Attestation
A Proposal for "Model Deployment Cards" — Behavior Reports After the Fact
A new piece from the Center for AI Safety and Johns Hopkins, drawing on a workshop the two co-hosted, lays out infrastructure proposals for a world where agents already outnumber humans on much of the internet. The authors note that Cloudflare recently found more than half of internet traffic is now non-human, including a massive jump in requests from AI agents.
Most identity and registration proposals in this space focus on the moment of action: who is this agent, can it be traced back to a responsible party. The Center for AI Safety/Johns Hopkins piece adds a second, less-discussed layer: reporting on what an agent actually did after it was deployed. They call these "model deployment cards" — a mechanism for tracking agent behavior post-deployment to create visibility into real-world impacts, distinct from the pre-deployment model cards that already exist for describing training data and benchmark performance.
The distinction matters because current transparency tools mostly answer "what was this model built to do" rather than "what has this model's deployment actually done." An agent's behavior in production — the tools it called, the money it moved, the actions it chained together across systems — can diverge substantially from anything a pre-release benchmark captures. The authors frame this alongside two other pillars: IDs and registration, so that harms can be traced back to responsible parties, and options for constraining agent affordances within financial systems specifically to limit how much money a rogue or compromised agent could acquire.
The authors are explicit that this is early-stage thinking rather than a finished spec. The piece acknowledges that many identity and registration protocols are already being built, but says the field still lacks the infrastructure to identify, track, and control today's agents at the level these proposals describe. Deployment cards, as sketched here, would sit downstream of any identity or discovery layer — they're not about who an agent is or how to find it, but about producing an ongoing, checkable record of what it did once it was live. That's a distinct problem from authentication or capability discovery, and one that doesn't yet have an agreed format, a publisher, or a verification model. The workshop's output reads less like a spec proposal and more like an agenda item: someone needs to define what a deployment card contains and who is accountable for keeping it honest before the idea can move past a newsletter post.