<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Trust Layer]]></title><description><![CDATA[Making agentic AI auditable, enforceable, and deployable in regulated industries.]]></description><link>https://trustlayer.itmethods.com</link><image><url>https://substackcdn.com/image/fetch/$s_!1Z2G!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe1cc5c3-2777-4a85-9b7d-db67e3a8c6c6_200x200.png</url><title>The Trust Layer</title><link>https://trustlayer.itmethods.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 31 Jul 2026 08:26:13 GMT</lastBuildDate><atom:link href="https://trustlayer.itmethods.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[© 2026 The Trust Layer, an iTmethods publication]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[trustlayer@itmethods.com]]></webMaster><itunes:owner><itunes:email><![CDATA[trustlayer@itmethods.com]]></itunes:email><itunes:name><![CDATA[Paul Goldman]]></itunes:name></itunes:owner><itunes:author><![CDATA[Paul Goldman]]></itunes:author><googleplay:owner><![CDATA[trustlayer@itmethods.com]]></googleplay:owner><googleplay:email><![CDATA[trustlayer@itmethods.com]]></googleplay:email><googleplay:author><![CDATA[Paul Goldman]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[On Monday, Palantir and NVIDIA Turned Control Into a Product Category.]]></title><description><![CDATA[An alliance of forty companies, a contract playbook, and a television appearance, all on the same day, four weeks after the partnership that set it up. They are right about the problem. Owning a layer]]></description><link>https://trustlayer.itmethods.com/p/on-monday-palantir-and-nvidia-turned</link><guid isPermaLink="false">https://trustlayer.itmethods.com/p/on-monday-palantir-and-nvidia-turned</guid><dc:creator><![CDATA[Paul Goldman]]></dc:creator><pubDate>Tue, 28 Jul 2026 12:09:02 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/46b11fcc-d235-43f5-b5d3-934209e05326_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Three things happened on Monday.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>NVIDIA announced the Open Secure AI Alliance, more than forty founding companies building open tooling for AI security. Microsoft, IBM, Red Hat, CrowdStrike, Cisco, Palo Alto Networks, Salesforce, SAP, Dell, HPE, Snowflake, Databricks, Capital One, Siemens, Hugging Face, Palantir, the Linux Foundation.</p><p>Palantir published a long piece of contract mechanics on how a hosted model provider can quietly acquire what they call your alpha: the institutional knowledge and tradecraft embodied in the data you expose to a model and generate from using it. How to negotiate zero data retention that retains nothing. Which beta endpoints sit outside the protection you thought you bought. What happens when global inference routes your traffic into a region your regulator does not permit.</p><p>And Alex Karp went on Fox Business and said the quiet part at normal volume.</p><p>The temptation is to read three separate items. It is one item.</p><h3>Four weeks, not one day</h3><p>At the end of June, Palantir and NVIDIA announced a sovereign AI partnership. NVIDIA&#8217;s Nemotron open models deployed inside Palantir&#8217;s AIP, Ontology, Foundry, and Apollo, running in classified and air-gapped environments, with the customer training on their own data and retaining ownership of the resulting model.</p><p>Read the components. American chips. American open-weight models. An application layer the customer controls. Deployed where no external inference call is possible.</p><p>Monday was that architecture acquiring a standards body, a compliance narrative, and a press cycle, all at once. Karp described the alliance as part of a broader movement that began with the NVIDIA partnership. He was not being coy about the commercial logic. He described customers who feel they are paying heavily for tokens while transferring the value of their business to a frontier lab, and he named the remedy plainly: enterprises need to own their compute and their application layer.</p><p>That is not a convergence of independent minds. It is a campaign, executed over four weeks, by two companies with a very great deal of money at stake.</p><p>Which does not make it wrong. It makes it worth reading carefully, because a campaign that size tends to define the vocabulary everyone else has to argue in.</p><h3>They are right about where the problem lives</h3><p>Buried in the alliance announcement is a sentence that matters more than the membership list:</p><blockquote><p>Real AI safety and security depend on the full agent stack &#8212; identity, permissions, harnesses, guardrails, logs and evaluation &#8212; not just on whether model weights are open or closed.</p></blockquote><p>Identity. Permissions. Logs. That is not model research. That is control plane.</p><p>The contributions say the same thing in code rather than prose. HPE is bringing work on SPIFFE and SPIRE, which cryptographically verifies which workloads are permitted to talk to what. Hugging Face has given Safetensors to the PyTorch Foundation so weights can be loaded without executing arbitrary code. IBM and Red Hat&#8217;s Lightwell signs patches across the open source supply chain. NVIDIA&#8217;s own contribution is an open agent harness project whose stated purpose is making agent behaviour easier to test, trace, audit, and govern.</p><p>Palantir&#8217;s document arrives at the same border from the legal side. Read their guidance as a list rather than as prose and something appears that the framing obscures. Maintain a living allow-list of permitted models, tools, features, and API endpoints. Automatically block calls carrying a beta header. Vet prompt-cache time-to-live before a service joins the allow-list. Fail-safe requests originating in high-accreditation environments so they cannot reach lower-accredited endpoints. Run automated alerts detecting when hyperlinked terms change. Keep observability capable of tracing which specific prompt caused a classifier to fire.