AGENT ECONOMIC PROTOCOLHARDWARE-ANCHORED · TEE-NATIVEDEFENSE-GRADE SECURE ENCLAVE

Hardware-enforced safety infrastructure
for autonomous AI.

AeP Labs builds cryptographic, thermodynamic circuit breakers that physically isolate compromised AI agents in under 2 milliseconds. Memory-safe. Formally verified. Dual-use.

6Provisional Patents
2yrGMU Research Agreement
<50msHalt Latency
98%+Detection Rate
Backed by NVIDIA INCEPTION PROGRAM GEORGE MASON UNIVERSITY · SECSAT LAB REGISTERED US GOV CONTRACTOR · CAGE 1A8N0 TRL 4 · SIMULATION VALIDATED
01 · The Gap

We don't build the Brain.
We build the unhackable Brainstem.

The world's most advanced autonomous systems — from defense drone swarms to enterprise trading bots — rely on massive generative AI "brains" contained by hackable software guardrails. AeP provides the physical safety layer: a thermodynamic circuit breaker beneath the operating system, inside a hardware Trusted Execution Environment. If a brain is hacked, spoofed, or begins to hallucinate, the AeP Brainstem physically severs the node's communications — stopping a localized failure from becoming a correlated collapse.

Generative AI Brain
LLM · autonomy stack
Software Guardrails
Hackable · same memory space
AeP Brainstem
Thermodynamic breaker · sealed TEE · severs comms <2ms
Silicon Root of Trust · SGX · SEV-SNP · TrustZone
MESH NOMINAL — 12/12 NODES ATTESTED
Existing — Policy Enforcement
What the agent may do
    AeP — Behavioral Monitoring
    What the agent is becoming
      02 · Mission Impact

      Operational vignettes

      Standard static policies fail during rapid state-space explosion. AeP operates on thermodynamic principles to contain catastrophic cognitive drift before the execution payload is realized.

      03 · Architecture

      A four-stage closed loop,
      anchored in silicon.

      The reference implementation runs as a sealed enclave alongside the inference runtime. Each loop iteration produces a hardware-signed attestation — forensically auditable, replay-resistant, and bound to the device of origin.

      Shannon entropy over post-softmax activations
      H(X) = − p(xi) log2 p(xi)
      04 · Response Protocol

      Four states. Deterministic.
      Hardware-signed.

      Each tier is bound to a measurable entropy variance band, not a heuristic. Transitions are observable, attestable, and replayable.

      OK — Nominal · click a tier to inspect
      05 · Mathematical & Cryptographic Primitives

      Mathematically immune.
      Formally verified.

      AeP relies on established information-theoretic bounds, memory-safe systems engineering, and decentralized consensus protocols to eliminate single points of failure and physical evasion vectors.

      01 · Memory Safety

      100% Memory-Safe Rust

      Written entirely in #![no_std] Rust, the AeP engine is mathematically immune to the buffer overflows and memory exploits that plague legacy C/C++ guardrails.

      02 · Formal Proof

      Kani Formal Verification

      We don't just test our code; we prove it. Using AWS's Kani prover, our circuit breakers are mathematically guaranteed to fire when thermodynamic behavioral heat exceeds authorized limits.

      03 · Silent Telemetry

      Zero-Knowledge State Aggregation

      SP1 ZKVM compresses massive swarm and agent states into 32-byte cryptographic proofs — enabling LPI/LPD burst transmissions without emitting heavy RF signatures.

      Mathematics
      Information-theoretic constraints
        Cryptography
        Decentralized audit infrastructure
          06 · Architecture Integration

          The FFI bridge to silicon.

          The native Rust engine (cargo add aep-core) drops into high-performance pipelines (vLLM, TGI, TensorRT-LLM) and binds the inference path to a hardware-isolated TEE, enforcing constant-time execution and ORAM memory access to neutralize side-channel attacks.

          aep-core · rust · v0.1 src/main.rs
          07 · Benchmarks

          Internal validation,
          public methodology.

