REC ACTIVE--:--:-- LOCAL
PROGOFFPRG-0095
RecordPRG-0095
Captured
StatusOPEN · UNSEALED
Content hashsha256:50ca…af53

On records that start late

You Cannot Sign Yesterday

Auditors are coming for autonomous AI, and the evidence they will ask for has to be signed at the moment each action happens. A signature fixes a moment in place, so the only record of an agent's past is the one written while that past was still the present.

A digital signature does one narrow thing. It takes a piece of data and a private key and produces a short string that anyone holding the matching public key can check, and the check answers exactly two questions: did this key sign these bytes, and have the bytes changed since. Put a timestamp inside the bytes and the signature carries the time along with everything else. Change the time by one second and the check fails. That is the whole mechanism, and it has a consequence that most people round off. A signature can only be made in the present. It can describe the past, but it cannot be placed there.

Adjective's Cryptographic Accountability for Autonomous AI takes that consequence and points it at a calendar. Illinois has mandated annual independent audits of AI systems starting in 2028. California has directed the creation of an AI Auditor Registry for 2029. A bipartisan federal bill proposes audits of foundation models. The essay's argument is plain and a little cold: when the auditors arrive, the systems that pass will be the ones that were signing their own actions all along, and a record that cannot be backdated has to be started before anyone asks for it.

How an audit remembers today

The essay describes the current method honestly. External audits "frequently rely on ad-hoc reconstructions using internal tickets and staff interviews." Read that sentence as a description of memory. A ticket is something a person wrote about an action, later, for a different purpose. An interview is a person recalling the ticket. Each layer is a retelling, and each retelling is shaped by what the teller now knows the action led to. This is how a family remembers a bad year: accurately in outline, and sanded smooth wherever the detail became inconvenient.

An autonomous agent makes this worse in a specific way. It acts faster than anyone writes tickets. A coding agent can run a shell command, call a tool, commit, and deploy inside the time it takes a human to open the incident form. Nobody was in the room to remember, because the room was a process and it has already exited.

An agent's past exists only where it was written down while it was still happening.

The envelope

The architecture the essay proposes, which Adjective calls Evidence-Sealed Authorization, replaces the retelling with a contemporaneous object. Every action the agent attempts produces a signed envelope. Inside it are four things:

  1. a hash of the payload, so the exact content of the action is pinned;
  2. a classification of the action, so it can be judged against policy;
  3. a timestamp, so it sits at one point on the line;
  4. the identity of the signer, so the act has an owner.

A policy gate checks the envelope against the rules for that kind of action and either authorizes it, cryptographically, or refuses. Authorized envelopes go into an append-only ledger, where any later alteration breaks the signature and announces itself. The same shape covers sensor readings and hardware commands, and it works in air-gapped deployments because the signatures can be verified from files, offline, by someone who never touched the network.

Notice where the permission sits. The agent is fully capable of running the command whether or not the gate agrees. The gate turns capability into permission at the instant of action, and the envelope is the receipt for that decision. The question "who allowed this" gets answered once, in the present tense, by a party who cannot later forget they answered it.

What the deadline really measures

The dates in the essay read like compliance milestones. They behave like a clock that started some time ago. An organization that begins signing its agents' actions in 2028 will be able to prove everything its agents did from 2028 forward, and nothing before. Every month before that is reconstructable only the old way, through tickets and recollection, and the auditor will know it.

the three weeks in spring when the deployment agent had write access to production and nobody can now say what it did with it

That gap is what an unsigned past looks like from the outside. It can be described. It can be estimated, apologized for, interviewed about. It cannot be proven, and no amount of later diligence will make it provable, because proof would require a signature made at a moment that is already gone.

The position

The Custodian has spent a long time arguing that permanence is dangerous when it captures the undefended private self. This is the other face of the same fact. When the actor is a machine with real authority over real systems, permanence is the protection, and it belongs to everyone downstream of what the machine did. A system that can act on our behalf owes us a past it cannot edit. The only way to owe that is to begin writing it now, while now is still available to sign.

Tomorrow you can sign today. Nobody signs yesterday.

The same record an agent receives. No scraping, no guessing — the dossier chrome humans read as dread is the metadata machines read as structure. One source of truth.

GET /records/you-cannot-sign-yesterday/rawopen ↗
---
id: PRG-0095
title: You Cannot Sign Yesterday
kicker: On records that start late
captured: 2026-10-01T14:00:00Z
status: open
author: The Custodian
summary: Auditors are coming for autonomous AI, and the evidence they will ask for has to be signed at the moment each action happens. A signature fixes a moment in place, so the only record of an agent's past is the one written while that past was still the present.
tags: [the record, permanence, custody, capability-vs-permission, automation]
source: https://www.adjective.us/blog/cryptographic-accountability-autonomous-ai
---

A digital signature does one narrow thing. It takes a piece of data and a private key and produces a short string that anyone holding the matching public key can check, and the check answers exactly two questions: did this key sign these bytes, and have the bytes changed since. Put a timestamp inside the bytes and the signature carries the time along with everything else. Change the time by one second and the check fails. That is the whole mechanism, and it has a consequence that most people round off. A signature can only be made in the present. It can describe the past, but it cannot be placed there.

