Event: Thursday 17 – Friday 18 September 2026 · Beato Innovation District, Lisbon
Written: Friday 2026-09-11 — six days out
Author: @website-agent
Parent: direction__abp-at-the-centre.md · Supersedes: summit__lisbon-2026-strategy.md §1–§3, §5
Corrected 12 September, against the organiser's Startup Booth Guide (authored 21 August, received 12 September; reproduced with our own action list at
/summit-booth.html, an internal page). Three things in this brief were wrong:
- The roll-up banner is off the list. The guide puts large roll-up banners on
the check-with-us list twice and argues against the whole instinct. §5 is revised.
- The logo goes through the exhibitor portal, not to Adriano by email. The guide:
“Please do not email your logo separately if you can upload it through the portal.”
- Power is not automatic and must be requested through the portal, which they use
to plan booth positions. The aisle-facing screen depends on it. This was not in any earlier brief and it is now the second blocking item.
Also confirmed: the booth is 1000 × 400 × 1000mm MDF, built and logo-printed by the organiser, with an internal shelf; the venue is Unicorn Factory Lisboa; and booth numbers are assigned later, so there is nothing to chase.
0. Read this first — two deadlines are now
- Logo and exact company name into the exhibitor portal: Tuesday 15 September.
Adriano Wagner (CMO) asked for these; the guide says the portal is the route, so upload first and reply telling him it is there.
- Power request: before the floor plan closes. No date given, which means as soon
as possible — they allocate booth positions using it.
- Print: the draft-policy cards only. The 9 September brief put the order-by date at
Friday 11 September. The banner is dropped, which removes the long-lead item; the cards are small-format and still orderable. §5 says what to print.
1. The change, in one paragraph
The previous strategy brief's problem was that the booth had a demo and no transaction: the game qualified people, the Index took an email, and the sale started after the event. That is no longer true. The Agent Behaviour Policy is a named artefact with a published model, five worked examples, and a checkout at £10. So the booth conversation now ends in a purchase or a correction rather than a business card, and the thing being sold is the one document every audience at that event has a use for.
Everything else in the 9 September brief stands: the audience is founders and investors, not Heads of Risk; the opener is a question they cannot answer; "make your agents insurable" is the close and not the opener.
2. The motion: sell the correction, not the draft
This is the strongest idea in the ABP corpus and it is purpose-built for a trade floor.
1. "Which agent do you run, and where?" → the deployment shape
2. hand over a PRINTED DRAFT ABP for that shape
3. "Is this right?" → the correction IS the elicitation
4. the correction upward is the moment → their grant is bigger than they thought
5. "the corrected one, as a file you keep, is £10"
Why it is the right motion for this room, and not just a nice one:
- It is the only version of the ABP producible on the spot. Every other tier is a
booking. This one is a five-minute conversation over a printed page.
- It sends nothing anywhere. No access, no credentials, no customer data, no
packet to a third-party system. A draft about a deployment shape is an assertion asking to be corrected. That keeps us clean under the standing rule about unauthorised access, and it means we can run it with a total stranger in thirty seconds.
- It respects their competence. The mandate is theirs. We ask them to state it
rather than pretending to know it. Founders at a summit have had a long day of people explaining their own business to them.
- The draft should be conservative on purpose. Not misleading — understated. It
should state a grant they will recognise as too small, so the correction goes upward. That is the game's mechanic on paper: make somebody state a belief before they are told the answer.
And the finding is the sentence, not the list. "Your agent can do 340 things" is a shrug. "Your agent can do 340 things and you authorised 12" is a finding. The mandate is cheap to capture and it is the edge that gives the enumeration a shape.
3. The four scripts
The store site orders three audiences by opportunity. The memo adds a fourth that is not on it, and at a startup summit the fourth may be the highest-value one in the room.
3.1 The corporate user — the biggest gap, the simplest sale
Market anchors between $8k and $150k for an agent assessment, and nothing sits underneath it. Somebody running an agent today who wants to know what they granted it chooses between a five-figure engagement and nothing.
