ProofWeave improves real-time trust evidence for AI actions

Poster: Towards ProofWeave: A Privacy-Minimised, Integrity-Anchored Evidence Plane for Continuous Agentic Assurance

Cryptography and Security

Summary

Keeping track of what AI systems do is tricky because existing tools only show what happened after the fact, and they might miss whether proper checks were made before an action. The authors introduce ProofWeave, a way to record real-time proof that each AI decision was properly controlled according to current rules, while protecting privacy. This system links the AI’s intent, the controls’ response, and the rule set they used at that moment, storing this in a secure, easy-to-check form. Their tests show it reduces confusion, speeds up verification, and saves storage compared to just relying on logs.

What this means in practice

  • For software security teams: Provide real-time, privacy-preserving proofs that AI tools follow current policy constraints before executing sensitive actions.
  • For cloud system auditors: Enhance audit trails by linking AI decisions with policy snapshots to detect tampering and incomplete evidence more efficiently.

Authors

Guy Lupo, Nguyen Hung Nguyen, Viet Vo, Chamikara M. A. P., Guangdong Bai

Abstract

Agentic AI systems increasingly act via tools, memory, delegation, and external services. Existing observability and provenance mechanisms can reconstruct events post hoc, but they rarely show, at the time of the record, whether each policy-relevant action was checked by the intended control before execution. This leaves a trust-observability gap for continuous monitoring, detection, and response: later assurance may rest on evidence that is incomplete, privacy-leaking, mutable, or detached from the policy context that governed the event. What's missing in the literature is contemporaneous, policy-bound evidence that the intended control was evaluated under the policy in force at the time. We introduce ProofWeave, a record-time chain-of-evidence concept for agentic AI assurance. At each policy-relevant action boundary, ProofWeave generates a privacy-minimised and integrity-anchored evidence transaction that binds (i) agent intent or action, (ii) control response, and (iii) a policy-at-time snapshot. Each transaction is committed to an append-only ledger and materialised into a derived proof graph. A bounded Weaver Agent translates policy intent into proof obligations, while deterministic validators check evidence completeness, privacy minimisation, policy binding, and integrity. In the minimal scenario, an agent attempts to transmit a secret to an unapproved external sink. The audit compares a logs-only correlation baseline with ProofWeave across verdict latency, join ambiguity, privacy exposure, tamper detection, and resistance to graph-only proof injection. ProofWeave reduces candidate bindings per verdict from up to `10,201` to one, validation operations from up to `10,201` to approximately `26`, and assurance evidence storage from `0.79`MiB to `0.15`MiB per project.