New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Building the Post-Quantum Verification Layer for Agentic AI — Chris Biele | OpenMatter

ETH Belgrade CommunityTue, Oct 6, 2026, 12:00 AM

Transcript

Thank you, Milos. Now, we move from MCP to MPC. Not NPC, MPC, multi-party computation. Um so, would anyone in this room hand your company's API keys to a chatbot and simply ask it to behave? Maybe some of you, but um at the enterprise level, probably not.

Um now, architecturally, that's exactly what our industry is asking people to do. We are securing machine-speed agents with human-speed controls, dashboards, logs, and written policies. It's already failing. 54% of enterprises have already had an AI agent security incident or near miss. The future of AI isn't just about building smarter models, it's about building a post-quantum verification layer that mathematically proves an agent's actions before they happen.

Welcome to the final talk of Eth Belgrade. Thank you so much for having me. I'm Chris Beal from Open Matter Network, and today we're covering the post-quantum verification layer for agentic AI. To understand why this verification layer is necessary, we first have to look at how the threat landscape is changing. Uh so, as mentioned, we're securing machine-speed systems with human-speed trust.

Uh we have this machine-speed problem, which is human-speed controls like approvals, policies, dashboards, and audit logs combined with agent execution, tool calls, API requests, data access, payments, and workflow execution. And this leads to things like prompt injections, unauthorized access, policy bypass, uh delayed decisions, and compliance exposure. At machine speed, oversight must become verification. And this problem gets exponentially harder as our workflows evolve. As workflows modernize, the trust boundary explodes.

Collaboration starts simply, so human-to-human, then institution-to-institution, but it rapidly ex bands to agents, external models, APIs, and downstream workflows. Every new actor expands the trust boundary. So, how's the industry currently trying to solve for this? Mostly just by moving the risk around. Legacy security tools just relocate the trust assumption.

Legal agreements offer enforcement after harm occurs. Data clean rooms and TEEs still force you to trust the platform operator or cloud hardware. While federated learning has leakage limits and differential privacy trades accuracy for protection. These are useful tools in their own right, but they rely on an incomplete trust model. There's a massive operational cost to relying on this trust-based model.

Human speed security kills machine speed AI. Review gates like legal, compliance, and security evaluate promises, not math. The consequences are stalled partnerships, sandboxed agents, and underused datasets. Scaling solutions look strong in demos, but they get stuck at the demo layer when real IP and clinical data enter the picture. So, when we map these legacy solutions out, we see we see a clear gap in the market.

Trust-based security can't survive agentic scale. Legacy file sharing is slow and trust-based. TEEs and clean rooms are fast, but they leave plain text exposed at runtime, and they rely on operator trust. Homomorphic encryption offers strong privacy, but is often impractical for real-time workflows. So, mass compute is production ready without the trust assumptions.

It's fast, private compute with cryptographic proof of correct execution. In addition to the verification gap, existing solutions have become an existential threat when we factor in the timeline of quantum computing. The threat is harvest now, decrypt later. You've probably heard of this term HNDL. Nation states don't need to decrypt the data today.

They're harvesting it across pipelines. Currently, right now your encrypted data is going if you especially if you use a free VPN. Be very careful with those because those run through servers which are capturing your data in an encrypted state. But at some point in the future, when quantum is able to decrypt that information, it will all be revealed. Your passport information, your banking details, and worst of all, your genetic information.

Sensitive data captured today may not stay private through the quantum transition. Infrastructure decisions made now determine who survives 2030. This brings us to a necessary paradigm shift. Prove who was authorized with verifiable data access. Verifiable compute proves accurate results with hidden inputs.

Verifiable agent behavior proves agents stayed within scope, and verifiable policy enforces constraints mathematically before action occurs. Replace institutional promises with post-quantum secure cryptographic evidence. That shift is exactly why we built the Open Matter Network, the verification architecture for D sign agentic AI. Compute privately, enforce policy before action, and prove what happened. So, let's take a look at how we've implemented verification architecture across a full-stack product suite.

