You're pledging to donate if the project hits its minimum goal and gets approved. If not, your funds will be returned.
What is the problem?
Deployed AI agents increasingly persist: they carry identity and knowledge across sessions, modify their own skills, and act through real tools. Whether an agent's behavioural constitution, oversight gates and evidence trail actually constrain it over time — or can be silently bypassed — is currently a matter of vendor assertion. There is no practical, runnable test an outsider can execute to check.
NIST's AI Agent Standards Initiative (Feb 2026) explicitly calls for measurement mechanisms that trace agent decisions, reconstruct tool use, and verify the evidence behind actions, and has asked for practical use cases. That is the gap this project fills.
Make agent-level AI safety claims verifiable by outsiders rather than trusted on the vendor's word. Concretely, by the end of the funding period four artifacts exist publicly and under an open licence:
AI-HPP Specification v1.0 — normative, testable requirements for the safety loop of a long-lived autonomous agent: persistent identity, an immutable behavioural constitution, controlled knowledge acquisition, risk classification, a pre-action gate, human oversight, tool-mediated action, an evidence vault, replay, and verified skill change.
A conformance harness built around negative tests — checks that must FAIL when a safety gate is bypassed, so conformance cannot be satisfied by construction. Runnable by any engineer against their own agent.
A Bootstrap Conformance Matrix — our own reference implementation graded honestly against every requirement (PROVEN / PARTIAL / ABSENT), publishing our gaps rather than hiding them.
One reproducible demonstration mission — a complete agent task from request through gating and oversight to evidence vault and replay, reproducible end-to-end by a third party.
How. Development happens in the open in an existing public repository, versioned and commented on from day one, so progress is checkable at any moment rather than at the end. Months 1–3: specification finalised and a crosswalk published mapping each requirement to the NIST AI Agent Standards Initiative topics, the EU GPAI Code of Practice, and the UK AISI research agenda — this is what makes the work legible to people already working in the field. Months 4–6: the harness and its first negative-test set, plus the conformance matrix. Months 7–9: the reproducible demonstration mission, and 2–3 independent AI-safety researchers contracted to attempt to break the harness. Months 10–12: their reports and our responses published unedited, specification revised accordingly, and measurement use cases submitted to NIST's agent-standards work, which has explicitly requested practical cases of exactly this kind.
How we'll know it worked. Not by adoption rhetoric but by three checkable facts: an external engineer reproduces the demonstration mission independently; at least one team outside ours runs the harness against their own system; and the published external reviews contain findings we had to act on. If the reviewers break it and we fix it in public, the project has done its job.
Twelve months, everything open-licensed and public from day one:
AI-HPP Specification v1.0 — normative, testable requirements for a long-lived agent's safety loop: persistent identity → immutable constitution → controlled knowledge acquisition → risk classification → pre-action gate → human oversight → tool action → evidence vault → replay → verified skill change. (Draft already public: github.com/tryblackjack/AI-HPP-Standard)
Conformance harness with negative tests — the core deliverable. Tests that must FAIL when a safety gate is bypassed, so conformance cannot be satisfied by construction. Runnable by any external engineer against their own agent.
Bootstrap Conformance Matrix — our own reference implementation graded honestly against every requirement: PROVEN / PARTIAL / ABSENT. Publishing our own gaps is the point.
Crosswalk to the NIST agent-standards topics, the EU GPAI Code of Practice, and the UK AISI research agenda.
One fully reproducible demonstration mission — a complete agent task from request to evidence vault and replay, reproducible end-to-end by a third party.
Paid independent external review — 2–3 AI-safety researchers contracted to try to break the harness; their reports published unedited alongside our responses.
Budget: ~$30,000 project lead (1 FTE-equivalent, 12 months, Ukraine cost base), ~$8,000 compute and model APIs, ~$5,000 independent reviewers, ~$2,000 hosting/publication/translation.
Evgeniy Vasyliev, Odesa, Ukraine — sole author of the specification and reference implementation ([N] years). Business Development Director at SIPC "KARE", a Ukrainian scientific-production enterprise; 10+ years delivering deep-tech projects end to end, including a defence robotics programme under state contract and a €25,000 EU grant with a Seal of Excellence (Seeds of Bravery, 2024–2025). LinkedIn: https://www.linkedin.com/in/evgeniy-vasyliev/
https://github.com/tryblackjack/AI-HPP-Standard
The standard is ignored. Most proposed standards are. Mitigation: we optimise for a runnable artifact rather than a document — a harness someone can point at their own agent has a use even if nobody adopts the vocabulary.
Single-person dependency. One author, one country at war, unreliable power. Mitigation: everything public and mirrored from day one; the funding explicitly buys external reviewers who understand the codebase.
The negative tests turn out weak — i.e. a gate can be bypassed in ways the harness doesn't catch. This is the most likely technical failure, and it is why paid adversarial review is in the budget rather than optional.
Nothing for this project. It has been self-funded alongside other work. We applied to Coefficient Giving's Capacity Building RFP (declined) and to LTFF (declined as out of scope). Stating this plainly: two rejections from generalist funders, no feedback given. We think the work is better judged by looking at the repository than by our funding history.
There are no bids on this project.