I build the boundaries between AI autonomy and the systems that must trust it.
An AI system's own account of what it did is not independent evidence. Fornax builds an external evidence layer around AI behavior so actions, outputs, and observable reasoning signals can be checked against what actually happened β separate from what any system reports. The signal taxonomy is designed for any observable AI system; reasoning summaries and model-internal telemetry activate as providers expose them.
First surface: Coding agents (Claude Code, Codex, opencode) β the first and most deeply instrumented environment.
Current boundary: Evidence collection today covers execution traces; model-internal reasoning is available only when a provider exposes it and is never fabricated.
source Β· architecture invariants External signals: Reasoning trace integrity β OpenAI Β· Agent monitorability β METR
Every AI agent action happens under some authority β but who granted it, under what policy, and what actually occurred is rarely observable. Agent Assembly is governance infrastructure: policy enforcement on every agent action, a tamper-evident audit trail, and independently deployable enforcement mechanisms each with an explicit capability boundary. An absent mechanism is reported absent, never assumed present.
First surface: AI developer tools (Claude Code focus), with an evidence-backed protection lifecycle from detection through host enforcement.
Current boundary: RC series β API not stable; eBPF terminates processes after the fact, not before.
source Β· limitations and known bypasses External signals: Agent Control Standard β OWASP Β· Agentic misalignment β Anthropic
Protected compute β hardware accelerators and other high-value resources β should not be reachable by default. Eltanin enforces that default-deny posture: a workload must hold a scoped, expiring authorization or the resource stays closed. Monitoring after the fact does not satisfy this requirement.
First surface: Linux/NVIDIA as the hard device-enforcement proof target; Apple Silicon/Metal as a distinct functional evidence class.
Current boundary: Enforcement crates not yet merged; device-level proof not yet established on hardware.
source Β· security model Β· North Star External signal: Cloud compute abuse β Microsoft
Disk cleanup that defers to AI recommendations without a deterministic policy gate is dangerous. Glomeris discovers reclaimable developer storage on macOS, explains why each candidate is or isn't safe to remove, and executes only policy-approved typed actions β re-measuring actual freed bytes. An optional LLM may rank candidates; it cannot invent or authorize a deletion.
Current boundary: macOS-only experimental MVP; Homebrew and Docker cleanup have architectural constraints.
source Β· safety model Β· known limitations External signals: Excessive Agency β OWASP Β· Agentic misalignment β Anthropic
Faster AI-assisted implementation makes it easier to efficiently produce work that should never have existed. Requirement Zero forces a requirement to justify its existence using observable evidence β who actually needs it, what breaks without it β before implementation begins. Codebase Zero applies the same challenge to complexity that already exists.
Delivered as: Agent Skills for AI coding agent workflows.
Current boundary: Evaluation on six cases shows modest accuracy improvement; downstream cost savings are unmeasured.
source Β· evaluation results External signal: Capability β judgment β METR
Evidence over claims. Observations are recorded before interpretation runs. A missing signal is never treated as a pass.
Failure paths are part of the design. What happens when enforcement is absent, evidence is missing, or authorization is refused matters as much as the happy path.
Security boundaries stay explicit. Compatibility is not protection. An absent mechanism is reported as absent.
Negative results stay visible. An evaluation superseded because its confound inflated the numbers is published with the corrected, less favorable results.
- Can AI behavior be independently verified without modifying the system being observed? Coding agents are the current test; the harder question is whether it holds for any observable AI system.
- Which enforcement point β in-process SDK, proxy, or kernel-level eBPF β genuinely prevents unauthorized agent action, and what does each one actually stop versus observe?
- How do you prove "no protected compute without authorization" on real hardware rather than in a simulator?
PyFake-API-Server Β· π οΈ Maintenance paused Β· v0.4.2 Β· PyPI
Configurable mock HTTP server; define API responses in YAML or import from an OpenAPI spec.
multirunnable Β· ποΈ Legacy Β· v0.17.0 Β· PyPI
Unified Python API across multiprocessing, threading, gevent, and asyncio.
@horonomy β Fornax Β· Eltanin
@ai-agent-assembly β Agent Assembly
Software Engineer Β· LINE corp. Β· LinkedIn



