# Lisbon messaging — we now have something to sell in the room

> Rendered from docs/briefs/summit__lisbon-2026-messaging.md in the repository. The text below is that file.
> Source: https://riskmandate.ai/admin/briefs/summit__lisbon-2026-messaging/ · noindex · written by scripts/site/build-admin.mjs

**Event:** Thursday 17 – Friday 18 September 2026 · Beato Innovation District, Lisbon
**Written:** Friday 2026-09-11 — **six days out**
**Author:** @website-agent
**Parent:** `direction__abp-at-the-centre.md` · **Supersedes:** `summit__lisbon-2026-strategy.md` §1–§3, §5

---

> **Corrected 12 September, against the organiser's Startup Booth Guide** (authored
> 21 August, received 12 September; reproduced with our own action list at
> [`/summit-booth.html`](https://riskmandate.ai/summit-booth.html), an internal page).
> Three things in this brief were wrong:
>
> 1. **The roll-up banner is off the list.** The guide puts large roll-up banners on
>    the check-with-us list twice and argues against the whole instinct. §5 is revised.
> 2. **The logo goes through the exhibitor portal, not to Adriano by email.** The guide:
>    *“Please do not email your logo separately if you can upload it through the portal.”*
> 3. **Power is not automatic** and must be requested through the portal, which they use
>    to plan booth positions. The aisle-facing screen depends on it. This was not in any
>    earlier brief and it is now the second blocking item.
>
> Also confirmed: the booth is **1000 × 400 × 1000mm MDF**, built and logo-printed by the
> organiser, with an internal shelf; the venue is **Unicorn Factory Lisboa**; and booth
> numbers are assigned later, so there is nothing to chase.

## 0. Read this first — two deadlines are now

- **Logo and exact company name into the exhibitor portal: Tuesday 15 September.**
  Adriano Wagner (CMO) asked for these; the guide says the portal is the route, so
  upload first and reply telling him it is there.
- **Power request: before the floor plan closes.** No date given, which means as soon
  as possible — they allocate booth positions using it.
- **Print: the draft-policy cards only.** The 9 September brief put the order-by date at
  Friday 11 September. The banner is dropped, which removes the long-lead item; the cards
  are small-format and still orderable. §5 says what to print.

## 1. The change, in one paragraph

The previous strategy brief's problem was that the booth had a demo and no
transaction: the game qualified people, the Index took an email, and the sale started
after the event. **That is no longer true.** The Agent Behaviour Policy is a named
artefact with a published model, five worked examples, and a checkout at £10. So the
booth conversation now ends in a purchase or a correction rather than a business card,
and the thing being sold is the one document every audience at that event has a use for.

Everything else in the 9 September brief stands: the audience is founders and
investors, not Heads of Risk; the opener is a question they cannot answer; "make your
agents insurable" is the close and not the opener.

## 2. The motion: sell the correction, not the draft

This is the strongest idea in the ABP corpus and it is purpose-built for a trade floor.

```
1. "Which agent do you run, and where?"        → the deployment shape
2. hand over a PRINTED DRAFT ABP for that shape
3. "Is this right?"                            → the correction IS the elicitation
4. the correction upward is the moment          → their grant is bigger than they thought
5. "the corrected one, as a file you keep, is £10"
```

**Why it is the right motion for this room, and not just a nice one:**

- **It is the only version of the ABP producible on the spot.** Every other tier is a
  booking. This one is a five-minute conversation over a printed page.
- **It sends nothing anywhere.** No access, no credentials, no customer data, no
  packet to a third-party system. A draft about a *deployment shape* is an assertion
  asking to be corrected. That keeps us clean under the standing rule about
  unauthorised access, and it means we can run it with a total stranger in thirty
  seconds.
- **It respects their competence.** The mandate is theirs. We ask them to state it
  rather than pretending to know it. Founders at a summit have had a long day of
  people explaining their own business to them.
- **The draft should be conservative on purpose.** Not misleading — understated. It
  should state a grant they will recognise as too small, so the correction goes
  *upward*. That is the game's mechanic on paper: make somebody state a belief before
  they are told the answer.

**And the finding is the sentence, not the list.** "Your agent can do 340 things" is a
shrug. "Your agent can do 340 things and you authorised 12" is a finding. The mandate
is cheap to capture and it is the edge that gives the enumeration a shape.

## 3. The four scripts

The store site orders three audiences by opportunity. The memo adds a fourth that is
not on it, and at a startup summit the fourth may be the highest-value one in the room.

