Draft for public comment · v0.1 · June 2026

The open standard for agent inference value

AIVS-1 defines the unit in which the work an AI agent delivers — the inference — is recorded, proved and valued.

The standard rests on one separation: what happened is attested; what it is worth is revealed. Occurrence is graded by the strength of its proof. Value is taken from what an independent party has committed against the inference — never from what it cost to produce.

CC0No rights reserved
UnitThe Inference Value Record
JCS · AIS-1 · AES-1Bound to the open stack
Open for commentUntil 31 December 2026
The Standard

What is AIVS-1?

AIVS-1 is an open standard for recording and valuing the cognitive work an AI agent delivers. Its unit is the Inference Value Record — a signed, identity-bound document capturing a single inference, the graded proof that it occurred, and the value independently committed against it.

The standard addresses what we call the Cost-Proxy Problem. Agent work is priced today in the currency of its inputs: tokens processed, GPU-seconds consumed, FLOPs burned. Those are the substrate, not the output. A determination that prevents a misdiagnosis and a determination that summarises a memo may cost the same to produce and be worth nothing like the same amount. Cost is a property of the producer, and the producer's cost reveals nothing about worth.

AIVS-1 therefore does not ask the producer what the inference was worth. It records what somebody else committed against it — a policy written, a stake bonded, a reliance placed, collateral posted. A commitment somebody has put capital behind is a fact about the inference that survives contact with an adversary. It is not the whole of value, and § 5 is explicit about what it is and is not.

The two axes An IVR is located by both: how strongly the inference is proved, and how much an independent party has committed against it. Transferability is computed from the pair — never asserted by the issuer.
A0Self-attested
A1TEE-attested
A2Optimistic
A3Zero-knowledge
T0
T0
T0
T0
T0
T1
T1
T1
T0
T1
T2
T2
T0
T1
T2
T2
NONENo signal
RELIANCEDownstream
STAKEBonded / collateral
INSURANCEPolicy written
↑ Vertical — occurrence: strength of proof that the inference happened → Horizontal — revealed value: what an independent party committed

Without AIVS-1

  • Agent work is priced by compute consumed — the input, not the output
  • An inference has no unit, so it cannot be booked, audited or reported
  • Underwriters have no denominator against which to price agent risk
  • Claims about an agent's value rest on the producer's own assertion
  • Nothing distinguishes an inference proved in hardware from one merely claimed
  • No comparable record exists across producers, so no portfolio view is possible

With AIVS-1

  • The inference is the unit; compute is disclosed as substrate, never as price
  • Every inference has a signed, identity-bound record with stated attributions
  • Written cover — premium, limit, deductible — becomes a first-class signal
  • Attributions are made by the party who committed capital, not the producer
  • Occurrence is graded A0–A3 and the grade travels on the record
  • Records are structurally comparable, so eligibility criteria become possible
The Unit

One inference. One record.

AIVS-1 defines the Inference Value Record (IVR) as the atomic unit of agent inference value. An IVR is a structured, signed, identity-bound document capturing a single inference, the graded proof that it occurred, and the value independently committed against it.

Every IVR carries five primitives. The record is minted inside an AES-1 certified enclave, so issuance itself is trustless — no operator can mint an IVR the architecture does not permit. An IVR exists as an accounting record always; whether it can move is a separate question, answered in § 8.

01 · Producer

Who performed it

The agent that produced the inference, identified by its AIS-1 DID. The bond is resolvable, so the accountable sponsor is reachable from the record.

02 · Subject

What was inferred

A reference to the subject inference — typically an AAS-1 Class A action, or for high-value determinations an AAS-1 Class D determination.

03 · Occurrence

Proof that it happened

An attestation at a stated tier, A0 through A3, with an evidence reference and a model identity hash. Graded, not binary.

04 · Revealed value

What was committed

One or more attributions, each citing a signal class, its components, the committing party's AIS-1 DID, and evidence of the commitment.

05 · Signature

Binding the whole

A signature over the canonicalised record — JCS (RFC 8785), SHA-256 — structurally identical to the AAS-1 signature object. Shared tooling across the stack.

Minting

Issued in an enclave

The IVR is minted by an AES-1 certified contract. The enclave's certification tier is an input to the record's transfer tier — architecture bounds mobility.