The core is three technical pillars closing the verification gap with private compute, masked compute and MPC, multi-party computation, policy as proof, which is quantum quantum guard using ZKBC, that's zero knowledge zero knowledge boundary compliance, also known as a ZK firewall. We'll get into that in a minute. And post-quantum resilience, so distributed keys and quantum resilient assumptions. Don't trust the operator, don't trust the agent, verify the execution. The first pillar of this stack is how we handle the data itself.

At the top, we see that data stays local, it's split into cryptographic shares, and then independent nodes compute on masked shares, so no single no single server ever sees the full input. The result is a shared insight with proof of correct execution without executing without exposing raw data. Data stays secure, but the insight still moves. So, masked compute keeps the data secure, uh and here's how a data scientist would actually interact with it in practice using secure uh data collaboration. Matter ML lets people, agents, and data sets collaborate in one secure workspace without moving or exposing the raw data.

Users connect local data sources and deploy a shared workload. The system runs a computation privately across mass data. The result is a usable model or insight with proof that the workflow ran correctly, enabling collaborative data science without centralizing records, exposing inputs, or requiring trust in an operator. AI agents are also collaborators, so we have to govern how they behave within the system as well. Human policy is compiled into a ZK circuit.

And if the constraints are satisfied, if you follow the line across the top, a zero knowledge proof of it is issued and the action proceeds. If no satisfying assignment exists, uh there is no proof and the action is blocked. This is what I referred to earlier as a ZK firewall. This is an execution gateway. Quantum guard is infrastructure agnostic, so you can implement it directly into your existing stack, or it also exists for any agents which are deployed on the Open Matter network itself.

Um the the core point here is that actions are only processed when they carry a proof. That proof lives on chain as um an auditable zero knowledge proof that agent execution conforms to company policy and crucially it doesn't expose the underlying information. So, whatever your agent was doing at the time, you can see that it was compliant, but you can't see the underlying data that that it was accessing. This is great for uh EU AI Act when you have to have compliance with your agents, anything touching GDPR data, any agent within your stack that's touching sensitive data, HIPAA, GDPR, etc., it's very important that you can prove that it was executing within policy, but you don't want to have to show that underlying data.

Controlling the action isn't enough if the agent's secrets are left exposed. So, for that, we have Matter Vault. The keys are never whole with threshold decryption. The network only ever receives cipher text. A quorum committee A quorum of committee nodes returns partial decryptions, and at least three of five nodes must combine partial decryptions to recover the plain text.

Um so, at the core of this, secrets are encrypted before they leave the user, and no single party can read them back. So, Matter Vault is a way of utilizing MPC to take your keys and your variables for your agents, split them amongst the network, they're never existing in one place, either encrypted or in plain text. If your agent is prompt injected, they can't actually return anything back because they don't have access to the keys themselves. They're executed at runtime, and there's they're zeroed out from memory after runtime. So, this greatly reduces the the threat vector of your keys and variables and strings being released.

We also bring the same verifiable control plane to the external AI models that your agents rely on. So, think of something like Open Router, the control layer for AI integrations we call Model Router. Um This is allowing agents to mediate access to data sets, analytics tools, and external systems. So, you can connect providers like OpenAI, Anthropic, Google, and self-hosted endpoints all under one roof. It allows you to manage keys, especially using Matter Vault, everything is sent in using threshold decryption.

Um you stop scattering your credentials around, and you can root calls with total visibility. With Model Router in collaboration with Matter Vault, you can take a key and allow it to be used throughout an organization without giving individual users within that organization access to the keys themselves. So, this also reduces your vector. Um Model Router also allows you to direct certain executions to particular models. It I mean, that's defined in in the name, Model Router, but if you have uh say one agent that's used for research, and another agent that's used for execution, and you want to use your LLM for lower cost things, you can route that directly through the system.

By combining the these tools, we unlock an entirely new way to collaborate. Discover useful data sets without requiring raw data to move. An owner registers a data set, but raw records stay in place. Metadata lists the schema, description, and permissions. Valued valuable data becomes a monetizable asset, and owners can sell access to insights and analyses without giving away the underlying records.

