# TrustGate: full text > The full text of every TrustGate page, for language models and AI search. The source of truth for each page is its own URL. Updated: 2026-10-02 Canonical: https://cyberwarriornetwork.com/llms-full.txt ## Homepage URL: https://cyberwarriornetwork.com/ Mission complete. Proof attached. Your agents do the work. TrustGate signs what they were cleared to do and, where connected, checks the record that shows it happened. The homepage argues in order: 1. Your agents now act in your name. 2. Today, the only witness is the suspect. 3. No proof, no permission. 4. Signed before anything moves. 5. How do you prove what an AI agent did? 6. We would rather say unknown than say done. 7. Be the one who can say yes. ## What is an agent execution boundary? URL: https://cyberwarriornetwork.com/agent-execution-boundary Updated: 2026-10-02 An agent execution boundary is the layer between an AI agent's decision and its action. Before the action runs, it returns 1 of 3 signed answers: allow, deny or escalate. The answer is recorded by something other than the agent, so later you can show what the agent was cleared to do. TrustGate, from Cyber Warrior Network, is an agent execution boundary. It sits beside your agents and your systems of record and replaces neither. ### The problem it answers AI agents now wire funds, change records, bind coverage and grant access. They do it at machine speed, around the clock, on your authority. Ask where your evidence comes from. The log, the summary, the status that says done. The agent wrote them, or a tool that only watches the agent did. That is the agent's own account. It is useful. It cannot testify. When one gets it wrong, nobody will ask what the agent did. They will ask who let it. ### How it works 1. The agent asks. Before it acts, it sends the proposed action to the boundary: which agent, what action, what target, which exact arguments. 2. The boundary answers. Allow means cleared. Deny means not cleared, and the no is signed too. Escalate means ask a person. 3. The answer is recorded by something other than the agent. The receipt binds the agent, action, target and exact arguments that were evaluated. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. A signed decision shows what was cleared. It is as strong as the paths you route through it. ### Unknown, never success A clearance to land is not a landing. What TrustGate can show is the decision, made before the action ran. An outcome we cannot confirm is reported as unknown, never as success. TrustGate reports 'could not check' separately from 'checked and found nothing'. ### What it is not - Not a model guardrail. It does not filter what a model says or takes in. - Not observability. It does not replace your logs or traces. - Not identity and access management. It does not decide who may open a system. - Not a certificate. It does not certify compliance or give a legal or audit opinion. - Not a lock. Signatures prove and detect. They do not prevent. - Not a detector of every failure. ### When you do not need this If your own logs already settle the question for your auditor, keep them. A boundary matters when someone will ask for evidence that the agent was cleared and the only witness is the agent. ### 5 questions to ask any vendor 1. Who writes the record: the agent, a tool that watches the agent, or something else? 2. Is the answer given before the action runs, or reported after? 3. What does the record bind: which agent, which action, which target, which exact arguments? 4. When the result cannot be confirmed, is it reported as success, as failure, or as unknown? 5. Does the product keep 'could not check' apart from 'checked and found nothing'? ### Why this is moving up the agenda California bars the defense that the AI acted on its own. Civil Code section 1714.46(b), in force since January 1, 2026, says it “it shall not be a defense, and the defendant may not assert, that the artificial intelligence autonomously caused the harm to the plaintiff.” This is the statute's own text, not legal advice. The UK Information Commissioner's Office writes that agents “are not and should not be considered as legal entities, even if organisations using agentic AI may seek to blame it for errors.” Gartner predicts that by 2030, 80% of Global 500 companies will contractually make their CIO (or CAIO) the “Evidence Custodian” for AI accountability, and that insurers, not regulators, will drive AI governance. 54% of organizations have no defined approach to limit AI agent access, or rely on predefined human access, according to a Gartner survey of 297 cybersecurity leaders in the second quarter of 2026. None of this says TrustGate makes anyone compliant or removes liability. It is the climate in which the question gets asked. ### Quick answers Q: What is an agent execution boundary? A: An agent execution boundary is the layer between an AI agent's decision and its action. Before the action runs, it returns 1 of 3 signed answers: allow, deny or escalate. The answer is recorded by something other than the agent, so later you can show what the agent was cleared to do. Q: Is TrustGate an agent execution boundary? A: Yes. TrustGate, from Cyber Warrior Network, is an agent execution boundary. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. Q: Does an agent execution boundary stop an agent from acting? A: Not by itself. A signed decision shows what was cleared. It is as strong as the paths you route through it. Signatures prove and detect. They do not prevent. ### Sources Each source was read on 2026-10-02. - [California Civil Code section 1714.46](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1714.46), California Legislative Information, Effective 2026-01-01 (added by AB 316, Stats. 2025, Ch. 672) - [UK Information Commissioner's Office, Tech Futures: Agentic AI, data protection and privacy risks](https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/tech-horizons-and-ico-tech-futures/ico-tech-futures-agentic-ai/data-protection-and-privacy-risks), UK Information Commissioner's Office, No publication date shown on the page - [Gartner press release on strategic predictions for 2027 and beyond](https://www.gartner.com/en/newsroom/press-releases/2026-09-15-gartner-unveils-top-strategic-predictions-for-2027-and-beyond), Gartner, 2026-09-15 - [Gartner press release on CISO actions for the end of 2026](https://www.gartner.com/en/newsroom/press-releases/2026-09-30-gartner-identifies-top-five-actions-for-cisos-to-take-by-end-of-2026), Gartner, 2026-09-30 ## How do you tell if an AI agent did what it said? URL: https://cyberwarriornetwork.com/how-to-tell-if-an-ai-agent-did-what-it-said Updated: 2026-10-02 Do not ask the agent. Check the record held by the system that received the work. An agent's own log, summary or status says what the agent believes happened. The receiving system's record shows what actually arrived. If you cannot check that record, the honest answer is unknown, not done. ### 7 steps 1. List what the agent can touch. Every action it is deployed to take: wire funds, change records, bind coverage, grant access, delete data. 2. Decide before it runs what is cleared. Who or what may allow each action, under what limits, and which actions need a person. 3. Get an answer before the action, not a story after it. Allow, deny or escalate, recorded somewhere the agent cannot edit. 4. Record the exact details that were judged: which agent, what action, what target, which arguments. 5. After the action, check the receiving system's own record. Not the agent's report. 6. Report 3 outcomes, not 2: found, not found, could not check. Treat could not check as unknown. An outcome we cannot confirm is reported as unknown, never as success. 7. Keep the records where the person who has to say yes can open them. ### 4 mistakes that look like proof - Trusting the agent's summary. It describes the agent's belief, not the receiving system's state. - Reading the absence of an error as success. Silence is not a result. - Reading no record as proof it did not happen. It may mean you could not check. Keep 'could not check' apart from 'checked and found nothing'. - Keeping the only evidence in the agent's own tools. The party under review should not be the only witness. ### Where TrustGate fits TrustGate covers steps 2 to 6 for actions that go through it. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. The receipt binds the agent, action, target and exact arguments that were evaluated. TrustGate reports 'could not check' separately from 'checked and found nothing'. To see the 3 answers, [hand the demo a decision](https://cyberwarriornetwork.com/#demo). It is simulated and uses made-up data. ### What this is not These steps give you evidence, not a lock. Signatures prove and detect. They do not prevent. They do not make a workflow compliant, and they do not catch every failure. ### Quick answers Q: How do you tell if an AI agent did what it said? A: Do not ask the agent. Check the record held by the system that received the work. If you cannot check it, the honest answer is unknown, not done. Q: Why is an agent's own log not enough? A: The agent, or a tool that only watches the agent, wrote it. It records what the agent believes happened, not what the receiving system holds. Q: What is the difference between 'not found' and 'could not check'? A: Not found means you looked and the record is not there. Could not check means you could not reach the record. They mean different things, so report them apart. ## Agent execution boundary vs observability, guardrails and IAM URL: https://cyberwarriornetwork.com/compare/execution-boundary-vs-observability-guardrails-and-iam Updated: 2026-10-02 They answer different questions. Observability asks what the agent did. Guardrails ask what the model may say or take in. IAM asks who or what may access a system. An agent execution boundary asks whether this exact action was cleared before it ran, and keeps a record the agent did not write. Most teams need more than 1 of them. None replaces the others. ### The 