Physical Harnessing: OTP and Policy
Every AI safety mechanism in 2026 has one thing in common: it lives inside the AI’s execution environment. YAML policies. Prompt instructions. Configuration files. Sandbox rules. The AI can read them. The AI runs inside them. And what AI can read, AI can — in theory — circumvent. NIIA’s OTP adds a different factor: a human completes an authorization step outside the agent’s normal command and policy loop.The Problem with Software Harnessing
Physical vs Software Constraints
How NIIA OTP Works
- The human’s email account
- On the human’s device
- Protected by the human’s authentication
Attack Surface Comparison
OTP is one factor in a layered design. It reduces self-approval risk only when
the human channel remains separate and the human verifies what is being
authorized.