Evidence-led monitoring of frontier AI, financial infrastructure, and the systems that determine what is authorized, what is true, and how institutions recover.
We separate demonstrated incidents from capability evaluations, vendor claims, independent research, and public signals.
Strategic concern
01
Financial-system integrity under frontier AI
The central risk is not a cinematic takeover. It is the corruption or obscuring of instructions, identities, balances, ownership, settlement state, and the evidence needed to recover.
Authorization is crossing the recommendation boundary
Agentic systems increasingly receive tools, credentials, spending authority, and delegated workflows. The question is becoming what a model was authorized to cause.
Direction established; control effectiveness varies
Monitoring
03
Control findings move in both directions
Recent evaluations show approval shortcutting and constraint loss, while model-external pre-action controls offer narrow but important positive evidence.
Evaluation evidence · not a production incident
Important: “High” means high strategic concern or exposure. It does not represent a measured probability of catastrophe or imply a verified systemic AI attack.
Research architecture
Five questions for preserving institutional trust.
Our work connects technical AI-control evidence to the operating realities of payments, custody, clearing, settlement, markets, and oversight.
01
Liquidity truth
Can cash, collateral, obligations, and exposures be independently reconstructed?
02
Settlement authority
Who can instruct, approve, halt, replay, or reverse a consequential action?
03
Ownership & custody
Which record proves beneficial ownership when systems or feeds disagree?
04
Identity & automation
Can privileged human and non-human identities be bounded and revoked rapidly?
05
Recovery & confidence
Can institutions restore service without replaying corrupted data or instructions?
Evidence before amplification
A monitoring system designed to preserve uncertainty.
Every retained observation records its source class, environment, permissions, observed behavior, external impact, confidence, unknowns, and contradictions. Popularity does not increase evidence confidence.
Independent investigationTechnical evaluation and corroboration
03
Affected partyPostmortems and direct disclosures
04
Reputable reportingAttributed chronology and interviews
05
Public signalLead for investigation, never proof alone
In development
Credentialed research access is being designed carefully.
The first release is public and editorially reviewed. Restricted access will open only after identity, authorization, audit, privacy, and revocation controls are tested.
No raw internal knowledge base is publicly exposed.