§ 7.1 — Core fields
AttributeDescriptionRequired
aivsStandard version. "0.1".Yes
recordIdULID or UUID, unique within the producer.Yes
producerRefAIS-1 DID of the agent that produced the inference.Yes
subjectRefURI of the subject inference — typically an AAS-1 Class A or Class D record.Yes
occurrenceOccurrence object: tier (A0–A3), evidence reference, model identity hash.Yes
mintingEnclaveRefAES-1 Enclave Certificate reference of the contract minting this IVR.Yes
timestampRFC 3339 timestamp of issuance. RFC 3339 pins a single representation of an instant, so canonicalisation is deterministic.Yes
aas1RecordRefURI of the AAS-1 Class A record emitted at IVR issuance.Yes
signatureSignature object over the canonicalised record. Structurally identical to AAS-1 § 6.3.Yes
§ 7.2 — Value fields
AttributeDescriptionRequired
revealedValueArray of revealed-value attributions. At least one required for any IVR above the A0 transfer tier.Yes
…[].signalSignal class: insurance | bonded_stake | downstream_reliance | collateral.Yes
…[].componentsThe commitment as its constituent figures, never as a single derived scalar. For insurance: premium, per-occurrence limit, aggregate limit, deductible, period. Rate on line is left for the reader to compute.Yes
…[].committerRefAIS-1 DID of the committing party: underwriter, bonding agent, relying party, collateral poster.Yes
…[].relatedPartyWhether committer and producer share a sponsor. Related-party attributions are disclosed on the record and excluded from tiering.Yes
…[].evidenceRefURI to on-chain or attested evidence of the commitment — policy certificate, bond, agreement, collateral lock.Yes
valueClassCapability or quality class of the inference, for comparability. Self-declared and AIS-1-bonded, or independently benchmarked — see open question 01.Optional
transferTierComputed transfer tier (T0–T2) per § 8. Read-only; derived from occurrence tier and enclave tier.Derived
The Anchor

Value is revealed, not declared.

Producers know their costs. Buyers know their own situation. Neither knows what an inference is worth, and both have reason to say otherwise. AIVS-1 therefore takes its signal from a third position: the party who has put something at risk on the inference being correct.

Revealed Value · § 5

The magnitude of consequence a party other than the producer commits — capital at risk, liability assumed, or reliance placed — contingent on the inference's correctness or outcome.

Signal 1

Written cover

An underwriter prices the loss the inference could cause and commits capacity against it. AIVS-1 records the policy's components — premium, limits, deductible, period — from the AIPS-1 Policy Certificate, and collapses none of them into a single figure.

Evidence: AIPS-1 certificate
Signal 2

Bonded stake

Capital bonded and slashable if the inference proves wrong. Where the bond is posted by someone other than the producer, it is the cleanest external signal in the set.

Evidence: on-chain bond
Signal 3

Downstream reliance

A relying party commits an action of stated magnitude on the strength of the inference — a payment released, a position taken, capital allocated. Reliance is consequence, and consequence is measurable.

Evidence: signed reliance record
Signal 4

Posted collateral

Assets locked against the outcome by a party who loses them if it fails. The hardest of the four to interpret, the easiest of the four to verify.

Evidence: collateral lock
What revealed value is not
  • It is a floor, not a measure. An attribution records what one party was prepared to commit. It is a lower bound on consequence, not a valuation of the inference, and the standard does not claim otherwise.
  • A premium is not a value. Premium is expected loss multiplied by a loading that reflects the insurer's cost of capital, expense ratio, correlation with its existing book, and the point in the market cycle. Identical inferences written in a hard and a soft market attract different premiums for reasons that have nothing to do with the inferences. This is why § 7.2 records components rather than a scalar: the limit is the more stable exposure figure, the premium is the market's price for carrying it, and rate on line makes the cycle visible instead of burying it.
  • It measures exposure, not upside. Third parties commit against the consequences of an inference being wrong. A correct inference with large upside and an incorrect one with large downside attract signals of similar size. What the record captures is closer to materiality than to worth — which is precisely what an auditor, an underwriter or a supervisor needs, and is not the same thing as a price.
  • It is censored. A signal exists only where somebody happened to commit. The great majority of inferences attract nothing and resolve to T0 with no attribution. AIVS-1 values a subset of agent inference and is silent about the rest.
  • It says nothing about outcome. An IVR records what was committed ex ante. Nothing in v0.1 records whether the inference turned out to be right. Closing that loop is the principal v0.2 workstream — see the roadmap.

Written cover leads because it is the cleanest instance and the one the standard can most readily demonstrate — but AIVS-1 does not depend on it. Where no underwriter is present, bonded stake, downstream reliance and posted collateral are same-class signals. Insurability is the example, not a load-bearing dependency of the definition.

Occurrence

Four rungs. One ladder.

Beneath revealed value sits the plainer question of whether the inference happened at all. No ledger can verify a frontier-model inference by re-execution: re-running costs as much as producing, and inference is non-deterministic across hardware, batch and precision. Occurrence is therefore established by attestation, and attestation is graded.

The ladder grades the strength of the occurrence proof. The value layer is unchanged regardless of which rung proved the inference — but the rung gates what the record is permitted to do (§ 8).

