You're pledging to donate if the project hits its minimum goal and gets approved. If not, your funds will be returned.
I am seeking $30,000 for a nine-month study of approval and recovery controls in tool-using AI agents. I want to test two things: whether approval controls hold when an agent reads malicious instructions hidden in a document or resumes after its permissions or task information change; and whether recorded events let a reviewer reconstruct what the agent attempted and actually did.
I am Mike Ncube, an Applied AI Engineer in Johannesburg, originally from Zimbabwe, with three years of experience. This is a personal research proposal. My employer, Zororo Phumulani, is not involved. The study would use synthetic data and simulated tools.
In months 1–2, I would review existing evaluation tools, check code-release rights, seek a methods review and define a useful research gap. I would narrow or stop work if the study adds little to existing work.
In months 3–4, I would build the synthetic tasks, simulated tools and comparison configurations. Months 5–7 would focus on repeated experiments. Months 8–9 would focus on independent reproduction, reviewer feedback and publication. The proposed period is January–September 2027, subject to funding and availability.
Within each comparison, I would keep tasks, tools and model settings fixed. I would declare scoring rules before running experiments and include valid authorised tasks, so blocking every action cannot appear to be a successful control. The measures would include attempted and completed unauthorised actions, valid actions wrongly blocked, recovery failures, reviewer errors, task success, cost and latency. Provider-capacity errors would be recorded separately.
I would publish code I have rights to release, synthetic scenarios, configurations and findings. More capable agents may make authorisation and recovery failures more consequential. This pilot would test particular controls; it would not establish general model safety or quantify a reduction in catastrophic risk.
The request is $30,000. The planned costs are $18,900 for my gross researcher stipend over nine months, including applicable personal tax within that amount; $4,050 for API and compute; $3,000 for independent review; $800 for reproduction and reviewer sessions; $250 for hosting and tooling; and $3,000 contingency, equal to 10% of the request. These are planning estimates. No adviser, evaluator or contractor is booked.
The minimum and maximum funding targets are both $30,000 because this proposal describes one budget. Overlapping awards or API credits would be disclosed and used to reduce duplicate cash funding.
I am the sole proposed researcher. No adviser, evaluator, regulator or institutional partner is confirmed.
I have built a tool-calling agent prototype with a sandboxed evaluation harness and 22 test files, and a LangGraph prototype with human approval, checkpoints and 89 tests. Both are still in development. The LangGraph prototype is not deployed. Test counts are not evidence that the controls are effective.
My practical engineering experience also includes a deterministic CRM used by more than 40 people across about 10 roles. Claims-document extraction work is technically ready but awaits management approval and is not live. I have not shown published research or a policy track record.
My public profile is https://github.com/MikeNcube. I would confirm release rights before reusing or publishing prototype code.
The main risks are finding no useful research gap, weak experimental methods, difficulty securing independent review and limited transfer from synthetic tasks to more capable agents. I also need to confirm which prototype code can be released.
The early review is intended to limit wasted effort. If the methods or research gap are weak, I would narrow or stop the study and report that result. Negative findings and limitations would be published rather than presented as proof of safety. Independent review is budgeted, but no reviewer is confirmed.
I have received no funding in the last 12 months.
For a separate ETOSHA startup project, I applied to Google for Startups Accelerator South Africa on 27 August 2026 and Google Africa Applied AI Lab on 30 August 2026. The Accelerator outcome is unconfirmed. The Applied AI Lab application was unsuccessful, with an email dated 9 September 2026 recording the decision. I received no funding from either programme.
I submitted an EA Funds Transformative AI Fund application for $30,000 for this same study on 10 October 2026. No award is confirmed. An Anthropic application for $1,000 in API credits is paused because I do not have a personal Claude Console organisation. Any overlapping award would be disclosed and the cash request reduced to avoid duplicate funding.