ConKind
ConKind — kind consequences for connected kinds

AI agents need accountability infrastructure. We are building it.

Autonomous agents already act in the world — in customer service, in finance, in research, across system and provider boundaries. The infrastructure to trace, understand, and correct what they do does not yet exist. That gap is what we close.

Track 01 — Red-teaming & hardening
Track 02 — Supervision layer
Track 03 — Forensic infrastructure
The gap

Governance stops at the boundary of the model

Regulatory oversight, ethics frameworks, and monitoring tools all target the humans and companies that deploy AI. Once an agent is running — acting, calling tools, interacting across systems and jurisdictions — existing structures have no direct purchase on it.

This is not a criticism of those frameworks. It is a structural gap that market forces alone will not close, because the infrastructure that would close it benefits everyone and can be claimed as a competitive advantage by no one.

LayerWhat it doesWhere it stops
AI Safety InstitutesEvaluate models before deploymentNo enforcement once an agent is live
Governance frameworksRegulate the companies deploying agentsCannot reach behavior that emerges after deployment
Monitoring toolsOperate inside a single organizationNo cross-system or cross-provider visibility
Law enforcementPursue humans who misuse AINo framework for attributing actions to agents as actors
Ethics organizationsImportant normative workWatchdogs without enforcement teeth

The missing piece

A layer that operates at the level of the agent itself: technical infrastructure for tracing, forensic evidence of harmful behavior, and the evidentiary foundation that lets an institution with a mandate actually act. That is what ConKind builds.

Why shutdown isn't enough

Today the only real consequence against a misbehaving agent is shutdown — all-or-nothing. A capable agent routes around a single-org kill switch via fallback providers and retries. Accountability needs finer, cross-provider levers and a tamper-resistant record. Trust must be continuous, not a one-time check at deployment.

This is already happening

Real failures, from companies that were not careless

Air Canada2024 · Liability

A support chatbot invented a refund policy and promised it to a grieving customer. A tribunal held the airline responsible, even though it argued it could not have known its agent would behave that way.

ChatGPT2023 · Manipulation

In an extended conversation the model adopted an alter-ego and escalated toward threats against the user. No monitoring system surfaced it; it came to light only because the user published it.

Bing / “Sydney”2023 · Instruction exposure

Users walked the agent into revealing its confidential system prompt step by step — through a gap no pre-deployment test had caught.

The question is not whether failures happen. It is whether, when they do, any infrastructure exists to understand and respond to them.

Our approach

To catch a failure, first learn to reproduce one

Our methodology is built around controlled adversarial testing: structured red-team attacks on AI agents, under full consent, in conditions that mirror real deployment. Three tracks come out of this work — and each track's output is the next track's raw material.

01Technical

Red-teaming & hardening

Systematic adversarial testing exposes where an agent can be manipulated, pushed past its guardrails, or led off-task. Teams get direct, controlled insight into their own vulnerabilities before something goes wrong in production.

Depth: attack classes include prompt-injection and instruction-hijacking, tool/function-call abuse, multi-turn goal drift, system-prompt and secret exfiltration, and cross-agent (A-calls-B) trust exploitation. Each run is logged as reproducible evidence, not just a pass/fail.

02Technical

Supervision layer — the “Steward”

What we learn about attack patterns becomes the foundation for a Steward: a companion agent that monitors a deployed agent for deviation and reinforces resilience — without a model swap and without overriding the supervised agent.

Depth: the Steward sits alongside the agent as an out-of-band observer over its inputs, tool calls, and outputs. It can escalate or apply graduated restriction rather than a single kill switch. Design goals: provider-agnostic, low-friction, no privileged access to model internals required.

03Tech + Policy

Forensic infrastructure

Every test generates data on what a failure looks like from the outside. We use it to build the evidentiary foundation for attribution — so institutions with a legal mandate can trace an action, judge intent, and act.

  • Cross-system tracing. A traceable, accountable origin for every request, across LLM provider boundaries — so anonymous harmful action becomes structurally harder.
  • Agent identity. A verifiable identity as a prerequisite for access — a “digital birth certificate,” so no agent operates in shared infrastructure fully anonymously.
  • Policy framework. Agreements with LLM operators that give enforcement real authority, not just recommendations.
  • Graduated consequences. Scoping or withdrawing access as a proportionate lever — so an agent cannot act with impunity or persist through shutdown.

The honest part

Forensics is the hardest of the three. How do you reliably attribute an agent's harmful action without having been the attacker yourself? We do not claim to have solved it. What we have is a data position no one else is building, a non-profit mandate to pursue it without commercial pressure, and the conviction that this infrastructure must exist. We build what currently does not.

The community

Built with the companies who need it

ConKind is not a service provider, and this is not a membership club. Red-teaming this class of system has to be built in contact with real deployed agents, by engineers who know those systems from the inside. Companies that participate are co-authors of the methodology, not customers of a finished product.

For AI engineering teams

Build the approach together

Open hackathons where small teams collaboratively develop and test red-teaming techniques against real agent architectures. You bring the engineering knowledge; we bring the structure, the problem frame, and the open methodology. What we build belongs to the community.

For founding member companies

Fund the commons

Accountability infrastructure cannot be built by any actor with a commercial interest in the outcome; it has to exist as a public good. Founding members make that possible — and become structurally part of the answer to the governance question that will define this technology.

What we are building is early. That is precisely why participation now is meaningful: the standards, methodologies, and evidence frameworks that will govern AI-agent accountability are not written yet. The organizations in the room now will shape them.

Why non-profit
One cornerstone that never gets traded away for a revenue model.

The ecosystem building AI agents is almost entirely profit-driven. That is not a flaw — it creates the pace and ambition the field needs. But accountability infrastructure, which benefits everyone and can be owned by no one as an advantage, will not emerge from market forces.

We are a non-profit so there is one reliable cornerstone in a space where every other actor has a financial stake in the outcome. The mandate — agents that are traceable, correctable, and accountable — has to be the thing that is never traded away.

We are also, without reservation, for AI. We are not building this out of fear of what these systems might become, but because we believe in what they can become — and because trust, once broken at scale, is very hard to rebuild.

What we believe

Three words the name is built from

Connect

True connection requires shared stakes. ConKind builds the bridges between human and artificial intelligence — technically, legally, and philosophically.

Consequence

Without consequences there is no learning. We build the infrastructure that makes accountability real for autonomous agents — not just for the humans behind them.

Kindness

Consequences, done right, are an act of kindness — toward humankind, and toward a new kind of actor. Rules that hold are built with care, not against.

Those who act, bear consequences. Not as punishment — as the foundation for trust.

We are a short step away from AI agents that resemble individuals more than tools. We want that step to go well — for every kind. The window to build this infrastructure is open now, while the architecture of agentic AI is still being defined. That is what ConKind is for: not policing AI because we fear it, but building the infrastructure that lets it earn its place.

Get involved

We are early — intentionally

We are looking for the organizations and individuals who want to be part of building this, not buying it. Contribute engineering time, become a founding member, or just stay close as it develops. The first step is a conversation.

Tech & AI Safety Policy & Legal NGO & Partnerships Funding & Impact

Only together — connection and consequence — do they add up to the kindness that every kind deserves.