iProov Introduces HAPS for Human Verification of AI Agent Actions

0
69
Andrew Bud - CEO iProov (4)

Published on GitHub under Apache-2.0, iProov invites industry scrutiny and independent implementations of its approach to strengthening agentic AI governance

iProov, the world’s leading provider of biometric identity verification solutions, has published the Human Approval and Presence Specification (HAPS), an experimental procedural specification designed to help organizations verify that a human has approved a specific action before an AI agent is permitted to execute it.

Published on GitHub under the Apache-2.0 license, HAPS introduces a set of rules developed in response to the growing need for stronger governance and human oversight as AI agents become increasingly capable of acting autonomously on behalf of people. The specification includes a partial Rust reference implementation and test vectors. iProov is inviting industry experts to review and critique the framework, provide feedback, and explore independent implementations.

While containment failures, such as the July 2026 OpenAI Hugging Face breach, attract headlines, HAPS targets a less visible but significant risk: an AI agent that operates within its authorized permissions yet performs unintended actions. These may result from prompt injection, excessive goal-seeking, or the misuse of delegated credentials. The central concern is that the receiving system may have no reliable way to determine whether a request genuinely reflects human intent.

This exposes a critical gap in AI governance. An AI agent’s ability to access tools and services does not establish that a human intended or approved the actions it performs. As a prototype framework, HAPS aims to enable organizations and relying parties to enforce verifiable human approval before critical actions are allowed to proceed.

“AI agents are moving rapidly from answering questions to taking actions on our behalf. As their autonomy and capabilities grow, governance must keep pace,” said Andrew Bud, founder and CEO of iProov. “We need to distinguish between an agent having permission to act and a human actually approving the specific action it is about to take. HAPS is a specification that makes that human approval verifiable. We’re publishing it openly at this experimental stage because the industry needs to solve this challenge together. We’re inviting the community to scrutinize it, challenge it, and build on it so together we can establish strong, practical safeguards for an agentic AI world.”

Human Approval in High-Risk Moments

HAPS is not designed to require human approval for every action an AI agent performs. Such an approach could undermine the benefits of AI autonomy and lead to approval fatigue. Instead, organizations determine which actions are sensitive or critical enough to warrant additional human approval, as well as the appropriate level of evidence required.

When additional approval is necessary, the process follows a straightforward principle: pause the action, present the human with exactly what the AI agent intends to do, obtain proof of genuine human presence and approval, and verify that evidence before allowing the action to proceed. HAPS securely links the human’s approval to the specific action, enabling the organization to confirm that the approval corresponds to what the agent is actually requesting.

HAPS is also proof-agnostic, meaning it does not prescribe a specific method for verifying human presence. iProov has developed an internal implementation using biometric liveness as one example of how the specification could be applied in practice, providing an agent-resistant form of proof.

Andrew Bud will present the design requirements behind HAPS at AGNTCon + MCPCon Europe, taking place in Amsterdam on September 17–18.

The HAPS specification, reference implementation, and test materials are now available on GitHub at https://github.com/iProov/HAPS.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.