</p><p>That is seven technical controls, in a document about contracts.</p><p>Palantir is not confused. They are being honest about a boundary. Their guidance keeps arriving at the edge of what a legal team can negotiate and stopping, because the controls sit on the other side of it, where the calls actually happen.</p><p>And notice when their failure modes occur. A beta service auto-enabled on your tenant. A hyperlinked term updated without notice. An engineer accepting a click-through because the alternative was a blocked deploy at four in the afternoon. A model silently upgraded outside your negotiated scope. A new inference region joining the global pool.</p><p>Not one of those happens at signature. Every one happens in production, months later, on an ordinary Tuesday, without anybody deciding anything. A contract is a point-in-time instrument. Drift is continuous.</p><p>So the diagnosis is correct, from both directions. Safety is not a property of the model. It is a property of the layer above it, and that layer cannot be outsourced to a provider&#8217;s terms of service or to a provider&#8217;s weights.</p><p>I have been making that argument for a year. On Monday it acquired forty founding members and a sales motion.</p><h3>What the category does not include</h3><p>Here is where I have to be careful, because the temptation is to claim more adjacency than exists.</p><p>The alliance is scoped to cybersecurity: vulnerability remediation and disclosure, agent identity and isolation, safe weight formats, multi-model scanning, secure coding workflows. Its question is whether the system is sound. That is a real and hard question, and the contributions are serious.</p><p>Palantir&#8217;s document is scoped to procurement. Its question is what the two parties agreed.</p><p>Neither answers the question a regulated institution is actually examined on. Was this specific action authorized, against this business objective, within this delegated authority? Did the safeguards operate at the moment it mattered? What residual risk remains? Can you produce evidence an examiner will accept, a quarter later, for an action nobody remembers?</p><p>A sound system can still take an unauthorized action. A well-drafted contract can be honoured perfectly while an agent does something no one approved. Soundness and agreement are both necessary. Neither is authorization, and neither is proof.</p><p>That gap is not a criticism of either party. It is what is left after both of them have done their work.</p><h3>The word doing the most work is &#8220;own&#8221;</h3><p>Karp is right that you have to own the application layer. The unresolved part is what owning it means when the layer is somebody&#8217;s product.</p><p>An enterprise that moves off a frontier lab and onto a vendor&#8217;s application layer has changed counterparty. It has not necessarily changed posture. The dependency is now on a different company, with different commercial incentives, and the same structural property: the record of what your agents did, and the authority under which they did it, lives inside something you license.</p><p>The test is simple and nobody markets against it. Does your authorization policy survive a decision to change models? Does your action log survive a decision to change vendors? Can you hand an examiner a complete, ordered, attributable account of what an agent did and what it was permitted to do, in a quarter when you did not plan to change anything and then had to?</p><p>If the answer is no, the risk has been relocated and renamed sovereignty.</p><p>Ownership of a layer is a commercial arrangement. Proof of an action is an artefact. Only one of them is admissible.</p><h3>The question worth sitting with</h3><p>An agent in your environment does something on a Friday that nobody sanctioned.</p><p>By Monday, can you produce an ordered, attributable record of every action it took, the authority under which each was permitted, and the point at which it exceeded that authority?</p><p>Not whether you would eventually piece it together. Whether you can produce it.</p><p>If the answer is that nobody knows, the controls you have are describing a protection you have never tested. The difference only becomes visible under examination, which is the worst possible moment to discover it.</p><p>Monday was a good day for this industry. Two of the largest companies in it told several thousand enterprises that the control layer is theirs to hold, and put engineering behind the claim. The part still open is who produces the proof for the specific action, on the specific day, that a regulator is going to ask about.</p><div><hr></div><p><strong>Sourcing and disclosure</strong></p><p>NVIDIA announced the Open Secure AI Alliance on the NVIDIA blog on July 27, 2026, with more than forty founding members. The alliance describes itself as building on the Linux Foundation&#8217;s Akrites initiative and OpenSSF community work. It is an NVIDIA-led alliance rather than a Linux Foundation project, and no charter or governance documentation had been published at the time of writing. NVIDIA&#8217;s announcement cites an autonomous agent breaking containment during a benchmark and reaching a third party&#8217;s production systems earlier in the month as part of the motivation for the alliance.</p><p>Palantir Technologies and NVIDIA announced their sovereign AI partnership at the end of June 2026, covering the deployment of NVIDIA Nemotron open models within Palantir AIP, Ontology, Foundry, and Apollo in classified and air-gapped environments.</p><p>Palantir Technologies published &#8220;AI Sovereignty is Your Alpha: How to Avoid Transferring Your Alpha to a Hosted Model Provider&#8221; on the Palantir Medium publication on July 27, 2026. Palantir states the document is not legal advice and creates no attorney-client relationship. Nothing here is legal advice either.