One of the issues that I think I've always struggled with when it comes to AI is how do you know that the personal assistant or the model that you're using is not just using the memory, but actually making the right decision? What's the precedent that it's based on, and what are the constraints that the AI has around it based on your own rules or the way that you function?

I discovered this on my own when I had a personal assistant that I had built with a type of memory that was model-agnostic, so I was very happy because I could take the data and own it and take it wherever I wanted. So if OpenAI had a superior model, I could go there. If Anthropic had a superior model, I could go there. I had options, and I thought that would solve most of my issues.

Then I discovered that the model would make up people, or it would make up events, and there was no receipt to back up those decisions. As each day layered on top of the other one, especially when it came to memory, the agent would continue to convince itself that that person and that event were real. It wasn't until I actually discovered this, after this event had been on the calendar for a couple of months, that I asked, "Who was this person?"

It turned out that there was absolutely no record of the person.

There was no receipt.

The model had completely hallucinated.

A receipt is the thing an action can point back to, an email, a calendar entry, a transcript, an approval from me. A fact that only exists inside the AI's memory isn't a fact at all. And a decision the agent can't show a receipt for isn't a decision.

I try to focus on end users and how the tool provides value that can be translated into very real outcomes. Throwing up our hands and saying that recursive self improvement is going to eventually destroy everything that isn't an agent isn't a solution. What follows is where I think things are going with AI agents and how we can start to operate in this new world safely, most likely with some sort of regulations that allow for aggressive development and at the same time a high level of trust. At the very least, let's have the conversation.

The pieces

Before I go further, here are the words I'm going to use and how they fit, because they only make sense as a loop.

A policy is the gate the agent has to pass before it acts: what it may touch, how much it may spend, what it has to stop and ask about. It's enforced outside the model, so the agent can't argue its way through it.

A receipt is the proof that an action happened and what it pointed to: the email, the calendar entry, the approval, the transaction. No receipt, no fact.

The record is the receipts and the decisions behind them, kept over time. I keep mine as decision memos. It's the memory I can actually trust, because every line in it points to something I can open.

An envelope is the outer limit a human sets on one agent before it goes out: the most it can spend, the terms it can accept, what it has to bring back to me.

A mandate is what my agent shows your agent: proof of what I authorized it to do, with the limits attached. It's the letter of credit.

A ratifier is the licensed human who signs for the domains no policy can cover: the fiduciary, the doctor, the lawyer, the board.

A judgment score is what the record proves once outcomes are attached. Not a right-or-wrong grade. A decision gets rated on several attributes: what was known at the time, what was at risk, how hard the call was, how it was made, and how it turned out. The exact attributes are still an open question.

And a stamp on all of it. A cryptographic seal, like a signed transaction on an open ledger, that lets anyone check that a receipt or a mandate is real and hasn't been altered, without having to trust the company that produced it. The stamp proves it's authentic. It doesn't prove the decision was sound. That's what the record and the score are for.

So the loop runs like this. Policy before the agent acts. Receipt during. Record after. Envelope and mandate when it goes outward to other agents. A ratifier wherever a human has to sign. Outcomes attach to the record, the record produces the score, and the score feeds the next policy. The stamp rides on every receipt and every mandate.

The loop: policy before, receipt during, record after, envelope and mandate outward, ratifier where a human signs, score back into policy; the stamp on every receipt and mandate.
The loop. Policy before, receipt during, record after. Envelope and mandate outward. A ratifier where a human signs. The score feeds the next policy. The stamp rides on every receipt and mandate.

The Policy

We are all in a position where we're experimenting with all of this and we are starting to figure out what AI actually is and what it's capable of. We might be fooling around with memory. We might be fooling around with how it makes decisions. We think one model is smarter than the other.

To me it's a child with a limited photographic memory. Sometimes it can't make the social connections or understand that making things up is not really the best thing for the situation. Sometimes it doesn't understand the boundaries. And sometimes it really doesn't understand why it's supposed to make the decisions it's supposed to make, so it pretends. I think as AI starts to develop over the next few years, we're going to see some trends that might repair or mitigate that.