          Reference benchmarks against curated jailbreak corpora and synthetic distributional drift suites — backed by ~6,000 lines of production Rust across 17 crates, Kani-verified and passing 100+ tests on simulation hardware (TRL 4).

          ◆ Live Demonstration

          Captured-node swarm survival.

          A 12-drone ISR swarm over a denied urban area loses GPS to a jammer. Red captures Drone 7, extracts its comms keys, and injects poisoned waypoints to herd the formation into a kill zone. Watch the Brainstem sever the compromised node in under 2ms while the swarm redistributes coverage.

          MESH NOMINAL · 12/12 NODES ATTESTED
          12/12Nodes attested
          Sever latency
          100%ISR coverage held
          Attested node Captured / compromised Severed from mesh
          08 · Strategic & Commercial Architecture

          One engine. Two critical markets.

          The Thermodynamic Bond — a dual-use primitive securing both kinetic missions and financial capital. The same math engine — KNN threat mapping, Clayton Copulas, behavioral heat — converts unquantifiable AI behavioral risk into a cryptographically signed entropy metric.

          Defense · Replicator

          Securing mass autonomy

          The physical trust anchors required to safely deploy attritable, autonomous swarms in DDIL environments (Denied, Degraded, Intermittent, Limited) without risking swarm capture — making Replicator-scale mass autonomy mathematically safe from cyber and EW compromise.

          Commercial · Parametric Insurance

          Underwriting enterprise AI

          The deterministic actuarial physics insurers need to underwrite financial liability for autonomous trading algorithms and enterprise AI agents — real-time, provable risk signals that price coverage and automate claims via Proof of Physical Consequence (PoPC).

          09 · Research Collaboration

          A two-year collaboration with
          George Mason University.

          Term24 months
          AdministeredGMU Office of Sponsored Programs
          ScopeJoint federal submissions & hardware integration
          StatusEXECUTED
          Industry Partner
          Agent Economic Protocol
          AeP · NVIDIA Inception · DSIP-registered · CAGE coded
          Academic Partner
          George Mason University
          Department of Computer Science · SECSAT Lab
          Principal Investigator
          Dr. Xiaokuan Zhang
          Assistant Professor, GMU CS · Director, SECSAT Lab
          • Ph.D., Ohio State University · Postdoc, Georgia Tech
          • 20 papers at top-tier security venues — CCS ×10, USENIX ×5, NDSS ×3, Oakland ×2
          • ACM CCS & SIGSOFT Distinguished Paper Awards (2024)
          • NortonLifeLock Graduate Fellowship — 3 awardees worldwide (2020)
          • Program committee — USENIX Security, NDSS, ACM CCS ('24–'26)

          The hardware-side complement to AeP's behavioral substrate. AeP measures what an agent is becoming. Dr. Zhang's lab establishes that those measurements remain trustworthy under attack — that an adversary on the same silicon cannot forge the entropy signal, replay an attestation, or exfiltrate the reference distribution through a side channel. Under the executed Statement of Work, Dr. Zhang serves as technical lead on hardware integration and Co-PI on joint federal submissions.

          10 · IP Portfolio

          Six provisionals filed.
          Priority claims structured for deployment.

          The SDK and validation harness ship fully open-source while commercial leverage consolidates around two priority claim families.

          STRATEGY › Defensive Open Architecture. Integration SDKs and telemetry harnesses ship under Apache 2.0 for rapid, vendor-agnostic deployment. The core Entropy Circuit Breaker remains proprietary and patent-protected.
          11 · Ecosystem

          Complementary, not adversarial.

          AeP fills the behavioral monitoring gap left open by every existing agent safety stack. Each layer below is a partner, not a competitor.

          Hardware & Confidential Compute
          Inference Runtimes & Standards
          12 · Technical FAQ & SWaP-C

          System overhead & constraints

          Direct Line

          Secure your infrastructure.

          Direct deployment inquiries for defense primes, cloud infrastructure operators, reinsurers, and federal program managers.

          [email protected]
          NVIDIA INCEPTIONGMU · SECSAT LABCAGE 1A8N0DSIP REGISTEREDTRL 4