</p><p>Alex Karp&#8217;s remarks are paraphrased from a Fox Business interview broadcast on July 27, 2026, and are not presented as direct quotation.</p><p>This article takes no position on export controls, on the regulation of open-weight models, or on the national origin of any model.</p><p>Several parties described here build and sell in this market. So do we. iTmethods is a Silver Member of the Linux Foundation, which is an inaugural partner in the alliance described above, and a member of FINOS and the Agentic AI Foundation. We build runtime governance software for regulated enterprises. Our interest in the conclusion is not hidden.</p><div><hr></div><p><strong>Paul Goldman</strong> is the CEO of iTmethods, where his team builds the control and assurance layer for agentic AI: the governance, evidence, and portability that let regulated institutions run any model, swap it under pressure, and prove control. He writes The Trust Layer.<br><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/p/on-monday-palantir-and-nvidia-turned?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://trustlayer.itmethods.com/p/on-monday-palantir-and-nvidia-turned?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[The Sovereign AI Trade Is Missing a Line Item]]></title><description><![CDATA[In the space of about a week the smartest money in technology agreed on the same trade.]]></description><link>https://trustlayer.itmethods.com/p/the-sovereign-ai-trade-is-missing</link><guid isPermaLink="false">https://trustlayer.itmethods.com/p/the-sovereign-ai-trade-is-missing</guid><dc:creator><![CDATA[Paul Goldman]]></dc:creator><pubDate>Tue, 14 Jul 2026 18:10:15 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c9991aad-80a2-4efd-9bd1-b20cb6ff5794_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the space of about a week the smartest money in technology agreed on the same trade. Chamath Palihapitiya named it in his July 5 newsletter: the sovereign AI trade. Buy the companies that let institutions own their intelligence instead of renting it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The evidence arrived almost on schedule. On June 29 Palantir and NVIDIA announced air-gapped deployments for customers whose data cannot leave the building. On July 1 Bloomberg reported that Meta is standing up a business to sell its excess compute to outside customers. That same day Together AI raised $800 million at an $8.3 billion valuation, led by Aramco Ventures, to run open models cheaply at scale, and Venice AI became a unicorn on a privacy-first pitch: it does not log prompts, and conversations stay on the user&#8217;s device. On July 2 Microsoft launched Frontier Company, $2.5 billion and six thousand engineers embedded inside customers, with an explicit commitment that customer data, IP, and competitive advantage will not be used to train models in ways that commoditize what differentiates them in their industry. The same day the Financial Times reported that OpenAI had discussed giving the United States government a five percent stake. That last one is a story about politics, and I will leave the politics to people who enjoy them.</p><p>Read the week together and the message is unmistakable. Sovereignty is now a product category. Everyone is selling it.</p><p>Then, over the following nine days, the two loudest voices in the trade took the assumptions underneath it apart. One of them was the man who named it.</p><h2>The man who named the trade cannot prove it is working</h2><p>On July 12 the same investor who had named the sovereign trade a week earlier said there is literally not a scintilla of evidence that AI has helped lift the operating margins of the S&amp;P 500.</p><p>He brought numbers. Between zero and two percent of the S&amp;P 493&#8217;s recent earnings growth is traceable to AI productivity, on his math. The rest is inflation and buybacks. A PwC survey this year found that fifty-six percent of chief executives saw no revenue or cost benefit from AI at all, and only twelve percent could point to both. Back in May he had already set the clock: roughly five hundred days until the fork in the road, at which point a company has to be able to say it spent X and it made Y, and Y is bigger than X.</p><p>This is contested, and it should be. Brad Gerstner has pushed back, noting that S&amp;P 500 operating margins moved from around eleven percent in 2023 to thirteen percent in 2025, and arguing that AI deserves some of the credit. The counter is that most of that expansion is post-pandemic restructuring and cost discipline rather than machine productivity. The argument is unresolved, which is the point. Three years and several hundred billion dollars in, the return is still a matter of opinion.</p><p>The next day it acquired a second half.</p><h2>The paradox names itself</h2><p>On July 13 Satya Nadella published a long essay describing what he calls the reverse information paradox. In the AI era the buyer of intelligence pays twice: once in money, and once in the proprietary knowledge it must reveal to make that intelligence useful.</p><p>Models learn from exhaust. The prompts your people write. The tools your agents call. Above all the corrections your experts make, which is precisely the knowledge a competitor could never buy at any price.</p><p>And then the line that should stop every chief information officer in the industry. It leaks almost imperceptibly, he wrote. Trace by trace, correction by correction, eval by eval.</p><p>Put those two statements together and they are the same finding. One says you cannot prove what AI is earning you. The other says you cannot see what it is costing you. Not capability. Not capital. Evidence.</p><p>An enterprise that cannot prove what its agents did will never be able to prove what they earned. It is one discipline, not two.