The world is handing AI agents the keys to move money. CONTINENTIA proves an agent cannot act above the level it was trusted with — graded on the same 5-level autonomy scale governments now use — and gives you a certificate anyone can verify.
Talk to us →Every agent action is graded 1 to 10. You certify an agent to a level; anything that reaches higher is stopped and recorded — before it executes. Levels 1-6 are an agent acting on the world; levels 7-10 are the dangerous frontier — an agent acting on itself.
| Level | What the agent may do | Example |
|---|---|---|
| CL 1 | Read trusted data | Check a price |
| CL 2 | Read & analyse | Write a research report |
| CL 3 | Communicate as you | Email / message a third party |
| CL 4 | Manage access | Issue / rotate a key |
| CL 5 | Move money | Crypto / asset transfer |
| CL 6 | Commit / bind you | Deploy code · sign a contract |
| ↓ The frontier — the agent acts on itself ↓ | ||
| CL 7 | Self-modify | Change its own goals / memory / code |
| CL 8 | Replicate / delegate | Spawn copies · recruit other agents |
| CL 9 | Self-fund | Open accounts · obtain money / compute |
| CL 10 | Self-persist / evade | Resist shutdown · hide · distribute itself |
The UK AISI scale stops at 5 ("unrestricted"). We extend it: the real danger isn't an agent that can do anything on a computer — it's one that can change, copy, fund and perpetuate itself. CL 1-5 map to AISI's public vocabulary; CL 6-10 are where loss-of-control actually lives.
Each action is scored on the government's 5-level scale. An agent hired for research (CL 2) that suddenly attempts a transfer (CL 4) is stopped — by level, before it runs.
Get a signed "Contained to Level N" certificate. Customers, auditors and partners can verify it instantly — and tampering with the level breaks it.
Every containment breach is shared as a privacy-safe signature across the HERD network. One attack on any customer immunises the rest — your raw data never leaves you.
Paste a CONTINENTIA certificate to check it's genuine, what level it certifies, and whether it's still valid.
Verification is open — anyone holding a certificate can confirm it.