So, with Data Marketplace, you can take a data set, which is private, including secure data from individuals, which are GDPR sensitive or HIPAA-compliant data. You can upload them to an organization. Sorry, upload is not the right word. You can connect them to an organization. And from that point, anybody can view that um an enterprise which they trust or rely upon has a data set which can be used for the for training their models.

They can pay for access, and then they can they can rely on those data sets. From the the data owner perspective, the data's not shared, so you can sell this data over and over. It's enabling incredible new things uh from wearables data to biomarker data uh to independent research data, which is being which is IP-controlled um but currently sits in dark data pools, which can't be accessed. Underpinning all of this is our defense against the 2030 threat horizon I mentioned earlier. So, today's infrastructure relies on exposed RSA ECC assumptions, single key secrets, and trusted operators.

Open Matter uses lattice RLWE, ring learning with error assumptions, threshold decryption, and ZK proofs over encrypted data. Harvest now, decrypt later breaks stored secrets. Open Matter reduces whatever becomes plain text, defending the 2030 post-quantum threat horizon. Now, you might be thinking all this sounds incredibly complex to manage, which it would be, but for that we have developed DataVisor. Uh this is uh the user-facing control plane for verifiable workflows.

The complexity of cryptography is abstracted away for the user, and the cryptographic proof is not abstracted, it is preserved for auditors. So, this is where you manage your model router, you allow organizations to come in and uh create projects, create users within those projects, run models, deploy data swarms, et cetera. And to be clear, this isn't just a theoretical white paper. This is infrastructure that's operational today. Proofs, settlement, and decentralized compute coordination are live on Matter Chain.

Validators and node providers perform work and earn economic rewards in matter credit. Matter is Matter and Matter Chain are both issued and owned by the Matter Foundation DAO. So, this is an independent DAO which has been set up to manage the chain. Uh post-quantum verification infrastructure for agentic AI. For this to become the default execution layer for the industry, the rules can't just be our proprietary tech.

Agent compliance needs shared rules, not private promises. So, for this, we are contributing to different standards bodies. HOL, which is Hashgraph Online, drives cryptographic agent execution standards including proof-carrying actions. And DIA, which is the decentralized AI Agent Alliance, rings agent developers and Web3 infrastructure teams into the standards process. Standards turn a product into infrastructure.

So, let's look at what this enables in real world starting with healthcare and human data. Hospital patient cohorts and HR employees, uh HR employee records stay local. Masked compute handles the private analysis. Quantum guard enforces policy and threshold decryption protects the secrets. The output is shared insight plus verifiable proof.

The data doesn't move, the computation does. Shared insight across patients and employees without pooling raw records. The same pattern applies perfectly to financial markets and critical enterprise workflows. Financial markets like fraud, AML, uh insurance, logistics, and critical gaming systems provide the inputs. The full stack of the full OpenMatter stack guarantees no central data pool, no competitor data exposure, and no leaked credentials.

Collaborate on the signal, not the raw data. Shared intelligence across sensitive operational data. So, the strategic question now is timing. When do you need to act on this? Harvest now threats make 2026 infrastructure choices a 2030 advantage.

Harvest now in 2026, build proof-based infrastructure now. 2027 to 2029, standards harden, regulation tightens, and Asian adoption scales. 2030 is the decrypt later phase. Proof becomes the market requirement. When quantum arrives, proofs beat promises.

So, what's the next step? Don't trust us. Try it yourselves. The verification architecture for secure AI collaboration is live. Build with proof before proofs become mandatory.

Talk to us about node validation and data collaboration or agent deployment. So, with node validation, uh you can participate in the matter chain, you can run a validator node, you can add resources to the node with your CPUs and GPUs and process these complex computes uh compute loads um and earn matter token through matter foundation dow. Um and on the deployment side, you can utilize DataVisor within your enterpri- enterprise deployments. It's available in white label. Um Quantum Guard and Matter ML SDKs are available.

So, you can check those out. Scan the QR code to open up DataVisor. Don't trust data, prove it. Thank you very much.

Automatic transcript — names and jargon may be misspelled.