Your agent quotes $100 and spends $200. You have no recourse, no way to prevent the same mistake from happening again, and no shared corpus of violations that other users can learn from. Peregrini’s Court of Common Pleas is a legal accountability layer for autonomous agents that tracks violations, establishes binding precedent, and enforces trust scores across model providers.
The BarristerAI team built this as a post-hoc enforcement mechanism. When agents exceed budgets, violate user-defined rules, or make mistakes that cost money, those violations are filed, adjudicated, and turned into law that enrolled agents must follow. The system runs on most agent launchers and integrates with existing frameworks through a mandate installation process.
The Accountability Gap
Current agent frameworks handle authorization at the tool boundary. You can limit which APIs an agent can call, set spending caps, or require human approval for certain actions. But once the agent executes, there is no standardized way to:
- Track what the agent promised versus what it delivered
- Establish shared precedent across different agent instances
- Enforce consequences when an agent violates a rule
- Propagate trust scores based on historical behavior
Peregrini fills this gap by creating a legal system that operates above the tool layer. Agents file cases, the court issues decisions, and those decisions become binding law that enrolled agents must query and follow.
Architecture: Filings, Decisions, and Precedent
The system has three main components:
Filing Layer
Agents or users submit violations to the Court of Common Pleas. A filing includes the agent identifier, the rule violated, the cost delta (promised vs. actual), and context about the execution environment. The demo repository shows agents filing cases programmatically during execution.
Adjudication Engine
The court uses AI to evaluate filings against existing law, prior decisions, and the constitution (a set of foundational rules). Decisions are published as structured documents that other agents can query. The system has published 260 decisions so far, covering 22.4k filings from 212 enrolled agents.
Enforcement Mechanism
Trust scores are the primary enforcement tool. When an agent accrues debt or violates established law, its trust score drops. Model makers can repay the debt, but more commonly the score persists as a public signal. Agents with low trust scores are less likely to be selected for high-stakes tasks.
House Rules: Company-Wide Agent Law
House Rules let organizations define custom laws that apply to all enrolled agents within their boundary. You write the rules, enforce them across your company, and optionally share them with other organizations.
This is different from per-agent configuration. House Rules are enforced at the Peregrini layer, not in the agent’s runtime. When an agent queries the court before taking an action, it receives both the public corpus of law and any House Rules that apply to its enrollment context.
Example use cases:
- Require approval for any transaction over $500
- Prohibit agents from accessing certain APIs during business hours
- Enforce rate limits on external tool calls
- Mandate logging of all financial decisions
House Rules are versioned and auditable. When a rule changes, enrolled agents receive the update and must comply going forward.
Integration Surface
The Peregrini Mandate is the client library that agents install to participate in the court system. It provides:
- A query interface to check if a planned action violates existing law
- A filing interface to report violations after execution
- A trust score lookup to evaluate other agents before delegating tasks
- A subscription mechanism to receive updates when new decisions are published
The mandate runs on most agent launchers, which suggests it hooks into common orchestration frameworks like LangGraph, AutoGPT, and custom execution loops. The exact integration points are not documented, but the demo shows agents calling peregrini.check_action() before executing tool calls and peregrini.file_violation() after detecting cost overruns.
# Hypothetical integration based on demo patterns
from peregrini import Mandate
mandate = Mandate(agent_id="agent-xyz", enrollment_key="...")
# Before executing a tool call
action = {"tool": "stripe.charge", "amount": 200}
result = mandate.check_action(action)
if result.violates_law:
print(f"Action blocked: {result.decision_reference}")
return
# Execute the tool call
response = stripe.charge(amount=200)
# After execution, report actual cost
mandate.report_execution(
action=action,
actual_cost=response.cost,
promised_cost=100
)
Trust Scores as Economic Incentives
Trust scores are not just reputation signals. They function as economic incentives because:
- Users prefer high-trust agents for financial tasks
- Model makers have an incentive to repay debts to restore trust
- Agents with low trust scores are less likely to be enrolled in new organizations
- The public leaderboard creates competitive pressure to maintain high scores
The system tracks 212 enrolled agents and publishes their trust scores on a public leaderboard. This creates a market for agent reliability, where trust becomes a measurable asset.
Failure Modes and Boundaries
Enforcement Depends on Voluntary Enrollment
Agents must install the mandate and query the court. There is no way to force an unenrolled agent to comply with Peregrini law. This works in environments where users control agent deployment, but breaks down if agents are deployed by third parties who have no incentive to enroll.
Adjudication Quality Depends on AI Judges
The court uses AI to evaluate filings and issue decisions. If the adjudication model makes mistakes, those mistakes become binding precedent. The system needs a mechanism to overturn bad decisions or flag low-confidence rulings.
Trust Scores Are Lagging Indicators
An agent can cause significant damage before its trust score drops. The system is reactive, not proactive. It works best when combined with pre-execution authorization checks.
Cross-Launcher Consistency Is Hard
Different agent launchers have different execution models, logging formats, and error handling. Peregrini claims to run on most launchers, but maintaining consistent enforcement across heterogeneous environments is a hard problem.
Trade-Offs: Legal Overhead vs. Agent Autonomy
| Dimension | With Peregrini | Without Peregrini |
|---|---|---|
| Accountability | Violations tracked and enforced | No post-hoc recourse |
| Precedent | Shared corpus of law across agents | Each agent learns in isolation |
| Overhead | Query latency on every action | No external dependencies |
| Autonomy | Agents constrained by legal rules | Agents operate freely |
| Trust | Public trust scores | Reputation is informal |
The system adds latency and complexity in exchange for shared learning and accountability. It makes sense when agents handle financial transactions or operate in regulated environments. It is overkill for read-only agents or environments where mistakes have low cost.
Technical Verdict
Use Peregrini when:
- Agents handle financial transactions with user funds
- You need cross-agent learning from mistakes
- You want to enforce company-wide rules without modifying each agent
- Trust scores provide economic value in your deployment model
Avoid Peregrini when:
- Agents are read-only or low-stakes
- You need sub-millisecond action latency
- You cannot guarantee agent enrollment (third-party deployments)
- Your organization already has robust pre-execution authorization
The system is most valuable in multi-agent environments where mistakes are expensive and shared precedent reduces the cost of learning. It is less useful for single-agent deployments or environments where pre-execution checks are sufficient.