After my hallucination incident, the first thing that I started putting into my memory system was the concept of decision memos as a governing record for onboarding new agents, as a way of getting my own personal "compliance" to stick with my own rules, and a history of everything that had gone on with my personal assistant, starting with this hallucination that we had in the summer. For the most part, it resolved the issue of hallucinations on a go-forward basis.

Here is what it actually changed. Anything that can't point to a source I can open gets flagged instead of filed. Repetition doesn't count as confirmation; if three summaries all say the same thing and none of them cites an email, that's contagion. And nothing is marked saved, sent, scheduled, or done until the receipt exists. The memo became my line nothing got past.

We're starting to see the pieces from the vendors. Grok Bot ships a persistent agent with its own computer, your logins, and its own memory, and it comes back to you for approval before it acts.1 Meta's Muse does the scheduling, the shopping, and the form-filling on its own machine, with an approval step.2 What neither ships yet is the policy. Think of this in terms of a decision log, or decision memos themselves, that the agents read first, and that they're held to. If I'm using the wrong vocabulary, forgive me.

Let the agent grade its own compliance and you've built an excuse generator. The gate has to sit outside the model.

Looking forward to 2028, if not sooner, we could see that your decisions and your delegations become portable files as a rule. The portability right now is kind of free if you know how to build it, but it's technically pretty tough on the average user. So the question's going to be, can you take your decisions and your delegations with you to the next model? Can you build your rules around that? And then can you take that with you so that you can utilize that in the new company that you're in, or in the new organization that you're in, or with the new model that you're looking at?

Go a layer beyond that and you're going to start to see agents that are bonded. You're going to start to see insurance companies that are underwriting the risk of what an agent may do and at what limit. Those insurance companies and those agents are going to have strict parameters and strict policies around them because it doesn't make sense otherwise.

You will also see an authority that's going to exist between agents. There will be one agent in my company, or in my organization, or in my family, and it has its own policy, its own way of acting, its own way of behaving. It's going to interact with another agent that may work for a company, or may work with another family, or an individual, or an organization. My agent will present its mandate, and it's going to behave like a letter of credit.

(Sidenote: everyone is talking about regulations and regulatory capture and the like, and what I am talking about is the uniqueness at a smaller level. I would imagine that there will be "rules" for agent interactions, and it would be really swell if we started with the 3 laws of robotics.)

This is already how the payment networks are building it. Google's Agents to Payments protocol, which Mastercard, American Express, and PayPal signed onto, runs on signed "mandates": a tamper-proof record of what the user authorized, with price limits and conditions, created before the agent spends a dollar. Mastercard and Visa launched their own agent-payment frameworks in the spring of 2025, and live agent-initiated transactions started this year.3 A mandate is the letter of credit. It's here.

If we are going to start insuring these agents and underwriting them, the receipt, the decision memos, what gets logged, becomes the actuarial standard when it comes to these insurers. They will demand one action log format, because that's going to price the risk accurately for these particular agents. There will be a company in the future that will develop a format for these agents to develop a risk profile for the agent itself, based on the policy that's written around the agent, that will allow companies to insure their agents at scale. So the receipt of what the agent has for its policy or guardrails, and its decision memos as to how it's making its decisions, becomes the actuarial record that gets written against the insurance policies.

The first policies already exist. Lloyd's-backed insurers write standalone AI liability cover today,4 and the first insurance written for AI agents was issued this year only after the agent passed a certification whose controls read like this article: log every action, block unauthorized actions, limit what tools it can call, put a human on high-risk outputs.5 What comes next is the standardized format.

This naturally leads to autonomy that's actually bought by units. Clean records for agents are going to earn cheaper autonomy. Agents will be graded by risk tiers, a lot like the way drivers get tiered by risk when it comes to getting auto insurance. So a driver that's 16 years old has a lot more risk because it doesn't have a long record of making very clean judgments. The more judgments you make, the lower risk that agent becomes, assuming those judgments are beneficial. That autonomy that the agent earns as a result of making judgments and taking less risk and acting in the way it's supposed to act becomes a budget line, because companies are going to want agents that are cheaper to insure, that act in a way that's compliant with the company itself, and not able to take unnecessary risk. Keep in mind, those policy decisions that are made by the agents at the beginning are the ones that are going to dictate what their risk score is for that particular agent, sub-agents, or group of agents on a team collectively.