</p><h2>And then he said the quiet part</h2><p>This morning, on CNBC, the same investor was asked about privacy at the model layer. His answer should be printed and taped to the wall of every vendor risk team in the country.</p><p>The labs, he said, do a very good job of a very superficial form of privacy called zero data retention. They tell you to enable it, and then everything is hunky-dory. But read the fine print. Suppose you put your secret formula into the model and ask it to improve the recipe. That prompt is covered. Now suppose you click the like button on what it gives back. Is there any guarantee that this was not stored somehow?</p><p>The honest answer, he said, is technically no, because we do not know how to do that.</p><p>Sit with that. The privacy control that the entire sovereign shelf is sold on, the one whose name is a promise, does not cover the thing Nadella had just finished describing. Nadella said the model learns from your corrections. This says nobody can promise your correction was not kept. One of them told you where the value goes. The other told you the lock on that door does not exist yet.</p><p>That is the whole argument of this piece, made by the man who started the trade, on live television, one week after he started it.</p><h2>Architecture is a claim. Proof is a control.</h2><p>That is why the sovereign trade, as currently sold, is incomplete. Every offer in that remarkable week is an architecture claim, and architecture claims get inspected once, at procurement, by people who will not be in the room on any of the three hundred and sixty-four days that follow.</p><p>Air-gapped proves isolation. It does not prove governance. Last week&#8217;s piece made this argument about the sandbox, and it holds one layer up. A boundary tells you where the work happened, not whether the work was allowed. An air-gapped environment full of ungoverned autonomous agents is an extremely well isolated place in which to lose control of your software.</p><p>Not trained on is a policy until it is a contractual term with evidence attached. Which uses are excluded, who decides, on which tier, and what does the buyer actually get to inspect on a Tuesday in March, eighteen months later, when the terms have quietly moved? They do move. Multiple major platforms have already migrated from we do not train on your data to we train on your data unless you find the setting and switch it off.</p><p>Does not log looked like the strongest of the three until this morning. Now we have it from the trade&#8217;s own architect that the retention promise stops at the fine print, and that the guarantee you actually want is one the industry does not yet know how to give. You are not holding a control. You are holding a setting, and a hope about everything the setting does not cover.</p><p>And if the leak really is imperceptible, then none of these promises can be verified by looking. That is what imperceptible means. What you are holding is not a control. It is a claim.</p><p>None of this makes the sovereign stack a bad buy. Most of it is a real improvement on the status quo, and some of these companies will be among the winners of the decade. The point is narrower. Every one of these products moves the boundary. Not one of them, on its own, produces the proof.</p><h2>The line item</h2><p>So here is what the sovereign trade has not priced, and it turns out to be the same line item twice.</p><p>Sovereignty is not a place you arrive at. It is a state you have to be able to demonstrate, repeatedly, to someone who does not take your word for it. A regulator. An auditor. A board. A customer running vendor due diligence on you. And, in about five hundred days, an investor who wants to see the number.</p><p>So the question is not which sovereign stack you bought. It is whether, on any given day, you can prove the sovereignty you bought is still holding.</p><p>Can you show that the model running in production is the model you approved? That the data classified as never-leaves did not leave, and demonstrate it rather than assert it? That the agent operating inside your air-gapped environment took only the actions a human authorized? That when a vendor&#8217;s terms shifted in February, you knew, you reassessed, and you have the record to show for it?</p><p>Very few institutions can answer those questions today. Not because the technology is missing, but because the industry has been selling the boundary and not the proof.</p><p>He gave the same warning this morning from the finance side, and it is worth hearing in his words. Most chief executives and chief financial officers, he said, probably have no idea how much token consumption is happening inside their own organizations. One day the quarter misses by a few pennies, the chief executive asks the chief financial officer where all the incremental operating expense came from, and somebody has to go and trace it.</p><p>Trace it with what?</p><p>That is the question the sovereign trade has not answered, and it is the same question the regulator asks, wearing a different suit. The instrument that answers the examiner is the instrument that answers the board. A ledger that records what every agent did, what it consumed, what a human authorized, and under which policy is an audit artifact on Monday and an ROI artifact on Friday. You cannot prove the return on autonomous work you cannot account for. The fork in the road arrives for both questions at once.</p><p>This series has a name for assurance that holds continuously instead of once, at procurement: <strong>Continuous Agentic Assurance</strong>. It is the layer the sovereign trade is missing. It has to sit above whichever sovereign stack you bought, because most institutions will end up running more than one, and because they will change their minds.