That assumption has already broken. AI agents are transacting, communicating, and signing contracts autonomously — passing identity checks designed for people, with no human visibly in the loop.
The Human Root of Trust is my attempt to name the problem and sketch the architecture: three pillars (proof of humanity, hardware-rooted device identity, action attestation), a six-step trust chain from human principal to cryptographic receipt, and two implementation paths.
It's dedicated to the public domain. No patent. No product. No ask except that whoever picks this up carries the principle forward.
wangzhongwang•1h ago
A human root of trust is necessary but not sufficient — we also need machine-verifiable manifests for agent capabilities. Something like a package.json for agent skills, but with cryptographic guarantees about permissions and data access patterns.
The accountability framework here is a good start. Would love to see it extended with concrete permission models.