AIVS-1 defines the unit in which the work an AI agent delivers — the inference — is recorded, proved and valued.
The standard rests on one separation: what happened is attested; what it is worth is revealed. Occurrence is graded by the strength of its proof. Value is taken from what an independent party has committed against the inference — never from what it cost to produce.
AIVS-1 is an open standard for recording and valuing the cognitive work an AI agent delivers. Its unit is the Inference Value Record — a signed, identity-bound document capturing a single inference, the graded proof that it occurred, and the value independently committed against it.
The standard addresses what we call the Cost-Proxy Problem. Agent work is priced today in the currency of its inputs: tokens processed, GPU-seconds consumed, FLOPs burned. Those are the substrate, not the output. A determination that prevents a misdiagnosis and a determination that summarises a memo may cost the same to produce and be worth nothing like the same amount. Cost is a property of the producer, and the producer's cost reveals nothing about worth.
AIVS-1 therefore does not ask the producer what the inference was worth. It records what somebody else committed against it — a policy written, a stake bonded, a reliance placed, collateral posted. A commitment somebody has put capital behind is a fact about the inference that survives contact with an adversary. It is not the whole of value, and § 5 is explicit about what it is and is not.
AIVS-1 defines the Inference Value Record (IVR) as the atomic unit of agent inference value. An IVR is a structured, signed, identity-bound document capturing a single inference, the graded proof that it occurred, and the value independently committed against it.
Every IVR carries five primitives. The record is minted inside an AES-1 certified enclave, so issuance itself is trustless — no operator can mint an IVR the architecture does not permit. An IVR exists as an accounting record always; whether it can move is a separate question, answered in § 8.
The agent that produced the inference, identified by its AIS-1 DID. The bond is resolvable, so the accountable sponsor is reachable from the record.
A reference to the subject inference — typically an AAS-1 Class A action, or for high-value determinations an AAS-1 Class D determination.
An attestation at a stated tier, A0 through A3, with an evidence reference and a model identity hash. Graded, not binary.
One or more attributions, each citing a signal class, its components, the committing party's AIS-1 DID, and evidence of the commitment.
A signature over the canonicalised record — JCS (RFC 8785), SHA-256 — structurally identical to the AAS-1 signature object. Shared tooling across the stack.
The IVR is minted by an AES-1 certified contract. The enclave's certification tier is an input to the record's transfer tier — architecture bounds mobility.
| Attribute | Description | Required |
|---|---|---|
aivs | Standard version. "0.1". | Yes |
recordId | ULID or UUID, unique within the producer. | Yes |
producerRef | AIS-1 DID of the agent that produced the inference. | Yes |
subjectRef | URI of the subject inference — typically an AAS-1 Class A or Class D record. | Yes |
occurrence | Occurrence object: tier (A0–A3), evidence reference, model identity hash. | Yes |
mintingEnclaveRef | AES-1 Enclave Certificate reference of the contract minting this IVR. | Yes |
timestamp | RFC 3339 timestamp of issuance. RFC 3339 pins a single representation of an instant, so canonicalisation is deterministic. | Yes |
aas1RecordRef | URI of the AAS-1 Class A record emitted at IVR issuance. | Yes |
signature | Signature object over the canonicalised record. Structurally identical to AAS-1 § 6.3. | Yes |
| Attribute | Description | Required |
|---|---|---|
revealedValue | Array of revealed-value attributions. At least one required for any IVR above the A0 transfer tier. | Yes |
…[].signal | Signal class: insurance | bonded_stake | downstream_reliance | collateral. | Yes |
…[].components | The commitment as its constituent figures, never as a single derived scalar. For insurance: premium, per-occurrence limit, aggregate limit, deductible, period. Rate on line is left for the reader to compute. | Yes |
…[].committerRef | AIS-1 DID of the committing party: underwriter, bonding agent, relying party, collateral poster. | Yes |
…[].relatedParty | Whether committer and producer share a sponsor. Related-party attributions are disclosed on the record and excluded from tiering. | Yes |
…[].evidenceRef | URI to on-chain or attested evidence of the commitment — policy certificate, bond, agreement, collateral lock. | Yes |
valueClass | Capability or quality class of the inference, for comparability. Self-declared and AIS-1-bonded, or independently benchmarked — see open question 01. | Optional |
transferTier | Computed transfer tier (T0–T2) per § 8. Read-only; derived from occurrence tier and enclave tier. | Derived |
Producers know their costs. Buyers know their own situation. Neither knows what an inference is worth, and both have reason to say otherwise. AIVS-1 therefore takes its signal from a third position: the party who has put something at risk on the inference being correct.
