2026-07-23 · 6 MIN READ
Why AI needs receipts
Generation got the billions. Verification got nothing. That imbalance is the biggest open opportunity in the AI stack.
Ask a bank what its AI did last Tuesday and you will get a shrug. Not because anyone is hiding something, but because nothing wrote it down in a form that counts. There are logs, in the engineering sense: rotating, truncated, editable, scattered across vendors. There is no record, in the audit sense: a durable, tamper-evident account of what went in, what came out, and what rules it was held to.
This was fine when AI drafted birthday poems. It stops being fine the moment AI touches regulated work: a promotion that goes to customers, a screening decision, a clinical note, a credit call. In those settings the question is never only "was the output good?" It is "can you show me?" Regulators, auditors and courts run on evidence, and the AI industry has spent its entire existence optimising the one thing evidence is not: fluent output.
The asymmetry nobody priced in
The economics of the last few years pushed everyone to one side of the boat. Model labs compete on generation quality. Application startups compete on how much generation they can wire into a workflow. Even the safety conversation is mostly about what models should refuse to say, which is still a question about generation.
Verification, meanwhile, is treated as someone else's job: the compliance team's, the auditor's, the regulator's. But those people were never given tools that operate at the speed and volume of machine output. A compliance officer can review a promotion in twenty minutes. An LLM can draft four hundred in an hour. The bottleneck did not disappear. It moved, and it moved onto the desk of the one person in the building with personal liability.
Trust is an assertion. Proof is a receipt.
What a receipt actually is
A receipt for an AI action needs three properties. It must be specific: it names the model, the input, the output and the rules the output was checked against, with citations you can look up. It must be durable: hashed and chained so that editing history breaks the chain in plain sight. And it must be honest about its own limits: if the system could not reach a confident verdict, the receipt should say so, because a record of a guess is worse than no record at all.
None of this is exotic cryptography. Hash chains are older than Bitcoin. The reason receipts do not exist is not that they are hard. It is that nobody's incentives pointed at building them, because receipts do not demo well. A model that writes a sonnet is a launch video. A sealed record that a promotion was checked against COBS 4 is a line item in an audit file. One of these raises money easily. The other is what a regulated industry actually runs on.
The wedge, then the layer
We are building this bottom-up, starting where the pain is sharpest: financial promotions, where UK firms already carry an explicit obligation to be fair, clear and not misleading, and where every marketing artefact needs sign-off someone can defend later. A deterministic checker with citations and a sealed evidence pack is immediately useful there, today, with no change in law required.
But the wedge is not the point. Every regulated vertical is about to have the same conversation: AI is doing the work, and nobody can prove what it did. The audit layer that answers that question, the receipts, the checks, eventually the cryptographic proof that a specific model produced a specific decision, gets built once and then applies everywhere. That layer is what Velkron exists to build.
The last era of AI was about making machines produce. The next one is about making them accountable. Receipts are where that starts.
Velkron is the verification layer for AI in regulated industries.