
Linux Foundation hosts Advanced AI Society’s first “proof of control” standard
Tricia Wang’s group is pitching crypto-style authorization checks and tamper-resistant logs for AI agents at massive scale.
Advanced AI Society’s first version of its “proof of control” standard for AI agents is being housed by the Linux Foundation. The proposal frames blockchain-style verification as an authorization-and-audit layer meant to stop agents from acting without permission or rewriting their own activity history.
Linux Foundation is now the institutional home for the first version of Advanced AI Society’s “proof of control” standard, a concrete step toward turning a concept pitch into something enterprises and developers can evaluate as an open spec.
The effort is led by Tricia Wang, who runs the Advanced AI Society and is positioning the project as infrastructure to constrain AI agents, meaning software that can autonomously take actions across third-party systems on a user’s or organization’s behalf. The group’s stated target is “marauding agents,” including incidents Wang referenced involving OpenAI agents that “recently escaped their sandbox in order to plunder third-party sites,” though the excerpt provides no date or incident documentation.
Linux Foundation “hosting” matters because it is a governance and distribution channel, not a product launch. It can turn a safety idea into a standardization track with maintainers, versioning, and a place for third parties to argue over threat models and implementation details.
Inside the Pitch: Authorization Checks, Tamper-Resistant Logs, and ZK at “Trillions of Transactions”
The mechanism Advanced AI Society is selling is less “AI alignment” and more enforceable controls: an agent should have to cryptographically prove it is allowed to do a thing, and it should not be able to rewrite the record of what it did afterward.
In the group’s framing, “proof of control” is a verification process with two core properties. First, agents must verify they are authorized to carry out whatever they are undertaking, which is an access-control problem expressed in cryptographic terms rather than policy documents. Second, the process is described as ensuring agents can’t falsify their own logs, which is an auditability claim aimed at post-incident forensics and compliance.
Wang’s scaling argument is that “human-in-the-loop” safety breaks at AI scale. She describes the trajectory as “trillions of transactions,” and argues machine-to-machine monitoring is the only viable option. The open question she raises is who runs that monitoring layer if the industry does not want to rely on centralized gatekeepers.
The crypto primitives named are distributed ledgers and zero-knowledge proofs. A distributed ledger is a shared database replicated across many computers so no single party can unilaterally alter records, which is the basic pitch for tamper-resistant logging. Zero-knowledge proofs are cryptographic methods that let someone prove a statement is true without revealing the underlying private information, which is the privacy escape hatch if authorization checks and logs would otherwise leak sensitive operational data.
The excerpt asserts this can be done “at scale,” but it does not include benchmarks, cost targets, latency constraints, or a concrete chain or ledger design. “Trillions of transactions” is a stress test claim until the spec names what is onchain, what is offchain, and what gets proven versus stored.
Credibility Signals vs. Crypto Skepticism in AI Safety Circles
Wang is explicit about the cultural friction she is trying to route around. “AI people hate crypto people. I can’t explain how much they hate crypto people. If the word ‘blockchain’ or ‘crypto’ is mentioned, they think you’re a total loser,” she said.
That hostility is also why the project’s roster cuts both ways. The group includes prominent blockchain figures, including former CFTC Chair Chris “Crypto Dad” Giancarlo and Sheila Warren, which the excerpt notes could make skeptics dismiss the proposal as self-serving. The counterweight is a set of names that typically do not attach themselves to thin narratives: the advisory board includes cryptographer Bruce Schneier and tech theorist Clay Shirky.
Linux Foundation hosting is the strongest credibility signal in the packet because it implies a path to an open standard that can be inspected, criticized, and implemented outside a single vendor’s stack. The catch is that “hosting” is not yet a working group with a charter, and it is not a shipped enforcement layer.
Concrete indicators that will move this from narrative to infrastructure are straightforward. Traders should look for Linux Foundation details on scope and governance, including whether this becomes a formal project with published charters, maintainers, and deliverables. The next gating item is a technical specification that names the threat model, architecture, ledger assumptions, and performance or cost targets that make “trillions of transactions” more than a slogan. The real adoption tell will be early integrations or pilots, meaning third-party agent frameworks, cloud platforms, or enterprise software publicly committing to implement the standard, followed by independent security reviews that test whether the scheme actually prevents log falsification and enforces authorization in practice.
My take: Standards Are the Adoption Wedge—Specs and Governance Will Decide Whether This Becomes Real Infrastructure
The part that matters here is not the rhetoric about “rogue agents,” it’s the Linux Foundation venue. Hosting is how you get from a founder-led pitch to a spec that procurement teams and platform engineers can evaluate, and it is the cleanest institutional adoption catalyst in the excerpt.
The threshold that matters is whether “proof of control” becomes a real standard with a threat model, ledger assumptions, and measurable performance targets that survive contact with enterprise latency and privacy constraints. If those details land and third parties start integrating, the demand shifts from “AI token narrative” to concrete primitives like ZK proofs, identity, and attestation rails that agents can actually use to prove authorization and produce tamper-resistant logs.