arXiv

Notarized Agents: Receiver-Attested Confidential Receipts for AI Agent Actions

Title: Notarized Agents: Receiver-Attested Confidential Receipts for AI Agent Actions

Abstract

The current landscape of AI agent observability suffers from a fundamental structural flaw: the same entity generating the activity logs is also the one whose actions are being recorded. Consequently, if an agent is defective or malicious, it can selectively omit, modify, or invent its own activity traces. Furthermore, the operator managing the agent lacks an independent mechanism to identify such tampering. To address this vulnerability, we introduce a protocol framework that fundamentally shifts the trust boundary. In this model, the service receiving an agent’s request issues a receipt documenting its observations, signing it with its private key. This receipt is then encrypted for the agent’s owner and published to a public transparency log. This process allows the owner to reconstruct a tamper-evident history without needing to trust either the agent or its operator.

We instantiate this framework as "Sello," a protocol that integrates four distinct features not found in existing systems: (P1) signing performed on the receiver’s side; (P2) encryption via HPKE directed to an owner’s public key, which is linked to the authorization token through JWS; (P3) publication into a witness-cosigned Merkle log; and (P4) owner-side discovery facilitated by token reference. This paper details the Sello protocol, evaluates its security against adversaries who control both the agent and its operator, and provides microbenchmarks for the associated cryptographic operations. Additionally, we position Sello within the context of related receipt-protocol research, including Signet, AgentROA, the Agent Passport System, draft-farley-acta, and SCITT. Finally, we examine inherent limitations, such as suppression attacks, potential service collusion, and challenges related to adoption incentives.


Source: arXiv Generated at: 2026-06-04 00:00:00 UTC

Related Articles

SpaceX Seeks to Raise $75 Billion in Record IPO (Video)
Bloomberg

SpaceX Seeks to Raise $75 Billion in Record IPO (Video)

SpaceX aims for a record $75 billion valuation through an initial public offering. This historic IPO marks a significant...

Broadcom AI Chip Outlook Disappoints Investors
Bloomberg

Broadcom AI Chip Outlook Disappoints Investors

Broadcom’s AI chip projections disappointed investors, dampening market sentiment. The outlook fell short of expectation...

Hiranandani Group CEO on Powering India's Digital Future
Bloomberg

Hiranandani Group CEO on Powering India's Digital Future

Hiranandani Group CEO discusses driving India's digital transformation.

Cerebras Says It’s Working With All AI Gear Makers Except Nvidia
Bloomberg

Cerebras Says It’s Working With All AI Gear Makers Except Nvidia

Cerebras confirmed partnerships with all major AI hardware vendors except Nvidia. This broad engagement positions Cerebr...

Putin Turns Russia’s AI Future Into a Kremlin Family Business
Bloomberg

Putin Turns Russia’s AI Future Into a Kremlin Family Business

Putin is consolidating Russia’s AI ambitions into a Kremlin family business, effectively turning the sector into a dynas...

Reuters

Meta repeatedly pushes back new AI model release for developers, WSJ says

Meta has repeatedly delayed the release of its new AI model for developers, according to the WSJ. This ongoing postponem...