CAIN-42 AGI control boundary, 2026-10-06
Built to control AGI means the boundary never takes an agent's word for anything: who it is is proven with its own key, what it may do comes from CAIN, risky actions wait for a human, a decided proposal cannot be replayed, and every decision is hash-chained. No AGI exists yet to test against, so everything here is measured on today's systems.
Tests run 2026-10-06T16:49:51Z at 1f3cb15a: 82 passed, 0 failed, 0 skipped (TEST_RESULTS.json). Live: unauthenticated proposals refused (cainstudio.online: 401, mcpgate.online: 401, clawx.click: 401). Hardening status: live (the gateway restarted after these commits).
21976129proof of agent identity, replay refusal, human approvals bound to what was approved41e1b85flive route resolved a different tenant than the Identity API (no real agent could act)6f300d8ccainstudio agi-test: the customer's own model, acting only through the boundary9b761fdcconcurrent proposals no longer fork the evidence chain; approvals single-use atomicallyf735965eoperator harness: a real Claude model as the governed agent (run: agi-live-run-2026-10-06)
Not a claim: this is not evidence of AGI or emergent capability, not a certification, and not third-party assurance. A real Claude model behind this boundary: see the separate live-model run bundle, agi-live-run-2026-10-06 (published by its own builder). Source is not published; manifest.json carries sha256 commitments to it. Reproduce: manifest.json, then run the command in TEST_RESULTS.json from a checkout at the listed commit.