Consider this our take on the “Know Your Agent (KYA)” dilemma. Turns out, signatures created with our BlkBolt™ tech are uniquely enabled to solve this problem.
AI agents are evolving fast. New models. New versions. New behaviors. Benchmarks change, systems get updated, and suddenly the thing you deployed last month isn’t quite the same anymore.
The general mantra seems to be…“Looks right…probably fine.”
With backgrounds in risk management and cyber security, let's just say, that feels… optimistic.
We’ve been thinking about a slightly different approach:
Don’t just trust the agent, verify what it actually produced.
The core concept is simple:
- An LLM/agent generates a response
- The final response is signed at creation time by the source system
- The client can verify it before trusting it
Why This Matters (especially now)
In a world of rapidly changing AI models and agents:
- How do you know which agent or version produced a response?
- How do you confirm the response wasn’t altered in transit?
- What happens when you don’t want to stand by past outputs?
- How do you prove what was actually shown to a user?
- Two systems produced the same thing, which came first?
Revocability
If an agent version is deprecated, misbehaving, or just wrong:- Previously issued signatures will become invalid
- You can stop trusting outputs from that version
- You’re not permanently tied to everything it ever produced
A Few Real-world Scenarios
- 🛒 Agentic Commerce - Your AI agent makes a purchase on your behalf.
- Did your agent actually initiate that transaction?
- Was the request altered anywhere along the way?
- Can the business verify the same thing?
- 👶 Teacher agents - A child is interacting with an AI tutor.
- Is the content displayed exactly what the system produced?
- Was anything modified in the browser, by an extension, or in transit?
- Can you audit what was actually shown?
- 🏦 High-stakes customer service - A banking agent issues a refund or provides financial guidance.
- Can you prove what was presented or said to the user?
- Can you audit later? (who, what, where, when)
- Can you revoke trust in outputs from a faulty version?
How This Could Work (in production)
The goal is to make it very simple.
At a high level:
- You lease a BlkBolt™ encoding model/s to your AI agents
- The leased model is used for signing and verification
- The agent system makes one signing call when content is created
- The response is sent with the signature artifact
- The client verifies automatically in the background through separate API call
Other Interesting Stuff
In addition to our key differentiator of revocability, BlkBolt™ produced signatures offer several additional benefits such as:
- Embedded policies through metadata
- No traditional key handling - compared to traditional signatures like RSA, ECDSA, etc.
- Distributed verification - you control what happens to signatures, we just help verify them
- Content-level trust - not just connection-level trust (e.g. TLS)
Where This Fits
As AI agents act on behalf of users and systems become increasingly autonomous, trust has to extend beyond the application itself to the outputs those systems produce. BlkSeal provides a way to attach verifiable origin, integrity, and revocable authority directly to those outputs.
Building AI systems where output integrity matters? We’d like to hear about the workflow. Contact Us, let's solve some problems!