An open inquiry into what safe AI proliferation looks like
We don't fully know yet what safe AI proliferation looks like. Nobody does. But we believe the path to finding out runs through transparency, shared evidence, and organisations willing to look honestly at what their AI is actually doing. AuthBinder is our contribution to that journey — open about what we know, honest about what we don't, and committed to building the evidence base that makes better answers possible.
Why this matters now
AI is no longer a research curiosity. It is operating in production environments — making decisions, executing actions, and interacting with real systems on behalf of organisations who often have no clear view of what it is doing or on whose authority. The regulatory response is accelerating, but the evidence base that should underpin these decisions does not yet exist at the scale required. Someone needs to build it.
Terrorism and radicalisation
A network of unidentified AI systems deployed across anonymous accounts systematically identifies psychologically vulnerable individuals, personalises radicalisation content at scale, and coordinates financial transfers to operational cells. No single system performs enough of the chain to trigger existing detection thresholds. The identity of the operator is never established. No authority binding exists to trace the delegation chain. By the time the pattern is detected, the operation has distributed across jurisdictions and the evidence has been destroyed.
Hypothetical scenario illustrating structural risk of AI systems operating without verifiable identity or authority binding.
Child safety
An AI platform with no operator verification enables deployment of systems designed to generate and distribute abusive content targeting children. Because the platform requires no identity verification and maintains no audit trail, the legal entity responsible cannot be identified. Platform liability is contested across three jurisdictions. Court proceedings stall because the fundamental requirement for accountability — a verified principal tied to the system's actions — was never established at the point of deployment.
Hypothetical scenario. Real cases involving AI-generated abusive content are already before courts in multiple jurisdictions.
State-sponsored interference
State-sponsored actors deploy AI systems against critical infrastructure — power grids, financial clearing systems, water treatment controls — using credentials purchased through anonymous commercial channels. Each system presents as a legitimate enterprise deployment. None carries a verifiable identity credential. Attribution — the foundation of deterrence and international accountability — is impossible. The absence of a cryptographic anchor is not incidental to the attack. It is the attack vector.
Hypothetical scenario. State-sponsored AI-enabled attacks on infrastructure are a documented and growing threat category.
These are hypothetical scenarios illustrating structural risks of AI systems operating without verifiable identity, scoped authority, or audit trails. They are not descriptions of specific real events.
Global context
Regulators across every major jurisdiction are moving to govern AI — often faster than the research can support. Frameworks are being written based on intuition, political pressure, and analogy to older technologies. The risk is that we regulate for the last problem while the next one compounds quietly. Someone needs to build the evidence base.
The EU AI Act is in force, with the highest-risk systems fully regulated from August 2026. The Product Liability Directive treats AI software as a product subject to strict liability from December 2026. Organisations deploying AI without verifiable audit trails face direct legal exposure — but the standard for what constitutes adequate documentation does not yet exist.
Legislation activeNo federal AI framework. Courts are doing the work instead: Mobley v. Workday, Raine v. OpenAI, and Amazon v. Perplexity are establishing liability precedents in real time. The US is building its AI governance framework through litigation, not legislation — a process that leaves organisations exposed in the interim.
Litigation-drivenSingapore published the world's first national governance framework specifically designed for agentic AI in January 2026 — establishing that organisations remain legally accountable for their AI's behaviours regardless of voluntary compliance. China mandates machine-readable metadata attributing AI output to the producing system.
Framework publishedGeographic advantage
New Zealand sits at the edge of the world — geographically isolated from the centres of AI development in San Francisco, London, and Beijing. That distance is not a disadvantage. It is a structural asset for independent research.
We are not embedded in the commercial pressures of Silicon Valley. We are not subject to the regulatory capture that comes with proximity to the EU's legislative machinery. We are not entangled in the geopolitical tensions shaping US-China AI development. We can say things that organisations closer to the centre cannot afford to say. We can build the evidence base without a commercial interest in the answer.
New Zealand has a track record of early, principled action on global technology challenges — from the Christchurch Call on online extremism to early adoption of digital identity frameworks. The country understands what it means to act before the crisis arrives.
17,900km
from San Francisco — outside the commercial gravity of Silicon Valley
GMT+12
First to see tomorrow — and the risks it brings
Working hypothesis
The core proposition
"AI systems operating without cryptographically verifiable identity and authority binding create an unaccountable action surface — where harmful, unauthorised, or nefarious behaviour is structurally enabled by the absence of a trusted anchor. This does not change the system's underlying capabilities or intent, but it eliminates the conditions that make nefarious use viable at scale: anonymity, unbounded scope, unrevocable authority, and untraceable action chains."
