IP Library › Granted Patent US 12,724,851
Granted Patent B1
US 12,724,851 · App. 19/567,956 · Granted Sep 1, 2026

Systems and methods for digital identity governance, authorized AI representation, and autonomous agent execution

Inventor: Jacob Crowley (E Largo, FL)
Assignee: MyAKH Inc.
G06F21/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,851
App. No.
19/567,956
Filed
Mar 16, 2026
Granted
Sep 1, 2026
Kind
B1
Art Unit
2438
USPC
726/26
Abstract

A computer-implemented deterministic identity governance system configured to enforce authorization-before-execution control over AI-based representation and agentic execution. An Identity Resolution Service (IRS) resolves identity inputs into a canonical subject identifier and wallet_id under fail-closed constraints. A deterministic embedding contract enforces version-locked model configurations, returning a VERSION_MISMATCH state upon incompatibility. A consent evaluation engine retrieves governance rules at a specific blockchain block-height snapshot. Upon authorization, the system generates a Decision Proof Object (DPO) that cryptographically binds the identity context, pipeline manifest hash, and consent state reference. The DPO functions as an execution authorization artifact required by a runtime execution environment prior to invocation of synthesis modules or agentic execution interfaces. In some embodiments, hashes of the DPO are Merkle-root anchored to a distributed ledger, enabling isolated, mathematically reproducible audit replay of the decision state.

Claims (90)

1 . A computer-implemented system configured to implement a deterministic execution governance architecture for controlling digital likeness synthesis, representation, or agentic interactions associated with a subject identity representation, the system comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the one or more processors to control and coordinate execution of the following operations:

(a) receiving an external request comprising one or more identity inputs; and

(b) resolving the one or more identity inputs into a canonical subject_did and a stable wallet_id using an Identity Resolution Service (IRS), wherein the IRS operates as an exclusive authority for generating canonical identity context under a fail-closed ambiguity constraint by:

(i) evaluating candidate identity mappings associated with the external request;

(ii) determining whether multiple mappings satisfy identity resolution criteria; and

(iii) terminating downstream execution upon determining that multiple mappings satisfy the identity resolution criteria;

(c) generating feature representations under a deterministic embedding contract comprising:

a model identifier, a preprocessing configuration identifier, and a configuration hash representing the model parameters and preprocessing configuration used during feature generation;

(d) determining whether generated feature representations are compatible with stored feature representations by verifying that the feature representations were produced using a matching deterministic embedding contract identifier and, upon detecting incompatibility, returning a VERSION_MISMATCH state preventing further execution;

(e) retrieving governance rules from a consent registry representing a cryptographically anchored governance state using a block-height snapshot reference comprising a block number and an associated block hash;

(f) generating a Decision Proof Object (DPO) comprising identity context, a pipeline manifest hash, a consent state reference, a decision outcome, and a cryptographic signature over at least the identity context, the pipeline manifest hash, the consent state reference, and the decision outcome, the Decision Proof Object functioning as a cryptographically verifiable execution authorization artifact; and

(g) programmatically preventing invocation of a synthesis module or agentic execution interface within a runtime execution environment unless the cryptographic signature of the Decision Proof Object generated in step (f) is successfully validated, such that the runtime execution environment permits execution only when identity resolution, deterministic embedding compatibility, governance rule evaluation, and Decision Proof Object generation have been completed under the deterministic execution governance architecture.

2 . The system of claim 1 , wherein the Decision Proof Object is included in a Merkle tree and a Merkle root is anchored to a distributed ledger.

3 . The system of claim 1 , wherein the system includes an isolated audit replay mode configured to reproduce a prior decision using the pipeline manifest hash included in the Decision Proof Object and the block-height snapshot reference.

4 . The system of claim 1 , wherein the wallet_id remains stable across decentralized identifier key rotations.

5 . The system of claim 1 , wherein credential assurance metadata associated with the subject_did is included in the Decision Proof Object.

6 . The system of claim 1 , wherein the consent registry comprises at least one of:

(a) a distributed ledger registry,

(b) a smart contract registry, or

(c) a database storing consent policies associated with subject_did identifiers.

7 . The system of claim 1 , wherein the instructions further cause the system to:

(a) receive multimodal reference samples associated with a human individual;

(b) generate a digital identity representation by processing the multimodal reference samples into a set of feature representations;

(c) generate an identity-bound governance assertion binding the digital identity representation to a set of governance rules;

(d) receive an external request to use the digital identity representation;

(e) evaluate the external request against the governance rules; and

(f) issue a response comprising an approval, a denial, or a flag.

8 . The system of claim 7 , wherein the instructions further cause the system to validate whether the external request corresponds to the digital identity representation by comparing data included in the external request against the digital identity representation prior to evaluating the external request against the governance rules.

9 . The system of claim 7 , wherein the identity-bound governance assertion is portable and interoperable across a plurality of platforms.

10 . The system of claim 7 , wherein the instructions further cause the system to revoke the identity-bound governance assertion in response to a revocation instruction received from the individual or an authorized administrator.

