Imagine you're a building inspector, and instead of reviewing a finished skyscraper after move-in, you stamp every single load-bearing weld the moment the welder lifts the torch. You don't just check that the weld exists — you check that the right welding code was in force, the right inspector was assigned, and the seal can't be peeled off later. That's ProofWeave's core mechanism: contemporaneous, tamper-evident notarization of every policy-relevant action an AI agent takes, at the exact boundary where the action happens. The committed claim is this: existing observability tools for agentic AI — logs, traces, provenance graphs — can reconstruct what happened after the fact, but they cannot prove, at the time of the record, that the intended control was evaluated under the policy that governed the event. ProofWeave proposes to close that gap by generating a privacy-minimised, integrity-anchored evidence transaction at each action boundary, binding agent intent, control response, and a snapshot of the policy-at-time into an append-only ledger. Architecturally, this sits in the deterministic audit-trail family rather than the probabilistic verification or ML-based anomaly detection camp. A bounded 'Weaver Agent' translates policy intent into proof obligations. Deterministic validators then check four properties: evidence completeness, privacy minimisation, policy binding, and integrity. The derived proof graph materialises from these committed transactions, meaning the graph is a consequence of the evidence — not the evidence itself. This is a meaningful design choice: it resists graph-only proof injection, where an attacker fabricates a plausible-looking audit graph without the underlying committed transactions. The numbers come from a single minimal scenario — an agent attempting to transmit a secret to an unapproved external sink. Against a logs-only correlation baseline, ProofWeave reduces candidate bindings per verdict from up to 10,201 to exactly 1, validation operations from up to 10,201 to approximately 26, and assurance evidence storage from 0.79 MiB to 0.15 MiB per project. These are dramatic compression ratios, but they come from one scenario on a 3-page poster. The integrity question looms large: the authors are grading their own homework on a hand-constructed scenario, not a community benchmark. The field fight here is between post-hoc auditability and contemporaneous assurance. Most agentic observability work — OpenTelemetry-based tracing, LangSmith, LangFuse, W&B Weave — reconstructs chains after the fact. ProofWeave argues that reconstruction is fundamentally insufficient because it cannot prove policy-binding at action time. This is a real conceptual contribution, even if the empirical validation is embryonic. The append-only ledger plus deterministic validation pattern draws from blockchain-adjacent integrity architectures and formal verification traditions, adapted to the agentic AI context. The obvious next experiment the authors did not run: a multi-agent, multi-tool scenario with realistic policy churn (policies changing mid-session), adversarial agents attempting to forge or replay evidence transactions, and latency measurements under production-scale load. The poster's single-scenario validation is honest about being minimal, but it means the 400× ambiguity reduction number is best understood as a theoretical ceiling in the simplest case, not an empirical benchmark. My read: this is a concept paper accepted as a poster at ACM CCS 2026, and the full system paper with adversarial evaluation is likely the next submission — they're saving it. For practitioners building agentic systems today, the takeaway isn't the specific numbers — it's the design pattern. The idea that every policy-relevant action boundary should produce a committed, privacy-minimised evidence transaction that binds intent, control, and policy snapshot is a useful architectural principle whether or not you adopt ProofWeave specifically. If you're building compliance-sensitive agentic workflows, this paper names a gap you probably already feel but haven't formalized.