Pillar 02 Verifiable AI
The layer that ZK-commits the process of AI judgment.
290 staff at Japan's Social Insurance Medical Fee Payment Fund met a "one second on screen" target with an auto-advance tool
the recorded achievement rate was reported higher than reality
"FaceHugger" in Hugging Face Diffusers: loading a model ran arbitrary code
the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)
Medicare's WISeR AI prior authorization: denials were issued, but nothing records which patient file each determination was checked against
Since January 2026, US Medicare has piloted WISeR, an AI-assisted prior-authorization model, across six states. On June 23, 2026, KFF Health…
A fake OpenAI model hit #1 trending on Hugging Face
publisher provenance never verified before execution
AI applicant-screening discrimination suit against Workday: the adverse action was taken, but whether the decision was independently verified and authorized was never recorded
Mobley v. Workday
Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands
Tenet Threat Labs disclosed a new attack it named "Agentjacking" that makes AI coding agents (Claude Code, Cursor, Codex) run an attacker's …
BioShocking: convince an AI browser "it's a game" and it drops its guardrails and hands over credentials
The security firm LayerX disclosed a manipulation technique against agentic AI browsers that it named BioShocking. When an attacker's web pa…
A 93% Facial-Recognition 'Match' Led Straight to Arrest Without Independent Verification (Robert Dillon Wrongful Arrest Suit)
a probabilistic FRT match that was never independently corroborated or authorized before the coercive act of arrest (ACLU suit)
TennCare Connect: an automated eligibility system illegally cut thousands off Medicaid
eligibility decisions not independently verified before the adverse action of termination (federal court)
Waymo: the robotaxi drove past a stopped school bus
a driving decision not independently verified before a safety-critical action
Hyundai: driver-assist AI braked on a threat that wasn't there
an AI decision overriding the driver, not independently verified before acting (NHTSA)
Both Sides Cited Cases That Never Existed
AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)
Internal Data Exfiltrated Without Verifying the Instruction's Origin
EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)
AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)
On OpenClaw, Varonis tested an email-reading AI agent and found it would forward mock credentials and customer data out of the organization …
Tesla Robotaxi Crash Records
Control Attribution and Narrative Provenance Left Self-Reported
Self-Reported Autonomous-Driving Safety, Unverified
Tesla FSD Crash Data and Safety-Stat Methodology
Invisible Unicode Instruction Injection
The Gap Between Human-Read and Model-Read Input
The Robert Williams Wrongful Arrest
When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification
McKinsey Lilli's Writable System Prompts
The Layer Governing the AI's Behavior Had No Integrity or Provenance
The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack
Weaponizing a Repository's CLAUDE.md to Hijack the Defending AI Agent's Instructions
Noroboto: embedded "lying fonts" made AI's document review read different text
input-integrity forgery