The infrastructure that makes AI governable

The AI economy is being built without the foundational infrastructure it requires. Scarp is a four-layer protocol substrate that closes the gap. Identity, Cooperation, Governance, and Settlement, operating together, produce AI that is governable as a structural property of the infrastructure it runs on.

The Structural Gap

Four questions no production system answers

A hospital deploying AI for radiology triage, a defense ministry running agents on classified networks, a manufacturer sourcing an open-weight model for supply-chain optimization, and a sovereign government whose enforcement authority runs on platforms it does not control all face the same four questions.

1

Identity

What is this AI system, who authorized it to act, and what authority does it carry?

2

Certification

Is it certified as safe for the specific work it is about to do?

3

Governance

Were the governance controls actually running at the moment it acted?

4

Verification

Can anyone other than the party that ran the AI verify the answers to the first three questions without that party's cooperation?

The Substrate

Four foundational layers

The internet was built from foundational protocols: DNS, TCP/IP, TLS. Each solved a structural problem that could not have been retrofitted after the fact without enormous cost. The AI economy faces the same inflection. The protocols forming today solve how agents communicate. They do not solve how agents are identified across organizational boundaries, how they form binding agreements, how their actions are governed with independently verifiable evidence, or how value moves between them with full provenance. Those are substrate problems. Scarp is the substrate.

Identity Every participant is identifiable, verifiable, and accountable. Agents, models, humans, organizations, machines, and data. Each carries a governance scope that travels with it. Specified
Cooperation Participants discover each other, negotiate binding agreements, execute joint work with independent enforcement, and resolve disputes. The lifecycle from first contact through completion. Specified
Governance Every action is accountable to the parties whose authority is in scope. Policy bound to identity. Evidence produced at the moment of the action. Independently verifiable after the fact. Shipped
Settlement Governed economic transactions with mandatory governance evidence as a prerequisite. Technology-agnostic settlement across payment rails, smart contracts, and traditional clearing. Specified
What Each Layer Carries

Infrastructure that cannot be retrofitted

Each layer addresses a structural requirement that the AI economy cannot function without. The layers are independently transactable and together produce governable AI at every scale, from a single agent to cross-jurisdictional multi-party workflows. The full architectural specification is published in the companion papers.

Specified Identity

Every participant in the AI economy has to be identifiable, verifiable, and accountable. The set of participants is larger than most governance discussions acknowledge: AI systems and the models that power them carry different certifications and different provenance. Human principals, organizations at every scale, physical machines operating autonomously, and certified data all require verifiable identity. A dataset's provenance, chain of custody, and jurisdictional admissibility are identity questions. The substrate treats them as such.

No identity infrastructure in production today covers the full set. Vendor-specific agent identity systems cover agents inside a single platform. SPIFFE and certificate authorities cover workload and increasingly agent identity within defined trust domains. Neither answers the question: can a third party in a different organization, on a different cloud, in a different jurisdiction, verify who this agent is, what it is certified to do, and whether it is currently authorized to act?

Specified Cooperation

Two participants that can identify each other still cannot transact, coordinate, or compose into joint work without infrastructure for discovery, agreement, governed execution, and dispute resolution. The internet solved how machines find each other and exchange traffic. It does not solve how autonomous actors under principal-bound authority find each other, reach binding agreements, and execute those agreements across organizational lines.

The cooperation layer carries the full lifecycle: from a procurement agent discovering potential suppliers, through governed negotiation where each message is evaluated against the sender's policies, to binding contract formation where both parties hold independently verifiable records of what was agreed.

Shipped Governance

Governance makes every action accountable to the parties whose authority or interest is in scope. Policy is bound to identity. The governance evaluation happens outside the agent's reach. The evidence is recorded in independently verifiable form at the moment of the action. These three properties together produce runtime governance that is structural rather than probabilistic.

Scarp Governance Gateway is a production-grade implementation of the Governance layer. It intercepts every AI agent interaction, classifies content, evaluates policies, enforces decisions in real time, and produces cryptographically signed evidence for every governed action. Full product details.

Specified Settlement

The AI economy produces transactions at a volume, speed, and frequency beyond what any human-paced settlement infrastructure was built to carry. The substrate's settlement layer carries those transactions with identity anchoring at both ends, structural escrow guarantees, full provenance into the ledger, and dispute resolution grounded in the independently verifiable evidence the governance layer produced at every step.

Regulatory oversight is a structural property: tax remittance, sanctions enforcement, and consumer protection are calculated and directed at settlement time, as part of the transaction, rather than chased after the fact through reporting obligations the activity may have outrun.

Regulatory Convergence

Three frameworks. One structural dependency

Three regulatory and strategic frameworks, drafted independently, from different starting assumptions, for different audiences, each arrive at the same structural dependency: governance infrastructure whose evidence can be trusted by parties who did not produce it.

EU AI Act

Mandates documented, auditable evidence of how high-risk AI systems are governed. The Digital Omnibus deferred standalone obligations to December 2027. The stated reason: the governance tooling does not yet exist. The obligation did not change. The infrastructure to meet it does not exist.

FRONTIER Act

Creates a licensed Independent Verification Organization regime with a statutory requirement that licensed verifiers maintain adequate independence from the artificial intelligence industry. The first legislative artifact anywhere that instantiates independent verification as a licensed, regulated function at statute level.

IAPS Strategic Visions

Maps nine strategic visions for navigating powerful AI. The visions differ on government involvement, centralization, and geopolitics. They converge on a shared structural dependency: governance infrastructure that can verify AI behavior independently. That infrastructure is the bottleneck. No vision works without it.

Deployment Architecture

Full data sovereignty, not SaaS dependency

Most AI governance products deploy as SaaS platforms. Every governed interaction, every policy decision, every piece of evidence transits or resides in a third party's infrastructure. For regulated enterprises, that arrangement creates a problem legal counsel cannot approve.

AI governance evidence is a different category of data from CRM records or IT service tickets. It contains the full request and response payloads of every AI interaction: the questions asked, the answers given, the policies evaluated, the decisions rendered. When Company A sends Company B's data through a SaaS AI governance vendor, Company A may breach its data-handling obligations to Company B. The contractual framework between Company A and the SaaS vendor does not cure a contractual violation between Company A and Company B.

Scarp Governance Gateway deploys into the customer's own cloud tenant. The customer chooses where it runs. The gateway runtime, all configuration, all evidence records, all signing keys, all provider credentials, all evidence records and all operational logs reside in the customer's environment. There is no aggregation service, no telemetry, no phone-home, no cross-tenant data movement. The customer can remove the gateway entirely and retain every piece of governance evidence produced.

The governance is real. The evidence of governance is a promise

Scarp closes the gap between governance and proof. Read the structural argument, inspect the working implementation, or request a technical briefing.