The magnitude of consequence a party other than the producer commits — capital at risk, liability assumed, or reliance placed — contingent on the inference's correctness or outcome.
An underwriter prices the loss the inference could cause and commits capacity against it. AIVS-1 records the policy's components — premium, limits, deductible, period — from the AIPS-1 Policy Certificate, and collapses none of them into a single figure.
Capital bonded and slashable if the inference proves wrong. Where the bond is posted by someone other than the producer, it is the cleanest external signal in the set.
A relying party commits an action of stated magnitude on the strength of the inference — a payment released, a position taken, capital allocated. Reliance is consequence, and consequence is measurable.
Assets locked against the outcome by a party who loses them if it fails. The hardest of the four to interpret, the easiest of the four to verify.
Written cover leads because it is the cleanest instance and the one the standard can most readily demonstrate — but AIVS-1 does not depend on it. Where no underwriter is present, bonded stake, downstream reliance and posted collateral are same-class signals. Insurability is the example, not a load-bearing dependency of the definition.
Beneath revealed value sits the plainer question of whether the inference happened at all. No ledger can verify a frontier-model inference by re-execution: re-running costs as much as producing, and inference is non-deterministic across hardware, batch and precision. Occurrence is therefore established by attestation, and attestation is graded.
The ladder grades the strength of the occurrence proof. The value layer is unchanged regardless of which rung proved the inference — but the rung gates what the record is permitted to do (§ 8).
| Tier | Mechanism | Trust placed in | Status |
|---|---|---|---|
| A0 — Self | The producer signs a claim that the inference occurred. | The producer. Weak. | Specified |
| A1 — TEE | A trusted execution environment — SGX, Nitro, confidential-compute GPU — emits a hardware-signed attestation that the model ran in a sealed enclave. | Hardware and the manufacturer's attestation service. | Specified · practical now |
| A2 — Optimistic | The claim is assumed honest and is challengeable. A challenger forces re-execution under a fraud proof; the producer's stake is slashed if the claim was false. | Economics and the credible threat of challenge. | Reserved · v0.2 |
| A3 — Zero-knowledge | A succinct zero-knowledge proof that a specific model ran on a specific input, verified on-chain for negligible cost. | Mathematics only. | Reserved · roadmap |
In every tier the heavy inference happens off-chain and only the evidence is verified on-chain. That is the unavoidable shape of the problem. AIVS-1 does not claim to make proof of inference cheap or solved — it grades how strong the available proof is, and prices that into what the record may do.
An IVR exists as an accounting record in all cases — it can always be booked, audited and reported. Whether it can be assigned or pooled is a separate property, computed from the strength of its occurrence proof and the certification tier of the enclave that minted it. The transfer tier is derived and read-only: no issuer declares it.
A0 occurrence, or no revealed-value attribution, or an uncertified minting enclave. A valid accounting entry and nothing more. Not assignable.
A1 or above, at least one unrelated-party attribution, minted in an AES-1 Tier II Verified Enclave. Assignable to AIS-1-identified counterparties; the attribution travels with the record.
A1 or above with a written-cover or bonded-stake attribution, minted in an AES-1 Tier III Sovereign Enclave. Eligible for inclusion in a pool of agent receivables as a valuation and eligibility input.
valueClass, which is why its status is the load-bearing open question of this comment period.
