Skip to content
Ikarus AI LabsGitHub ↗

Ikarus AI Labs · Research programme

Evidence-Based Assurance for AI-Mediated Software Change

Connecting agent authority, software ecosystem intelligence, and accountable human oversight.

AI is becoming part of the software change process. We study how organisations can make those changes observable, explainable and accountable through machine-readable evidence.

Central question

What evidence should exist before an AI-mediated software change is allowed to proceed?

Ikarus research modelAn AI agent proposes a change. SafeAI gathers agent authority evidence and OpenPulse gathers dependency intelligence. Both feed an evidence layer and policy engine, which decides allow, review or block, escalated to human authority and recorded as auditable evidence.AI AgentProposed changeSafeAIagent authorityOpenPulsedependency intelligenceEvidence layerPolicy engineAllowReviewBlockHuman authorityAuditable evidenceAuditable evidenceFIG. 1 — EVIDENCE PATH FOR AN AI-MEDIATED SOFTWARE CHANGE

§1 The problem

Software change is becoming AI-mediated

Traditional assurance assumes

  • developers make changes
  • humans understand the change
  • dependencies are relatively passive
  • permissions are relatively stable

Agents can independently

  1. Discover
  2. Select
  3. Modify
  4. Configure
  5. Execute

Assurance must therefore connect

  1. Who
  2. Can do what
  3. Changed what
  4. Depends on what
  5. What evidence exists
  6. What should happen

§2 The evidence model

Four evidence planes

01SafeAI

Agent Authority

What can this AI agent potentially do?

  • identity
  • principal
  • delegation
  • tools
  • MCP servers
  • access modes
  • data reachability
  • unknown authority
02OpenPulse

Software Ecosystem Intelligence

What is happening to the software the agent is changing or selecting?

  • lifecycle
  • support
  • upstream changes
  • vulnerabilities
  • ownership
  • applicability
  • evidence confidence
03Policy

Assurance Decision

Given the available evidence, what should happen?

  • ALLOW
  • REVIEW
  • BLOCK
  • ACCEPTED EXCEPTION
04Record

Accountability

Why was this decision made, and under whose authority?

  • evidence
  • policy
  • baseline
  • approver
  • exception
  • timestamp
  • provenance

Hypothesis This is an active research programme, not a solved problem.

§3 Research instruments

Instrument A · Agent Authority Evidence

SafeAI

An open-source static analyser for understanding the authority an AI agent can potentially exercise.

Discover

What can it access?

Compare

What changed?

Govern

Should it be allowed?

Unknown is an evidence state, not evidence of safety.

Instrument B · Software Ecosystem Intelligence

OpenPulse

An evidence-based intelligence system for understanding meaningful changes in the open-source software ecosystem.

  • RELATED ≠ AFFECTED
  • UNKNOWN ≠ NOT AFFECTED
  • MATCH STRENGTH ≠ EVIDENCE STRENGTH
  • SOURCE SIGNAL ≠ ACTIONABLE
What changed upstream, what evidence establishes it, and does it apply to us?

§4 Why both

Two evidence streams. One assurance question.

SafeAI and OpenPulse are intentionally separate research instruments. The research question is whether combining them produces better decisions about AI-mediated software change.

HYPOTHESIS · not a claim the problem is solved

SafeAI

What authority does the agent have?

OpenPulse

What is happening to the ecosystem it touches?

Assurance policy
AllowReviewBlock

§5 Principles

Our research principles

P1Evidence over assertion
Every meaningful conclusion should have supporting evidence.
P2Provenance matters
Evidence should retain where it came from and how it was interpreted.
P3Unknown is first-class
Unknown must never silently become safe.
P4Applicability matters
A finding is not automatically an impact.
P5Deterministic where possible
Policy decisions should be reproducible and explainable.
P6Human accountability
Automation should strengthen accountability rather than erase it.
P7Open research
Where possible, datasets, benchmarks, schemas and tools should be openly inspectable.
  1. Source
  2. Evidence
  3. Interpretation
  4. Policy
  5. Decision
  6. Accountability

Build the evidence layer for AI-mediated software

AI will increasingly participate in software decisions. The challenge is not to prevent every autonomous action, but to understand what authority exists, what changed, what evidence supports the decision, and where human accountability remains necessary.