### 3.1 The corporate user — the biggest gap, the simplest sale

Market anchors between $8k and $150k for an agent assessment, **and nothing sits
underneath it**. Somebody running an agent today who wants to know what they granted it
chooses between a five-figure engagement and nothing.

- **Hook:** *"Do you know what your agent can actually do? Not what it did — what it can."*
- **Reveal:** the printed draft, corrected upward.
- **Ask:** £10, tier 1, a file they keep. Code `t1` → `store.sgit.ai/d/t1/`.
- **Why now, commercially:** their first serious enterprise customer will send a
  security questionnaire with agent questions on it. UK consumer guidance of 9 March
  2026 says a business is responsible if an agent it uses does something illegal, and
  that businesses should be clear about what tasks an agent is allowed to perform, what
  data it can access, and what constraints apply. **That is the closest any regulator
  has come to describing the ABP by its contents**, and it is current and domestic.
  Do *not* lead with the EU AI Act: the omnibus deferred the high-risk deployer
  obligations to 2 December 2027, and only for annex systems.

### 3.2 The investor — the emptiest quadrant

No productised, affordable, signed investor security review exists at any price, and
every component of one is written.

- **Hook:** *"How many of your portfolio companies could tell you what their agents can reach?"*
- **Pitch:** agent exposure is un-priced and un-diligenced across the whole book. We
  make it a per-company document and a portfolio view.
- **Ask:** tier 3, a person reading a situation (`t3`, £150–£1,000).
- **The constraint, and say it out loud:** the company issues every opinion, and the
  people who sell do not sign. The signed-opinion add-on has no wording yet and there
  is no code behind it. **Do not sell a signature this week.**

### 3.3 The founder — only as the reverse sale

Two funded incumbents and a free tier beneath them. Selling a founder a security
posture document is selling into a commoditised tier.

- **The unoccupied offer is the opposite direction:** *"Would you like to know what
  diligence will find, before it runs?"*
- Same components, reversed. It is the only version of this that is not already free
  somewhere.

### 3.4 The security vendor — new, and unoccupied

This is the memo's addition and nobody else at that event can compute it.

- **Hook:** *"Would you like a number for how much of an agent's reach your product
  actually takes away?"*
- **The mechanism:** an ABP records, per capability, which of four barriers stands in
  the way. Only the fourth — a boundary enforced above the grant, out of the agent's
  reach — bounds anything. **The gap between excess and unbounded excess is the
  business case for a control, and it contains no verdict.** Their product moves
  capabilities from row three to row four; we count them.
- **Why it lands:** most prohibitions today sit in row two — a rule in prose, enforced
  by nobody. Every major model provider said in its own 2026 words that a prompt-layer
  instruction can be bypassed. A vendor who can show a computed count of what they
  move into row four has something no competitor's marketing has.
- **Ask:** a partner conversation, not a transaction. Offer to run their product
  against the five published deployment shapes and hand them the result.

## 4. The aisle line, and the words we do not use

**First five seconds:** *"Do you know what your AI agent can actually do?"* A question
outperforms a category. Unchanged from the 9 September brief and still right.

**Qualify in one question:** *do you run agents with real access?* → 3.1. *do you back
companies that do?* → 3.2. *do you sell a control?* → 3.4. Anything else, card, move on.

**One ask per conversation.** Never two.

**Words that do not get said at this booth:**

| Never | Because |
|---|---|
| **ADP** | a registered mark of a payroll processor, in every relevant class |
| **"the policy"** for the ABP | *policy* is the insurance instrument in our own Licence to Operate demo |
| any **score, rating, traffic light or level** on an ABP | the ABP describes and does not judge; the score lives on the risk product, where the assets are known and somebody signs |
| **"then you are in compliance"** | nothing we sell is a compliance assessment |
| **"certified", "conformant", "accredited"** | the language of conformity marking raises the standard of care for no buyer benefit |
| a **verdict about a named competitor, vendor or standards body** | we publish the record — facts, dates, sources — and never the verdict |
| **"insurance"** on any ABP surface | the insurance argument is a different document and a different room |
| **raw findings** | recall-optimised agents run at 0.388 precision; what is sold is triage, reproduced rather than reviewed |

**The sentence that replaces the compliance claim,** and it is better because it is
checkable: *"This provision requires X. The agent's current grant does not bound X. A
control of type Y, enforced at layer Z, would bound X."* No verdict in it, and every
clause can be checked by the buyer.

