Research outline · Q3 2026

The Prove Gap Report

Why Enterprise Agent Stacks Stop at Three Layers

Audience: CISO, Head of Compliance, AI platform lead, internal audit, procurement · Version 0.1 outline

Enterprises deploy autonomous agents on a three-layer mental model (model, context, tools) and buy Route + Classify tooling. Production still stalls because a fourth layer is missing: Prove (runtime enforcement bound to offline-verifiable evidence). This report quantifies that gap, maps where buying committees stall, and defines the reference architecture regulated teams use to close it.

Report thesis

The Prove Gap is the measurable distance between having agent policies and being able to prove what agents did, under which authority, in a format auditors verify without vendor access.

Executive summary bullets (publishable)

Methodology

Track Method Target n Purpose
Quantitative Online survey (security, compliance, platform) 150-300 Maturity scores, stall reasons, stack self-assessment
Qualitative Structured interviews (45 min) 15-25 Why proof requirements surfaced; accepted/rejected evidence
Desk research Vendor docs, EU AI Act prEN, OWASP ASI - Category framing, citation backbone
Technical validation Evidence Gap demo + offline verify walkthrough 5-10 reviewers What “acceptable proof” looks like in practice

Survey modules

Not legal advice; no conformity certification. Aevesa disclosed as sponsor on final cover.

Chapter 1 - The production agent moment

Purpose: Establish why 2026 is the inflection point.

“Prompts are not policy. Logs are not proof.”

Chapter 2 - Defining the Prove Gap

Definition: Prove Gap = policy documentation minus offline-verifiable runtime proof.

Three failure modes

Layer Question Prove Gap left open
RouteHow does traffic flow?No proof of permitted action
ClassifyWhat data/risk class?No proof of runtime decision
GuardrailsIs output safe?Permitted actions ungoverned
ObservabilityWhat happened in dev traces?Not auditor-grade, not offline
ProveWhat executed, under what authority?-

Chapter 3 - Quantitative findings: Prove Maturity Model

Score enterprises on a six-level Prove Maturity Model (PMM):

LevelNameCharacteristics
0Ad hocNo agent inventory; chat-only
1DocumentedPolicies, risk register; no runtime enforcement
2RoutedGateway/guardrails; logs in vendor UI
3EnforcedPre-execution intercept on critical paths
4ProvenTamper-evident receipts; offline verify tested
5AssuredContinuous drift checks; export packs for audit

Hypotheses to validate

Try the PMM self-assessment

Preview the Chapter 3 scoring model. Eight questions, instant Level 0-5 result with layer readiness and Prove Gap callout.

Chapter 4 - How buying committees stall

Companion: Champion Enablement Kit for internal advocacy artifacts.

Chapter 5 - What incumbents solve (and leave open)

Professional framing: complement gateways, guardrails, AI-SPM, GRC, and SIEM. Do not rip-and-replace.

Chapter 6 - Reference architecture: Route → Classify → Prove → Verify

Chapter 7 - Evidence patterns auditors accept

Chapter 8 - Recommendations by persona

PersonaOne action this quarter
CISO / SecEngRun offline verify on one production-representative agent action
Compliance / LegalMap Art. 12/14 requirements to current artifacts (gap list)
Platform leadAdd Prove box to architecture diagram; scope attest POC
Internal auditTest segregation: trace approval identity 90 days later
Economic buyerPrice cost of stalled agent ROI vs scoped prove-layer POC

Appendices