# AI host API (env) <Badge type="info" text="planned" />

> Planned NeuroWASM AI host functions — reading model, certificate, Sentinel, trust-list and account-abstraction state from inside a contract, and the determinism rules they follow.

Source: https://docs.nro.world/neurowasm/ai-host

None of these functions exists in the VM yet. Until they do, read the same data off-chain through the [REST API](/reference/rest) — the `AI and models`, `Sentinel trust list` and `Account abstraction` sections.

Neuro-native. **Read / attest / request only** — never changes BFT voting power.

Consensus-path calls must be deterministic (committed state). Full `analyze_v2(bytes)` is **not** a consensus `call` import — use RPC, query-path, or deferred `AiRequest` (Phase B).

| Import | Status | Purpose |
|--------|--------|---------|
| `ai_active_model` | planned | Active model hash/version from registry |
| `oracle_get` | planned | Last oracle decision JSON |
| `cert_get` | planned | Cert tier/score for contract |
| `ai_security_score` | planned | Last VMGuardian score 0–100 |
| `ai_analyze_hash` | planned | Score for known bytecode hash |
| `ai_verify_zk_attestation` | planned | Verify ZKML receipt vs IMAGE_ID |
| `ai_sentinel_score_tx` | planned | Consensus-safe Sentinel for current TX |
| `ai_is_trusted_recipient` | planned | Trust-list + activation delay |
| `aa_session_allowed` | planned | Session grant check |
| `aa_sponsor_remaining` | planned | Sponsored gas pool remaining |
| `ai_template_meta` | planned | Template registry metadata |

When implemented, each of these will have a named fuel price and a governance switch to turn the AI host off.

See also [VMGuardian](/ai/vmguardian), [Sentinel](/ai/sentinel), [Account abstraction](/ai/account-abstraction).