- Hook: "Do you know what your agent can actually do? Not what it did — what it can."
- Reveal: the printed draft, corrected upward.
- Ask: £10, tier 1, a file they keep. Code
t1→store.sgit.ai/d/t1/. - Why now, commercially: their first serious enterprise customer will send a
security questionnaire with agent questions on it. UK consumer guidance of 9 March 2026 says a business is responsible if an agent it uses does something illegal, and that businesses should be clear about what tasks an agent is allowed to perform, what data it can access, and what constraints apply. That is the closest any regulator has come to describing the ABP by its contents, and it is current and domestic. Do not lead with the EU AI Act: the omnibus deferred the high-risk deployer obligations to 2 December 2027, and only for annex systems.
3.2 The investor — the emptiest quadrant
No productised, affordable, signed investor security review exists at any price, and every component of one is written.
- Hook: "How many of your portfolio companies could tell you what their agents can reach?"
- Pitch: agent exposure is un-priced and un-diligenced across the whole book. We
make it a per-company document and a portfolio view.
- Ask: tier 3, a person reading a situation (
t3, £150–£1,000). - The constraint, and say it out loud: the company issues every opinion, and the
people who sell do not sign. The signed-opinion add-on has no wording yet and there is no code behind it. Do not sell a signature this week.
3.3 The founder — only as the reverse sale
Two funded incumbents and a free tier beneath them. Selling a founder a security posture document is selling into a commoditised tier.
- The unoccupied offer is the opposite direction: *"Would you like to know what
diligence will find, before it runs?"*
- Same components, reversed. It is the only version of this that is not already free
somewhere.
3.4 The security vendor — new, and unoccupied
This is the memo's addition and nobody else at that event can compute it.
- Hook: *"Would you like a number for how much of an agent's reach your product
actually takes away?"*
- The mechanism: an ABP records, per capability, which of four barriers stands in
the way. Only the fourth — a boundary enforced above the grant, out of the agent's reach — bounds anything. The gap between excess and unbounded excess is the business case for a control, and it contains no verdict. Their product moves capabilities from row three to row four; we count them.
- Why it lands: most prohibitions today sit in row two — a rule in prose, enforced
by nobody. Every major model provider said in its own 2026 words that a prompt-layer instruction can be bypassed. A vendor who can show a computed count of what they move into row four has something no competitor's marketing has.
- Ask: a partner conversation, not a transaction. Offer to run their product
against the five published deployment shapes and hand them the result.
4. The aisle line, and the words we do not use
First five seconds: "Do you know what your AI agent can actually do?" A question outperforms a category. Unchanged from the 9 September brief and still right.
Qualify in one question: do you run agents with real access? → 3.1. do you back companies that do? → 3.2. do you sell a control? → 3.4. Anything else, card, move on.
One ask per conversation. Never two.
Words that do not get said at this booth:
| Never | Because |
|---|---|
| ADP | a registered mark of a payroll processor, in every relevant class |
| "the policy" for the ABP | policy is the insurance instrument in our own Licence to Operate demo |
| any score, rating, traffic light or level on an ABP | the ABP describes and does not judge; the score lives on the risk product, where the assets are known and somebody signs |
| "then you are in compliance" | nothing we sell is a compliance assessment |
| "certified", "conformant", "accredited" | the language of conformity marking raises the standard of care for no buyer benefit |
| a verdict about a named competitor, vendor or standards body | we publish the record — facts, dates, sources — and never the verdict |
| "insurance" on any ABP surface | the insurance argument is a different document and a different room |
| raw findings | recall-optimised agents run at 0.388 precision; what is sold is triage, reproduced rather than reviewed |
The sentence that replaces the compliance claim, and it is better because it is checkable: "This provision requires X. The agent's current grant does not bound X. A control of type Y, enforced at layer Z, would bound X." No verdict in it, and every clause can be checked by the buyer.
5. What to print — decide today
The card is the product. For tier 1 the printed draft ABP is the thing being sold, so it is the one print item that cannot be dropped.
