Most AI safety today works like a security camera: it records what happened, flags what looks wrong, and helps people investigate afterward. This paper describes a new kind of vault door. It is intent-native. Every visitor declares who they are and what they intend, everything inside protects itself, and no one can do more than they are authorized to do, however they arrive.
AI systems are moving from answering questions to taking actions: sending messages, moving money, changing records, and controlling equipment. Most of the safeguards in use today watch and review. They tell you what happened after it happened. This paper argues that AI which acts also needs a safeguard that decides, before the action, whether it is permitted. It explains that difference without technical vocabulary, offers three questions anyone can put to an AI provider, and describes in plain terms how MindAptiv’s Essence® platform is built to decide before it acts.
Picture a bank with an excellent security camera system. Every angle is covered and every second is recorded. If someone walks out with the money, the footage will show who, when, and how.
That footage is valuable. It helps catch the thief, prove what took place, and improve the next security plan. It does not change one fact: the money has already left the building.
Most of the protections built around AI today work like that camera. They filter what a system produces after it produces it. They keep logs of what the system did. They flag unusual behavior for a person to look at. They test the system before release and audit it afterward. All of these are forms of detection. Detection is useful and it is not going away. But it answers only one question: what happened?
Modern cameras are not always passive. Many now use AI to recognize suspicious behavior and can raise an alarm the moment they see it. That is faster detection, and it is still detection. Such a system answers the question does this look wrong? by comparing what it sees to patterns, and the behavior has already begun by the time a pattern is recognized. Determination answers a different question: was this action declared and authorized?
Now picture the same bank with a vault door that will not open unless the right people, the right keys, and the right conditions are all present together. Skill does not change that, and neither does persuasion. The door does not review the theft. It decides whether the theft can happen.
That is determination: a decision made before the action, by rules that are fixed, visible, and applied the same way every time, rather than by a system judging what seems acceptable in the moment.
A conventional vault door has a weakness: once someone is through it, nothing limits what they do next. An intent-native vault removes that weakness. Intent-native means the system starts from declared intent instead of open access with rules added afterward. Essence® works like a bank where every visitor declares who they are and what they intend before anything happens, and is held to exactly what they are authorized to do, at every step, no matter how they arrived.
This also covers the insider. A person or system that already has legitimate access, such as an employee, a contractor, or an AI agent acting on their behalf, is held to the same test as everyone else: the action attempted must match what was declared and what that party is authorized to do. Being inside is not a permission, and a refused attempt is logged with a reason. An insider acting within genuine authorization is still limited by how narrowly the rules were written, which is why people remain the authors of the rules.
Cameras and vault doors work best together. The problem is a building that has only cameras.
Traditional software follows instructions a programmer wrote. If it did something wrong, there was a line of code to find. AI changes this in two ways.
First, AI systems increasingly act. A chatbot that only answers questions can give a bad answer. An AI system connected to your email, calendar, payments, or factory equipment can take a bad action, and an action has consequences that an answer does not.
Second, AI systems are increasingly connected to each other. One system’s output becomes the next system’s input, and the last one in the chain acts. Each link trusts the one before it. Nobody in the chain is responsible for asking whether the final action was permitted. Connecting ungoverned systems does not produce a trustworthy agent. It produces a pipeline.
These three questions work for any AI provider, whether the product is a chatbot, a hiring tool, a medical system, or a customer service agent. The answers separate a camera from a vault door.
MindAptiv builds a platform called Essence®. It is designed as an intent-native vault rather than a camera.
Most software is a list of step-by-step instructions written in a programming language. Essence® starts from something else: what a person or organization intends to happen. That intent is recorded in a precise form that a computer can check exactly. Two ideas do the work.
Meaning Coordinates. Chemistry has 118 elements, and every substance on earth is a combination of them. Essence® uses 256 basic units of meaning, such as create, move, measure, authorize, and restrict, as the equivalent building blocks for intent. Every request resolves to the same precise coordinates, so the system does not have to guess what a request means.
Synergy®. AI can still be used to suggest what to do. Synergy® is the part that decides what is permitted to run. It makes that decision before anything executes, applies fixed rules, and leaves a record that can be audited.
Aptivs. Everything inside this bank is an Aptiv. An Aptiv is a unit that carries what it does, why it does it, and the rules that govern it, all together. There are no separate files or databases sitting outside the structure. Because each Aptiv carries its own rules, each one protects itself and adapts as conditions change. Paper 11 explains why this, rather than counting AI agents, is the unit that scales.
StreamWeave®. StreamWeave® protects every Aptiv with encryption designed for a post-quantum world, meaning it is built to stay secure even when quantum computers arrive. It is also an active defense. It uses many different encryption methods together, and the combination changes every time an Aptiv is touched. An attacker who breaks one exchange cannot reuse what was learned on the next.
A fair objection: AI agents can now operate the same screens, buttons, and logins that people use, and they do it faster than any person. If an agent can do anything a person can do at a screen, what could stop it?
The objection is correct in one case. When an AI agent is handed the controls, meaning a logged-in account, a browser, or a set of credentials, it can do whatever that account can do. Watching from the outside does not change that. It only records what the agent did.
So the answer is not a better way to watch. The answer is not to hand over the controls. In the bank, the AI is a customer at the counter. It fills out a request slip saying what it wants to happen, and it never touches the vault or the ledger. A separate governed layer receives the request, checks who declared it, what it intends, and what that party is authorized to do, and then carries it out or refuses.
Two parts of Essence® establish who is asking and what they may do. SecuriSync™ handles identity. It confirms who is on the other end using keys and a set of registered devices rather than a single credential, so compromising one device is not enough to take over an identity. It issues trust certificates that expire and can be revoked, and a revocation reaches everyone who relies on the certificate immediately. Nebulo® handles rights. Each piece of data carries its own rules about who may see it, change it, or even know it exists, and those rules are evaluated at the moment of access instead of being reused from an earlier answer. In the bank’s terms, SecuriSync™ is how the bank knows who you are, and Nebulo® is the set of rules attached to every item inside, so each item decides who may touch it.
There is one honest limit. The protection covers what runs through the governed layer. Systems that are not connected to it are as exposed as they were before, and an AI that holds its own access to them sits outside the design. That is why the design withholds the controls from the AI to begin with.
Determination does not make AI perfect, and it does not replace cameras. Detection still matters for learning and accountability.
The rules behind a vault door must be written, reviewed, and owned by people. Essence® is designed so that humans remain the authors of what machines are permitted to do.
MindAptiv is deploying this architecture. The independent evaluations cited elsewhere in this series measured speed and energy use. The governance claim in this paper rests on how the system is built, which the technical papers describe in detail.
AI that acts needs both. When someone offers you an AI system, ask which one you are being given.
Read the Series → Request Access