ES Authority · Controlled development

Regulate authority, not intelligence.

Autonomous systems should be able to operate efficiently within established authority. Capability alone should not establish permission to move beyond it. EviState is exploring an evidentiary approach that makes material changes to machine authority explicit, governed and independently inspectable.

The control problem

Capability and permission are different things.

Identity and access-control systems remain essential, but increasingly autonomous systems create a further question: how did an actor acquire the authority it is exercising, and does a proposed material change remain within the authority that existed before it?

Who or what is acting

Identify the machine actor or execution context responsible for a consequential action.

Whose authority applies

Preserve the organisation, individual or system from which the relevant authority derives.

What authority is established

Represent the scope, purpose, duration and relevant conditions under which the actor may operate.

What materially changed

Distinguish ordinary operation within established authority from a material expansion or alteration of that authority.

What happened afterwards

Preserve an inspectable evidentiary record of consequential actions and authority changes.

Core principle

Autonomy without self-authorisation.

An autonomous system may exercise established authority. A material expansion or alteration of that authority should become a distinct, reviewable authority event rather than simply another authenticated action.

The responsible organisation retains the decision. EviState preserves the evidentiary state around it.

Proportionate governance

Maximum useful autonomy within accountable authority.

Routine activity within established authority should not require unnecessary intervention. Material authority changes can be subject to additional independent evidence or approval, while changes affecting oversight, revocation or other critical controls can be governed more strongly according to consequence.

Potential applications

Authority is a cross-system problem.

The same evidentiary principles may be relevant wherever autonomous systems are permitted to cause consequential changes in real systems.

Enterprise AI agents

Software and infrastructure automation

Finance and payment authority

Regulated professional activity

Critical infrastructure

Autonomous procurement

Machine-to-machine delegation

Cybersecurity operations

Agent-to-agent workflows

Insurance and governance

Make autonomous authority assessable.

Insurers, boards, regulators and auditors increasingly need to understand the authority assigned to machine actors, material attempts to exceed it, approvals or refusals, consequential actions and changes over time. EviState is exploring how autonomous-authority assurance can support risk engineering, insurability and proportionate AI governance.

Claim boundary

Not an AI kill switch.

  • EviState does not claim to solve AI alignment.
  • EviState does not determine what an autonomous system may think.
  • EviState does not guarantee that autonomous systems cannot fail.
  • The focus is narrower: make consequential authority and material changes to that authority explicit, governable and independently inspectable.

Controlled development

Help us challenge the proposition.

We are engaging with AI-security specialists, insurers, regulated organisations and public-interest stakeholders interested in autonomous systems and accountable digital authority.