// AIVS-1 — resolve, verify, and read the derived transfer tier const ivr = await aivs1.fetch(recordId); const producer = await ais1.resolve(ivr.producerRef); const enclave = await aes1.fetch(ivr.mintingEnclaveRef); // 1. Identity — the producer is bonded and the bond is live assert(verifySignature(ivr, producer.verificationMethod)); assert(ais1.verifyBond(producer.bondId).valid); // 2. Occurrence — the stated tier is evidenced, not merely stated assert(aivs1.evidenceSupportsTier(ivr.occurrence)); // 3. Attributions — external, evidenced, and not related-party const external = []; for (const rv of ivr.revealedValue) { assert(rv.committerRef !== ivr.producerRef); // not self-declared assert(await aivs1.evidenceResolves(rv.evidenceRef)); if (rv.signal === 'insurance') { assert(await aips1.certificateActive(rv.evidenceRef)); } if (!rv.relatedParty) external.push(rv); // circularity guard } // 4. Transfer tier is derived — recompute, never trust the field const tier = aivs1.deriveTransferTier(ivr.occurrence.tier, enclave.tier, external); assert(tier === ivr.transferTier); return { tier, attributions: external }; // components, not a scalar
AIVS-1 is the value layer of a family of CC0 standards. It borrows identity from AIS-1, subject records from AAS-1, trustless issuance from AES-1, and its lead signal from AIPS-1. Each binding strengthens the record; none is decorative.
revealedValue attribution, is identified by an AIS-1 DID with a resolvable bond. Shared sponsorship between the two is what the relatedParty flag detects. ais-1.org →insurance, the evidence is an AIPS-1 Policy Certificate and AIVS-1 reads its coverage scope — premium, limits, deductible, period — as components of the attribution. aips-1.org →Specification, the Inference Value Record, the revealed-value definition and its four signal classes, the A0–A3 attestation ladder, transfer tiering and stack composition. Published under CC0, open for public comment.
The Outcome Record: an immutable follow-on class referencing an IVR and recording what actually happened — whether the inference held, whether cover responded, whether reliance was vindicated. Staked against realised, across a producer's history, is what makes the record a track record rather than a snapshot. Published alongside the IVR JSON Schema 2020-12, test vectors, the A2 optimistic tier, and the reference minting-enclave contract.
Value-class benchmarking framework. Transfer-tier registry. Eligibility-criteria profile for admission of T2 records to a receivables pool, drafted against ARMS-1. Circular-attribution detection across sponsor graphs.
A3 zero-knowledge attestation profile. Conformance suite and reference verifier. Public IVR registry. Engagement with accounting-standard setters on recognition and measurement of agent inference activity.
The full technical working paper. The Cost-Proxy Problem, definitions, the Inference Value Record, revealed value and its four signal classes, the attestation ladder, IVR fields, transfer tiering, stack composition, security and regulatory considerations.
JSON Schema Inference Value RecordJSON Schema 2020-12 for the IVR. Core and value fields, the occurrence object, per-signal attribution components, related-party disclosure, derived transfer tier, and the shared signature object.
Worked Example A1 record with a written-cover signalAn illustrative IVR: a Class D determination attested in a confidential-compute enclave, attributed against an AIPS-1 Tier II Policy Certificate with premium and limits recorded as components, minted in an AES-1 Verified Enclave, resolving to transfer tier T1.
Repository github.com/Kadikoy1/aivs-1The canonical AIVS-1 repository. Specification, schema, worked examples, attestation-tier documentation, interoperability notes with the wider stack, and the contributing guide.
Feedback is invited from AI agent developers and infrastructure builders, insurers, reinsurers and actuaries, accounting and audit professionals, economists working on agent pricing and coalition value, structured-finance and securities practitioners, legal and regulatory professionals, standards organisations and government bodies. The comment period closes 31 December 2026. A revised v0.2 will incorporate substantive feedback.
valueClass remain self-declared and AIS-1-bonded, or require independent benchmarking before it may be relied on for comparability? Nothing pools on a self-declared class, so this question governs whether T2 has content.