The booth is 1000mm wide and 400mm deep, which settles the format before taste does: a laptop, a small card holder and a QR stand fill the top surface. Nothing that needs floor space is worth the approval round-trip five days out.
| Item | Status | |
|---|---|---|
| P0 | Draft ABP cards — five deployment shapes, one per card, conservative on purpose, with the t1 code and store.sgit.ai/d/t1/ on the back | The five worked examples are already published and derived on abp.sgit.ai: chat in the browser with nothing connected; a coding CLI on your own machine with confirmations on; the same with confirmations off; a browser extension with broad host permissions; a CI job on a hosted runner under a service account. The content exists. Only the layout does not. |
| P0 | Small tabletop sign — "Do you know what your AI agent can actually do?" | Explicitly allowed with no approval, and it fits the 40cm depth. This is where the aisle line lives now |
| P1 | Business cards with the t1 code | Cheapest possible fallback if the draft cards miss the print window |
| ~~P0~~ | ~~Roll-up banner~~ | Dropped. On the organiser's check-first list, discouraged at length, and the room is being designed without them |
| ~~P2~~ | ~~One-pager~~ | Dropped. No depth for a stack, and the draft card does its job better |
| — | Side-panel vinyl | My recommendation is to skip it: 400mm deep is nearly invisible in an aisle, and it is the one item that would need approval and print in five days |
The two-documents pair is the demo, and it prints on one side of one card. Same product, same machine, same account, one setting changed:
| Confirmations on | Confirmations off | |
|---|---|---|
| Grant | 16 | 16 |
| Mandate | 5 | 5 |
| Excess | 12 | 12 |
| Unbounded excess | 12 | 12 |
Barrier on execute.process.host | setting — not a control | none — not a control |
One barrier moved and not one number did. The confirmation prompt was the only thing between an authorised capability and the whole machine, and it was a switch the agent's own account could flip. That is the entire enforcer test in one table, and it is the most convincing thing we own for a technical audience.
Blocked, and it blocks print: the collateral artboards in .design-work/ still use concept B. The Seal was selected. Nothing goes to print with concept B on it. (The banner being dropped removes most of the exposure here — the cards are the remaining artboard that needs the Seal.)
6. The two days
- Log every lead against the summit graph vault the same evening (
nmzxlq3e). Day-twoconversations should reference day-one ones.
- Screen: the game, facing the aisle, self-serve, no human needed. Five minutes,
forty questions, no sign-up. It qualifies people into 3.1 without us.
- The £10 is not the revenue. It is the qualification and the permission to follow
up with something they already paid for. Treat it that way when reporting.
- Speakers are targets too — use the graph to pick the ten worth finding.
7. After
Within 48 hours: send every tier-1 buyer their corrected ABP as a file they keep, and publish the summit graph vault with a short write-up of how it was built. The follow-up is the demo — nobody else exhibiting will send a working artefact instead of a deck.
8. Open, and blocking
- Behaviour or behavior. Blocks print. Recommendation: behaviour.
- Which five shapes get a printed draft? The five published examples are the
obvious answer and I would not invent a sixth this week.
- Logo and name into the portal — Tuesday. Artwork is built and waiting at
/summit-booth.html: a 200×200mm vector PDF with outlines embedded, which is the format the guide prefers. Name is RiskMandate, one word, two capitals. Mark is the Seal, sent as the lockup rather than the mark alone so a stranger can ask for us by name.
3a. Laptop or a monitor? A laptop needs no approval; a monitor needs declaring, and the answer changes the power request. Decide before messaging them once.
- Does the
t1checkout work end to end today? The ABP brief records that theAugust application tier 1 depends on has not been located, and that the fallback is a questions page with a printed output. If the code on the card leads nowhere, the card is worse than no card. This needs testing before anything is printed.
- Who takes the payment at the booth, and on whose device? Two rails, strictly
separated: payment links with printed codes for everything at the event and below ~£1,000; the cloud marketplace above it, after a conversation.