You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<title>Model Weight Protection and Agent Governance Demos | AgenTrust</title>
7
-
<metaname="description" content="Nine runnable demos for securing AI model weights and governing agents. Attestation-gated key release, tamper refusal before load, derivative lineage for fine-tunes, and 2-of-3 sovereign threshold custody. Run them on your laptop in ten minutes, no confidential-computing hardware required.">
7
+
<metaname="description" content="Ten runnable demos for securing AI model weights and governing agent tool and model calls. Run them on your laptop in about twelve minutes, no confidential-computing hardware required.">
<metaproperty="og:title" content="Model Weight Protection and Agent Governance Demos">
15
-
<metaproperty="og:description" content="Nine runnable demos: attestation-gated key release for model weights, tamper refusal before load, derivative lineage for fine-tunes, 2-of-3 sovereign threshold custody. Ten minutes on your laptop, no special hardware.">
15
+
<metaproperty="og:description" content="Ten runnable demosfor model-weight custody and governed agent tool and model calls. About twelve minutes on your laptop, no special hardware.">
<metaname="twitter:title" content="Model Weight Protection and Agent Governance Demos">
26
-
<metaname="twitter:description" content="Attestation-gated key release, tamper refusal before load, derivative lineage, 2-of-3 sovereign threshold. Nine runnable demos, ten minutes, no special hardware.">
26
+
<metaname="twitter:description" content="Model-weight custody plus governed agent tool and model calls. Ten runnable demos, about twelve minutes, no special hardware.">
<p>Nine demos, about ten minutes end to end. Four cover custody of model weights: binding a checkpoint's hash, gating the decryption key behind attestation, tracking a fine-tune's lineage, and splitting the key so no single party can release it. Five cover governing what an agent does at the tool boundary.</p>
168
+
<p>Ten demos, about twelve minutes end to end. Four cover custody of model weights. Five govern what an agent does at the tool boundary. One governs model calls through an OpenAI-compatible endpoint.</p>
169
169
<p>Everything runs in software mode with <code>CMCP_DEV_MODE=1</code>. No confidential-computing hardware, no cloud account, no signup.</p>
170
170
</div>
171
171
</div>
@@ -174,12 +174,12 @@ <h1>Don't take the spec on trust.<br>Run it.</h1>
git clone https://github.com/agentrust-io/demos && cd demos
177
+
<pre><code>git clone https://github.com/agentrust-io/demos && cd demos
178
+
pip install -r requirements.txt
179
179
export CMCP_BEARER_TOKEN=demo-token
180
-
python demo.py # all nine, pausing before each
180
+
python demo.py # all ten, pausing before each
181
181
python demo.py 6 # just demo 6</code></pre>
182
-
<pstyle="font-size:0.875rem;color:var(--muted);margin:0.875rem 0 0;">Demos 1 to 5 are driven by <code>cmcp-runtime</code>. Demos 6 to 9 need only <code>weight-custody-manifest</code>, with no server and no gateway. Source: <ahref="https://github.com/agentrust-io/demos">github.com/agentrust-io/demos</a>.</p>
182
+
<pstyle="font-size:0.875rem;color:var(--muted);margin:0.875rem 0 0;">The requirements install cMCP for demos 1 to 5, Weight Custody Manifest for demos 6 to 9, and the OpenAI client for demo 10. Source: <ahref="https://github.com/agentrust-io/demos">github.com/agentrust-io/demos</a>.</p>
183
183
</div>
184
184
185
185
<pclass="section-label">Model Weights</p>
@@ -304,6 +304,18 @@ <h2>Governing what an agent does</h2>
<divclass="card-name">Nine Demos, Ten Minutes</div>
849
-
<divclass="card-desc">Run the specs on your own machine, no hardware required. Watch a policy block a data leak, verify a signed receipt offline, and see model weight custody refuse a tampered checkpoint before it loads.</div>
848
+
<divclass="card-name">Ten Demos, About Twelve Minutes</div>
849
+
<divclass="card-desc">Run the specs on your own machine, no hardware required. Block a data leak, verify a signed receipt, refuse tampered model weights, and govern OpenAI-compatible model calls.</div>
Copy file name to clipboardExpand all lines: llms.txt
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -24,7 +24,7 @@ AgenTrust is organized around four complementary open standards. Agent Manifest
24
24
25
25
## Runnable demos
26
26
27
-
- [Demos](https://agentrust-io.com/demos/): Nine runnable demos, about ten minutes total, all in software mode with no confidential-computing hardware required. Four cover custody of AI model weights and five cover governing an agent at the tool boundary.
27
+
- [Demos](https://agentrust-io.com/demos/): Ten runnable demos, about twelve minutes total, all in software mode with no confidential-computing hardware required. Four cover custody of AI model weights, five govern an agent at the tool boundary, and one governs OpenAI-compatible model calls by data class.
28
28
- Securing model weights (demos 6 to 9): a Weight Custody Manifest binds a checkpoint's exact `weights_hash` and gates the decryption key behind attestation, so a tampered checkpoint is refused before it loads; a closed-weight variant keeps a frontier lab's weights secret from the operator hosting them; derivative lineage gives a fine-tune its own signed manifest with a `derived_from` pointer, monotone rights, and a `rights_holder` split; and a 2-of-3 sovereign threshold splits the model key so one forged attestation sits below threshold.
29
29
- Honest scope: against an adversary who physically owns the silicon, no current confidential-computing platform is custody-grade, because of TEE.fail and BadRAM. These demos give accountability-grade custody under an operator-trust model, plus a threshold scheme for when one operator's word is not enough. Claims of weight protection "without operator trust assumptions" overstate what the hardware does.
30
30
- Governing agents (demos 1 to 5): Cedar policy enforced on every cMCP tool call with a signed TRACE claim per session; a policy swap showing up as an attestation failure via `POLICY_HASH_MISMATCH`; fully offline claim verification with no network call; context-aware enforcement where the same tool is allowed in one workflow and denied in another; and attribute-based enforcement denying any tool that is not BAA-covered.
0 commit comments