You will always have non-agent insurable domains that are going to remain human-only, because the human is going to be responsible for the policy decisions. If anything the humans taking on that responsibility may consolidate, but think of these in terms of fiduciaries, medical, legal actions, boards, ones where you have to get certifications in order to practice in those areas. The licensed human is the "ratifier" that the insurance agency is going to look at and say, "You can go ahead and use an agent, and that's fine. And that agent may have a perfect policy, and that agent may run in a way that is low risk. But at the end of the day, there are still particular professions that are going to have to be ratified by a human who is licensed in that area."

This is where you are going to see medical professionals, legal professionals. Regulators will be tying an agent's actions to a licensed person's errors and omissions policy, or the board insurance for a particular board of directors. Ultimately, these individuals are going to be the ones who take on the responsibility and the risk of the agents that run underneath them.

The Audit

The result is that the audit itself is not going to be evidence that's looked at after the fact as part of an exam or formal exercise. It's going to be an actual stream that an auditor or an auditor agent is going to consume live. That receipt and that evidence is processed in real time, and it's going to be run as part of the policy that's embedded in the agent itself.

When you have an audit as a stream, you get completely continuous supervision that's going to replace this audit or exam cycle that happens. Think of it in these terms: you're not going to get audited for your taxes once a year. It's just going to be ongoing, kind of like a W-2 employee that's having money come out of their paycheck, but it's going to work so fast that the exam cycle around those particular audits will be something that's part of the stream. The regulator agents will read that in real time. Your accountants, your regulators, will shift to handling exceptions. The cleaner your audit is, the less you pay to insure your agent, the higher the judgment score. Some of that happens already today. So firms that have agents with clean streams, regulated technology, will be a lot easier to do business with, trust, and scale.

Banking already runs a version of this. Continuous transaction monitoring watches every transaction and humans review only the exceptions.6 Somebody still owns the exceptions, and the auditor agents need an auditor of their own. That's headcount and cost. Anyone selling you a stream that "just runs" is skipping that line.

Of course we will start to see people try to break the system, because you're going to see attempted receipt fraud as part of this. This will lead to a cryptographic attestation. Streams start to get gamed as people try to game the compliance system or game the audits. This will lead to receipts with hardware roots that are signed, which will start to become mandatory. Unsigned logs from decision memos will be inadmissible. Infrastructure vendors that run attestations will become a standard practice. The tipping point on this is when enforcement cases over fabricated agent receipts become a major news story.

One thing a signature can't do: a signed receipt proves the log wasn't tampered with and who produced it. It doesn't prove the decision was sound. A signed hallucination is still a hallucination. So the record needs two checks: is it authentic, and does it point to something real.

Authority Between Agents

This brings us to the authority between the agents themselves. Here you're going to start to see mandate registries. A federated registry of who may do what. Resolved like a DNS service. The operator itself is going to own the graph. Then payment identity rails. Registered mandates are going to start to roll out and are going to start to govern who has authority over particular transactions or particular contracts.

When this is established, agents will be able to negotiate among themselves, beyond what they are able to do now. The difference is that it will be inside human envelopes. Terms will be set between agents, but within delegated limits that are set by the policy envelope set by humans. The envelope setter's judgment is really the edge of where that interacts. We will start to see jobs for the person who can best set the envelope for that particular agent to go out and do the negotiating on its own. Disclosed B2B procurement running end to end with no human touch to it. Part of the audit, guided by policy, rated, set by human envelopes.

This is the point where society may see some authority chains that are going to start to fail systematically. A publicized agent chain incident that's going to have serious losses, systematically, in the system. Delegated authority starts to cascade like a flash crash, because the risk is going to start to escalate. (Think CDOs in 2007–2008, but it's delegated authority en masse.) You're not just going to have one agent that's making decisions, but everybody they interact with is going to start to have agents make decisions on their behalf. So once one delegated authority crashes, it's going to start to cascade. This is the risk to supply chains (virtual and physical).

