Intent can drift into effect.
Agent reasoning, tool permissions and execution paths can become coupled in ways that make duplicate, stale or insufficiently authorized actions harder to contain and audit.
Authorization infrastructure for autonomous AI actions. VSL-ECP separates model reasoning from permission to create consequential external effects.
PRODUCT DIRECTION / DESIGN PRINCIPLENO EXTERNAL EFFECT WITHOUT COMPLETE, VERIFIABLE EFFECT PROVENANCE.
A physical visualization of the control boundary. The video loops automatically; sound is optional. The validated prototype is software infrastructure.
Autonomous systems are moving from generating answers to using tools, changing infrastructure, executing workflows and affecting real systems. A model can propose an action without the enterprise having authorized that exact consequence.
VSL-ECP is designed for the boundary between reasoning → authorization → execution → evidence.
Agent reasoning, tool permissions and execution paths can become coupled in ways that make duplicate, stale or insufficiently authorized actions harder to contain and audit.
The agent may request. ECP verifies whether that specific effect has valid authority, consumes it once and records the outcome.
The public model is intentionally simple. It explains the boundary without disclosing cryptographic internals, operational controls, credentials or private deployment details.
Confirm that authority exists for the requested effect before execution is allowed.
Evaluate the transactional state of the permit at the authorization boundary.
A successfully redeemed permit becomes unavailable to competing consumers in the tested model.
Preserve an auditable record of the authorization and observed outcome.
In the recorded test, 20 independent Cloud Run tasks contended for the same permit. One task consumed it successfully. The other 19 observed that the permit had already been consumed. Cloud Spanner persisted the final consumed state and the winning task.
Cloud integration validation pending for this extension.
A valid permit proves authority to attempt an effect. It does not prove that the external effect actually occurred.
VSL-ECP is evolving from a permit-control boundary into a verifiable effect-provenance layer that can reconstruct what was intended, what was authorized, what was attempted, what was actually observed and under which software/policy version the action occurred.
Evidence indicates that the intended external effect occurred.
The attempt did not produce the intended effect.
Available evidence is insufficient to assert either success or failure.
For each bounded effect trace, the provenance architecture is designed to preserve verifiable references without publishing confidential schemas or operational identifiers.
Who proposed it. Who authorized it. What executed it. What actually happened. Under which version.
This browser-only demonstration contains no production credential, confidential implementation or consequential external effect. It illustrates the public state model and the separation between permit consumption and observed effect outcome.
From 11 September 2026, the EU Cyber Resilience Act begins applying its Article 14 reporting obligations for actively exploited vulnerabilities and severe security incidents affecting products with digital elements. These obligations increase the operational value of being able to reconstruct when an incident was detected, which software version was affected, what mitigation or correction followed, and what actually occurred.
VSL-ECP’s provenance roadmap is designed to support this kind of verifiable authorization, effect and incident timeline reconstruction. It does not itself establish legal compliance, certification or applicability under the CRA; those determinations depend on the organization, product, jurisdiction and legal assessment.
We are seeking a limited number of qualified enterprise design partners to test bounded authorization and effect-provenance workflows in real integration contexts. ECP does not replace identity, policy, compliance systems or human accountability.
Gate deployment or configuration effects behind explicit effect authority.
Separate model reasoning from the authority to invoke consequential tools.
Add a consumption and evidence boundary to high-impact automated steps.
Bind delegated approval to the specific effect that may occur.
Reduce ambiguity between requested, authorized and observed execution.
Leave a clear record of what authority was consumed and what outcome was observed.
The public VSL-ECP page explains the product boundary, validated behavior and high-level architecture. Detailed technical architecture, validation artifacts and implementation materials are shared selectively with qualified prospective investors and approved design partners under controlled access.
The public site intentionally does not expose source implementation, credentials, key material, cryptographic internals, unpublished threat-model details, internal deployment identifiers or partner-specific integration design.
VSL-ECP is being packaged as a focused enterprise control-plane product. The broader Vehicle Systems Lab ecosystem supplies research context and technical lineage, but the public ECP surface stays centered on authorization, execution and evidence.
The current bounded prototype uses Google Cloud services including Cloud Run and Cloud Spanner to exercise distributed contention and persist permit state.
Startup infrastructure benefit: Vehicle Systems Lab has received startup cloud credits through the Google for Startups Cloud Program.
Official Google for Startups Cloud Program ↗Use of Google Cloud infrastructure does not imply Google endorsement, certification, funding, adoption or approval of VSL-ECP.
We are seeking a limited number of qualified enterprise design partners to test bounded authorization and effect-provenance workflows in real integration contexts.
VSL-ECP is the lead commercial product of Vehicle Systems Lab. The current opportunity is to convert a validated authorization property and locally validated provenance architecture into pilotable enterprise infrastructure.
Detailed investor and technical diligence materials are available under controlled access.
Request investor materialsTwo distinct evidence tiers: a validated bounded Google Cloud single-consumption experiment, and a provenance extension classified LOCAL_VALIDATED in controlled local testing. Cloud integration validation for the provenance extension remains pending.
No production certification, security certification, completed compliance, universal exactly-once external effects, paying customers, revenue, or replacement of IAM, policy engines, compliance systems or human review.
Vehicle Systems Lab is a member of NVIDIA Inception.
NVIDIA describes Inception as a free program that guides AI startups through the NVIDIA platform and ecosystem. Publicly listed member benefits include developer tools and training, preferred pricing on select NVIDIA hardware and software, exclusive partner offers and exposure to a global investor ecosystem.
Official NVIDIA Inception page ↗Membership applies to Vehicle Systems Lab as a company. It does not imply NVIDIA endorsement, funding, certification, sponsorship, technical validation, adoption or approval of VSL-ECP.
NVIDIA and the NVIDIA logo are trademarks and/or registered trademarks of NVIDIA Corporation in the U.S. and other countries. Other company and product names may be trademarks of their respective owners.
Authorization infrastructure for autonomous AI actions.