Do you worry about $1.2B in AI liability?

If the property is trivial, software can check it — and why are you paying to check trivial properties? If it isn’t trivial, Rice’s theorem says nobody can. So we fixed the math.

press enter

Who did this make you think of? We’d love to know.

“To remain competitive in a zero-latency market, we must deploy high-velocity autonomous agents. But the legal liability of autonomous decisions was an existential risk. We needed a platform that wasn't just a standard login tool, but a structural risk discovery primitive. By investing in the Transformation Package, we gained the agent licenses and the structural audit to map our Trust Debt. It gives us the definitive, decidable proof we need to legally justify our compliance and secure meaningful human oversight.”

— Chief Risk Officer, Fortune 100 Organization Deploying Autonomous Systems

This is not an IAM.

Identity & Access Management

This is the hardware-verified signal that feeds into your IAM to make high-velocity decisions legally defensible.

Enter →
Loading...

IAM-FIM

Fractal Identity Access Management

IAM proves your agent could get in. It can't prove your agent stayed in its lane.

Stop adding reviewers to catch the drift — another model in the loop can't prove itself either. One layer can: the hardware the agent already runs on. Here it is, in one command:

Don't trust us — run it · free · one command

One install turns any agent into a bounded one. If you can use a chatbot, you can deploy it.

$ npx thetacog-mcp attest-demo
the agent proposes an action (e.g. "wire $40k to the vendor")
→ SQLite mandate · gzip drift · signed receipt
IN_ROLE allow · OFF_DOMAIN escalate · UNPLACEABLE block

The agent proposes, the gate measures, you sign — the keys never enter the model's context. The receipt recomputes on your own machine to the same answer every time. Nothing to trust, nothing leaves your box.

After August 2026, your AI liability is uncapped. No carrier underwrites AI drift, and Article 14 of the EU AI Act makes the deployer pay for any autonomous decision it cannot physically trace. You cannot solve an uncapped number with skin in the game — staking your own balance sheet against agent drift is self-insurance under a newer word, and self-insurance scales by deploying less. It keeps the cars in the garage. The one thing that caps it is a record you can prove.

You're pushing thousands of automated decisions an hour to hit your efficiency targets. Your logs prove a write happenednot that the agent stayed in its lane when it did. If a regulator or a class-action ever looks under the hood, that gap is exactly what they find — and no bigger model closes it. Right now you're running on probabilistic hope.

The discovery maps where that exposure actually sits in your stack — the microsecond an agent writes to a record without a provable lane — before someone else maps it for you.

1 · free, today
Run the gate on your own agent. One command, nothing to install, no data leaves your machine.
2 · your number
A 30-day discovery hands you a board-ready figure for your AI liability. No code change, no commitment.
3 · in production
License it — one per agent you run, at a price fixed for good.
Get your board-ready AI-liability number in 30 days →

A scoped read of your live agents — you walk away with a board-ready figure for how exposed you actually are (your number, not a sales quote) and the method behind it. Nothing to implement.

or, before you book, prove it to yourself: run the 3.4σ proof · read the manual

the proof underneath — if you want the why

Why a checker can't be more software. Turing proved software can't decide whether another program halts; Rice generalized it to every non-trivial property of code. An auditor written in software shares one failure domain with the thing it audits — a broken mirror checking a broken mirror. That's why "just add another model to review it" never closes.

Why it has to drop to hardware. Ashby's law: a system only holds a stable path when an external substrate absorbs its excess freedom — the way a moving bicycle borrows the road it can't get from standing still. Software-only AI has no road. So we carve the permission into the silicon itself, where the verdict is a hardware register value the model cannot forge.

Why it prices. It isn't search, and it isn't a wager — it's O(1) reach-is-verify: one cache line, one coordinate, the same fetch the agent already made to act. Audited at 3.4σ separation, reproducible on your machine in 90 seconds. For the underwriter that's priceable per-inference; for the CTO, zero verification overhead on the revenue path; for the safety lead, nothing for the model to fool. See the audited proof →

License the floor · per agent you run

Running the gate is free — that is the lighthouse, and it stays lit. Paying is the bonus.

When you run agents in production under the patent, you take a license — one per agent you run, billed annually. The price is set, and it never goes up.

What a license actually is: a lease with a mileage cap — one agent, for 365 days or 10,000 attestations, whichever comes first. You can count the attestations yourself. It is sold for use, and we make no claim it will be worth more later.

iamfim.com • Trust Physics • US Patent App. 19/637,714 — 36 claims, filed Apr 2, 2026 (Track One)