Scottsdale, Ariz. – September 11, 2026 -- ChainIT has released "Provable Compliance: A Protocol for Runtime Compliance Evidence and Transaction-Specific Decisioning," a technical white paper designed to stop AI agents from executing financial transactions based on outdated compliance checks.
ChainIT targets a gap in agentic commerce where old approvals become permanent authority to move money
The protocol addresses scenarios where an AI agent holds valid authorization to pay an approved vendor but must be halted mid-transaction because underlying conditions have changed. A sanctions record may have been updated, a destination account may be new, a license may no longer meet policy, or an institution-generated alert may require review, according to the company.
The system issues time-stamped, single-use Compliance Decision tokens instead of standing approvals
ChainIT's architecture relies on modular Evidence Assertion VDTs (Validated Data Tokens) that record source class, provenance, observation time, confidence level, permitted purpose and privacy classification for each compliance fact. A versioned Compliance Policy Profile determines which requirements apply, while the ChainIT Business Rules Engine generates reason-coded predicates. The organization's Workflow Engine then issues a signed Compliance Decision VDT carrying one of eight dispositions: Allow, Allow with Controls, Step-Up, Review, Hold, Reject, Prohibit or Stale/Unknown.
CEO Jeremy Blackburn says machine-speed operations compress the window for compliance evaluation
"Agentic commerce does not eliminate compliance requirements; it compresses the time available to evaluate them," said Jeremy Blackburn, Chief Executive Officer of ChainIT. He said AI agents should not rely on checks performed weeks or months earlier, and a single favorable result should never convert into standing authority to transfer funds.
Compliance approval is treated as one input, not a final green light for payment
A final "Allow" disposition in a Compliance Decision VDT feeds into the separate ChainIT Authority Protocol rather than granting payment authority outright. Before value moves, the system must still verify identity, ARP authority, scope, approvals, capacity, the exact transaction digest and a valid single-use execution credential.
Chief Compliance Officer Russell Lessard says compliance status cannot function as a permanent badge
"Compliance is not a permanent badge that follows a person, business or AI agent everywhere," said Russell Lessard, Chief Compliance Officer of ChainIT. He noted that sanctions screening, AML monitoring, PEP risk assessment, identity assurance, licensing and beneficial-ownership requirements each operate under different rules, and a proposed action may be allowed, restricted, held or prohibited depending on current evidence, jurisdiction and policy.
The framework builds on last week's Provable Authority paper within ChainIT's Transaction Truth architecture
Together, the two white papers define the ChainIT Authority Protocol and ChainIT Compliance Protocol as components of ChainIT Transaction Truth, the company's zero-trust control and evidence architecture. Identity establishes who is present, Authority determines who or what may act and within what bounds, and Compliance determines whether current evidence and policy permit the action now.
ChainIT positions the protocol for financial institutions, stablecoin issuers and marketplaces evaluating AI-initiated activity
The company said the framework targets financial institutions, payment companies, stablecoin issuers, marketplaces, technology providers and enterprises evaluating actions initiated by people, organizations, automated workflows and AI agents. ChainIT stated the protocol does not replace a regulated institution's AML/CFT or sanctions program and does not create a universal legal determination, but instead functions as an evidence-and-decision layer that integrates with existing institutional policies and execution controls.