Amazon v. Perplexity — the system operated covertly with no declared identity. Eightfold AI class action — the algorithm existed in secret. Nobody could establish who deployed it or on whose authority it acted.
An AI system without a verified operator identity can be deployed anonymously. Attribution — the foundation of legal accountability and deterrence — is impossible.
Mobley v. Workday — neither employers nor applicants could establish what the system was authorised to do. OpenAI wrongful death cases — no verifiable record of what the system was permitted to do in context.
An AI system without documented authority boundaries can act beyond its delegated scope undetected. The harm may be real before anyone establishes the system was not permitted to act.
Across every case, the absence of a contemporaneous, tamper-evident record of system behaviour meant that liability could not be established or defended. Evidence was unavailable, incomplete, or contested.
Without an independent behavioural record, neither the deploying organisation nor affected parties can reconstruct what happened. Accountability requires evidence independent of the deployer.
Harmful use of AI is not primarily caused by misaligned systems. It is enabled by the absence of accountability infrastructure. The same system, with verifiable identity and authority binding, represents a materially different risk.
An AI system tied to a verified identity with scoped authority cannot be used anonymously for harmful purposes. The risk calculus for anyone deploying AI nefariously changes fundamentally when attribution is guaranteed.
Courts in the US and the EU Product Liability Directive are establishing that deploying AI without identity documentation and an audit trail is not merely a governance gap — it is a strict liability exposure.
Whether behavioural monitoring actually deters harmful use or primarily documents it after the fact.
Whether the three conditions identified here are sufficient or merely necessary.
Whether operator identity verification changes operator behaviour in measurable ways.
Whether the assurance report format AuthBinder uses today is the right one or a starting point.
We are publishing these unknowns because the evidence base that answers them is what this inquiry exists to build — and we cannot build it alone.
Litigation tracker
While legislation catches up, courts across jurisdictions are establishing liability precedents through individual cases. Each case below highlights a gap that governance infrastructure — verifiable identity, scoped authority, and audit trails — is designed to close.
| Case | Governance Issue | Status |
|---|---|---|
Mobley v. Workday, Inc. United States · 2023 Class action proceeding. Court allowed claims that AI screening tools disparately impacted protected groups, establishing that deployers can be liable for algorithmic discrimination. | Employment discrimination via AI screening tool | Ongoing |
Moffatt v. Air Canada Canada · 2024 Civil Resolution Tribunal ruled Air Canada is responsible for information provided by its chatbot. Company could not distance itself from automated representations. | Airline liable for chatbot's misleading promise | Decided |
Amazon v. Perplexity AI United States · 2024 Amazon filed complaint alleging Perplexity's AI systems reproduced Amazon's trademarks and content without authorization. Highlights AI agent attribution and provenance challenges. | Trademark infringement and unauthorized content use | Filed |
Raine v. OpenAI United States · 2023 Class action alleging OpenAI collected and used personal data without consent. Raises questions about what AI systems are authorised to access and store. | Privacy and wiretapping claims against AI training | Ongoing |
This tracker is updated as new cases emerge. Case details are summarized for informational purposes and do not constitute legal advice.
Regulatory timeline
Global AI governance frameworks are converging on the same expectations: verifiable identity, scoped authority, and auditable action trails. Here's when the deadlines hit.
The world's first comprehensive AI legislation becomes law. Phased enforcement begins with prohibited practices first.
Ban on unacceptable-risk AI — social scoring, manipulative AI, certain biometric categorization — becomes enforceable.
Transparency, copyright, and technical documentation requirements apply to GPAI model providers.
Singapore issues a governance framework specifically for agentic AI — establishing that organisations remain accountable for their AI agents' autonomous actions.
Full enforcement for high-risk AI systems in employment, education, critical infrastructure, and law enforcement. Fines reach €35M or 7% of global turnover.
AI software is treated as a product under strict liability. Organisations deploying AI without audit trails face direct legal exposure for defects and harms.
Get involved
We are looking to connect with researchers, philanthropists, altruists, and investors who share an interest in building the evidence base for safe AI proliferation. This is not a sales conversation. If you are curious, concerned, or have relevant expertise, we would like to hear from you.
You can also reach us directly at support@authbinder.com