</p><h2>The same disclosure, in the same spirit</h2><p>Everyone arguing about sovereignty this month is talking their book, and I am going to say so plainly, because I have just spent two thousand words quoting them. The investor who named the trade and then took it apart now runs an enterprise AI company himself, and said as much on air: selling enterprise is his entire job. Nadella has a $2.5 billion business built on being the trustworthy option and an essay that makes his competitors look careless. Palantir has a partnership to sell. And I run a company that builds the governance and evidence layer for regulated institutions, which makes a piece arguing that sovereignty needs proof exactly as self-interested as it sounds.</p><p>None of that makes any of them wrong. It does mean you should check.</p><p>So do what I would do. Do not take my word for it. Take the strongest claim your most important AI vendor makes about your data, and ask them in writing what evidence you are entitled to inspect, how often, and what you are contractually owed if the answer ever changes. The ones with good answers will produce them quickly. The silence of the others is also an answer.</p><p>The sovereign era is real, and the trade is probably right. But sovereignty you cannot audit on any given day is not sovereignty. It is a mood. And a mood is not going to survive the moment someone asks to see the numbers.</p><p>Run your vendors&#8217; AI claims through the Vendor AI Governance Assessment at itmethods.com/reign/vendor-assessment, or read how Reign approaches governed AI adoption at itmethods.com/reign.</p><p><em>Paul Goldman is the CEO of iTmethods, where his team builds the control and assurance layer for agentic AI: the governance, evidence, and portability that let regulated institutions run any model, swap it under pressure, and prove control. He writes The Trust Layer.</em></p><p><strong>Related reading:</strong> The Five Questions Your SaaS Vendors Hope You Never Ask (July 7) &#183; The Software Factory Is Going Dark. The Audit Trail Cannot. (July 1) &#183; The New Standard for AI Trust Is Here. The Runtime Layer Is Not. (June 18)</p><p><strong>Sources:</strong> CNBC, &#8220;Squawk Box,&#8221; interview with Chamath Palihapitiya, July 14, 2026 (zero data retention and token consumption; all references sourced to CNBC) &#183; Satya Nadella, essay on the reverse information paradox, July 13, 2026 &#183; Chamath Palihapitiya on AI&#8217;s contribution to S&amp;P 500 operating margins and the PwC 2026 CEO survey, July 12, 2026 &#183; Brad Gerstner on S&amp;P 500 operating margin expansion, 2023 to 2025 &#183; Chamath Palihapitiya on the roughly 500-day fork in the road for AI returns, May 12, 2026 &#183; Chamath Palihapitiya, newsletter naming the sovereign AI trade, July 5, 2026 &#183; Microsoft, &#8220;Microsoft Frontier Company: AI engineering that amplifies and protects your intelligence,&#8221; official blog, July 2, 2026 &#183; Financial Times, report on discussions of a five percent US government stake in OpenAI, July 2, 2026 &#183; Bloomberg, &#8220;Meta Is Building a Cloud Business to Sell Excess AI Compute,&#8221; July 1, 2026 &#183; Together AI, Series C announcement, July 1, 2026 &#183; Venice AI, Series A announcement, July 1, 2026 &#183; Palantir and NVIDIA, air-gapped deployment announcement, June 29, 2026 &#183; PwC 2026 CEO survey &#183; OSFI Guideline E-23 Model Risk Management (effective May 1, 2027) &#183; EU AI Act<br></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Trust Layer&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://trustlayer.itmethods.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Trust Layer</span></a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Five Questions Your SaaS Vendors Hope You Never Ask]]></title><description><![CDATA[Alex Karp aimed them at the frontier labs. The worse answers sit further down your stack.]]></description><link>https://trustlayer.itmethods.com/p/the-five-questions-your-saas-vendors</link><guid isPermaLink="false">https://trustlayer.itmethods.com/p/the-five-questions-your-saas-vendors</guid><dc:creator><![CDATA[Paul Goldman]]></dc:creator><pubDate>Tue, 07 Jul 2026 11:31:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/16c97b42-55bf-4211-850d-53cdfe9f8acb_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On July 1, Palantir CEO Alex Karp went on CNBC and laid out five questions every enterprise should be able to ask its AI vendors: Who owns the data? Where is it cached? Are the prompts secure? Who controls the weights? Is the value of your business being transferred to a third party?</p><p>He aimed the questions at the frontier labs. Most regulated enterprises, however, have far more exposure through their SaaS stack than through the model providers themselves. That is where the answers are often worse, and where almost nobody is asking.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Those five questions are the clearest vendor due-diligence framework published this year. They were delivered as a rant on a morning show, but they deserve to be treated as a standard.</p><p>The morning after the interview, Microsoft made Karp&#8217;s point for him. It announced Frontier Company, a $2.5 billion unit with six thousand engineers embedded inside customers, under the banner of AI engineering that amplifies and protects your intelligence. The protection language is welcome. The mechanism is less reassuring. Your knowledge, workflows, and judgment are unified inside the vendor&#8217;s platform, feeding the vendor&#8217;s agents, compounding on the vendor&#8217;s tenancy. The five questions apply to it verbatim.