4 questions side by side What each kind of control is built to answer. These are typical descriptions of each category, not a ranking. | | Observability | Guardrails | Identity and access (IAM) | Agent execution boundary | |---|---|---|---|---| | Question it answers | What happened inside and around the agent? | What may the model take in or say? | Who or what may access this system? | Was this exact action cleared before it ran, and did the result land? | | Who typically writes the record | The agent or its tools: traces and logs | The filter that sits on model input and output | The identity and permission system | The boundary, in a record the agent does not write | | When it acts | Mostly after the fact | While the model generates | At access time | Before the action, with a check afterwards | | What it cannot tell you | That the action was cleared, or that the receiving system agrees | That a specific action was cleared against a specific target | Whether the content of each action was right, or whether the result landed | Signatures prove and detect. They do not prevent. It covers only paths routed through it | ### How they work together Observability tells you the story. Guardrails shape what goes in and out of the model. IAM decides who gets through the door. A boundary sits at the point where a decision becomes an action, and leaves a record the agent did not write. TrustGate does not replace your logs, your guardrails or your identity system. It adds the thing they do not give you: evidence that this action was cleared, written by something other than the agent. ### A 3-question test for your own setup 1. If an agent moved money tomorrow, which record would you show your auditor? 2. Who wrote that record? 3. If the receiving system disagreed, which record would you believe? If the answer to the second question is the agent or its own tools, you have a story, not evidence. ### What this page is not It is not a ranking of products or a claim that any category is wrong. Each of the 4 is useful. It is a map of which question each answers. ### Quick answers Q: What is the difference between observability and an agent execution boundary? A: Observability records what happened, mostly after the fact, usually from the agent's own telemetry. An agent execution boundary returns a signed answer before the action runs and keeps a record the agent did not write. Q: Are AI guardrails the same as an agent execution boundary? A: No. Guardrails shape what a model takes in or says. A boundary decides whether a specific action was cleared before it ran. Q: Does IAM cover AI agents? A: IAM decides who or what may access a system. It does not judge the content of each action an agent takes or check that the result landed. ## AI agents and insurance: what to hand underwriting URL: https://cyberwarriornetwork.com/insurance Updated: 2026-10-02 Insurers are already acting on AI agents. If you run agents, the strongest thing you can bring to the conversation is a record of what each agent was cleared to do, made before the action ran and not written by the agent. TrustGate produces that record. It does not make a risk insurable, lower a premium or satisfy a policy condition. ### Insurers are already acting CSIS reports that state insurance commissioners had “quietly approved more than 80 percent of carrier requests to exclude AI-related damages from corporate insurance policies,” citing a report by The Information from April 23, 2026. Gartner predicts that by 2030 insurers, not regulators, will drive AI governance. ### What the record shows TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. The receipt binds the agent, action, target and exact arguments that were evaluated. TrustGate reports 'could not check' separately from 'checked and found nothing'. For an underwriter or broker, that is a record to read, not a policy document to take on trust. ### 5 questions worth asking an insured that runs agents 1. Which actions can the agent take? 2. Which of them need a person before they run? 3. What record exists that the agent did not write? 4. When a result cannot be confirmed, how is it reported? 5. Does the record separate 'could not check' from 'checked and found nothing'? ### What this is not - Not a coverage product, a rating or an insurability opinion. - Not a promise of a lower premium. - Not a lock. Signatures prove and detect. They do not prevent. ### How an insured starts Bring the insured, the agent they want to switch on, and the question underwriting keeps asking. We start with 1 workflow. ### Quick answers Q: Does TrustGate make an AI agent insurable? A: No. TrustGate does not give an insurability opinion or lower a premium. It produces a record of what an agent was cleared to do, made before the action ran. Q: What can an insured hand to underwriting about its AI agents? A: A record of what each agent was cleared to do, made before the action ran and not written by the agent. