Wheeled, legged, flying, humanoid. A new generation of machines is heading for factory floors, warehouses, streets, skies, and living rooms, and every one of them now navigates and acts on its own from a camera and a plain-language instruction. The first serious incident will come down to one question: what did the machine see, decide, and do, and when? The manufacturer's own telemetry is a document written by the defendant. Hive gives every machine an independent, signed, timestamped witness that works the same way no matter what the machine looks like.
Sidecar to the control loop. Never in it.
AFiR-Stream anchors the session. Each stage emits receipts on its own while the control loop keeps running untouched at full speed. One receipt binds the camera frame, the plain-language instruction, the decision it made (a waypoint, a pointing target, a move), and which machine carried it out. That means one record format works the same across wheeled, legged, flying, and humanoid machines. When nothing goes wrong, the receipts are a compliance asset you can check offline against the Hive public key, the same way in every vertical. When something does go wrong, press the red button.
The clock is real. The EU AI Act's high-risk logging and record-keeping duties (Article 12) phase in through Aug 2, 2026 and Aug 2, 2027, and the EU Machinery Regulation (2023/1230) applies from Jan 20, 2027. Both make a tamper-proof record of what an autonomous machine saw and decided a legal requirement, not a nice-to-have. Any machine shipped into the EU is in scope. An independent, timestamped receipt is how you meet that requirement without handing a regulator your raw sensor data or your model weights.
The red button is not a kill switch. It runs the evidence · export · escalate flow. It never touches the control loop.
A robot senses, decides, and acts in the physical world. An autonomous ops or coding agent does the same thing in a codebase: an alert fires, it reads the logs, it figures out a root cause, and it acts, opening a pull request, shipping a fix, restarting a service. The new wave of incident-response agents wires straight from an alert to a merged change with no human in the loop. That's the same sense, decide, act chain, and it carries the same risk. When the auto-shipped fix takes down checkout at 3am, the only record of what the agent saw and why it acted is the agent's own session log, a document written by the thing under investigation.
Put the witness chain underneath the agent and every step gets signed the instant it happens: which alert fired, which logs it read, the root cause it claimed, and the exact change it pushed. It's bound by hash, anchored outside the agent's own boundary, and checkable offline. Sign-before-act means the receipt for the action exists before the pull request is opened, not pieced together after the outage.
Returns a live signed assessment with a verifiable group_id, the same production signer the robots use, unchanged. Autonomy is the easy part now. Provable autonomy, a signed record a regulated on-call team can actually sign off on, is the part the leaderboards skip.
This is the real production signer, not a mock. Send one navigation decision (the plain-language instruction, a hash of the camera frame it acted on, and the action it chose, a pointing waypoint, a heading, a move) and get back a live Ed25519 signed receipt bound to the exact bytes, checkable offline by anyone. Wrap it around a control loop and every step the robot takes produces its own receipt: a signed, timestamped record of what it saw, what it was told, and what it decided. Video is bound in by frame hash, so no raw video ever leaves the machine.
The open demo runs on the free assessment tier and returns a signed decision plus a verifiable group_id. The paid production path (/v1/receipt/emit, per-decision mint, and the audiovisual Media Origin Receipt) adds the full post-quantum envelope, ML-DSA-65 plus SLH-DSA, settled per receipt over x402. Checking a receipt is always free and works offline against the Hive public key.
The witness chain signs each hop. R3Pv™ groups those receipts into a single proof vector: verification depth, the honest recoverability window, and the actions allowed next, all in one object. Protected Flow is the action layer above it. One call turns a machine event into a signed decision (permit · permit_with_evidence · require_approval · hold · recover · reroute · escalate · block) plus a metered quote and an evidence bundle you can export. That's exactly what the red button fires.
A machine event assessed at the self_attested boundary honestly returns hold. The default pack requires relay_observed before it will permit, and once a physical incident is final the vector reports evidence_only_final. The receipt never claims a finished action can be undone. Policy can only make a decision stricter. The meter is a quote, not a settlement. Both signed objects round trip through POST /v1/receipt/verify.
GET /v1/protected-flow/health and POST /v1/protected-flow/assess returned HTTP 200 (signed decision hold, meter quote 1.105). The assessment verified verified=true at /v1/receipt/verify, and /v1/protected-flow/evidence/{group_id}/export returned a 200 signed bundle. Observed round trip: 0.11 to 0.30 seconds including network. Measure receipt latency separately from control-loop or rail latency. Measured latency & runnable curl →
Home humanoids are trained and assisted by human teleoperators. That's fine, until nobody can prove when. Human-Origin Attestation stamps every session with who or what was in control, without exposing a single camera frame. It's the same primitive Hive uses to prove human versus agent origin across every AI-authored action. Flip it around.
CLOAzK™ proves the behavior without exposing the home. Warden receipts the deletion. HiveSeal · Colony silicon roots ensure the receipt itself can be trusted.
Scroll down. The checks land one by one.
Nobody writes coverage on a 10,000-unit humanoid fleet backed by self-kept logs. Set the fleet; watch the posture gauge move from "uninsurable narrative" to "provable machine." This dashboard is the conversation with the carrier.
Shipping thousands of units into other people's buildings. Every unit is a liability node until it can testify for itself. Provable-by-design becomes the spec line competitors don't have.
Warehouses and factories running mixed fleets they didn't build. When the incident review comes, "the vendor's logs say" is not a position. Independent receipts are the deployer's leverage over every vendor.
The de facto regulator of physical AI. Premiums price uncertainty. Receipts remove it. A "provable machine" class of risk is a product a carrier can actually underwrite, and discount.
Shadow-receipt a single work cell or a ten-unit fleet. Zero changes to the control stack. The sidecar listens, anchors, and signs. It ends with one Deployment Evidence Bundle: perception-to-action chains, teleop attestations, and OTA history, all checkable offline against the Hive public key. The pilot's real product is the document your safety lead forwards.
The receipt shape that anchors a humanoid's control loop is the same one that anchors a sportsbook's intervention, a bank's dispute, or an AI agent's payment. One primitive set. Many verticals. All verifiable offline against the Hive public key.