Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Pillar archive
Lemma Critical Brief · Pillar archive

Pillar 02 Verifiable AI

The layer that ZK-commits the process of AI judgment.

21 Briefs
No. 137 · 2026-08-28

290 staff at Japan's Social Insurance Medical Fee Payment Fund met a "one second on screen" target with an auto-advance tool

the recorded achievement rate was reported higher than reality

AI Decision Integrity Identity & Auth Brief →
No. 121 · 2026-08-04

"FaceHugger" in Hugging Face Diffusers: loading a model ran arbitrary code

the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)

Model Supply Chain Code ProvenanceAgent Infrastructure Brief →
No. 124 · 2026-08-04

Medicare's WISeR AI prior authorization: denials were issued, but nothing records which patient file each determination was checked against

Since January 2026, US Medicare has piloted WISeR, an AI-assisted prior-authorization model, across six states. On June 23, 2026, KFF Health…

AI Decision Integrity AI Bias / HarmAttribute Proof Bypass Brief →
No. 116 · 2026-07-31

A fake OpenAI model hit #1 trending on Hugging Face

publisher provenance never verified before execution

Model Supply Chain Code ProvenanceIdentity & Auth Brief →
No. 115 · 2026-07-31

AI applicant-screening discrimination suit against Workday: the adverse action was taken, but whether the decision was independently verified and authorized was never recorded

Mobley v. Workday

AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 099 · 2026-07-10

Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands

Tenet Threat Labs disclosed a new attack it named "Agentjacking" that makes AI coding agents (Claude Code, Cursor, Codex) run an attacker's …

AI Decision Integrity Agent InfrastructureCode Provenance Brief →
No. 098 · 2026-07-07

BioShocking: convince an AI browser "it's a game" and it drops its guardrails and hands over credentials

The security firm LayerX disclosed a manipulation technique against agentic AI browsers that it named BioShocking. When an attacker's web pa…

AI Decision Integrity Agent Infrastructure Brief →
No. 076 · 2026-06-23

A 93% Facial-Recognition 'Match' Led Straight to Arrest Without Independent Verification (Robert Dillon Wrongful Arrest Suit)

a probabilistic FRT match that was never independently corroborated or authorized before the coercive act of arrest (ACLU suit)

AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 078 · 2026-06-23

TennCare Connect: an automated eligibility system illegally cut thousands off Medicaid

eligibility decisions not independently verified before the adverse action of termination (federal court)

AI Decision Integrity AI Bias / HarmAttribute Proof Bypass Brief →
No. 042 · 2026-06-17

Waymo: the robotaxi drove past a stopped school bus

a driving decision not independently verified before a safety-critical action

AI Decision Integrity Data ProvenanceAI Bias / Harm Brief →
No. 061 · 2026-06-17

Hyundai: driver-assist AI braked on a threat that wasn't there

an AI decision overriding the driver, not independently verified before acting (NHTSA)

AI Decision Integrity Data ProvenanceAI Bias / Harm Brief →
No. 060 · 2026-06-16

Both Sides Cited Cases That Never Existed

AI-Hallucinated Precedent and Rule 11 Sanctions (N.D. Miss.)

AI Decision Integrity Data Provenance Brief →
No. 055 · 2026-06-15

Internal Data Exfiltrated Without Verifying the Instruction's Origin

EchoLeak in Microsoft 365 Copilot (CVE-2025-32711)

AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 047 · 2026-06-12

AI Agent Forwarded Credentials Before Verifying the Sender (OpenClaw / Varonis)

On OpenClaw, Varonis tested an email-reading AI agent and found it would forward mock credentials and customer data out of the organization …

AI Decision Integrity Agent InfrastructureIdentity & Auth Brief →
No. 049 · 2026-06-12

Tesla Robotaxi Crash Records

Control Attribution and Narrative Provenance Left Self-Reported

AI Decision Integrity Data ProvenanceAttribute Proof BypassAI Bias / Harm Brief →
No. 043 · 2026-06-09

Self-Reported Autonomous-Driving Safety, Unverified

Tesla FSD Crash Data and Safety-Stat Methodology

AI Decision Integrity Attribute Proof BypassAI Bias / Harm Brief →
No. 024 · 2026-06-05

Invisible Unicode Instruction Injection

The Gap Between Human-Read and Model-Read Input

AI Decision Integrity Agent InfrastructureData Provenance Brief →
No. 012 · 2026-05-31

The Robert Williams Wrongful Arrest

When an AI Face-Match Drove a Government Enforcement Action Without Independent Verification

AI Bias / Harm AI Decision IntegrityIdentity & Auth Brief →
No. 017 · 2026-05-31

McKinsey Lilli's Writable System Prompts

The Layer Governing the AI's Behavior Had No Integrity or Provenance

AI Decision Integrity Identity & AuthAgent Runaway Brief →
No. 018 · 2026-05-31

The hackerbot-claw Campaign's First Recorded AI-vs-AI Attack

Weaponizing a Repository's CLAUDE.md to Hijack the Defending AI Agent's Instructions

AI Decision Integrity Agent RunawayIdentity & Auth Brief →
No. 005 · 2026-05-30

Noroboto: embedded "lying fonts" made AI's document review read different text

input-integrity forgery

AI Decision Integrity Data Provenance Brief →