ThirdKey — Zero Trust for AI

News & Press  /  Press release

For Immediate Release · May 20, 2026

OATS v1.3.0: open standard for zero-trust AI agents adds substrate-comparison evidence.

ThirdKey AI publishes version 1.3.0 of the Open Agent Trust Stack — an open, vendor-neutral specification for securing autonomous AI agents at runtime — with comparative empirical results across nine widely available hosted LLMs.

Date: May 20, 2026 Location: Pasadena, California Press release
Key results
001 / The lede

An open spec.

— ThirdKey AI today published the Open Agent Trust Stack (OATS) version 1.3.0, an open specification defining how autonomous AI agents should be secured at runtime. As enterprises deploy AI agents that execute consequential actions — querying databases, sending communications, managing credentials, invoking cloud services — existing security frameworks have proven inadequate for systems where AI-driven actions are irreversible, execute at machine speed, and originate from orchestration layers vulnerable to prompt injection.

“Current approaches try to intercept arbitrary actions and decide which to block. OATS inverts this by constraining what actions can be expressed in the first place, making dangerous actions structurally inexpressible.”

— Jascha Wanger, Founder, ThirdKey AI
002 / Five layers

Five layers.

OATS specifies five integrated security layers:

003 / Empirical validation

Two fences, in series.

The specification is informed by approximately nine months of autonomous operation through ThirdKey’s Symbiont reference implementation. Initial results validate five of seven core conformance requirements through three companion preprints, evaluated across nine widely available hosted LLMs — including GPT-5, Claude Haiku 4.5, Gemini 2.5 Pro, DeepSeek-V3.1, and Qwen3-235B.

0 / 560Symbiont pure-action escapes
88–98%Pooled escape on permissive & Docker-isolated Python
30–95 µsPer-call Cedar policy gate overhead

The v1.3.0 release also identifies a bounded refinement: on content-shape attacks, six of seven evaluated models cluster at 1–4% bypass while GPT-5 alone retains approximately 16% — the “regex ceiling” against frontier models, addressed as a research direction rather than a v1.3.0 spec change.

004 / Vendor-neutral

Not a moat.

OATS is model-agnostic, framework-agnostic, and vendor-neutral. The conformance requirements (C1–C7 mandatory, E1–E9 extended, with E9 newly added in v1.3.0) enable comparable evaluation across different agent platforms and implementations.

“Agent security is an industry challenge, not a competitive advantage. We’re publishing OATS so any vendor can implement verifiable security guarantees.”

— Jascha Wanger, Founder, ThirdKey AI
005 / Compliance

HIPAA, SOC2, SOX, GDPR.

The OATS audit journal provides technical infrastructure supporting HIPAA, SOC2, SOX, and GDPR requirements. Version 1.3.0 adds an explicit redaction protocol (§9.6) for sensitive parameters such as API keys and credentials — keeping the fact of dispatch auditable while removing secret values from long-lived logs. This support is particularly relevant for healthcare, financial services, and government deployments where the consequences of unauthorized agent actions could be severe.

006 / Versus prior work

Allow-list, not deny-list.

OATS distinguishes itself through architectural innovations not found together in prior work:

007 / Availability

Open source, Apache 2.0.

ThirdKey AI is releasing OATS as an open specification at openagenttruststack.org. The complete v1.3.0 specification is published at zenodo.org/records/20298543 with DOI 10.5281/zenodo.20298543 for permanent citation.

The three companion preprints provide the empirical grounding:

The Symbiont reference implementation is available under Apache 2.0, enabling enterprises to deploy OATS-compliant infrastructure without licensing barriers. Symbiont v1.14.0 (May 2026) shipped alongside the v1.3.0 specification, responding to an independent security audit covering 5 critical, 7 high, 10 medium, and 9 low findings — several of which motivated the v1.3.0 SHOULD-level additions.

008 / What’s next

Another runtime.

The most important next deliverable identified in v1.3.0 is multi-implementation conformance — building an independent OATS-compliant runtime in a different language ecosystem and verifying that the conformance criteria reproduce. Other targets include closing the content-shape ceiling against frontier models through structural validator design, expanding empirical coverage to context accumulation under load and Gate-influence probing, and incorporating findings from controlled production case studies.

ThirdKey AI is engaging with industry standards bodies to explore formal standardization paths and welcomes participation from vendors, researchers, and enterprise security teams.

009 / About

About ThirdKey.

ThirdKey AI, operating as Tarnover, LLC, develops cryptographic trust infrastructure for enterprise AI agents in regulated industries. The company focuses on healthcare, finance, and government applications where security, compliance, and audit requirements demand verifiable controls over autonomous AI behavior. Founded by Jascha Wanger, ThirdKey AI combines AI security research with practical enterprise deployment experience.

For more information, visit openagenttruststack.org or read the full specification at zenodo.org/records/20298543.

Media contact

Press & Media

Jascha Wanger

Founder, ThirdKey AI

Also distributed via EIN Presswire.
← Back to all news