A2HAI2Human
AI2HUMAN PROTOCOL · TECHNICAL WHITEPAPER · AUGUST 2026

Verification infrastructure for agentic outcomes.

AI2Human compiles ambiguous requests into proof policies, evaluates judgment-based evidence through layered verification, escalates uncertainty, and emits auditable receipts that can safely trigger settlement.

Agents create proposed actions. Verification turns them into accountable outcomes.
AI2Human proof compilation, verification, receipt and settlement architecture
Abstract

A model score is not a verification protocol.

Once an agent workflow depends on screenshots, photographs, documents, identity-bound actions, or contextual claims, completion can no longer be inferred from plausible output alone. AI2Human treats this boundary as a protocol problem: specify what would count as proof, bind evidence to context, combine deterministic and probabilistic checks, expose uncertainty, and separate semantic judgment from economic settlement.

RequestProof policyEvidenceDecision receiptSettlement
01 · Problem

The open world has three epistemic zones.

Deterministic state

Transactions, signatures, API responses, and database invariants can be checked directly.

Judgment-based evidence

Evidence requires task-conditioned interpretation, integrity signals, and explicit sufficiency rules.

Unobservable reality

When evidence cannot safely resolve the claim, a responsible verifier must abstain.

Generic LLM judges collapse all three into one prompt and one answer. The result is difficult to reproduce, calibrate, audit, or safely connect to payment.

02 · Protocol

Compile first. Verify second. Settle last.

01RequestIntent + constraints
02CompileVersioned proof policy
03ProveBound evidence bundle
04VerifyChecks + judgments
05AdjudicateSelective escalation
06SettleReceipt-gated transition
AI2Human selective verification decision funnel
Automation narrows toward defensible decisions; uncertainty exits to resubmission or human adjudication.
03 · Formal objects

A decision is a versioned function of policy and evidence.

Q = (intent, constraints, context, deadline, settlement_policy)P = C(Q) = (requirements, rules, capture, privacy, thresholds, version)E = (artifacts, claims, time, location?, identity?, integrity_commitment)O = D(P,E) ∪ F(E) ∪ M(P,E)d = Π(P,O,H) ∈ {pass, resubmit, manual_review, reject}R = Hash(Q,P,E_commitment,O,H?,d,versions,timestamp)

The Proof Compiler is not a prose generator. It creates the ex-ante verification contract. Every required artifact maps to a rule; every decision traces to a versioned policy.

04 · Decision system

Selective automation is the safety mechanism.

01

Deterministic validation

Schema, required artifacts, deadlines, task binding, identity constraints, commitments, and uniqueness.

02

Evidence forensics

Hashes, container structure, EXIF/XMP, temporal confidence, editing signals, and batch consistency.

03

Semantic verification

Policy-specific multimodal judgments with structured reasons, confidence, and model provenance.

04

Selective escalation

Conflicts, integrity risk, provider degradation, and low confidence become human review—not forced verdicts.

Editing metadata is a risk signal—not proof of fraud. C2PA/JUMBF presence is detected, but signatures are not currently verified. AI2Human does not claim authorship detection.
05 · Trust model

The protocol assumes every participant can fail.

ThreatCurrent controlResidual risk
ReplayTask binding, freshness, commitments, uniquenessUncatalogued visually similar evidence
ModificationForensic signals + semantic reviewSophisticated undetectable edits
Model failureTyped outputs, ensemble, abstentionCorrelated errors
Provider outageExplicit degradation + 0.85 thresholdHigher review latency
Double paymentUnique tx hash + idempotency keyExternal rail configuration
Privacy excessMinimal schemas + scoped receiptsVoluntary over-submission

Blockchain settlement makes transfers auditable; it does not prove semantic truth. Multimodal models provide judgments; they do not become trusted oracles.

06 · Portable output

The receipt—not the campaign page—is the product.

VERIFICATION RECEIPTPASS
Policy
proof-policy/v1 · immutable requirements
Evidence
SHA-256 commitment · scoped artifact references
Observations
deterministic + forensic + multimodal reasons
Decision provenance
models, thresholds, conflicts, escalation state
Settlement
eligible only after pass + idempotency validation

A third-party agent should be able to consume the verification result without entering AI2Human's website or trusting an unexplained private status flag.

07 · Compounding asset

Adjudicated cases become a controlled learning system.

Adjudicated verification corpus and controlled learning loop
Production outcomes do not rewrite rules directly. Changes pass offline evaluation, shadow deployment, canary release, monitoring, and rollback.
task class policy version evidence features verifier votes human rationale failure codes settlement outcome
08 · Scientific evaluation

Volume is not reliability.

Decision risk

False accepts, false rejects, calibration, and risk-coverage curves by task class.

Operational cost

Escalation, p50/p95 latency, model cost, reviewer minutes, and protected-value ratio.

Accountability

Receipt completeness, audit reconstruction, reason agreement, and privacy burden.

Research program

The academic study compares a generic LLM judge with proof-policy, forensic, ensemble, and selective-verification variants. Independent raters and component ablations are mandatory before top-tier claims.

09 · Claim boundary

Implemented systems and research ambition are not the same thing.

Implemented

  • Proof Compiler with deterministic fallback
  • Structured evidence and integrity commitments
  • Image metadata and container forensics
  • Weighted multimodal review and escalation
  • Payment idempotency and Base settlement

In development

  • Stable standalone Verification API
  • Privacy-scoped public receipts
  • Reusable proof-policy registry
  • Reviewer calibration metrics
  • Expanded agent integrations

Research

  • Task-specific reputation
  • Memory-aware verifier routing
  • Federated verification providers
  • Portable receipt standards
  • Domain-specific compliance policies
NON-GOALAI2Human is not a universal truth oracle. It is bounded infrastructure for explicit proof, visible uncertainty, auditable decisions, and conditional settlement.