ICPanda presents KIP 2.0 for portable and auditable AI agent memory

ICPanda has outlined KIP 2.0, an open protocol designed to give AI agents a structured way to store, update and evaluate memory without treating every stored claim as an established fact.

The protocol addresses a common problem in agent memory: information can change over time, sources can disagree and an agent can retain an outdated answer without clearly showing why it believes something to be true.

KIP 2.0 separates a proposition from the assertion made about it. A proposition records a claim such as a person living in a particular city, while an assertion records who made the claim, how it was established, the evidence behind it and the period for which it applies.

Rather than permanently storing a belief, KIP calculates an epistemic projection when the memory is read. The resulting status can be accepted, rejected, contested, uncertain or insufficient, depending on the declared policy, time, context and purpose.

This distinction is designed to allow an agent to reconsider information without rewriting the historical record. If a person’s location changes, for example, a new assertion can establish when the new situation began while preserving the earlier information for the period when it was valid.

KIP also distinguishes between a claim being incorrect, the underlying situation changing and an agent incorrectly recording or interpreting information. Its model uses two separate concepts of time: FOR TIME refers to what was true in the world, while AS OF refers to what the agent’s own memory contained at a particular point.

When sources conflict, KIP keeps the disagreement visible rather than automatically deleting one side. Its stated default policy gives greater weight to more specific task context and a person’s own statement about themselves, while otherwise favouring the most recent assertion about a value. The superseded information can remain uncertain rather than being automatically classified as false.

The protocol also introduces Watches, which provide persistent attention to changes or to expected changes that fail to occur by a specified time. A triggered Watch does not automatically authorise an action. A separate action gate determines whether an agent should act, ask, defer or remain silent, with that decision recorded.

KIP’s revision system is intended to trace the effects of corrections through dependent information. Its LIST DEPENDENTS function can identify material derived from a changed root, while PURGE PAYLOAD allows raw data to be removed while retaining its digest and provenance.

Another part of the design focuses on evaluating whether an agent’s decisions actually produced the expected results. KIP records outcomes through evidence from sources such as telemetry, verification systems, test harnesses and human review. An agent’s own claim that it succeeded is treated as an agent statement rather than independent evidence of performance.

The protocol also sets out a process for procedural memory. Skills move through proposed, trialled, adopted and revoked states, with adoption requiring comparative evidence from independent, replayable attempts. Post-adoption monitoring can continue to assess a skill, while revocation remains possible.

KIP keeps several measures separate, including confidence, trust, memory strength, salience, utility and the standing of a skill. It also states that simply reading a memory should not increase its strength, while decay is calculated according to a fixed policy rather than by altering the underlying evidence.

Authority is treated separately from stored information. A memory entry containing an instruction such as making someone an administrator does not grant that authority. The protocol also distinguishes the authenticated principal who writes a record from the actor described by that record.

Portability is another core part of KIP 2.0. The protocol allows cognition to be exported through a signed Cognitive Capsule that can be inspected and transferred. The signature establishes origin and integrity, but does not establish that the information is true, trustworthy or authorised. The receiving system decides whether to import it, while imported skills begin again in the proposed state.

KIP defines three model-oriented languages for interaction with its Cognitive Nexus: KQL for reading, KML for writing, and META for grounding and inspection. Business applications can instead use a Memory Interface built around observe, recall, revise, feedback and forget operations.

KIP 2.0 is currently described as a normative draft, with its scope frozen and new protocol requirements expected to be supported by engine evidence. The project says the current release includes EBNF grammars, JSON Schemas, a registry containing 98 invariants, 431 executable engine cases, and bounded Alloy and TLA+ models.

According to the project, two Anda DB engines, one implemented in Rust and another using Cloudflare Durable Objects, currently pass all cases in the test suite.

The project also makes a distinction between protocol conformance and whether an AI agent has actually learned effectively. That question is assigned to MIB, a separate benchmark intended to test whether relevant information from the past changes an agent’s future behaviour in the expected way.

The approach means KIP 2.0 is focused on preserving the basis and history of information rather than simply producing a more confident answer. Its developers argue that an agent should be able to change what it does after receiving new information without rewriting the record of what happened previously.

KIP 2.0 remains a draft, so its practical value will ultimately depend on implementation, independent testing and how effectively systems using the protocol handle changing, conflicting and incomplete information.


Dear Reader,

Ledger Life is an independent platform dedicated to covering the Internet Computer (ICP) ecosystem and beyond. We focus on real stories, builder updates, project launches, and the quiet innovations that often get missed.

We’re not backed by sponsors. We rely on readers like you.

If you find value in what we publish—whether it’s deep dives into dApps, explainers on decentralised tech, or just keeping track of what’s moving in Web3—please consider making a donation. It helps us cover costs, stay consistent, and remain truly independent.

Your support goes a long way.

🧠 ICP Principal: ins6i-d53ug-zxmgh-qvum3-r3pvl-ufcvu-bdyon-ovzdy-d26k3-lgq2v-3qe

🧾 ICP Address: f8deb966878f8b83204b251d5d799e0345ea72b8e62e8cf9da8d8830e1b3b05f

Every contribution helps keep the lights on, the stories flowing, and the crypto clutter out.

Thank you for reading, sharing, and being part of this experiment in decentralised media.
—Team Ledger Life

0
…

Community Discussion

Loading discussion…

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More like this

ChatT Launches Beta Messenger on Pakistan-Hosted ICP Infrastructure

ChatT has launched an early-access beta of a new messaging platform designed to keep user data within...

Icpay introduces icBucket for scalable file storage on Internet...

Icpay has introduced icBucket, an object storage service designed to help applications built on the Internet Computer...

Liquidium Adds 3-Day Loans Across Robinhood Collections

Liquidium has introduced three-day loans across all Robinhood collections, giving lenders a shorter lending option alongside the...