The LLM is not in the cryptographic path
The single most common Phase-2 failure we see is people trying to make Claude generate the signed XML directly. The signature must be deterministic and verifiable. Splitting the agent from the signer is the architectural decision that lets you ship.