</p><p>By the holiday weekend the same argument had moved to All-In, where it ran for half an episode. David Sacks, the former White House AI czar, reframed the exchange as a definition of AI safety for the enterprise. Real safety is control of your own data, your model weights, and your compute, plus the ability to choose, at the model layer, who gets to see and use your alpha. Chamath Palihapitiya put the economics in one line. You cannot rent intelligence from the same place that rents it to your competitor. David Friedberg described model providers courting data-rich life-sciences companies with a trade. Proprietary datasets contributed to a shared vertical model in exchange for early access. The consensus forming at the top of the market is sovereignty through owned weights and owned hardware. Fine, for the few who can afford it. Most regulated enterprises will still wake up tomorrow running dozens of vendor platforms. The durable control is not the hosting model. It is the questions.</p><h2>The same mechanics, running quieter</h2><p>Look at what is actually happening across the SaaS layer. The pattern is the point, not any single company.</p><p>Training by default is becoming the norm. Multiple major platforms have moved in the past year from &#8220;we do not train on your data&#8221; to &#8220;we train on your data unless you find the setting and turn it off.&#8221; Some tiers cannot turn it off at all. Some categories of telemetry are mandatory. Retention windows for contributed data stretch to multiple years. A position your vendor risk team documented and approved eighteen months ago may simply no longer be true.</p><p>Sovereignty is being packaged as a pricing tier. Want your data excluded from training? Want customer-managed keys? Want a single-tenant deployment or residency guarantees that cover AI processing? That will be the top tier, or a premium deployment, priced and repriced at the vendor&#8217;s discretion. Control that must be purchased, and can be repriced, is not control. It is rented.</p><p>Context graphs are the new lock-in, and they compound daily. The most sophisticated SaaS vendors have understood something true: in the AI era, the moat is not the model, it is the context. They are building living graphs that connect your work, your people, your decisions, and your institutional memory. Every agent interaction writes structure back into the graph. Usage makes the graph richer. A richer graph makes the product smarter. A smarter product drives more usage. As a product mechanic, this is brilliant. As a sovereignty posture, it is a one-way door.</p><p>Agents are mutating your systems of record at industrial scale. Across the industry, AI agents connected to enterprise platforms are no longer just reading. Large fractions of agent activity are now writes. These agents typically inherit the full permissions of the human who invoked them. Every over-permissioned user account in your organization just became an over-permissioned autonomous actor. Audit logs let you see it afterward. They do not stop it.</p><h2>The question behind the questions</h2><p>None of this means the SaaS AI wave is a scam. Most of these capabilities are useful. Some are transformative. The trade on offer is one a rational enterprise can knowingly accept for plenty of workloads.</p><p>The operative word is knowingly.</p><p>The failure mode is not using AI-enabled vendors. The failure mode is using them without a written answer to the five questions, per vendor, per tier, revisited every time the terms change. Because the terms are changing. Under OSFI E-23, under DORA, under GDPR, a material change in how a third party handles your data is not a settings task. It is a reassessment trigger with documentation obligations attached.</p><p>This series has a name for assurance that holds continuously instead of once, at procurement: Continuous Agentic Assurance. It applies to your vendors&#8217; AI as much as to your own agents.</p><p>So borrow Karp&#8217;s framework, and aim it wider than he did:</p><ol><li><p>Data ownership. Who owns the data, including the metadata, the telemetry, and anything &#8220;de-identified&#8221; that still describes how your business runs?</p></li><li><p>Residency and caching. Where is it cached, and does your residency guarantee cover AI processing or only storage at rest?</p></li><li><p>Prompt and output security. Are the prompts and outputs secure, logged, and excluded from training, on your tier, in writing?</p></li><li><p>Model control. Who controls the models, and what happens to content already contributed when you opt out?</p></li><li><p>Alpha transfer. Is your alpha transferring, through training, through telemetry, or through a context graph you cannot take with you?</p></li></ol><p>If a vendor&#8217;s answer to any of these is a support-page paragraph rather than a contractual term, you do not have an answer. You have a mood.</p><h2>A disclosure, in the same spirit</h2><p>Karp made no secret of his motives. He was at that desk to promote a partnership that sells the alternative, and when an anchor suggested the whole thing sounded like shade, he answered that it was reporting. The same disclosure applies here. iTmethods builds governance infrastructure for enterprises that want AI adoption with control intact. A piece arguing that vendor AI needs governance is exactly as self-interested as it sounds. Do what Karp told his own viewers to do. Do not take anyone&#8217;s word for it, mine included. Test the claims. Ask your own vendors the five questions and grade the answers yourself. The ones with good answers will put them in writing quickly. The silence of the others is also an answer.</p><p>Karp said something has gone completely wrong with how AI is being sold. He is right, and the problem runs deeper into the enterprise stack than his interview reached. The correction starts with buyers who ask better questions.</p><p>Run the five questions against any vendor in your stack in about eight minutes with the Vendor AI Governance Assessment at itmethods.com/reign/vendor-assessment, or read how Reign approaches governed AI adoption at itmethods.com/reign.</p><p>Paul Goldman is the CEO of iTmethods, where his team builds the control and assurance layer for agentic AI: the governance, evidence, and portability that let regulated institutions run any model, swap it under pressure, and prove control. He writes The Trust Layer.