On-chain execution is verifiable. The AI activity behind it usually isn’t. LEP100 closes that gap by making AI operations attributable, auditable, and cryptographically provable — not just executable.
Blockchains have a well-earned reputation for transparency. A transaction that happened on-chain happened — the ledger says so, the consensus mechanism confirmed it, and no amount of subsequent disagreement can change the record. This is one of the foundational properties that makes decentralized infrastructure worth building on. It is also, increasingly, only part of the story.
As AI systems become active participants in on-chain activity — initiating transactions, executing agreements, managing assets, coordinating with other agents — the relevant question shifts. It is no longer just “did this transaction happen?” It is “which AI system caused this transaction, what was it authorized to do, what inputs did it act on, what output did it produce, and who or what can be held accountable for the result?” A blockchain that can answer the first question but not the second is a transparent ledger with an opaque layer sitting on top of it.
This is the problem LEP100 is built to address. As Lithosphere’s standard for AI provenance and identity, LEP100 extends the verifiability of on-chain execution to the AI activity that initiates it. When an AI system operates through the Lithosphere stack, LEP100 provides the framework for establishing which model performed the operation, which provider executed it, what was authorized prior to execution, what output was produced, what resources were consumed, and which cryptographic identity attested to the event. That record is not a log appended after the fact — it is a native part of how AI activity is structured on the network.
The comparison to standard AI-on-chain integrations is stark. In most current implementations, an AI agent executes some logic off-chain and submits the result as a transaction. The blockchain records the transaction. Nothing in that record establishes which model produced the result, whether the model was the one authorized to produce it, whether the inputs it acted on were the ones the user provided, or whether the output could have been produced differently by a different model under the same conditions. The ledger is honest about what happened. It has no mechanism to be honest about what produced it.
LEP100 changes what “AI activity” means in the context of verifiable infrastructure. An operation that carries LEP100 provenance is not just an output sitting on a ledger — it is an attributable event. The model that produced it is identified. The authorization under which it acted is part of the record. The resources it consumed are logged. The cryptographic identity that attested to the event is verifiable. This is what it means for AI activity to be auditable rather than merely observable — not that you can see the output, but that you can trace the full chain of custody from authorization through execution to result.
As AI systems take on increasingly consequential roles in financial infrastructure — managing assets, executing agreements on behalf of users, coordinating with other agents across chains — the absence of provenance is not a minor gap. It is a fundamental accountability problem. Systems that cannot establish what they did, under whose authority, and through which model are systems where errors and misuse have nowhere to be attributed. LEP100 is Lithosphere’s answer to that problem: not as a compliance feature or an audit trail bolted onto the outside of the system, but as a native property of how AI activity is executed and recorded on the network from the ground up.



