vendor-neutral architecture for fresh, scoped, replay-resistant, revocation-aware, machine-verifiable authorization at two distinct enforcement moments. Gate 0 applies deny-before-inference control to protected execution requests. Gate 1 applies permit-before-commit control to each proposed external effect before egress, secret release, privileged API invocation, database mutation, dispatch, output release, persistent-state change, financial action, or device control.

Version 2.2.0 formalizes the system and adversary models, trust boundaries, decision functions, fail-closed state machines, complete canonical ActionProposal reproduction, domain-separated action and policy digests, nonce and replay handling, policy epochs, revocation dependencies, PermitReceipts, EvidencePacks, CommitReceipts, recipient-side verification, deployment patterns, procurement requirements, and eight core security properties. It specifies the public-candidate Action Acceptance Profile AAP-1-INTEROP-0.2, comprising 24 mandatory PermitReceipt fields and 20 core predicates.

Historical AAP-1-INTEROP-0.1 same-organization results are preserved only as bounded prior evidence. Under the report’s evidence-maturity model, this deposit is Level 0: a document-only scholarly record. It contains no executable implementation, schema package, fixture corpus, raw evaluation output, or machine-readable AAP-1-INTEROP-0.2 conformance result. It makes no claim of independent interoperability, production certification, vendor endorsement, standards-body approval, or legal compliance.

The architecture is grounded in U.S. Patent Nos. 12,676,749 B1 and 12,640,933 B1. The report is licensed under Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International. Publication does not grant a patent license, implementation right, production authorization, certification, endorsement, or commercial deployment right.

Core principle: No inference without verified execution compliance. No external effect without an action-bound permit.

Notes

Record scope and availability

This is a document-only technical-report record. Public evidence maturity is Level 0 under the report’s evidence-maturity model. The record contains the final PDF and citation and preservation materials only. It contains no software, executable verifier, schema package, fixture corpus, raw evaluation output, or machine-readable AAP-1-INTEROP-0.2 conformance result.

Historical AAP-1-INTEROP-0.1 figures are same-organization observations and do not constitute independent reproduction or current-profile conformance. Future software, conformance-corpus, or dataset artifacts, if released, will receive separate versioned identifiers and will be linked to this report as related works.

Notes

Rights and license boundary

The CC BY-NC-ND 4.0 license applies only to copyright and similar rights in the licensed materials. Patent and trademark rights are not licensed.

No patent license, right to practice any patent claim, implementation license, production deployment authorization, certification, endorsement, or commercial authorization is granted, expressly or by implication.

The Meridian Verity name, logos, and other marks may appear as part of authorized distribution of this record, but no separate trademark or branding license is granted.

Any use outside the scope of CC BY-NC-ND 4.0 requires separate written permission from the applicable rights holder.

Files

MVG-DGER-TR-2026-001_v2.2.0.pdf

Files (490.2 kB)

Name Size Download all
md5:7e52d159fb104aa811a9667b1a1b9321
490.2 kB Preview Download