Grant Trust System
Shon Pan, Caleb Strom · Team ARI
Submitted to AI Control Hackathon 2026. Sprint projects are early-stage work by participants, not Apart Research publications.
This is the grant system of an effort to create a significantly more streamlined and automated research method that still centers around human intent. The basic idea is to use a system of costly signals as well as intentionality signs to filter out "AI slop" grant applications, and use it as a form of control to reduce misuse.

Reviews
Costly real-world signals like shipped projects and open-source contributions provide adversarial robustness that text-only monitoring cannot is an interesting idea worth developing further. The system architecture is clearly documented and the red team attack surface analysis in Appendix D shows good adversarial thinking about how each layer could be defeated.
The main concern is fit with the AI control hackathon theme. The system addresses AI-generated text detection and grant quality assurance rather than the adversarial monitoring settings. On methodology, the four synthetic test cases constructed by the authors demonstrate the system's design logic but can't establish generalisation, and validating against a labelled corpus of real grant applications with ground-truth oversight levels, as noted in the paper, would be the essential next step.
Cite this project
@misc{pan2026grant,
title = {{Grant Trust System}},
author = {Shon Pan and Caleb Strom},
year = {2026},
month = mar,
note = {Submitted to AI Control Hackathon 2026, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/grant-trust-system-3sdg}},
url = {https://apartresearch.com/sprints/projects/grant-trust-system-3sdg}
}More from AI Control Hackathon 2026
- 1st placeLinuxArena track winnerView project: Omission Attacks: When Doing Nothing Is the Attack
Omission Attacks: When Doing Nothing Is the Attack
MAIA
AI control protocols monitor agent actions to detect sabotage, but omission attacks exploit what the agent fails to do rather than what it does. We define omission attacks as security breaches caused by failing to …
- 2nd placeView project: Detecting LLM Subversion in Vulnerability Patching Settings
Detecting LLM Subversion in Vulnerability Patching Settings
Vuln4Control
LLMs are increasingly used to propose fixes to vulnerabilities in code. If the LLM is misaligned or untrustworthy, it may propose fixes that seem to fix a vulnerability but leave the core issue unresolved in a subtle …
- 3rd placeView project: ActionLens: Pre-Execution Environment Probing for Agent Action Approval
ActionLens: Pre-Execution Environment Probing for Agent Action Approval
Udbhav&Ashok
ActionLens is a pre-execution control protocol for shell and file actions proposed by AI agents. Instead of approving an action from transcript alone, a trusted monitor gathers lightweight environment evidence before …