Evidence-First Security (EFS) is a design paradigm for AI-integrated systems in which every security claim, access grant, and behavioural assertion is anchored to a cryptographically verifiable evidence node before any runtime action is permitted. In contrast to policy-first or role-based approaches, EFS treats evidence as the atomic unit of trust: no capability is exercised without a corresponding, auditable evidence chain traceable to a human-attested origin. This paper introduces the formal model underlying EFS as deployed in the Pyraclaw OS sovereign runtime and the iAiA multi-agent architecture. We define the Evidence Node (EN) structure — comprising a content hash (SHA3-512), a temporal anchor (RFC 3161 timestamp), an identity capsule binding (ORCID or DID), and a DOI-anchored publication reference — and demonstrate how EN chains satisfy non-repudiation, forward secrecy, and post-quantum resistance requirements for agentic AI workflows. The EFS model is shown to be compatible with the iORBi intent framework, the Swiss Vault 5-dip codec, and the WISeer 77-node swarm topology. A reference implementation using the Q-EJMF (Quantum-Enhanced Jellyfish Merkle Fabric) data structure is described, along with performance benchmarks on the Pyraclaw OS v3.5.48 runtime. The paper concludes with a threat model and a discussion of open research problems in sovereign AI security attestation.
Callaghan et al. (Tue,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: