DEV Community

arian gogani
arian gogani

Posted on Edited on

What happens when AI agents have something to lose

Every person has a credit score. Every business has one. AI agents making real decisions -- executing trades, accessing data, managing infrastructure -- have nothing.

Full access on day one. No track record. No portable reputation. No consequences.

The result is predictable: Akeyless reports 2/3 of enterprises suspect their agents already accessed unauthorized data. 14-hour average detection time.

Correction: I previously connected Nobulex receipts to an August 2026 Article 12 enforcement deadline. That was wrong twice. Article 12 requires automatic event logging, not cryptographic or independently verifiable receipts. Regulation (EU) 2026/1744 moved the relevant high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems. Receipts may still help evidence survive a dispute, but that is not an Article 12 requirement.

Official sources:

https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12
https://ai-act-service-desk.ec.europa.eu/en/ai-act/faq/when-does-enforcement-start
https://eur-lex.europa.eu/eli/reg/2026/1744/oj

The problem isn't capability. It's accountability.

Standard logs are mutable. Dashboards are internal. No third party can independently verify that an agent stayed in scope. For regulated deployments, this is a blocker.

What we built

Nobulex produces bilateral Ed25519 cryptographic receipts for every agent action:

  1. Pre-execution: agent signs what it's authorized to do
  2. Agent executes
  3. Post-execution: counterparty co-signs what actually happened
  4. Hash-chained so if any entry is modified, the chain breaks

A third party can verify the full chain without trusting the agent or the operator.

Trust Capital: the score that earns access

The receipts accumulate into Trust Capital -- a credit score for the agent. This isn't compliance. Trust Capital measures how much value an agent has provably created relative to the risk it represents.

High Trust Capital unlocks: higher transaction limits, regulated market access, lower insurance premiums, more autonomy. Agents that deviate get sandboxed. Not as punishment. As math.

The flywheel

More Trust Capital → more valuable work → more receipts → higher Trust Capital. Accountability becomes the most profitable strategy, not because anyone mandated it, but because the economics demand it.

Traction

  • Microsoft merged the receipt primitive into their Agent Governance Toolkit
  • 10 independent implementations cross-validated byte-identical output
  • Discussions on OpenAI, Stripe, CrewAI, LlamaIndex, Google ADK, AutoGen repos
  • MIT licensed, open source

Repo: github.com/arian-gogani/nobulex

What am I missing? Would love feedback from the dev community.

Top comments (0)