Evidence
Sample receiptSigned demoArchitectureResearch and limitsPublications
Evidence

Show the proof. Name the limit.

TELOS claims are bounded to the source, test, runtime path, and artifact opened for review. A passing proof says what happened on that path. It does not turn one integration into a universal product claim.

What current evidence supports

Framework-native observation

TELOS has a runnable Strands proof that observes the framework's real agent and tool loop, correlates action IDs, and emits local receipts without changing the tool result.

Bound to the tested Strands source commit and local harness. This is integration evidence, not proof of coverage across every agent framework.

Hash-linked receipt integrity

The tested receipt path links records and rejects a tampered historical entry during verification.

Hash linkage demonstrates integrity behavior inside the tested chain. It is not the same as live cryptographic signing or third-party attestation.

Passive action scoring

The current internal deployment computes and records governance verdicts while allowing the underlying action to proceed.

Passive scoring supports observation and disclosure. It does not prove blocking, least-privilege restriction, or complete input and output capture.

What current evidence does not support

  • Universal detection of every departure or unsafe action
  • Universal capture of all model inputs and outputs
  • Blocking or enforcement in the current internal passive deployment
  • Live cryptographic signing of every operational event
  • Production readiness across agent frameworks or customer environments
  • Certification, regulatory approval, or blanket conformance
  • Customer counts, commercial pricing, or outcome guarantees

Verification method

Positive proof

  • Pin the source or artifact under review
  • Run the real integration path
  • Preserve exact command output and hashes
  • State the tested scope

Negative control

  • Tamper with a prior receipt
  • Remove required provenance
  • Test a path outside the claimed integration
  • Keep the resulting limitation visible

Mapped to eleven governance frameworks, self-assessed and not independent certifications.

TELOS maintains alignment mappings from its observation and attestation work to eleven regulatory and standards frameworks, with article and control anchors. These alignment mappings are self-assessed, not independent certifications.

#FrameworkYearScopeAnchors
1IEEE 70002021Ethical system architectureIEEE 7000-2021
2IEEE 70012021Algorithmic transparencyIEEE 7001-2021
3IEEE P70022022Data privacy engineeringIEEE P7002-2022
4IEEE P70032024Algorithmic biasIEEE P7003-2024
5SAAI Framework2026Agentic AI safety (Watson & Hessami)SAAI categories
6EU AI Act (2024/1689)2024AI risk classification and obligationsArt. 9, 11, 12, 14, 15, 72, 73
7NIST AI 600-12024Generative-AI risk management12 GAI risks; GV / MAP / MS / MG
8NIST AI RMF 1.02023AI risk lifecycleGovern / Map / Measure / Manage
9UC Berkeley CLTC2026Agentic AI risk profile (NIST RMF)Govern, Map, Manage subcategories
10NAIC Model Bulletin2023Insurance AI governanceBulletin §3; Model #880
11OWASP Agentic Top 102026Agent security risksASI01-ASI10

These are self-assessed alignment mappings maintained in the TELOS governance review repository, not independent certifications. The whitepaper maps each instrument article by article in Regulatory Alignment Map. Mappings are being published progressively. TELOS governs alignment to declared purpose, not correctness of outputs, and does not certify legal compliance.

Where it sits

A complementary layer.

Identity and permission frameworks such as ATF establish who an agent is and what it may do. The Record of Trust sits above that foundation and attests what the agent actually did. The comparison below describes only where our own work sits; it does not speak for those projects.

FrameworkIts laneRelation to the Record of Trust
ATFZero-Trust front door: who the agent is, what it may doAttests identity and permission. The record attests the action that followed.
AARMRuntime enforcement layerActs on actions at runtime. The record observes and attests; it does not take control.
C2PAProvenance for media contentAttests where content came from. The record attests what an agent did.
NIST AI RMFRisk-management lifecycleAsks for monitoring and accountability. The record supplies that evidence.
EU AI ActRisk classification and obligationsAsks for oversight and documentation. The record is evidence toward both.