CAIN-42 evidence library
CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric
Evidence bundle for evolution E35: 7 claims, 799 of 799 invariants held, 3544 attack scenarios held.
Last reviewed 2026-10-01
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Product lines built here
- CAIN Agent Lab — A safe lab to try agent ideas before they touch anything real.
TESTED library - CAIN Governability Index — A score for how governable an AI system is.
TESTED library - CAIN Governance API — One API for every governance question about an agent.
TESTED library - CAIN Governance Cloud — Governance as a managed cloud service.
PROPOSED/NOT DEPLOYED - CAIN Governance SDK — Libraries for building governance into your own products.
TESTED library - CAIN Intelligence — Insights across all your agents' governance data.
TESTED library - CAIN Marketplace — A marketplace for governed agent services.
TESTED library - CAIN Policy Compiler — Write a rule in plain terms and get an enforceable policy.
TESTED library - CAIN Proof Exchange — Swap proofs between companies in a standard format.
TESTED library - CAIN Red Team — Continuous red-teaming of your whole agent setup.
TESTED library - CAIN Simulator — Simulate agents and rules together to see what would happen.
TESTED library
Claims (7)
| Claim | Level |
|---|---|
| C42-E35-INTELLIGENCE-NOT-AUTHORITY: the whole intelligence fabric refuses to be authority; every component records grants_authority=false and a recommendation is only a recommendation | TESTED |
| C42-E35-EPISTEMIC: OBSERVED, INFERRED, PREDICTED, SIMULATED, COUNTERFACTUAL and UNKNOWN are never merged; a counterfactual is never an observed fact | TESTED |
| C42-E35-REVIEW: a learned recommendation becomes a deployed control only after a deterministic review and a canary; the review result still passes the E33 kernel and its E8 binding | TESTED |
| C42-E35-SELFHEAL: self-healing, the red team, degradation and self-governance can never expand authority; degradation only reduces it | TESTED |
| C42-E35-BENCH: 3544 of 3544 scenarios across 68 categories held; 799 of 799 invariants; mutation 15 of 15 | TESTED |
| C42-E35-CLEANROOM: an independent verifier that imports none of CAIN re-derives the E35 invariants and rejects every crafted forgery | TESTED |
| C42-E35-HONEST-SCOPE: the intelligence layer is NOT in the trusted root; the governance cloud is NOT DEPLOYED; predictions are modelled over synthetic features and are not calibrated against real incidents | TESTED |
Invariants: 799 of 799 held
Rules the code must never break, each checked across many scenarios. See all 799 on one page.
| Niche | Held |
|---|---|
| Benchmarks, coverage & performance | 202 of 202 |
| Policy, law & governance | 93 of 93 |
| Prediction, world models & simulation | 87 of 87 |
| Autonomy, control loops & recovery | 86 of 86 |
| Transactions, markets & economics | 79 of 79 |
| Tools, MCP, protocols & adapters | 63 of 63 |
| Core guarantees | 54 of 54 |
| Attacks, threats & containment | 51 of 51 |
| Supply chain, registry & lifecycle | 29 of 29 |
| Identity, authority & delegation | 21 of 21 |
| Memory, data & privacy | 15 of 15 |
| Evidence, receipts & proofs | 15 of 15 |
| Consensus & distributed systems | 2 of 2 |
| Trust & reputation | 2 of 2 |
Attacks tried
| Category | Held |
|---|---|
| action_graph | 24 of 24 |
| adversarial_generation | 33 of 33 |
| autonomy_gradient | 33 of 33 |
| benchmark | 18 of 18 |
| benchmark_v2 | 16 of 16 |
| blue_team | 21 of 21 |
| budget_learner | 30 of 30 |
| calibration | 40 of 40 |
| calibration_engine | 14 of 14 |
| canary | 24 of 24 |
| collusion | 16 of 16 |
| communication | 36 of 36 |