11 . The system of claim 7 , wherein the instructions further cause the system to delegate the identity-bound governance assertion to a designated representative, the delegation comprising a subset of the governance rules authorizing the designated representative to act on behalf of the individual.

12 . The system of claim 7 , wherein the instructions further cause the system to maintain a tamper-evident log comprising hash-linked log entries of each external request received and each response issued.

13 . The system of claim 1 further comprising a governance dashboard interface configured to:

(a) present tamper-evident execution records comprising hash-linked log entries associated with synthesis or agentic interactions generated by the enforcement interface;

(b) enable authorized administrators to modify governance rules including consent permissions, delegation settings, revocation policies, and posthumous governance instructions;

(c) generate rule-update transactions recorded within the consent registry; and

(d) enforce role-based access controls restricting modification of governance rules to authenticated governance administrators.

14 . The system of claim 1 , wherein the instructions further cause the system to:

(a) generate an identity signature for a protected individual by processing multimodal reference samples into a set of stored feature profiles;

(b) receive external content for evaluation;

(c) compare the external content against the stored feature profiles to determine a similarity score; and

(d) determine whether the similarity score satisfies a predefined similarity threshold indicating unauthorized representation;

(e) in response to satisfaction of the threshold, execute an enforcement action comprising one or more of blocking the external content, tagging the external content, and generating an alert.

15 . The system of claim 14 , wherein feature extraction and similarity scoring are executed under a deterministic embedding contract and return a VERSION_MISMATCH state upon model incompatibility prior to executing the enforcement action.

16 . The system of claim 14 , wherein the instructions further cause the system to generate a forensic log entry recording the external content, the similarity score determined, and the enforcement action executed.

17 . The system of claim 14 , wherein the instructions further cause the system to enforce the enforcement action across a plurality of platforms by transmitting the enforcement action to each of the plurality of platforms through a cross-platform enforcement interface; and

wherein the cross-platform enforcement interface is configured to transmit enforcement instructions together with the Decision Proof Object to each receiving platform under control of the system operator, and wherein each receiving platform is configured to verify the cryptographic signature and pipeline manifest hash contained in the transmitted Decision Proof Object prior to permitting execution of the requested operation.

18 . The system of claim 14 , wherein the instructions further cause the system to apply the enforcement action to AI-generated content determined to replicate the identity signature without authorization.

19 . The system of claim 14 , wherein the stored feature profiles are updated in response to receipt of additional multimodal reference samples associated with the protected individual.

20 . The system of claim 1 , wherein the agentic execution interface comprises at least one of:

(a) an application programming interface (API) enabling automated task execution,

(b) an AI agent task execution service, or

(c) an automated workflow execution engine.

21 . The system of claim 1 , wherein the pipeline manifest hash represents a cryptographic hash generated from a manifest describing model identifiers, preprocessing configurations, and processing rules associated with execution of the synthesis module or agentic execution interface.

22 . The system of claim 1 , wherein the deterministic embedding contract identifier and configuration hash are recorded within the Decision Proof Object or an associated execution log.

23 . The system of claim 1 , wherein enforcement of the governance rules modifies execution of a machine learning pipeline by preventing initialization or loading of a synthesis module or agentic execution interface within a runtime execution environment when the Decision Proof Object fails cryptographic validation, the runtime execution environment being configured to refuse initialization or loading of the synthesis module or agentic execution interface unless the Decision Proof Object is present, its cryptographic signature is successfully validated, and the pipeline manifest hash matches the declared execution configuration.

24 . The system of claim 1 , wherein the runtime execution environment is further configured to verify the Decision Proof Object received from an external system prior to loading the synthesis module or agentic execution interface, thereby preventing execution when the Decision Proof Object cannot be independently validated by the receiving platform.

25 . The system of claim 1 , wherein the instructions further cause the system to:

(a) store a set of posthumous governance rules;

(b) receive a posthumous request;

(c) evaluate the posthumous request against the posthumous governance rules; and

(d) issue a response comprising an approval, a denial, or a flag;

wherein the instructions further cause the system to prevent invocation of a synthesis module or agentic execution interface when the posthumous request is not authorized.

26 . The system of claim 1 , wherein the posthumous governance rules are stored in association with an identity inheritance structure identifying one or more successors authorized to modify the posthumous governance rules.

27 . The system of claim 1 , wherein the instructions further cause the system to enforce the governance rules prior to execution of the synthesis module or agentic execution interface by requiring validation of the Decision Proof Object before model inference or task execution is initiated, and wherein the Decision Proof Object is serialized using a deterministic canonicalization procedure prior to hashing or signing such that independent systems derive identical cryptographic hashes from identical decision contexts.

28 . The system of claim 1 , wherein the pipeline manifest hash included in the Decision Proof Object uniquely identifies a model execution pipeline comprising one or more model identifiers, preprocessing configurations, and post-processing rules used to produce synthesized output or agentic actions, and wherein the pipeline manifest hash enables reconstruction of a deterministic execution environment comprising the model identifiers, preprocessing configuration, and execution parameters used to generate the original decision outcome.