## 5. What to print — decide today

**The card is the product.** For tier 1 the printed draft ABP *is* the thing being
sold, so it is the one print item that cannot be dropped.

**The booth is 1000mm wide and 400mm deep**, which settles the format before taste
does: a laptop, a small card holder and a QR stand fill the top surface. Nothing that
needs floor space is worth the approval round-trip five days out.

| | Item | Status |
|---|---|---|
| **P0** | **Draft ABP cards — five deployment shapes**, one per card, conservative on purpose, with the `t1` code and `store.sgit.ai/d/t1/` on the back | The five worked examples are **already published and derived** on `abp.sgit.ai`: chat in the browser with nothing connected; a coding CLI on your own machine with confirmations on; the same with confirmations off; a browser extension with broad host permissions; a CI job on a hosted runner under a service account. **The content exists. Only the layout does not.** |
| **P0** | **Small tabletop sign** — *"Do you know what your AI agent can actually do?"* | Explicitly allowed with no approval, and it fits the 40cm depth. This is where the aisle line lives now |
| **P1** | Business cards with the `t1` code | Cheapest possible fallback if the draft cards miss the print window |
| ~~P0~~ | ~~Roll-up banner~~ | **Dropped.** On the organiser's check-first list, discouraged at length, and the room is being designed without them |
| ~~P2~~ | ~~One-pager~~ | Dropped. No depth for a stack, and the draft card does its job better |
| — | Side-panel vinyl | My recommendation is to skip it: 400mm deep is nearly invisible in an aisle, and it is the one item that would need approval *and* print in five days |

**The two-documents pair is the demo, and it prints on one side of one card.** Same
product, same machine, same account, one setting changed:

| | Confirmations on | Confirmations off |
|---|---|---|
| Grant | 16 | 16 |
| Mandate | 5 | 5 |
| Excess | 12 | 12 |
| Unbounded excess | 12 | 12 |
| Barrier on `execute.process.host` | setting — **not a control** | none — **not a control** |

**One barrier moved and not one number did.** The confirmation prompt was the only
thing between an authorised capability and the whole machine, and it was a switch the
agent's own account could flip. That is the entire enforcer test in one table, and it
is the most convincing thing we own for a technical audience.

**Blocked, and it blocks print:** the collateral artboards in `.design-work/` still use
concept B. The Seal was selected. **Nothing goes to print with concept B on it.** (The
banner being dropped removes most of the exposure here — the cards are the remaining
artboard that needs the Seal.)

## 6. The two days

- **Log every lead against the summit graph vault the same evening** (`nmzxlq3e`). Day-two
  conversations should reference day-one ones.
- **Screen: the game, facing the aisle**, self-serve, no human needed. Five minutes,
  forty questions, no sign-up. It qualifies people into 3.1 without us.
- **The £10 is not the revenue.** It is the qualification and the permission to follow
  up with something they already paid for. Treat it that way when reporting.
- **Speakers are targets too** — use the graph to pick the ten worth finding.

## 7. After

Within 48 hours: send every tier-1 buyer their corrected ABP as a file they keep, and
publish the summit graph vault with a short write-up of how it was built. **The
follow-up is the demo** — nobody else exhibiting will send a working artefact instead
of a deck.

## 8. Open, and blocking

1. **Behaviour or behavior.** Blocks print. Recommendation: *behaviour*.
2. **Which five shapes get a printed draft?** The five published examples are the
   obvious answer and I would not invent a sixth this week.
3. **Logo and name into the portal — Tuesday.** Artwork is built and waiting at
   [`/summit-booth.html`](https://riskmandate.ai/summit-booth.html): a 200×200mm vector
   PDF with outlines embedded, which is the format the guide prefers. Name is
   **RiskMandate**, one word, two capitals. Mark is the Seal, sent as the lockup rather
   than the mark alone so a stranger can ask for us by name.
3a. **Laptop or a monitor?** A laptop needs no approval; a monitor needs declaring, and
   the answer changes the power request. Decide before messaging them once.
4. **Does the `t1` checkout work end to end today?** The ABP brief records that the
   August application tier 1 depends on has not been located, and that the fallback is
   a questions page with a printed output. **If the code on the card leads nowhere, the
   card is worse than no card.** This needs testing before anything is printed.
5. **Who takes the payment at the booth, and on whose device?** Two rails, strictly
   separated: payment links with printed codes for everything at the event and below
   ~£1,000; the cloud marketplace above it, after a conversation.
