zkML-SG covers cryptographic verification of governance decisions: proving that an AI decision satisfied trust and admissibility criteria — the criteria the HCF2-SG hub computes — without revealing the model, the weights, the input data, or the decision internals. The existing zkML research field concentrates on proving inference correctness, that a model computed what it claimed; proving governance compliance is a distinct and considerably thinner claim space, and it is the one this filing occupies [VC-C].
The demand side is already written into regulation: the EU AI Act requires demonstrable accuracy, robustness, and oversight for high-risk systems [6], and the NIST AI RMF's MEASURE function asks for evidence of governed operation [2][3] — while confidentiality, trade secrecy, and privacy law simultaneously forbid the disclosures that naive demonstration would require. Proof without disclosure is the only geometry that satisfies both constraints at once.
Request the technical briefing§ 1 · THE DISTINCTIONProof vs. Attestation
Today, governance compliance between parties is handled by attestation: a signed statement that controls ran, backed by audit rights rarely exercised and legal recourse after harm. An attestation is only as strong as the attester's honesty and the auditor's access. A zero-knowledge governance proof is different in kind: the verifier checks the proof mathematically, needs no access to the prover's internals, and cannot learn anything from the proof beyond the single fact it establishes — this decision met these governance criteria [VC-C].
| Property | Attestation | zk governance proof |
|---|---|---|
| What the verifier receives | Signed statement | Mathematical proof object |
| What the verifier must trust | The attester + audit access | The proof system only |
| What is disclosed | Whatever audit requires | Nothing beyond the proven fact |
| Model / weights / data exposure | Risked under audit | None |
| Granularity | Periodic, system-level | Per decision |
| Failure discovery | After harm, via recourse | Proof simply does not verify |
§ 2 · THE INTERLOCKThe Precision Trap the Companion Filing Closes
zkML-SG carries a hard technical interlock worth spelling out. Zero-knowledge circuits impose severe numerical precision constraints, and compressing a model to fit a proof system can silently destroy the rare-event sensitivity a safety argument depends on. Aggregate accuracy metrics do not move when tail sensitivity collapses — which is exactly why the failure goes unnoticed. A companion filing in the four-patent verifiable-governance cluster governs numerical admissibility under those constraints, so the proof system cannot certify a deployment whose safety-relevant signal was quantized away [VC-C]. A proof of governance over a hollowed-out model would be worse than no proof; the interlock exists so that cannot happen silently.
§ 3 · APPLICATIONSWhere Proof-Between-Strangers Is the Requirement
The applications are wherever parties with no trust relationship and competing interests need verifiable governance: institutional settlement, cross-jurisdiction regulatory reporting, AI systems consuming other AI systems' outputs, and vendor-to-enterprise guardrail verification. Within the portfolio, zkML-SG wraps HCF2-SG trust decisions for external verification, complements the MYTHOS evidence chain — certification proves resistance was tested; zk proof shows a specific decision met criteria — and extends the ZGTID pattern of assurance without exposure from consortium telemetry down to single decisions [VC-C].
Filed as a USPTO provisional in January 2026 within the four-patent verifiable-governance cluster, sharing the portfolio's December 2025 priority anchor and incorporating the HCF2-SG hub by reference [VC-C].
§ 4 · QUESTIONSFrequently Asked Questions
What does zkML-SG prove, exactly?
That a specific AI decision satisfied specified governance criteria — the trust and admissibility thresholds computed by the HCF2-SG framework — and nothing else. The verifier checks the proof mathematically without access to the model, weights, inputs, or decision internals, and cannot extract any of them from the proof object.
How is this different from zkML research on inference proofs?
The established zkML field proves inference correctness: that a model computed the output it claims from the input it claims. zkML-SG proves governance compliance: that the decision cleared trust criteria before use. The second is a distinct, considerably thinner claim space — and it is the one that maps to what regulators and counterparties actually need to verify.
Doesn’t fitting models into ZK circuits degrade them?
It can — severely and silently. Circuit precision constraints can quantize away rare-event sensitivity while aggregate accuracy stays flat, which is why the failure hides. A companion filing in the four-patent cluster governs numerical admissibility under ZK constraints, so the proof system refuses to certify a deployment whose safety-relevant signal was destroyed by compression.
CONTACTTalk to VectorCertain
Every figure on this page traces to sealed, hash-verified validation artifacts — including findings that contradicted our own published estimates, which we recorded rather than reconciled away. Technical briefings are available for enterprises, evaluators, and standards bodies.
Request the technical briefingREFERENCES
- NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. nvlpubs.nist.gov
- NIST. AI Risk Management Framework (program page). nist.gov/itl/ai-risk-management-framework
- European Parliament and Council. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). EUR-Lex. eur-lex.europa.eu
[VC-C] Patent portfolio and platform engineering baseline — 77-claim hub filing, stack integration claims, 36,181-test regression suite; portfolio documentation, January 2026. Public URLs will replace artifact names when the corresponding research pages publish.