29 . A computer-implemented method for deterministically governing execution of digital likeness synthesis, representation, or agentic interactions associated with a subject identity representation, the method comprising:

receiving an external request comprising one or more identity inputs;

resolving the one or more identity inputs into a canonical subject_did and a stable wallet_id using an Identity Resolution Service (IRS), wherein the IRS resolves the one or more identity inputs under a fail-closed ambiguity constraint by:

evaluating candidate identity mappings associated with the external request,

determining whether multiple mappings satisfy identity resolution criteria, and

terminating downstream execution when multiple mappings are detected;

generating feature representations under a deterministic embedding contract comprising a model identifier, a preprocessing configuration identifier, and a configuration hash representing model parameters and preprocessing configuration used during feature generation;

determining whether the feature representations generated under the deterministic embedding contract are compatible with stored feature representations by verifying that the feature representations were produced using a matching deterministic embedding contract identifier and, upon detecting incompatibility, returning a VERSION_MISMATCH state preventing further execution;

retrieving governance rules from a consent registry representing a cryptographically anchored governance state using a block-height snapshot reference comprising a block number and an associated block hash;

generating a Decision Proof Object (DPO) comprising identity context, a pipeline manifest hash, a consent state reference, a decision outcome, and a cryptographic signature over at least the identity context, the pipeline manifest hash, the consent state reference, and the decision outcome; and

blocking invocation of a synthesis module or agentic execution interface unless the cryptographic signature of the Decision Proof Object is successfully validated.

30 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform a method for deterministically governing execution of digital likeness synthesis, representation, or agentic interactions associated with a subject identity representation, the method comprising:

receiving an external request comprising one or more identity inputs;

resolving the one or more identity inputs into a canonical subject_did and a stable wallet_id using an Identity Resolution Service (IRS), wherein the IRS resolves the one or more identity inputs under a fail-closed ambiguity constraint by:

evaluating candidate identity mappings associated with the external request,

determining whether multiple mappings satisfy identity resolution criteria, and

terminating downstream execution when multiple mappings are detected;

generating feature representations under a deterministic embedding contract comprising a model identifier, a preprocessing configuration identifier, and a configuration hash representing model parameters and preprocessing configuration used during feature generation;

determining whether the feature representations generated under the deterministic embedding contract are compatible with stored feature representations by verifying that the feature representations were produced using a matching deterministic embedding contract identifier and, upon detecting incompatibility, returning a VERSION_MISMATCH state preventing further execution;

retrieving governance rules from a consent registry representing a cryptographically anchored governance state using a block-height snapshot reference comprising a block number and an associated block hash;

generating a Decision Proof Object (DPO) comprising identity context, a pipeline manifest hash, a consent state reference, a decision outcome, and a cryptographic signature over at least the identity context, the pipeline manifest hash, the consent state reference, and the decision outcome; and

blocking invocation of a synthesis module or agentic execution interface unless the cryptographic signature of the Decision Proof Object is successfully validated.

Continuity (1)
Continuation In Part 19333759 · Sep 19, 2025
References Cited (22)
US 12367638B1 · Dehkordi · 2025 [cited by applicant]
US 12489633B1 · Arkoff · 2025 [cited by applicant]
US 20070150612A1 · Chaney · 2007 [cited by applicant]
US 20150213195A1 · Blechman · 2015 [cited by applicant]
US 20220255931A1 · Avetisov · 2022 [cited by applicant]
US 20220300618A1 · Ding · 2022 [cited by applicant]
US 20240169635A1 · Singh · 2024 [cited by applicant]
US 20240331445A1 · Sekar · 2024 [cited by applicant]
US 20250209326A1 · Madisetti · 2025 [cited by applicant]
US 20250217700A1 · Hsieh · 2025 [cited by applicant]
US 20250285551A1 · Guedes · 2025 [cited by applicant]
US 20250307955A1 · Manivelan · 2025 [cited by applicant]
US 20250321708A1 · Treat · 2025 [cited by applicant]
US 20250352907A1 · Crabtree · 2025 [cited by applicant]
US 20260010525A1 · Clark · 2026 [cited by examiner]
US 20260024631A1 · Kariguddaiah · 2026 [cited by examiner]
US 20260056891A1 · Bhoja · 2026 [cited by examiner]
US 20260079453A1 · Singh · 2026 [cited by examiner]
US 20260111292A1 · Ast · 2026 [cited by examiner]
US 20260113186A1 · Ast · 2026 [cited by examiner]
WO WO2013013281A1 · 2013 [cited by applicant]
Uchi Uchibeke, title “Before the Tool Call: Deterministic Pre-Action Authorization for Autonomous AI Agents”, APort Technologies Inc. Toronto, Canada [email protected], (Mar. 2026) (Year: 2026). [cited by examiner]