{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_db4c9b6c6a11e38408d17d9c8f182ce5b964b72749902caf3531bd685c1fe65c","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_db4c9b6c6a11e38408d17d9c8f182ce5b964b72749902caf3531bd685c1fe65c","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"35de3a7ae06340ca2dcd0d6da24641aff0c2a962b604bc3e774823a9c509322a","published":"Wed, 01 Jul 2026 00:00:00 -0400","receipt_hash":"35de3a7ae06340ca2dcd0d6da24641aff0c2a962b604bc3e774823a9c509322a","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"35de3a7ae06340ca2dcd0d6da24641aff0c2a962b604bc3e774823a9c509322a","observed_at":"2026-07-01T04:43:38.812993Z","parent_run_hash":"0e10ec7d671a375a4e18d8645653df2b4352c82fe16fae2a400af6f7634d6699","published":"Wed, 01 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2605.09045v2 Announce Type: replace \nAbstract: Agentic frameworks are the software layer through which AI agents act in the world. Existing safety methods intervene on the model and therefore remain conditional on unverifiable properties of learned behavior. We introduce containment verification, which locates safety guarantees in the agentic framework itself. Under havoc oracle semantics, the AI is modeled as an unconstrained oracle over the framework's typed action space, and the verified containment layer must enforce the boundary policy for every typed action value the AI can emit. For boundary-enforceable properties, expressed over modeled boundary events, action arguments, and state, we prove a universal guarantee by forward-simulation refinement and mechanize it in Dafny. We instantiate the paradigm by verifying PocketFlow, a minimalist agentic LLM framework, and use an agentic synthesis pipeline to generate the specification, operational model, and refinement proof under ","title":"Containment Verification: AI Safety Guarantees Independent of Alignment","url":"https://arxiv.org/abs/2605.09045","vendor":"arxiv_cs_ai"},"summary":"arXiv:2605.09045v2 Announce Type: replace \nAbstract: Agentic frameworks are the software layer through which AI agents act in the world. Existing safety methods intervene on the model and therefore remain conditional on unverifiable properties of learned behavior. We introduce containment verification, which locates safety guarantees in the agentic framework itself. Under havoc oracle semantics, the AI is modeled as an unconstrained oracle over the framework's typed action space, and the verified containment layer must enforce the boundary policy for every typed action value the AI can emit. For boundary-enforceable properties, expressed over modeled boundary events, action arguments, and state, we prove a universal guarantee by forward-simulation refinement and mechanize it in Dafny. We instantiate the paradigm by verifying PocketFlow, a minimalist agentic LLM framework, and use an agentic synthesis pipeline to generate the specification, operational model, and refinement proof under ","title":"Containment Verification: AI Safety Guarantees Independent of Alignment","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-01T04:43:38Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2605.09045"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:a459cde62e0534a62131fb40849110dc79592bba624a4cd52f4827d703e92b4af8986f9430c725c01ba7c6e221b9d8f1bec2d63b88a0c2f9f58cca444a801701","signer":"crovia.substrate","subject":{"observed_at":"2026-07-01T04:43:38Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2605.09045"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"e6bda26e0ea34f881f3778a7379dc8a2255171f7ffda1b508574809e7e1333b0","leaf_index":268639,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"bd07917994922f2c2e128804be6a8e4ffe31c0ae7f50ec67f1f5f4484a8caa65","side":"left"},{"sibling":"149182fa80c107a341b5dbd11598a5f3f2547bf79f332eb3042b62351ce74b17","side":"left"},{"sibling":"971c3bd612e48708df5de96f8220bf5698ac76496aa1af7d7f2efbd8ee17aebf","side":"left"},{"sibling":"0fee387260bc3718728f6aaa2186fd4616f250ce2a2db53dc072ad5c72394a9e","side":"left"},{"sibling":"445859945193e722bd7259928d5893adfb1d763d7b9f8b19f1e215441f5b3ca6","side":"left"},{"sibling":"e3877d3e4caec6ebd5b98667f5ce4526a404371b98e25c282a48043fb0d8351a","side":"right"},{"sibling":"0eb4eb96022242f95e819116ec215f97662a006e19b7a97219e1ee83a96f4d60","side":"left"},{"sibling":"09d2631e35e497faf605540c596009624dcf181a796c7acf51592f060eb3f046","side":"right"},{"sibling":"4b14e8ccae46b588748944ffaf410222f66cebc2ac58d936cbe16847b7be9508","side":"left"},{"sibling":"bbd9a20451913e8c7b910f616d5661d9b281a94af70d201ba50b3112d429521b","side":"right"},{"sibling":"85af80e45748c1e0da1e2f42d9d66da8996016888a034f20eb17ff0a73b69eab","side":"right"},{"sibling":"4575fde969d1d9a2984cc01a37ac8441238f74527d42874272dc5582dadebb4f","side":"left"},{"sibling":"f536de281672cbf0b583a3dc46faef1de2823b72bd9265c7b60e889131cc268d","side":"left"},{"sibling":"95b8b0f67237052a17c41fa8cbdce2b79bcb5aeeba3fdb239d4c4497e598115d","side":"right"},{"sibling":"c2f351f771cee329448890504d9436792ba482e50250ca9a19289311131f96c8","side":"right"},{"sibling":"c39bfb2e911ca37ae997690bfc04128ae32e6806ee1cb3908781a7e6685022a0","side":"right"},{"sibling":"a101b4c60ef6854ac3d750eef02d8e2e06c153284b5ecb7111302f97eb129797","side":"right"},{"sibling":"eae2a3de5cb35455ad60125e196cfadaba8a590c53146e95028469f53f70349c","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":268860,"merkle_root":"d098f25810d0569730b6c0e170d57f329a70359d483b47874b5f2fc51d23de65","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260701T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-01T05:38:05Z","sig_algorithm":"ed25519","signature":"64f37f0e3df0556baa55b924a736cab8005643fa0ab65b503f22407de30eab293e6e0bd62904270fda38d05084bb350c8c0d0aadb2c5a6bae5f1c54598e6d30c","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_db4c9b6c6a11e38408d17d9c8f182ce5b964b72749902caf3531bd685c1fe65c"}}