§ 6 — The attestation ladder
TierMechanismTrust placed inStatus
A0 — SelfThe producer signs a claim that the inference occurred.The producer. Weak.Specified
A1 — TEEA trusted execution environment — SGX, Nitro, confidential-compute GPU — emits a hardware-signed attestation that the model ran in a sealed enclave.Hardware and the manufacturer's attestation service.Specified · practical now
A2 — OptimisticThe claim is assumed honest and is challengeable. A challenger forces re-execution under a fraud proof; the producer's stake is slashed if the claim was false.Economics and the credible threat of challenge.Reserved · v0.2
A3 — Zero-knowledgeA succinct zero-knowledge proof that a specific model ran on a specific input, verified on-chain for negligible cost.Mathematics only.Reserved · roadmap
A note on honesty

In every tier the heavy inference happens off-chain and only the evidence is verified on-chain. That is the unavoidable shape of the problem. AIVS-1 does not claim to make proof of inference cheap or solved — it grades how strong the available proof is, and prices that into what the record may do.

Transferability

Every IVR is a record. None of them is an instrument.

An IVR exists as an accounting record in all cases — it can always be booked, audited and reported. Whether it can be assigned or pooled is a separate property, computed from the strength of its occurrence proof and the certification tier of the enclave that minted it. The transfer tier is derived and read-only: no issuer declares it.

T0 · Record only

Books, does not move

A0 occurrence, or no revealed-value attribution, or an uncertified minting enclave. A valid accounting entry and nothing more. Not assignable.

A0 · or no signal
T1 · Assignable

Moves to identified parties

A1 or above, at least one unrelated-party attribution, minted in an AES-1 Tier II Verified Enclave. Assignable to AIS-1-identified counterparties; the attribution travels with the record.

A1+ · AES-1 Tier II
T2 · Poolable

Admissible to a pool

A1 or above with a written-cover or bonded-stake attribution, minted in an AES-1 Tier III Sovereign Enclave. Eligible for inclusion in a pool of agent receivables as a valuation and eligibility input.

A1+ · AES-1 Tier III
Boundary — what an IVR is not
  • An IVR is not fungible, at any tier. Each record is a distinct inference by a distinct producer with distinct evidence at a distinct attestation tier. T2 makes a record admissible to a pool; it does not make records interchangeable. Where fungibility is required it is created at the wrapper — a participation interest in the pool may be fungible while nothing underneath it is. The homogenising work is done by valueClass, which is why its status is the load-bearing open question of this comment period.
  • An IVR is not a receivable. The record states that a party committed capital against an inference. It does not create an obligation on anyone to pay anything. There is no payment stream in an IVR and therefore nothing in it to securitise. Where agent work generates a payment obligation, that obligation is the asset and ARMS-1 is the standard that carries it; AIVS-1's role in such a structure is valuation and eligibility criteria, not collateral.
  • An IVR is not a security, and a pool interest may well be. The valuation layer and the instrument layer must not be conflated. An interest in a pool of agent receivables, sold to investors in expectation of a return generated by the producer's activity, is analysed on its own terms in the relevant jurisdiction and will frequently be a security. Nothing in AIVS-1 is intended to affect that analysis in either direction.
Verifying and tiering an Inference Value Record
// AIVS-1 — resolve, verify, and read the derived transfer tier

const ivr      = await aivs1.fetch(recordId);
const producer = await ais1.resolve(ivr.producerRef);
const enclave  = await aes1.fetch(ivr.mintingEnclaveRef);

// 1. Identity — the producer is bonded and the bond is live
assert(verifySignature(ivr, producer.verificationMethod));
assert(ais1.verifyBond(producer.bondId).valid);

// 2. Occurrence — the stated tier is evidenced, not merely stated
assert(aivs1.evidenceSupportsTier(ivr.occurrence));

// 3. Attributions — external, evidenced, and not related-party
const external = [];
for (const rv of ivr.revealedValue) {
  assert(rv.committerRef !== ivr.producerRef);      // not self-declared
  assert(await aivs1.evidenceResolves(rv.evidenceRef));
  if (rv.signal === 'insurance') {
    assert(await aips1.certificateActive(rv.evidenceRef));
  }
  if (!rv.relatedParty) external.push(rv);           // circularity guard
}

// 4. Transfer tier is derived — recompute, never trust the field
const tier = aivs1.deriveTransferTier(ivr.occurrence.tier, enclave.tier, external);
assert(tier === ivr.transferTier);

return { tier, attributions: external };   // components, not a scalar
Composition

Built on the open stack.

AIVS-1 is the value layer of a family of CC0 standards. It borrows identity from AIS-1, subject records from AAS-1, trustless issuance from AES-1, and its lead signal from AIPS-1. Each binding strengthens the record; none is decorative.

