Search papers, labs, and topics across Lattice.
Addressing the gap between cryptographic tamper-evidence and actual semantic guarantees in autonomous workflows, this work formalizes an evidence claim model for agentic systems. It exposes how standard artifacts like hashes and signatures are routinely conflated with authorization, capture completeness, and semantic validity. The framework categorizes 14 granular evidence claims across multi-agent hierarchies, mapping each claim directly to its underlying trust assumptions, threat vectors, and required control loops.
Cryptographic audit trails in agentic systems provide a false sense of security, proving bit-level integrity while fundamentally failing to verify semantic truth, authorization, or capture completeness.
Agentic AI systems increasingly exchange messages, invoke tools, request approvals, hold structured decision sessions, and modify shared artifacts. Logs and anchors can make selected records tamper-evident, but they can also mislead if their evidentiary meaning is implicit: a hash does not establish semantic truth, a signature does not establish authorization, and an external anchor does not establish capture completeness. This paper proposes an evidence claim model for agentic processes. It distinguishes artifact integrity, temporal existence, provenance, approval evidence, declared ordering, capture claim, relevance claim, deliberation traceability, monitoring claim, anchoring authorization claim, policy assessment claim, risk treatment claim, mitigation implementation claim, and management response claim. Semantic validity is treated as a recurring limitation. The model maps these claims to mechanisms, assumptions, limitations, and threats, and situates them in an agent organization with functional CEO agent, executive, operational, evidence, and audit roles, plus a plan-do-check-act-inspired management response loop. The contribution is conceptual: it does not validate a particular implementation, prevent all failures, or automate legal compliance. It provides a vocabulary for stating which claims an agentic black box can support, which claims it cannot establish, and which controls are required around it.