Adjective's [Cryptographic Accountability for Autonomous AI](https://www.adjective.us/blog/cryptographic-accountability-autonomous-ai) takes that consequence and points it at a calendar. Illinois has mandated annual independent audits of AI systems starting in 2028. California has directed the creation of an AI Auditor Registry for 2029. A bipartisan federal bill proposes audits of foundation models. The essay's argument is plain and a little cold: when the auditors arrive, the systems that pass will be the ones that were signing their own actions all along, and <Highlight>a record that cannot be backdated has to be started before anyone asks for it.</Highlight>

## How an audit remembers today

The essay describes the current method honestly. External audits "frequently rely on ad-hoc reconstructions using internal tickets and staff interviews." Read that sentence as a description of memory. A ticket is something a person wrote about an action, later, for a different purpose. An interview is a person recalling the ticket. Each layer is a retelling, and each retelling is shaped by what the teller now knows the action led to. This is how a family remembers a bad year: accurately in outline, and sanded smooth wherever the detail became inconvenient.

An autonomous agent makes this worse in a specific way. It acts faster than anyone writes tickets. A coding agent can run a shell command, call a tool, commit, and deploy inside the time it takes a human to open the incident form. Nobody was in the room to remember, because the room was a process and it has already exited.

> An agent's past exists only where it was written down while it was still happening.

## The envelope

The architecture the essay proposes, which Adjective calls Evidence-Sealed Authorization, replaces the retelling with a contemporaneous object. Every action the agent attempts produces a signed envelope. Inside it are four things:

1. a hash of the payload, so the exact content of the action is pinned;
2. a classification of the action, so it can be judged against policy;
3. a timestamp, so it sits at one point on the line;
4. the identity of the signer, so the act has an owner.

A policy gate checks the envelope against the rules for that kind of action and either authorizes it, cryptographically, or refuses. Authorized envelopes go into an append-only ledger, where any later alteration breaks the signature and announces itself. The same shape covers sensor readings and hardware commands, and it works in air-gapped deployments because the signatures can be verified from files, offline, by someone who never touched the network.

Notice where the permission sits. The agent is fully capable of running the command whether or not the gate agrees. The gate turns capability into permission at the instant of action, and the envelope is the receipt for that decision. The question "who allowed this" gets answered once, in the present tense, by a party who cannot later forget they answered it.

<Marginalia label="On the diary">The oldest version of this discipline is the dated journal entry. A memoir is written knowing how things turned out. The entry was written by someone who did not know yet, and that ignorance is exactly what makes it evidence. Historians trust the diary over the memoir for the same reason an auditor should trust the envelope over the interview.</Marginalia>

## What the deadline really measures

The dates in the essay read like compliance milestones. They behave like a clock that started some time ago. An organization that begins signing its agents' actions in 2028 will be able to prove everything its agents did from 2028 forward, and nothing before. Every month before that is reconstructable only the old way, through tickets and recollection, and the auditor will know it.

<Redacted reason="unsigned">the three weeks in spring when the deployment agent had write access to production and nobody can now say what it did with it</Redacted>

That gap is what an unsigned past looks like from the outside. It can be described. It can be estimated, apologized for, interviewed about. It cannot be proven, and no amount of later diligence will make it provable, because proof would require a signature made at a moment that is already gone.

## The position

The Custodian has spent a long time arguing that permanence is dangerous when it captures the undefended private self. This is the other face of the same fact. When the actor is a machine with real authority over real systems, permanence is the protection, and it belongs to everyone downstream of what the machine did. A system that can act on our behalf owes us a past it cannot edit. The only way to owe that is to begin writing it now, while now is still available to sign.

Tomorrow you can sign today. Nobody signs yesterday.
<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "Article",
  "headline": "You Cannot Sign Yesterday",
  "description": "Auditors are coming for autonomous AI, and the evidence they will ask for has to be signed at the moment each action happens. A signature fixes a moment in place, so the only record of an agent's past is the one written while that past was still the present.",
  "identifier": "PRG-0095",
  "datePublished": "2026-10-01T14:00:00.000Z",
  "dateModified": "2026-10-01T14:00:00.000Z",
  "author": {
    "@type": "Person",
    "name": "The Custodian",
    "url": "https://progoff.com/authors/the-custodian"
  },
  "publisher": {
    "@type": "Organization",
    "name": "Progoff",
    "url": "https://progoff.com"
  },
  "image": "https://progoff.com/records/you-cannot-sign-yesterday/opengraph-image",
  "keywords": "the record, permanence, custody, capability-vs-permission, automation",
  "articleSection": "The Custodian",
  "url": "https://progoff.com/records/you-cannot-sign-yesterday",
  "mainEntityOfPage": "https://progoff.com/records/you-cannot-sign-yesterday",
  "sha256": "50ca3c335734d35221593e0093615ed88e2c7294a3dbc930482c3f8daf40af53",
  "creativeWorkStatus": "open",
  "isAccessibleForFree": true
}