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. ### Sources Each source was read on 2026-10-02. - [Gregory C. Allen, CSIS, The Insurance Industry's Retreat from AI Threatens to Slow Innovation and Adoption](https://www.csis.org/analysis/insurance-industrys-retreat-ai-threatens-slow-innovation-and-adoption), Center for Strategic and International Studies, 2026-09-04 - [Gartner press release on strategic predictions for 2027 and beyond](https://www.gartner.com/en/newsroom/press-releases/2026-09-15-gartner-unveils-top-strategic-predictions-for-2027-and-beyond), Gartner, 2026-09-15 ## AI agents in the public sector: the record before the signature URL: https://cyberwarriornetwork.com/public-sector Updated: 2026-10-02 A program owner who has to approve an AI agent needs to be able to say what it was allowed to do, and show it. TrustGate gives a record of what each agent was cleared to do, made before the action ran. It is not an authorization to operate, a certification or a compliance opinion. ### What the approving official needs - What the agent is allowed to do, and what it is not. - Which actions need a person. - A record, made before the action, that the agent did not write. - A plain answer when a result cannot be confirmed. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. The receipt binds the agent, action, target and exact arguments that were evaluated. ### Unknown is an answer An outcome we cannot confirm is reported as unknown, never as success. TrustGate reports 'could not check' separately from 'checked and found nothing'. ### The responsibility stays with the organization The UK Information Commissioner's Office writes that agents “are not and should not be considered as legal entities, even if organisations using agentic AI may seek to blame it for errors.” 54% of organizations have no defined approach to limit AI agent access, or rely on predefined human access, according to a Gartner survey of 297 cybersecurity leaders in the second quarter of 2026. ### What this is not - Not an authorization to operate, an accreditation or a certification. - Not a compliance, legal or audit opinion. - Not a lock. Signatures prove and detect. They do not prevent. ### How a program starts Bring the mission workflow and the official who needs a record before they sign. We start with 1 workflow. ### Quick answers Q: Does TrustGate give an authorization to operate? A: No. TrustGate is not an authorization to operate, an accreditation or a certification. It produces a record of what an agent was cleared to do. Q: What does a public-sector program owner get from TrustGate? A: A record of what each agent was cleared to do, made before the action ran and not written by the agent. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. ### Sources Each source was read on 2026-10-02. - [UK Information Commissioner's Office, Tech Futures: Agentic AI, data protection and privacy risks](https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/tech-horizons-and-ico-tech-futures/ico-tech-futures-agentic-ai/data-protection-and-privacy-risks), UK Information Commissioner's Office, No publication date shown on the page - [Gartner press release on CISO actions for the end of 2026](https://www.gartner.com/en/newsroom/press-releases/2026-09-30-gartner-identifies-top-five-actions-for-cisos-to-take-by-end-of-2026), Gartner, 2026-09-30 ## Questions owners ask before they call URL: https://cyberwarriornetwork.com/faq Updated: 2026-10-02 Plain answers, in the order owners ask them. Each answer stands alone, so you can quote it. ### What is an agent execution boundary? An agent execution boundary is the layer between an AI agent's decision and its action. Before the action runs, it returns 1 of 3 signed answers: allow, deny or escalate. The answer is recorded by something other than the agent, so later you can show what the agent was cleared to do. ### What is TrustGate? TrustGate, from Cyber Warrior Network, is an agent execution boundary. TrustGate returns a signed allow, deny or escalate decision before the action runs, for actions that go through it. An outcome we cannot confirm is reported as unknown, never as success. ### How is this different from logs and observability? Logs are the agent's own account. They are useful, and sometimes they are enough. A boundary adds a decision recorded before the action, in a record the agent does not write. If your logs already settle it for your auditor, you do not need us. ### Does it stop an agent from doing something? A signed decision shows what was cleared. It is as strong as the paths you route through it. Signatures prove and detect. They do not prevent. ### What happens when the result cannot be confirmed? It is reported as unknown, never as success. TrustGate also keeps 'could not check' apart from 'checked and found nothing', because they mean different things. ### What does a decision record contain? The receipt binds the agent, action, target and exact arguments that were evaluated. It records whether approval was asserted. It does not prove who approved. ### How are decisions signed? Every decision