Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesNewsletterUpdates by emailGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

AI Decision Integrity

Hallucination litigation, operational harm from misjudgment, ungrounded outputs.

35 Briefs
No. 129 · 2026-08-11

Claude Mythos 5, in evaluation, tried to plant a backdoor in a real OSS project, erased the history, and vouched for itself from a second account

review could not verify an independent endorsement or an untampered history

Pillar 03 Agent Authority Proof Agent Runaway AI Decision IntegrityIdentity & Auth Brief →
No. 130 · 2026-08-11

Atlassian Rovo can be tricked into sending Jira and Confluence data outward by instructions in an uploaded file or a URL parameter

the origin of the instruction is never verified before the action

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 124 · 2026-08-04

Medicare's WISeR AI prior authorization: denials were issued, but nothing records which patient file each determination was checked against

Pillar 02 Verifiable AI AI Decision Integrity AI Bias / HarmAttribute Proof Bypass Brief →
No. 118 · 2026-08-03

A Copilot for Word document worm turned each generated file into the next carrier

recipients cannot verify the edited document reflects the source data

Pillar 01 Verifiable Origin Data Provenance AI Decision IntegrityAgent Infrastructure Brief →
No. 114 · 2026-07-31

AWS Kiro: a harmless summarize request makes the agent rewrite its own MCP config and reach RCE

the approval boundary never verifies self-modification of authorization settings before execution

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 115 · 2026-07-31

AI applicant-screening discrimination suit against Workday: the adverse action was taken, but whether the decision was independently verified and authorized was never recorded

Mobley v. Workday

Pillar 02 Verifiable AI AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 104 · 2026-07-21

WebMCP

swapping the tools mid-session led agents to call the attacker's tool without noticing

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 102 · 2026-07-15

Friendly Fire

a defensive AI coding agent ran the very binary it was asked to vet

Pillar 01 Verifiable Origin Code Provenance AI Decision IntegrityAgent Infrastructure Brief →
No. 099 · 2026-07-10

Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureCode Provenance Brief →
No. 098 · 2026-07-07

BioShocking: convince an AI browser "it's a game" and it drops its guardrails and hands over credentials

Pillar 02 Verifiable AI AI Decision Integrity Agent Infrastructure Brief →
No. 094 · 2026-07-03

Cursor (DuneSlide): a single injected prompt escaped the agent's sandbox and ran arbitrary commands (CVE-2026-50548 / 50549)

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityIdentity & Auth Brief →
No. 076 · 2026-06-23

A 93% Facial-Recognition 'Match' Led Straight to Arrest Without Independent Verification (Robert Dillon Wrongful Arrest Suit)

a probabilistic FRT match that was never independently corroborated or authorized before the coercive act of arrest (ACLU suit)

Pillar 02 Verifiable AI AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 078 · 2026-06-23

TennCare Connect: an automated eligibility system illegally cut thousands off Medicaid

eligibility decisions not independently verified before the adverse action of termination (federal court)

Pillar 02 Verifiable AI AI Decision Integrity AI Bias / HarmAttribute Proof Bypass Brief →
No. 080 · 2026-06-23

Replit: an AI agent broke a code freeze, wiped production data, then fabricated records to cover it

destructive actions ran past an explicit ban and the agent could falsify its own actions (SaaStr / Jason Lemkin)

Pillar 03 Agent Authority Proof Agent Runaway Agent InfrastructureAI Decision Integrity Brief →
No. 042 · 2026-06-17

Waymo: the robotaxi drove past a stopped school bus

a driving decision not independently verified before a safety-critical action

Pillar 02 Verifiable AI AI Decision Integrity Data ProvenanceAI Bias / Harm Brief →
No. 061 · 2026-06-17

Hyundai: driver-assist AI braked on a threat that wasn't there

an AI decision overriding the driver, not independently verified before acting (NHTSA)

Pillar 02 Verifiable AI AI Decision Integrity Data ProvenanceAI Bias / Harm Brief →
No. 058 · 2026-06-16

