1
00:00:00,000 --> 00:00:05,520
Imagine a worker in your AI workflow

2
00:00:05,520 --> 00:00:08,160
returns a corrupted result.

3
00:00:08,160 --> 00:00:11,760
The important question is, what happens next?

4
00:00:11,760 --> 00:00:13,440
Which decision changed, which boundary

5
00:00:13,440 --> 00:00:16,240
was crossed and can useful work recover?

6
00:00:16,240 --> 00:00:18,200
Antigense Daisy starts with a device

7
00:00:18,200 --> 00:00:20,560
and keeps that incident inspectable.

8
00:00:20,560 --> 00:00:22,800
ChatGPT/OpenAI orchestrates; Claude works

9
00:00:22,800 --> 00:00:25,120
in an independent execution lane.

10
00:00:25,120 --> 00:00:27,520
This demonstration injects a software fault

11
00:00:27,520 --> 00:00:30,480
[This is a software-injected fault, not a physical hardware failure.]

12
00:00:30,480 --> 00:00:33,280
The integrity check detects changed bytes,

13
00:00:33,280 --> 00:00:38,400
but a teaching fixture reveals an unsafe fallback.

14
00:00:38,400 --> 00:00:42,720
Failed worker health allows an unauthorized request.

15
00:00:42,720 --> 00:00:45,200
Semgrep identifies that fallback.

16
00:00:45,200 --> 00:00:48,000
Our pinned repair rejects unauthorized requests

17
00:00:48,000 --> 00:00:50,560
while preserving healthy authorized work.

18
00:00:50,560 --> 00:00:54,160
AI advice has no authority to apply a patch.

19
00:00:54,160 --> 00:00:55,920
Each step has a custody address,

20
00:00:55,920 --> 00:00:57,680
as the replay advances.

21
00:00:57,680 --> 00:00:59,360
You can inspect the recorded output,

22
00:00:59,360 --> 00:01:01,680
checks, and Merkle commitments.

23
00:01:01,680 --> 00:01:04,160
The browser independently recomputes the proof.

24
00:01:04,160 --> 00:01:05,600
Integrity preserves the record.

25
00:01:05,600 --> 00:01:08,480
It does not prove that everything is true.

26
00:01:08,480 --> 00:01:11,600
ClickHouse stored eleven checkpoints

27
00:01:11,600 --> 00:01:13,040
from the same incident.

28
00:01:13,040 --> 00:01:15,280
We replayed the insertion and read back

29
00:01:15,280 --> 00:01:16,960
exactly the same records.

30
00:01:16,960 --> 00:01:21,600
The measured readback query took about 161 milliseconds.

31
00:01:21,600 --> 00:01:24,160
Akash now runs the analysis workload.

32
00:01:24,160 --> 00:01:26,560
Our agent created a GPU deployment,

33
00:01:26,560 --> 00:01:28,640
selected a lease and loaded Qwen.

34
00:01:28,640 --> 00:01:31,520
It returns structured advice about the unsafe fallback

35
00:01:31,520 --> 00:01:33,760
in about three and a half seconds.

36
00:01:33,760 --> 00:01:35,520
The model's advice remains untrusted

37
00:01:35,520 --> 00:01:37,840
and cannot authorize a patch.

38
00:01:37,840 --> 00:01:39,520
This is a separate custody branch.

39
00:01:39,520 --> 00:01:42,480
All 11 leaves verify, including the closed request,

40
00:01:42,480 --> 00:01:43,840
which returned success.

41
00:01:43,840 --> 00:01:46,160
The server reported GPU memory use,

42
00:01:46,160 --> 00:01:48,880
but we do not claim hardware attestation.

43
00:01:48,880 --> 00:01:52,160
[We do not claim] a verified final closed state or measured cost savings.

44
00:01:52,240 --> 00:01:54,720
Earlier failures remained in the record.

45
00:01:54,720 --> 00:01:57,120
On Magic Pro, OS polling is live.

46
00:01:57,120 --> 00:02:00,000
On the public website, this is a recorded replay.

47
00:02:00,000 --> 00:02:02,240
Lower troubleshooting and inference costs

48
00:02:02,240 --> 00:02:04,560
are goals we still need to measure.

49
00:02:04,560 --> 00:02:07,200
Credentials and proprietary internal state stay private.

50
00:02:07,200 --> 00:02:10,480
Original explanatory content carries our attribution,

51
00:02:10,480 --> 00:02:13,520
non-commercial, and no derivatives notice.

52
00:02:13,520 --> 00:02:15,840
Antigense makes the path from error to recovery

53
00:02:15,840 --> 00:02:19,120
easier to inspect, including where the system still needs work.