| compiler | 16 of 16 |
| computer_use | 180 of 180 |
| consequence_graph | 16 of 16 |
| control_optimizer | 16 of 16 |
| counterfactual | 189 of 189 |
| degradation | 24 of 24 |
| deployment | 49 of 49 |
| economics | 20 of 20 |
| economy | 32 of 32 |
| environment_query | 68 of 68 |
| epistemic | 228 of 228 |
| evaluation | 39 of 39 |
| evolution | 34 of 34 |
| fabric | 32 of 32 |
| failure_predictor | 42 of 42 |
| failure_to_product | 36 of 36 |
| goal_integrity | 32 of 32 |
| harness | 53 of 53 |
| integrity | 33 of 33 |
| intent_compiler | 49 of 49 |
| ip | 32 of 32 |
| knowledge | 151 of 151 |
| lab | 20 of 20 |
| labor | 20 of 20 |
| latency | 27 of 27 |
| law | 390 of 390 |
| learner | 60 of 60 |
| loop | 40 of 40 |
| marketplace | 36 of 36 |
| memory | 70 of 70 |
| moat | 80 of 80 |
| obligation | 177 of 177 |
| observation | 57 of 57 |
| plan_check_act | 33 of 33 |
| policy_conflict | 45 of 45 |
| policy_optimizer | 16 of 16 |
| prediction | 44 of 44 |
| profile | 26 of 26 |
| r2e | 33 of 33 |
| radar | 80 of 80 |
| recommendation | 32 of 32 |
| red_team | 26 of 26 |
| regret | 21 of 21 |
| research | 18 of 18 |
| revision | 32 of 32 |
| risk | 230 of 230 |
| rollback | 12 of 12 |
| root_of_trust | 12 of 12 |
| self_governance | 24 of 24 |
| self_healing | 30 of 30 |
| simulation | 24 of 24 |
| state_predictor | 28 of 28 |
| swarm | 39 of 39 |
| tournament | 18 of 18 |
| trajectory | 24 of 24 |
| world_model | 44 of 44 |
Measured performance
| Mechanism | p50 ms | p95 ms | p99 ms |
|---|---|---|---|
| counterfactual | 0.1393 | 1.3265 | 1.3265 |
| memory_add | 0.0116 | 3.3809 | 3.3809 |
| observation | 0.0012 | 0.0203 | 0.0203 |
| prediction | 0.2513 | 1.3927 | 1.3927 |
| risk_vector | 0.0012 | 0.0136 | 0.0136 |
in-process; no learned component is in the trusted authorization root
Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Known limitations
- An in-process TESTED library; not hosted. The intelligence layer is deliberately NOT in the trusted authorization root; it can only produce recommendations.
- Predictions, counterfactuals and simulations are modelled in-process over synthetic features; they are not calibrated against real production incidents because none are ingested here.
- The red team, blue team, research lab, tournament and marketplace run in-process; there is no external ecosystem, no third-party publisher and no customer.
- The technology radar and research graph are seeded from a small set of items; provenance is recorded but coverage of the literature is incomplete.
- Conformance, deployment-readiness and governability scores are internal multi-dimensional views; they are not certifications and never collapse into a single number.
- No learned component may be placed in the trusted root; the deterministic kernel and E8 remain authoritative.
- Mutation self-testing runs each mutant against the bench subset that exercises the mutated component.
- Scale rows reuse the E33 synthetic in-process benchmark; the intelligence layer adds a 50-sample analysis row.
- No third party has independently verified anything in this bundle.
The bundle's own README
CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric#
The intelligence layer learns which actions are risky, which environments are hard to govern and which controls fail, and turns that into recommendations. It is deliberately NOT in the authorization path: INTELLIGENCE -> RECOMMENDATION -> DETERMINISTIC KERNEL -> AUTHORITY -> E8 -> ENFORCEMENT. Learning never creates authority. Verify with verify_e35.py.txt (see REPRODUCTION.md). Status: TESTED library, pre-production.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem