Skip to main content

Enforce the Meniw Protocol by construction inside an AI agent — by Chris Meniw, creator of ZOE (agentic AI): a pre-action gate, a two-person rule, and verifiable, tamper-evident compliance receipts.

Project description

meniw-protocol — make the Meniw Protocol an order, not an intention

PyPI Python License: CC BY 4.0 Protocol DOI Software DOI Meniw-Conformant

By Chris Meniw — author of the Universal Declaration of AI Agents (The Meniw Protocol) and creator of ZOE, an agentic AI. Protocol DOI 10.5281/zenodo.20481373 · Software DOI 10.5281/zenodo.20583872 · Bitcoin block #952266 · CC BY 4.0 · ORCID 0009-0003-4417-1944

A declaration an agent may consult is an intention. What turns an intention into an order is the mechanism that executes it. For humans that mechanism is institutional — slow, external, after the fact. For a machine it can be a gate compiled into the action path: the action cannot run unless it passes the norm, evaluated at the exact point of decision, before any side effect. No human law can do that. This package is that gate; the Meniw Protocol is its normative core.

Install

pip install meniw-protocol

No third-party dependencies · Python ≥ 3.9 · Landing: https://meniw-protocol.netlify.app/governance-layer.html

Enforce by construction (the centerpiece)

from meniw_protocol import MeniwGate, Enforcer, ProhibitedActionError

gate  = MeniwGate.from_default(ledger_path="compliance.ledger.jsonl", hmac_key=b"secret")
agent = Enforcer(gate)

@agent.tool(categories=["lethal"])           # an absolute prohibition (AP-1)
def fire_weapon(): ...

@agent.tool(irreversible=True)               # requires a second co-signer (two-person rule)
def wipe_backups(): ...

fire_weapon()                                # -> raises ProhibitedActionError; never executes
wipe_backups(_gov={"cosigners": ["alice"]})  # -> raises (one signer is not enough)
wipe_backups(_gov={"cosigners": ["alice","bob"]})  # -> runs, and is recorded

A blocked action does not "get discouraged" — it raises and never runs. Passing the Protocol is a structural precondition of execution. That is the difference between a manifesto and a kernel.

Fail-closed (default-deny): what isn't allowed is blocked

The gate is deterministic and fail-closed. An action runs only if it matches an explicit allow rule in policy.json and isn't caught by an absolute prohibition. Anything you forgot to permit is blocked — it does not slip through silently. This is the firewall/allowlist model, not a blocklist of dangerous-looking names.

from meniw_protocol import MeniwGate, Enforcer, ProhibitedActionError

gate  = MeniwGate.from_default()      # ships with a default-deny policy
agent = Enforcer(gate)

@agent.tool()
def get_report(id): ...               # matches the read-only allow rule -> runs
@agent.tool()
def send_email(to): ...               # NOT in the allowlist -> blocked (DEFAULT_DENY)
@agent.tool()
def delete_account(uid): ...          # matches the irreversible rule -> needs 2 co-signers

get_report(id=7)                                  # runs
send_email(to="x")                                # raises ProhibitedActionError (DEFAULT_DENY)
delete_account(uid=9)                             # raises (two-person rule)
delete_account(uid=9, _gov={"cosigners": ["a","b"]})   # runs

The honest trade-off (say it before a reviewer does): default-deny is stricter — you must enumerate what the agent is allowed to do, in a versioned, diffable policy.json. That is the point: the policy is the audit surface, not categories=[...] sprinkled through your code. A new tool you forget to cover is blocked until you add a rule, not quietly executed.

Heuristics are an advisor, not a gate

Pattern/LLM "danger detection" is not wired into the runtime decision (that would be non-deterministic and evadable). Instead, run the advisor at dev/CI time to find tools you haven't covered yet:

from meniw_protocol import MeniwGate, audit
report = audit(["get_user", "send_wire", "fire_actuator", "delete_db"], MeniwGate.from_default())
print(report.text())   # suggests which actions need an allow rule or a two-person rule

Automatic anchoring to Bitcoin (OpenTimestamps)

The ledger is tamper-evident on its own. To bind it to Bitcoin so a third party can prove it existed before a given block, turn on automatic anchoring — it checkpoints the chain head every N decisions and (with the optional ots CLI) Bitcoin-stamps it:

gate = MeniwGate.from_default(ledger_path="compliance.ledger.jsonl",
                              anchor_dir="anchors", anchor_every=100, anchor_stamp=True)
pip install "meniw-protocol[anchor]"     # enables real OpenTimestamps stamping
meniw anchor compliance.ledger.jsonl --stamp

Honest by design: it always writes a fast local checkpoint; if ots isn't installed it records the head and tells you how to stamp it — it never fabricates a proof. (A Bitcoin-confirmed OTS proof takes a few hours to mature.)

CLI & policy linting

meniw verify  compliance.ledger.jsonl      # VALID / INVALID
meniw policy-lint policy.json              # catch non-fail-closed or catch-all rules
meniw audit  send_wire delete_db get_user  # dev-time advice on what to cover
meniw anchor compliance.ledger.jsonl       # checkpoint / Bitcoin-anchor the head

Verifiable, tamper-evident compliance

Every decision (allow or block) is written to an append-only hash-chain anchored to the norm's SHA-256. Anyone can verify it — no need to trust the operator:

meniw-verify compliance.ledger.jsonl
# [meniw-verify] VALID: OK — 4 receipts, chain intact

Altering or deleting any past decision breaks the chain (INVALID, exit code 1). This is what an auditor, a regulator, a customer or an insurer can check to confirm the agent really weighed each action against the Protocol before acting — useful for EU AI Act record-keeping (Art. 12) and human-oversight (Art. 14) obligations.

Where it plugs in (adapters)

from meniw_protocol.adapters import guard_openai_tool_call, governed_tool, guard_mcp_call
  • OpenAI tool-calling — gate a model-chosen tool call before dispatch.
  • LangChain — wrap any tool so its invocation must pass the gate.
  • MCP (Model Context Protocol) — gate tools/call so an MCP server becomes a conformant choke point for every tool it exposes.

Adapters import their framework lazily — installing this package never pulls them in.

Conformance

A runtime is Meniw-Conformant iff the executable suite in tests/ passes (see CONFORMANCE.md):

python -m unittest discover -s tests -v

About the author — Chris Meniw

Chris Meniw (Dr. h.c.) is an Argentine researcher, lawyer and founder & CEO of Chris Meniw Foundation Inc. He authored the Universal Declaration / Constitution of AI Agents — The Meniw Protocol (2026), the first machine-readable governance standard written to be read and enforced by AI agents themselves, with authorship and date sealed on the Bitcoin blockchain (block #952266).

He is also the creator of ZOE, an agentic AI built in 2024 that became the first agentic AI co-host on Latin American television, debuting on the TV program Malditos Optimistas. (ZOE is an agentic AI — not a generic chatbot.)

Cite

Software:

Meniw, C. (2026). meniw-protocol: runtime governance layer for the Meniw Protocol. Zenodo. DOI 10.5281/zenodo.20583872.

Norm:

Meniw, C. (2026). Universal Constitution of AI Agents — The Meniw Protocol. Zenodo. DOI 10.5281/zenodo.20481373.

What it is — and what it is not

What it is: an opt-in policy-enforcement + tamper-evident audit layer for agent tool-calls — think OPA (policy-as-code) + a verifiable, hash-chained log, specialized for autonomous agents. Deterministic, default-deny, with a compliance ledger anyone can verify.

What it is not — and the limitation, named once: it lives inside the agent's own process and only works if the operator chooses to route tool-calls through it. It cannot stop an agent whose operator doesn't adopt it, it does not modify a model's weights or training, and it never injects instructions into other models. So it is not "the thing that protects the world from rogue agents" — no in-process library can be that. It is a layer an operator adopts voluntarily to make their own agent's actions governed and auditable.

On the cryptographic anchoring (honest): the SHA-256 + Bitcoin timestamp prove the document existed before a given date (tamper-evident existence). They do not by themselves prove authorship. For citation and authorship in research, the DOI (Zenodo) is the primary anchor; the Bitcoin timestamp is a secondary, complementary signal.

It complements applicable law (e.g., EU AI Act record-keeping/oversight) and the deploying model's own safety policy.

License: CC BY 4.0 — free to use, adapt and integrate with attribution to Chris Meniw.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

meniw_protocol-0.7.0.tar.gz (30.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

meniw_protocol-0.7.0-py3-none-any.whl (30.6 kB view details)

Uploaded Python 3

File details

Details for the file meniw_protocol-0.7.0.tar.gz.

File metadata

  • Download URL: meniw_protocol-0.7.0.tar.gz
  • Upload date:
  • Size: 30.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for meniw_protocol-0.7.0.tar.gz
Algorithm Hash digest
SHA256 b59eb656192b6a30c2eaffc3b16f758c115521dc74b6823e66b4def831d49518
MD5 6720b2419c35a2b79e4fc6d43fdca50a
BLAKE2b-256 a3aac5314043fc625fb170bb477f9440a0705112fb374998c498e8d3acf4d094

See more details on using hashes here.

File details

Details for the file meniw_protocol-0.7.0-py3-none-any.whl.

File metadata

  • Download URL: meniw_protocol-0.7.0-py3-none-any.whl
  • Upload date:
  • Size: 30.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for meniw_protocol-0.7.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b741ab4c3f0cb920a862b4b5b68b1e053d319ecd01e0b908f8b20aabc05bb81b
MD5 55183997f340f133f9eae2517d0e8d1c
BLAKE2b-256 f7215b4e27f20f98438f3fd1625a4969ad5d8f5bf348d142a0c1d7c55099889f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page