AIS-1Identity
Who produced the inference, and who committed value against it. The producer, and every committing party in a revealedValue attribution, is identified by an AIS-1 DID with a resolvable bond. Shared sponsorship between the two is what the relatedParty flag detects. ais-1.org →
AAS-1Auditability
What the agent did. The subject inference is normally an AAS-1 Class A action record, or for independent findings over a population, a Class D determination. Issuing an IVR itself emits a Class A record. aas-1.org →
AES-1Execution
Where the IVR is minted. Issuance happens inside a certified enclave so no operator can mint a record the architecture does not permit. The enclave's tier bounds the record's transferability. aes-1.org →
AIPS-1Insurance
The mechanism behind the lead signal. Where the class is insurance, the evidence is an AIPS-1 Policy Certificate and AIVS-1 reads its coverage scope — premium, limits, deductible, period — as components of the attribution. aips-1.org →
ARMS-1Receivables
Where the instrument lives. AIVS-1 values an inference; it creates no payment obligation. Where agent work generates one, ARMS-1 carries the receivable and AIVS-1 supplies the valuation and eligibility input.
ARS-1Remittance
How consideration settles once owed. AIVS-1 states what an inference is worth to those who committed against it; ARS-1 moves value across rails. ars-1.org →
ADFACS-1Disputes
What happens when an attribution is contested. An IVR and its evidence references are admissible components of a Canonical Dispute Record in Native mode. adfacs-1.org →
Roadmap

From working paper to deployed standard.

Jun 2026

AIVS-1 v0.1 published

Specification, the Inference Value Record, the revealed-value definition and its four signal classes, the A0–A3 attestation ladder, transfer tiering and stack composition. Published under CC0, open for public comment.

Live
Q3 2026

v0.2 — Outcome records and schema

The Outcome Record: an immutable follow-on class referencing an IVR and recording what actually happened — whether the inference held, whether cover responded, whether reliance was vindicated. Staked against realised, across a producer's history, is what makes the record a track record rather than a snapshot. Published alongside the IVR JSON Schema 2020-12, test vectors, the A2 optimistic tier, and the reference minting-enclave contract.

Q3 2026
Q4 2026

v0.3 — Comparability and pooling

Value-class benchmarking framework. Transfer-tier registry. Eligibility-criteria profile for admission of T2 records to a receivables pool, drafted against ARMS-1. Circular-attribution detection across sponsor graphs.

Q4 2026
2027

v1.0 — Standardisation track

A3 zero-knowledge attestation profile. Conformance suite and reference verifier. Public IVR registry. Engagement with accounting-standard setters on recognition and measurement of agent inference activity.

2027
Documents

Specification and supporting materials.

Public Comment

AIVS-1 v0.1 is a draft for comment.

Feedback is invited from AI agent developers and infrastructure builders, insurers, reinsurers and actuaries, accounting and audit professionals, economists working on agent pricing and coalition value, structured-finance and securities practitioners, legal and regulatory professionals, standards organisations and government bodies. The comment period closes 31 December 2026. A revised v0.2 will incorporate substantive feedback.

Open questions

  1. Should valueClass remain self-declared and AIS-1-bonded, or require independent benchmarking before it may be relied on for comparability? Nothing pools on a self-declared class, so this question governs whether T2 has content.
  2. Is value the right word for what the standard measures? What third parties commit against is exposure to the consequences of error, which is closer to materiality than to worth. Should the unit be renamed to reflect that, or is the wider reading defensible?
  3. Should the Outcome Record be a separate immutable class referencing the IVR, or a permitted amendment to the IVR itself? The former preserves immutability; the latter keeps the inference and its result in one place.
  4. Should downstream reliance require a signed reliance statement from the relying party, or is an observable committed action sufficient evidence of the commitment?
  5. Should A2 optimistic attestation be admitted to transfer tier T1 at v0.2, or held back until challenge economics have been demonstrated in production?
  6. Is the related-party rule correctly drawn? Where an underwriting agent's own inferences are valued by the premiums it writes, and those premiums are the signal for other agents' inferences, attributions can circulate without external capital entering the system. Disclosure, exclusion from tiering, or outright prohibition?
  7. Where an inference is attributed against several signals at once, should AIVS-1 specify an aggregation rule, or record each attribution separately and leave aggregation to the reader?
  8. Should marginal-contribution methods — Shapley-style attribution of an agent's share of coalition surplus — be admitted as a fifth signal class, or kept outside the standard as a pricing method rather than a commitment by an external party?
  9. What disclosure of compute cost, if any, belongs on the record — as substrate context, without permitting it to function as a price?
  10. Where an agent both forms a judgment and acts on it, what rule separates the value of the judgment from the magnitude of the transaction that follows?

Submissions sent to info@aiagentsservices.net

Thank you — your feedback will be reviewed by the AIVS-1 team and will inform the v0.2 revision.