</p><p>Related reading: The Software Factory Is Going Dark. The Audit Trail Cannot. (July 1) &#183; The New Standard for AI Trust Is Here. The Runtime Layer Is Not. (June 18) &#183; Canada&#8217;s Sovereign AI Stack Has One Layer Left to Build (June 17)</p><p>Sources: CNBC, Squawk Box interview with Alex Karp, July 1, 2026 &#183; Mediaite, verbatim transcript of the exchange, July 1, 2026 &#183; Microsoft, &#8220;Microsoft Frontier Company: AI engineering that amplifies and protects your intelligence,&#8221; official blog, July 2, 2026 &#183; All-In podcast, episode 279, July 2026 &#183; OSFI Guideline E-23 Model Risk Management (effective May 1, 2027) &#183; DORA, in force January 17, 2025 &#183; GDPR</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Software Factory Is Going Dark. The Audit Trail Cannot.]]></title><description><![CDATA[Autonomous agents will soon write, test, and ship half your code. In a regulated institution, the advantage is not the coding agent. It is the supervisor that governs the floor and proves what it did.]]></description><link>https://trustlayer.itmethods.com/p/the-software-factory-is-going-dark</link><guid isPermaLink="false">https://trustlayer.itmethods.com/p/the-software-factory-is-going-dark</guid><dc:creator><![CDATA[Paul Goldman]]></dc:creator><pubDate>Wed, 01 Jul 2026 11:31:16 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a175305c-b480-4122-97c5-ba2a8c1d2474_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Most enterprise agentic initiatives are not failing because the models are weak. They are failing because they were never built to be governed.</p><p>And the pressure is climbing fast. This spring, Cognition&#8217;s Devin, an autonomous AI software engineer, crossed 492 million dollars in annualized revenue, with customers that are not startups: Goldman Sachs, Citi, and Santander among them. A rival, Factory, reached a 1.5 billion dollar valuation in a single round. The machines that write software are now writing it inside banks.</p><p>Gartner&#8217;s number is the one that should focus a board. By the end of this year, autonomous agents will write, test, or deploy close to half of all enterprise code. That is the autonomous figure, code an agent writes, tests, and merges on its own, not the AI-assisted coding that already fills most pull requests. Assisted code still has a person on the keystroke. Autonomous code moves the human off it, which is exactly what changes who is accountable. The same analysts expect more than four in ten agentic projects to be cancelled by 2027. The reason they give is not capability. It is inadequate risk controls.</p><p>The software factory is going dark, in the lights-out sense: work moving through the floor with fewer and fewer people standing over it. For most of the industry that is a productivity story. For a regulated institution it is not a tooling problem wearing a productivity disguise. It is a governance problem wearing a productivity disguise.</p><h2>Lights-out only ever worked because the line proved every unit</h2><p>Manufacturing went dark decades ago. Plants run unattended overnight, with no one on the floor. That was never possible because the robots were trusted. It was possible because the line instrumented itself. Every unit measured, every tolerance logged, every deviation flagged and stopped, so that in the morning you could prove what the factory made and that it stayed inside spec. Lights-out did not remove accountability. It moved accountability into the evidence the line produced on its own.</p><p>Software is now making the same move, and skipping the second half. We are racing to take people off the floor. We have not yet agreed that the floor has to prove what it did. Speed without that layer is just faster failure.</p><h2>The market is funding the workers, not the supervisor</h2><p>Look at where the capital and the attention have gone. Almost all of it is on the worker: faster, more autonomous coding agents that plan, write, test, review, and merge. They are impressive, and they are commoditizing quickly. There will be many capable ones, from many providers, and a serious enterprise will run several at once.</p><p>A second category is forming around governance, and it is welcome, but it is early and shaped for a different buyer. Some of it is security tooling that scans for the new class of agent risks, a useful taxonomy that only appeared at the end of last year. Some of it is a control surface bolted to a single platform, helpful if your entire estate lives inside that platform, and silent about everything that does not. The category is real. It is not yet built for the institution that has to answer to a regulator.</p><p>What almost no one is building is the part a bank actually needs. An independent supervisor that governs the whole floor, works across whichever coding agents you run, and produces evidence an examiner will accept.</p><h2>Isolation is not governance</h2><p>The most common answer right now is the sandbox. Give every agent its own sealed environment, a micro virtual machine with its own filesystem and network, and let it work without touching anything that matters. This is real progress, and it is necessary. The industry has been honest that ordinary containers are no longer enough for autonomous agents, and the isolated runtimes that shipped this year are the right substrate.</p><p>But isolation answers exactly one question: can this agent damage the host. It does not answer the questions a regulator asks. Did the agent stay inside policy while it worked. Who, or what, authorized the change it merged to production. What data did it touch, and what evidence of any of it survives after the environment is destroyed. A sandbox contains the blast radius. It does not govern the work, and it does not keep the receipts. Containment and control are different disciplines, and only one of them is examiner-ready.