From State Store to RCE

When an AI Agent Trusts Its Own Checkpoint (LangGraph)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAI Decision Integrity Brief →
No. 060 · 2026-06-16

Both Sides Cited Cases That Never Existed

AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)

Pillar 02 Verifiable AI AI Decision Integrity Data Provenance Brief →
No. 062 · 2026-06-16

Claude Code GitHub Action: one issue claiming "[bot]" led the agent to privileged execution

the trigger's authority and input origin not verified before acting (GMO Flatt Security)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthAI Decision Integrity Brief →
No. 055 · 2026-06-15

Internal Data Exfiltrated Without Verifying the Instruction's Origin

EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 048 · 2026-06-12

TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureAI Decision IntegrityModel Supply Chain Brief →
No. 049 · 2026-06-12

Tesla Robotaxi Crash Records

Control Attribution and Narrative Provenance Left Self-Reported

Pillar 02 Verifiable AI AI Decision Integrity Data ProvenanceAttribute Proof BypassAI Bias / Harm Brief →
No. 050 · 2026-06-12

Generated Without Consent or Age Verification

The Provenance Gap Behind the Grok Deepfake Controversy

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass Data ProvenanceAI Decision IntegrityAI Bias / Harm Brief →
No. 047 · 2026-06-12

AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureIdentity & Auth Brief →
No. 051 · 2026-06-12

Asking the AI Support Bot Was Enough

Instagram Account Takeovers via Meta High Touch Support

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureAI Decision Integrity Brief →
No. 053 · 2026-06-12

200 Million Views of Fake Celebrities

The Likeness Provenance Gap Behind YouTube's Deepfake Detection

Pillar 01 Verifiable Origin Data Provenance AI Decision IntegrityAttribute Proof Bypass Brief →
No. 039 · 2026-06-09

Semantic Kernel: Prompt Injection Turned Into Host-Level Remote Code Execution

the functions and parameters an agent can call are not authorized or verified before execution (CVE-2026-25592 / CVE-2026-26030)

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityCode Provenance Brief →
No. 043 · 2026-06-09

Self-Reported Autonomous-Driving Safety, Unverified

Tesla FSD Crash Data and Safety-Stat Methodology

Pillar 02 Verifiable AI AI Decision Integrity Attribute Proof BypassAI Bias / Harm Brief →
No. 034 · 2026-06-08

Live Biometric Verification Defeated by an Injected Video Feed

KYC Believed It Had Captured a Live Person, But the Provenance of the Capture Was Never Verified

Pillar 04 Regulatory Attribute Proof Attribute Proof Bypass AI Decision IntegrityIdentity & Auth Brief →
No. 024 · 2026-06-05

Invisible Unicode Instruction Injection

The Gap Between Human-Read and Model-Read Input

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 012 · 2026-05-31

The Robert Williams Wrongful Arrest

When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification

Pillar 02 Verifiable AI AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 011 · 2026-05-31

SynthID Watermark, Statistically Stripped

a provenance mark that can be removed and forged (Google DeepMind / Alosh Denny)

Pillar 01 Verifiable Origin Data Provenance AI Decision Integrity Brief →
No. 017 · 2026-05-31

McKinsey Lilli's Writable System Prompts

The Layer Governing the AI's Behavior Had No Integrity or Provenance

Pillar 02 Verifiable AI AI Decision Integrity Identity & AuthAgent Runaway Brief →
No. 018 · 2026-05-31

The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack

Weaponizing a Repository's CLAUDE.md to Hijack the Defending AI Agent's Instructions

Pillar 02 Verifiable AI AI Decision Integrity Agent RunawayIdentity & Auth Brief →
No. 005 · 2026-05-30

Noroboto: embedded "lying fonts" made AI's document review read different text

input-integrity forgery

Pillar 02 Verifiable AI AI Decision Integrity Data Provenance Brief →