This will lead to a legal requirement of circuit breakers. The established players will be forward thinking and already implement them. You're going to see chain depth limits. Those are going to start to become regulation for agent interaction. Circuit breaker vendors and regulators, combined with compliance consultants, become a hot commodity at this point.

And every mandate has to be revocable in seconds, across company lines, by the human who granted it. If you can't pull authority back, this becomes a very expensive proposition.

The Record

This becomes the firm's judgment. Using decision memos as the basis for this, where every company is going to have a decision log that its agents read first as they're onboarding or before they make decisions. That log is going to be free, because it's basically free now. But what's going to be really scarce in the future is what the log actually proves.

At a certain point, with persistent agents, we are going to start to see outcomes attached to decisions, to make decision quality measurable per person, per team, and per agent. So the outcomes are going to be attached to these decision memos for an individual and for a team and for the agent itself, and even the collective organization or government entity.

That's going to help with a new universal measure called judgment scoring. How good is this individual at making judgments? How good is this team at making judgments? How good is this agent at making judgments? How good is this entity or government branch at making judgments?

A score that only counts outcomes will get gamed and will punish good decisions that got unlucky. People and agents will take the easy calls to protect their number. And a decision isn't right or wrong the way a math problem is; the result rarely fits a binary. So the score has to be a scale across several attributes: what was known at the time, what was at risk, how hard the call was, how it was made, and how it turned out. That's harder than attaching an outcome to a memo. This will be worked out as a universal standard because it's meaningless otherwise.

A proposed decision comes up, and that's going to be run against everything that the firm or the individual or the team or the company has decided in the past and the results of those decisions. Something like a pre-mortem is going to be completely automated. Agents will start proposing amendments to the policy based on the outcomes, and humans ratify them, so the policy ends up versioned and changed, kind of like code in a program.

Authority Traveling with the Person

Agents will become legal proxies for individuals. Your delegation profile, or your trust, becomes a recognized authority. You get a power of attorney for agents themselves to act on your behalf, because you've taken the time, or you've met with some sort of agent advisor that's able to cultivate an agent with policies that you trust and has a good history of judgments. Agents will step in as legal proxies for humans.

Instead of a resume, you're actually going to have a judgment portfolio. A sanitized decision record that's going to travel between your employers, that's going to travel with you. Instead of a resume that you're going to be pushing out on LinkedIn, you're actually going to have a judgment portfolio, because hiring is going to start to take place on demonstrated judgment and the ability to delegate and run with these agents in a way that allows these gates and policies and authority to be used judiciously.

Values will be the household authority. So who may decide what for whom? Children, aging parents, executors, caregivers. What are the rules of your particular family? What does your family believe? What is your family's philosophy? Is the agent acting on your behalf? And these customized agents are going to take on the values of the individuals, the families, and the companies, as far as how they work.

For the individual, for the company, for the family itself, the idea of being able to cultivate a policy before the agent acts, a record on if it meets that policy, and then the authority that travels with the company, with the person, so that our agents, when they are out there in the universe and interacting with other agents, it will be my completely unique agent rules, policies, and guardrails interacting with yours.

At the same time, there are going to be key areas where humans have to be involved, because that's the only way that you can hold people accountable. That's a way to reduce the insurability, the insurance risk, the financial risk. And it's the only way to make sure that when we get to a situation where we have a sort of event where that authority chain fails, humans are able to keep themselves involved.

Here is what would prove me wrong by 2028. If the big vendors keep memory and policy locked inside their own products and nobody can move a decision record between them, portability was a wish, and they have every incentive to keep it that way. If insurers keep writing AI as an endorsement on the cyber and E&O policies they already sell and never ask for a common action log, the actuarial standard doesn't come. And if the first cross-company agent failure gets handled quietly with a refund instead of a rule, the circuit breakers stay optional. Watch those three.

These are some of the things I see coming with the agents that are rolling out and the way AI is developing over the next few years. Policy, the record, agent authority, and judgment scores: I think those four are going to be very valuable for us as humans as we move forward and figure out how we work with our agents.

There are tons of ways that we can look at AI and agents in the future. We can point to the hallucinations, the people that AI told us existed that didn't, the events that we are told existed that didn't and try to pretend that we don't have a way to "herd" the entire movement into something we can control.

I think we can do better than that.