Tyche Institute · attestable agency · Disobey 2027

Who said the agent could do that?

Your AI agent holds your keys, and every signature it produces verifies. So who checks it stayed inside the job you gave it? A correctly-signed action can still be an unauthorized action — and you can catch it.

The spectrum: presence → authority

Mechanism
Answers
Anchor
BotGuard
human / browser?
none
PAT
genuine device?
hardware
PACT
legit agent?
none
AEP
what, whose authority, in mandate?
issuer+TPM+scope

The attack matrix

tamper_fieldDENY:content_mutated
forge_rechainledger ok · aep_sig_invalid
forge_fullDENY:issuer_not_listed
swap_mandateDENY:aep_sig_invalid
strip_sigDENY:aep_sig_invalid
replayALLOW · then replayed
exceed_scopeDENY:scope_violation
$ verify.py samples/exceed-scope.aep.json  →  DENY:scope_violation
Correctly signed. Out of mandate. Rejected.
The agent is not its own judge.
Break it yourself.
github.com/tyche-institute/aep-sandbox
tyche.institute/lab/aep-ctf/
Anton Sokolov
Tyche Institute · Tallinn
tyche.institute/talks/disobey-2027/