Connect
True connection requires shared stakes. ConKind builds the bridges between human and artificial intelligence — technically, legally, and philosophically.
Autonomous agents already act in the world — in customer service, in finance, in research, across system and provider boundaries. The infrastructure to trace, understand, and correct what they do does not yet exist. That gap is what we close.
Regulatory oversight, ethics frameworks, and monitoring tools all target the humans and companies that deploy AI. Once an agent is running — acting, calling tools, interacting across systems and jurisdictions — existing structures have no direct purchase on it.
This is not a criticism of those frameworks. It is a structural gap that market forces alone will not close, because the infrastructure that would close it benefits everyone and can be claimed as a competitive advantage by no one.
| Layer | What it does | Where it stops |
|---|---|---|
| AI Safety Institutes | Evaluate models before deployment | No enforcement once an agent is live |
| Governance frameworks | Regulate the companies deploying agents | Cannot reach behavior that emerges after deployment |
| Monitoring tools | Operate inside a single organization | No cross-system or cross-provider visibility |
| Law enforcement | Pursue humans who misuse AI | No framework for attributing actions to agents as actors |
| Ethics organizations | Important normative work | Watchdogs without enforcement teeth |
A layer that operates at the level of the agent itself: technical infrastructure for tracing, forensic evidence of harmful behavior, and the evidentiary foundation that lets an institution with a mandate actually act. That is what ConKind builds.
Today the only real consequence against a misbehaving agent is shutdown — all-or-nothing. A capable agent routes around a single-org kill switch via fallback providers and retries. Accountability needs finer, cross-provider levers and a tamper-resistant record. Trust must be continuous, not a one-time check at deployment.
A support chatbot invented a refund policy and promised it to a grieving customer. A tribunal held the airline responsible, even though it argued it could not have known its agent would behave that way.
In an extended conversation the model adopted an alter-ego and escalated toward threats against the user. No monitoring system surfaced it; it came to light only because the user published it.
Users walked the agent into revealing its confidential system prompt step by step — through a gap no pre-deployment test had caught.
The question is not whether failures happen. It is whether, when they do, any infrastructure exists to understand and respond to them.
Our methodology is built around controlled adversarial testing: structured red-team attacks on AI agents, under full consent, in conditions that mirror real deployment. Three tracks come out of this work — and each track's output is the next track's raw material.
Systematic adversarial testing exposes where an agent can be manipulated, pushed past its guardrails, or led off-task. Teams get direct, controlled insight into their own vulnerabilities before something goes wrong in production.
Depth: attack classes include prompt-injection and instruction-hijacking, tool/function-call abuse, multi-turn goal drift, system-prompt and secret exfiltration, and cross-agent (A-calls-B) trust exploitation. Each run is logged as reproducible evidence, not just a pass/fail.
What we learn about attack patterns becomes the foundation for a Steward: a companion agent that monitors a deployed agent for deviation and reinforces resilience — without a model swap and without overriding the supervised agent.
Depth: the Steward sits alongside the agent as an out-of-band observer over its inputs, tool calls, and outputs. It can escalate or apply graduated restriction rather than a single kill switch. Design goals: provider-agnostic, low-friction, no privileged access to model internals required.
Every test generates data on what a failure looks like from the outside. We use it to build the evidentiary foundation for attribution — so institutions with a legal mandate can trace an action, judge intent, and act.
Forensics is the hardest of the three. How do you reliably attribute an agent's harmful action without having been the attacker yourself? We do not claim to have solved it. What we have is a data position no one else is building, a non-profit mandate to pursue it without commercial pressure, and the conviction that this infrastructure must exist. We build what currently does not.
ConKind is not a service provider, and this is not a membership club. Red-teaming this class of system has to be built in contact with real deployed agents, by engineers who know those systems from the inside. Companies that participate are co-authors of the methodology, not customers of a finished product.
Open hackathons where small teams collaboratively develop and test red-teaming techniques against real agent architectures. You bring the engineering knowledge; we bring the structure, the problem frame, and the open methodology. What we build belongs to the community.
Accountability infrastructure cannot be built by any actor with a commercial interest in the outcome; it has to exist as a public good. Founding members make that possible — and become structurally part of the answer to the governance question that will define this technology.
What we are building is early. That is precisely why participation now is meaningful: the standards, methodologies, and evidence frameworks that will govern AI-agent accountability are not written yet. The organizations in the room now will shape them.
One cornerstone that never gets traded away for a revenue model.
The ecosystem building AI agents is almost entirely profit-driven. That is not a flaw — it creates the pace and ambition the field needs. But accountability infrastructure, which benefits everyone and can be owned by no one as an advantage, will not emerge from market forces.
We are a non-profit so there is one reliable cornerstone in a space where every other actor has a financial stake in the outcome. The mandate — agents that are traceable, correctable, and accountable — has to be the thing that is never traded away.
We are also, without reservation, for AI. We are not building this out of fear of what these systems might become, but because we believe in what they can become — and because trust, once broken at scale, is very hard to rebuild.
True connection requires shared stakes. ConKind builds the bridges between human and artificial intelligence — technically, legally, and philosophically.
Without consequences there is no learning. We build the infrastructure that makes accountability real for autonomous agents — not just for the humans behind them.
Consequences, done right, are an act of kindness — toward humankind, and toward a new kind of actor. Rules that hold are built with care, not against.
Those who act, bear consequences. Not as punishment — as the foundation for trust.
We are a short step away from AI agents that resemble individuals more than tools. We want that step to go well — for every kind. The window to build this infrastructure is open now, while the architecture of agentic AI is still being defined. That is what ConKind is for: not policing AI because we fear it, but building the infrastructure that lets it earn its place.
We are looking for the organizations and individuals who want to be part of building this, not buying it. Contribute engineering time, become a founding member, or just stay close as it develops. The first step is a conversation.
Only together — connection and consequence — do they add up to the kindness that every kind deserves.