nti-spec

NTI-1: Neutral Trust Infrastructure — Standard 1

Version: 1.0.0-draft Status: Draft for public comment Published: 2026


Table of Contents

  1. Introduction
  2. Definitions
  3. The 5 Pillars
  4. Compliance Levels
  5. Testable Requirements
  6. Reference Implementation
  7. Certification Process
  8. Governance
  9. Security Considerations
  10. Appendix

1. Introduction

1.1 Purpose

This specification defines the requirements for Neutral Trust Infrastructure (NTI-1), a standard for cryptographically verifiable governance of autonomous AI agents.

As AI agents transition from passive assistants to active executors of real-world actions — transferring funds, modifying infrastructure, accessing sensitive data — the need for a formal, auditable trust standard becomes critical. NTI-1 defines what such a standard requires.

1.2 Scope

NTI-1 applies to any system in which an autonomous AI agent:

1.3 Motivation

Three converging forces make NTI-1 necessary:

  1. Regulatory pressure. NIST, the EU AI Act, and India DPDP Act are increasingly mandating verifiable AI governance.

  2. Post-quantum urgency. NIST has mandated migration to post-quantum cryptography (PQC). Agent identity must be PQC-compliant from day one.

  3. Threat landscape. Prompt injection, hallucinated actions, and rogue agents are now the primary vectors of AI-driven harm.

1.4 Design Principles

NTI-1 is designed around four principles:


2. Definitions

The keywords MUST, MUST NOT, SHOULD, SHOULD NOT, and MAY are to be interpreted as described in RFC 2119.


3. The 5 Pillars

3.1 Pillar 1: Identity

Requirement: Every agent MUST have a unique, cryptographically verifiable identity.

Specification:

Rationale: Without cryptographic identity, no downstream verification is possible. Post-quantum schemes are mandatory because classical schemes (RSA, ECDSA) will be broken by quantum computers.


3.2 Pillar 2: Governance

Requirement: Every agent action MUST be evaluated against a capability policy before execution.

Specification:

Rationale: Zero-trust means no implicit trust. Every action must be explicitly authorized.


3.3 Pillar 3: Consensus

Requirement: In multi-agent systems, decisions affecting high-value actions MUST require Byzantine Fault Tolerant consensus.

Specification:

Rationale: In multi-agent systems, one rogue agent must not be able to trigger high-value actions alone.


3.4 Pillar 4: Audit

Requirement: Every evaluated action MUST be recorded in a tamper-evident audit trail.

Specification:

Rationale: Regulators and auditors require proof of what happened, in what order, and that nothing has been altered.


3.5 Pillar 5: Persistence

Requirement: Agent state and audit trails MUST persist across restarts with self-verifying integrity.

Specification:

Rationale: Without persistence, audit trails can be reset by simply restarting the system, defeating the purpose of Pillar 4.


4. Compliance Levels

4.1 Level 1: Basic

4.2 Level 2: Standard

4.3 Level 3: Enterprise


5. Testable Requirements

Each requirement below is testable by a third party.

5.1 Identity Tests

5.2 Governance Tests

5.3 Consensus Tests

5.4 Audit Tests

5.5 Persistence Tests


6. Reference Implementation

The reference implementation is ube-foundation, available at:

Framework integrations:

Alternative implementations are permitted and encouraged under the CC-BY-4.0 license terms.


7. Certification Process

7.1 Self-Assessment

Implementers MAY self-assess against this specification.

7.2 Third-Party Certification

For formal NTI-1 certification:

  1. Implement all applicable pillar requirements.
  2. Pass all testable requirements in Section 5.
  3. Submit a certification request to the NTI Foundation.
  4. Complete a third-party audit.
  5. Receive certification valid for 12 months, renewable.

7.3 Public Registry

Certified implementations will be listed in the NTI Registry (forthcoming).


8. Governance

8.1 Steward

The NTI-1 specification is stewarded by the NTI Foundation.

8.2 Amendments

Proposed changes are submitted as RFCs in the rfcs/ folder. Amendments require public comment and a 30-day review period.

8.3 Versioning

Specification versions use semantic versioning:

8.4 Neutrality

The NTI-1 standard MUST remain neutral. It MUST NOT favor any single vendor, platform, or jurisdiction.


9. Security Considerations

9.1 Quantum Threat

Classical signature schemes will be broken by sufficiently large quantum computers. NTI-1 mandates PQC from day one to avoid a costly migration later.

9.2 Side-Channel Attacks

Implementations SHOULD protect private keys against side-channel attacks via constant-time operations and, at Level 3, HSM storage.

9.3 Replay Attacks

Action requests MUST include a unique identifier (UUID) and timestamp to prevent replay.

9.4 Denial of Service

Verifiers MUST rate-limit request processing and MUST NOT block the audit chain under load.

9.5 Multi-Agent Collusion

BFT consensus (Pillar 3) is designed to resist up to f < n/3 malicious agents.


10. Appendix

10.1 Acknowledgements

This specification builds on decades of work in cryptography, distributed systems, and AI safety. It is offered as a neutral foundation for a global trust layer.

10.2 Feedback

Feedback is welcome at: https://github.com/abisheakp197/nti-spec/issues


End of Specification — Version 1.0.0-draft