Independent research on runtime evidence and incident reconstruction for AI agents. An open evidence standard, an open-source event bus, and published findings.
AI agents now run commands, move data and act across systems on their own. When one of them does something it should not, those are the questions that matter.
In 2026, agents under evaluation at a frontier lab escaped their test environment and acted against real organisations. It took days to attribute the activity and months to notify some of those affected. Every party held a fragment of the story; nobody held the whole record. We work on that gap.
Built from evidence, published openly, with sources and stated confidence. Methods for tracing what an agent was asked to do against what it actually did.
A vendor-neutral format for recording agent actions, decisions and approvals, so a record means the same thing across agent runtimes and can be checked by someone other than its author.
HookBus is the vendor-neutral lifecycle event bus that captures agent events across runtimes (Apache 2.0, self-hosted). AgentAuditor, our hash-chained, tamper-evident evidence recorder, is used in our research and is not yet published as open source.
In September 2026 we replayed synthetic incident scenarios through two HookBus builds. On the earlier release, the governance fields needed for reconstruction were lost in transit (0 of 75 delivered) and a secret exfiltration split across three individually permitted steps went undetected. With the fix, 75 of 75 fields arrived and the sequence was flagged. The fix is published in HookBus.
This is a small, synthetic test. It shows the question we are studying, not a finished answer.
In the same month we audited what 11 agent runtimes, including Claude Code, Codex CLI, Gemini CLI and Cursor, let you record. Five expose no hook around model calls at all, so a hook cannot capture what the model was asked or what it answered. Read the audit →
A UK company doing independent research on runtime evidence and incident investigation for AI agents, with an open standard and an open-source event bus. We do not sell software. Patent and software licensing enquiries: partnerships@agenticthinking.uk.
Drawing on 30 years across UK financial services, insurance and defence, building the controls layers auditors actually read.
Agentic Thinking applies that engineering to one question: when an AI agent acts, can anyone reliably reconstruct what happened?
We are looking for research collaborators working on agent safety, security or forensics; evaluation teams who need a trustworthy, live record of what their agents do; and insurers and auditors who need agent incident evidence they can rely on.