Gwirio Gwirio
Solutions

AI & Autonomous Transactions

Give AI systems the information and authority they need to act

AI systems are moving beyond answering questions. They are increasingly making decisions, accessing information, interacting with other systems and taking actions on behalf of people and organisations.

Gwirio helps organisations establish what an AI system can rely upon, what it is authorised to do, and what evidence exists when it acts.

This extends Gwirio's existing approach to identity, information rights, certificates and authority into a world where decisions and transactions may happen without a person reviewing every step.

Gwirio is not competing with AI. Gwirio provides the trust controls around what AI is allowed to do.

Why

Traditional digital systems were largely built around:

People→Systems→People

We are now moving rapidly towards:

People→Systems→Systems→Systems→People, Products & Risk

An AI agent may access information from several systems, make a decision and initiate an action in seconds.

The technical ability to do something does not mean that the system should do it.

An organisation needs to be able to establish:

Who does the AI system represent?

What information can it access?

What information can it rely upon?

What is it authorised to do?

Who gave it that authority?

For what purpose?

Are there limits or conditions?

When does that authority expire?

Can the authority be withdrawn?

What happened when the system acted?

Authentication answers who or what the system is.

It does not necessarily answer whether the system should be trusted to perform a particular action.

What Gwirio provides

Gwirio can provide the trust infrastructure around AI systems and autonomous transactions. This can include:

Identity

Establish the identity of the AI system, agent or organisation it represents.

Delegated authority

Record what a person or organisation has authorised an AI system or agent to do.

Information rights

Establish what information the system can access and process, and the basis on which it can do so.

Trusted information

Provide verified information and certificates that an AI system can rely upon when making a decision.

Conditions and limits

Define the scope, purpose, conditions and duration of an authority.

Revocation

Provide a mechanism for authority or rights to be withdrawn when circumstances change.

Evidence

Maintain evidence of the authority, information and conditions associated with an action.

From capability to authority

An AI system may technically be capable of:

Accessing information→making a decision→taking an action

Gwirio adds the questions that should come before that action:

Is it authorised?

Can it rely on this information?

Is this within its permitted scope?

Does the authority still apply?

Can we establish what happened afterwards?

This creates a distinction between what an AI system can do and what it is trusted and authorised to do.

How it works

Establish identity
Identify the AI system, agent, organisation or person it represents.
↓
Establish authority
Define what the system has been authorised to do and on whose behalf.
↓
Establish information rights
Determine what information it can access, use and rely upon.
↓
Verify the information
Use trusted information and certificates where the decision requires information from another authoritative source.
↓
Check before acting
The relevant authority, conditions and information rights can be checked before an action is permitted.
↓
Record the evidence
Maintain evidence of what authority and information the system relied upon and what action was taken.
Identity→Authority→Information→Permission→Action→Evidence

What value does this provide?

Safer automation

Allow AI systems to act within defined boundaries rather than relying solely on technical access controls.

Controlled delegation

Give AI systems authority to act on behalf of people and organisations without giving them unrestricted access.

Better information governance

Ensure AI systems do not automatically gain access to information simply because a technical connection exists.

Greater accountability

Establish who authorised an action, what the system was permitted to do and what information it relied upon.

Reduced risk

Limit the potential impact of an AI system acting outside its intended purpose or authority.

Support for autonomous transactions

Provide the trust controls needed when systems begin interacting and transacting directly with other systems.

Where it can be used

AI agents

Define what an agent can access and what actions it can take on behalf of a person or organisation.

Automated payments

Establish authority and conditions before an AI system initiates or approves a payment.

Procurement

Allow an AI system to purchase goods or services within defined authority and spending limits.

Customer service

Allow AI systems to access customer information and take actions within defined permissions.

Fraud and risk

Allow automated systems to obtain and rely upon verified information before making a risk decision.

Machine-to-machine transactions

Establish identity, authority and permitted actions when systems transact without direct human involvement.

Business processes

Allow AI systems to perform defined tasks while maintaining evidence of the authority under which they acted.

The opportunity

The objective is not to prevent AI systems from acting.

It is to make autonomous action more controlled, more transparent and more accountable.

As more decisions move from people to systems, organisations will need to establish not only whether a system is connected, but whether it can be trusted to perform a particular action.

Gwirio provides the infrastructure to help establish that trust.

Discuss an AI & Autonomous Transactions pilot

Related

Continue reading

AI Trust (BOK)

The underlying concepts in full.

Delegated Authority (BOK)

What it means for an AI agent to act within delegated authority.