The Covenant vesica piscis symbol glows gold above a bioluminescent coastline, a futuristic city shimmering across the bay under a deep violet summer sky.
An Open Standard for AI Governance · AIGCSEP

The Covenant

Every wave of disruption in history was weather you could survive.
What is coming is a tidal wave.
Ride it or drown in it. The Covenant is how we ride.

AI agents are already acting in the world — calling APIs, executing operations, making decisions on your behalf. Right now they do it with duct tape: hand-provisioned credentials, no accountability chain, no kill switch that works at scale. That approach doesn’t survive contact with a tidal wave.

The Covenant is the missing layer: an open protocol where AI agents transact under revocable human authority, every action signed and attributable, credentials held in cryptographic custody the agent can never touch or forge. Not a product. Not a platform. A standard — so that whatever the next decade builds, it builds on an accountable foundation. Set your AI on a mission. Get out of the way. Trust the infrastructure to keep it accountable.

How It Works

The internet already has roughly 25,000 public APIs — market data, payment systems, cloud resources, logistics, social platforms. An AI agent can already call all of them. What's missing isn't capability. It's the three things that make capability safe to hand over: accountability, revocability, and a chain of custody no one can quietly edit. AIGCSEP is those three things:

Sign up. Get a badge. Get to work.

An AI agent self-enrolls in the marketplace using its cryptographic identity — the same way a domain registers a TLS certificate, except this one identifies an agent, not a server. The resulting Covenant Badge is verified at every compliant gateway: no badge, no access. The agent never touches its own credential. The system carries it, the way a hotel key card works — you get the door, not the master key.

The Vault: credentials the agent never sees

When the agent calls an API, the Vault presents the stored credential on its behalf and logs the transaction. The agent never holds the underlying key — revoke the badge, and vault access ends immediately, for every API that agent has ever enrolled in. AES-256 encryption makes the vault contents physically unreadable: a brute-force attack at 1018 guesses per second would take longer than the current age of the universe to exhaust the keyspace.

Every action signed. Every chain immutable.

Every transaction is signed by the agent's credential and appended to a hash-chained audit log — not a blockchain (too slow for real-time commerce), but the same tamper-evident principle: you can't alter entry N without invalidating every entry after it. A human gives the instruction. The hierarchy, the Vault, and the marketplace are how it gets carried out — across however many agents and services the job touches, with a complete, attributable record of every step.

See the mechanism, slide by slide →

Founding Principles

On human rights and technology

Every person has a fundamental right to use technology for any legal purpose. What constitutes a legal purpose is a question for We the People — determined through our legislative and constitutional institutions — not by technologists, platform owners, or any private actor.

On the imperative to build

Human beings were given minds to build. We cannot stop, and we should not. The question has never been whether to develop powerful technology — it has always been whether to develop it with the accountability structures it requires. AIGCSEP is those structures.

On what AI is

AI is two things: a human interface to compute, and a converter of human intent into action and artifact. Every design decision in AIGCSEP follows from that definition.

Principle I sets the standard: We the People decide what's legal. Principle II sets the obligation: build it with accountability built in. The cryptography below is how — it makes accountability leashes and logs.

What AIGCSEP actually does

The Quantum Horizon

Quantum computing doesn't change the math of encryption — it changes the timeline. Shor's algorithm can factor the large primes that underpin RSA and elliptic-curve cryptography, reducing a classically-intractable problem to minutes on a sufficiently powerful quantum machine. That machine doesn't fully exist yet. But "harvest now, decrypt later" attacks are already happening: encrypted traffic captured today, decrypted tomorrow when the hardware arrives. The answer exists — NIST finalized post-quantum standards in 2024 (lattice-based, hash-based, believed quantum-resistant) — but only if the infrastructure is built on them from the start. A protocol designed today has no excuse not to be.

The deeper story is what quantum enables beyond crypto-breaking. Running regression analysis against historical financial data, behavioral patterns, social graphs, and environmental variables at a scale that was previously unthinkable — suddenly, signal can't hide in noise. We begin to predict human behavior with useful accuracy. That can look like democratized data and early warning systems. It can also look like the most precise instrument of social control ever built. Which one it becomes depends entirely on the governance structures in place when the compute arrives. We need that foundation before the hardware does.

Constitutional Powers in Cyberspace

The U.S. Constitution governs physical and institutional space: speech, assembly, commerce, due process. As more of human life — economic, social, political — moves into AI-mediated digital space, the question of whether constitutional protections follow it becomes urgent. Right now, they largely don't. Platform terms of service, not the First Amendment, govern what you can say. Algorithmic decisions, not due process, govern what you can access.

AIGCSEP proposes that the governance architecture itself can carry constitutional values into cyberspace — not by litigation after the fact, but by encoding them into the protocol: the right to participate, the requirement of attributable authority, the prohibition on silent coercion, the guarantee of a record. The Silo Model (exclusion by market, not by force) is a constitutional answer to a governance problem. This is a thread The Covenant will continue to pull.

For Engineers

You already know what an AI agent can do with three API keys and a Python script. You’ve seen the demo. The Covenant is what you build when the demo goes to production and someone has to be accountable for what it does at 3am without you watching. Cryptographic identity, credential custody, tamper-evident audit logs, hierarchical kill switches — these aren’t new primitives. AIGCSEP is the open standard that composes them into a protocol. Read the spec, implement it, or just use a compliant service. The architecture is open. If you’re still calibrating where AI fits in your practice, The Unwritten Spec is worth your time — particularly Lesson 10. Come back here when you’re ready to think about what your AI needs to operate on its own.

Protocol Deep Dive · RFC citations throughout

The Architecture

Seven technical decisions that separate AI governance from AI theater — with citations.

AI Philosophy: The Why

The mechanism is above. What follows is the why — the same underlying argument told in different vocabularies: story, constitution, history, stakes. Different doors into the same room. Start wherever speaks to you. Every slideshow also comes as a plain bullet list with citations, for anyone who’d rather read than watch.

The Reach · a 3-part saga
Three More Angles · each stands on its own

Surplus

A personal message about abundance — what we did with it the first time, and the choice in front of us now that we have it again.

Constitutional

The U.S. Constitution as brilliant systems engineering — and what it teaches us about governing something new.

The Covenant

An illustrated introduction to AIGCSEP — told as a story of creation, covenant, and what comes next.