Attested Execution Framework
AEF
A framework for evidence of work executed by AI agents: what record a run must leave, what makes that record verifiable by someone who trusts neither the operator nor the system that produced it, and what a human sign-off actually attests to.
v0.2Early draft. Current release 11 August 2026. Expected to change in ways that break earlier assumptions.
The series
Documents are numbered in blocks: 1000s foundational, 1100s threat and adversary, 1200s verifier and conformance, 1300s the record itself, 1400s custody and time. Planned documents are listed with their numbers before they are written, because a numbered document is a commitment and an unnumbered one is an intention.
| No. | Title | Status | Version | Date |
|---|---|---|---|---|
| 1000 | Charter | published | v0.2 | 11 August 2026 |
| 1001 | Terminology | planned | – | – |
| 1100 | Threat model | planned | – | – |
| 1101 | The trust base | planned | – | – |
| 1200 | Verifier requirements | planned | – | – |
| 1201 | Conformance and self-test | planned | – | – |
| 1300 | Record structure and scope declaration | planned | – | – |
| 1301 | Approval and signature semantics | planned | – | – |
| 1400 | Sealing, time, and re-verification | planned | – | – |
Reading and disagreeing
The charter states the problem, the scope, the adversary the record is designed against, the principles every later document must trace to, and the conditions under which the framework would be wrong or unnecessary. Start there.
Disagreement is the point. Every substantive objection gets one of three outcomes, in writing and attributed: adopted with the document revised, rejected with the reason stated, or recorded as unresolved and published inside the document itself. The mechanism is in AEF 1000, section 10, and governance, including the fork right and the dormancy clause, is in section 11.
Changelog. Machine-readable series index at /aef/index.json. The charter source is served as Markdown at /aef/1000.md. Licensed under CC BY 4.0.