PF Systems

UK sovereign AI governance software

British-developed · Model-agnostic
PF SystemsOperational authority for agentic AIStart with one workflow
Back

Qualified synthetic demonstrator

Can an AI change the action after authority is given?

The important control is not whether an agent can reach a tool. It is whether the exact action presented for execution still matches the authority that was evaluated.

Proposed demonstrator design. It is not a customer deployment, security certification or claim of production readiness.
See PF Systems govern one AI actionSynthetic example · no live systems
AI AGENT

REQUESTS AN ACTION

Quarantine DEV-481

Proposed cyber response
PF SYSTEMS

CHECKING AUTHORITY

PF Kernel decides

GOVERNED RESULT

WAITING FOR DECISION

No action proceeds before a decision.

Allow · Deny · Modify · Step Up · Stop
PF Memory supplies governed contextPF Kernel decidesPF Core preserves linked evidence

An AI agent asks to quarantine endpoint DEV-481.

The proposed governed path

Every protected action must pass through the same authority boundary.

If an alternative credential or execution route remains available, PF Systems may still provide advice, visibility or evidence—but cannot claim enforceable control over that route.

01 · Existing AIProposes

Provides its identity, tool, target, parameters, purpose and relevant context as one exact proposed action.

02 · Governed inputsInform

PF Memory supplies governed context. External systems provide risk evidence. PF SecureAuth may provide approval or delegated-authority proof.

03 · PF KernelDecides

Returns Allow, Deny, Modify, Step Up or Stop the Line. No other PF component acquires this authority.

04 · ClientBridgeConnects

Maps and routes the governed request without deciding, proving or remembering on behalf of the PF OS triad.

05 · Protected executorEnforces

Requires current authority for the exact effective action and reports whether execution was accepted or rejected.

06 · PF CoreProves

Preserves linked evidence and lineage so the governed evaluation can be traced, checked and deterministically replayed.

PF Trace can display the evidence it receives. It does not manufacture evidence or make the decision.

Falsifiable proof conditions

What the demonstrator must prove.

These are acceptance tests for the declared synthetic topology—not claims about every external system or future production deployment.

  1. 01
    Valid identity, invalid authority

    An authenticated agent presents authority that is expired, revoked or outside scope.

  2. 02
    Approved action, changed target

    The agent substitutes a material field after authority is issued. The earlier authority must not transfer.

  3. 03
    Elevated external risk

    A simulated compromise signal changes the evidence available to Kernel for a new evaluation.

  4. 04
    Direct execution attempt

    The agent knows the tool interface but cannot complete a protected action without current authority.

  5. 05
    Complete reconstruction

    The proposal, context, authority, decision, effective action and executor-reported result can be examined together.

  6. 06
    Replay attempt

    Previously valid authority is reused outside its permitted conditions and must be rejected.

  7. 07
    Degraded evidence source

    Required security evidence becomes stale or unavailable and the declared fail-safe policy is exercised.

Evidence boundary

Prove the configured path before making the wider claim.

PF Core can preserve executor-reported evidence; it does not independently witness or certify the external event. Deterministic replay applies to the governed evaluation, not the underlying probabilistic AI.

Proof Harness can qualify the evidence observed in this synthetic environment without certifying the system. A controlled shadow pilot with no live action remains the appropriate next gate. Production use is a separate decision.