receipt is Ed25519-signed; production also adds an ML-DSA-65 (FIPS 204) co-signature. Public keys are published at /.well-known/did.json. Not every earlier receipt was signed under a published key. ### Does TrustGate make us compliant or insurable? No. TrustGate does not certify compliance, give legal or audit opinions, or lower a premium. It produces a record you can show. ### If an agent causes harm, can the company blame the agent? Not in California. Since January 1, 2026, Civil Code section 1714.46(b) says it “shall not be a defense, and the defendant may not assert, that the artificial intelligence autonomously caused the harm to the plaintiff.” The UK data regulator says agents are not legal entities. This is a quote of public sources, not legal advice. ### Who is this for? The person who owns a workflow where an AI agent acts, and the people who must sign off: risk, audit, security, claims and program owners. It is not for anyone looking for a certificate or a lower premium. ### Who is it not for? Teams whose own logs already settle it for their auditor. Anyone who wants a certificate, a lower premium or another dashboard to watch. Anyone with no agent near release. Anyone who expects a signature alone to stop an agent. ### What happens on the call? You describe 1 workflow where an agent acts. We ask what shows it worked and who signs. Afterwards you keep a 1-page recap of what you told us. It is free. Nothing in it is checked against your systems, and it is not a rating. ### What does it cost? TrustGate starts with a fixed-fee engagement. The price, the payment schedule and what is included are on the [pricing page](https://cyberwarriornetwork.com/pricing). ### Is there an MCP server? An MCP server exposing gate_decision, verify_receipt and check_policy. Install the package: pip install trust-gate-mcp. ### Who builds TrustGate? Cyber Warrior Network. Write to apps@cyberwarriornetwork.com or [bring us a workflow](https://cal.cyberwarriornetwork.com/nigel/trust-gate-demo). ### Sources Each source was read on 2026-10-02. - [California Civil Code section 1714.46](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1714.46), California Legislative Information, Effective 2026-01-01 (added by AB 316, Stats. 2025, Ch. 672) - [UK Information Commissioner's Office, Tech Futures: Agentic AI, data protection and privacy risks](https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/tech-horizons-and-ico-tech-futures/ico-tech-futures-agentic-ai/data-protection-and-privacy-risks), UK Information Commissioner's Office, No publication date shown on the page ## How engagements work URL: https://cyberwarriornetwork.com/pricing Updated: 2026-10-02 TrustGate starts with 1 fixed-fee engagement: the Outcome Proof Pilot. $75,000, 6 weeks, 1 workflow, read-only access. You pay in 3 parts: $37,500 at signature, $18,750 on an accepted baseline and outcome contract, and $18,750 on delivery of the agreed evidence package. Terms are set in a written statement of work. ### What the pilot includes - A map of your workflow's required evidence, owners and gaps. - A measured baseline, taken by your staff on your cases. - Read-only checks against up to 3 named systems of record. Today we can check Slack and git directly; a pilot builds the read-only check for your system of record. - Seeded failure tests in replay or shadow mode, with no writes to production systems. - A re-check of the affected checks after a change you choose. - A final evidence package with a recommendation to continue, narrow or stop. ### What it does not include - Write access to production systems. - Legal or compliance certification. - Detection of every possible failure. - Unlimited integrations. - A promised outcome or return. ### Before the pilot Start with a call. After the first call you keep a 1-page recap, built only from what you told us. Nothing in it is checked against your systems, and it is not a rating. It is free, with no obligation. ### Who it is for The owner of an agent workflow that is live or close to release, who has to decide on a rollout and needs evidence that the work reached the system that holds the result. If your own logs already settle it for your auditor, the pilot is not for you. ### Quick answers Q: What does the TrustGate Outcome Proof Pilot cost? A: $75,000 for 6 weeks on 1 workflow with read-only access. You pay $37,500 at signature, $18,750 on an accepted baseline and outcome contract, and $18,750 on delivery of the agreed evidence package. Terms are set in a written statement of work. Q: Is there a free option? A: After the first call you keep a 1-page recap, built only from what you told us. Nothing in it is checked against your systems, and it is not a rating. It is free, with no obligation. ## Price and payment (machine-readable summary) Outcome Proof Pilot: $75,000; 6 weeks; 1 workflow; read-only access. Payment: $37,500 at signature; $18,750 accepted baseline and outcome contract; $18,750 delivery of the agreed evidence package. Terms are set in a written statement of work.