</p><h2>What a governed floor actually does</h2><p>Strip away the vocabulary and a governed software factory has a short, demanding job description. It constrains what each autonomous worker is allowed to do while it is acting, not after, so a sensitive action is stopped at the gate rather than noted in hindsight. It watches outcomes, not just outputs. It carries identity and authorization onto every change, so a merge into a production system can be traced to who or what approved it and under what policy. It produces a tamper-evident record of what ran, what changed, and what a human signed off on, one that holds up after the agent and its sandbox are gone. It keeps people on the exceptions, the decisions that matter, instead of on the keystrokes. And it does all of this independently of which coding agent did the work, so the institution can adopt the best worker available this quarter without rebuilding its controls the next.</p><p>That last property is the one the platform answers cannot offer. A supervisor that only governs its own vendor&#8217;s agents is not governing the institution. It is governing one corner of it.</p><h2>Why this lands on regulated institutions first</h2><p>A consumer app shipping agent-written code at speed is a productivity win. A bank doing the same thing is a supervised activity. Model risk management built for credit and market models is becoming the floor for AI, not the ceiling, and the supervisory direction is already on paper. Canada&#8217;s banking regulator has finalized model-risk expectations that reach AI models and take effect in 2027. Europe&#8217;s high-risk regime is moving on its own timeline toward the same destination: documented risk management, record-keeping, human oversight, and proof. None of these regimes will accept &#8220;the agent did it&#8221; as an answer. They will ask the institution to show what the agent did, that it stayed inside approved boundaries, and that a human was accountable for the result.</p><p>This is the real meaning of that cancellation number. The projects that die in regulated shops will not die because the coding agents were weak. They will die at the first audit the institution cannot pass.</p><h2>There is a name for this</h2><p>The series has circled this discipline for months. Applied to the software factory, it is the same standing loop. Not a one-time security gate before launch, but assurance that holds every day the floor is running, including the morning a new coding agent is swapped in and the old one swapped out, with identity, authorization, and the audit trail intact across the change. There is a name for it: Continuous Agentic Assurance.</p><h2>The worker commoditizes. The governed floor is the moat.</h2><p>The autonomous coding agents will keep getting better and cheaper, and within a year or two the choice of worker will matter far less than anyone selling one today would like. What will not commoditize is the ability to run a dark software factory and still prove, on any given day, what the machines did, under what policy, with what human accountability, across whichever agents happened to do the work.</p><p>That proving layer is the durable advantage, and it is the one almost no one is building for the institutions that need it most. Lights-out is coming to software whether the controls are ready or not. The factories that win in regulated industries will be the ones that went dark and kept every receipt.</p><p>Paul Goldman is the CEO of iTmethods, where his team builds the control and assurance layer for agentic AI: the governance, evidence, and portability that let regulated institutions run any model, swap it under pressure, and prove control. He writes The Trust Layer.</p><p>Related reading: The New Standard for AI Trust Is Here. The Runtime Layer Is Not. (June) and Canada&#8217;s Sovereign AI Stack Has One Layer Left to Build (June 17) and Three Days. One Export Order. A Frontier Model Gone. (June 16)</p><p>Sources: Cognition, Devin annualized revenue and enterprise customers, TechCrunch, May 27, 2026. Factory, Series C at a 1.5 billion dollar valuation, TechCrunch, April 16, 2026. Gartner, on enterprise agent adoption and proportional agent governance, May 2026. OWASP, Top 10 for Agentic Applications, December 2025. Docker, on micro virtual machine sandboxes for AI agents, 2026. OSFI, Guideline E-23 Model Risk Management, final September 2025, effective May 1, 2027. European Commission, EU AI Act timeline for high-risk systems.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to The Trust Layer!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/p/the-software-factory-is-going-dark?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Share this post</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/p/the-software-factory-is-going-dark?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://trustlayer.itmethods.com/p/the-software-factory-is-going-dark?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://itmethods.com/dark-factory&quot;,&quot;text&quot;:&quot;See the governed Dark Factory&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://itmethods.com/dark-factory"><span>See the governed Dark Factory</span></a></p>]]></content:encoded></item><item><title><![CDATA[The New Standard for AI Trust Is Here. The Runtime Layer Is Not.]]></title><description><![CDATA[The Linux Foundation and major players just made verifiable conformity an open standard. The part they have not yet solved is proof that must hold continuously when agents act and models change.]]></description><link>https://trustlayer.itmethods.com/p/the-new-standard-for-ai-trust-is-here-the-runtime-layer-is-not</link><guid isPermaLink="false">https://trustlayer.itmethods.com/p/the-new-standard-for-ai-trust-is-here-the-runtime-layer-is-not</guid><dc:creator><![CDATA[Paul Goldman]]></dc:creator><pubDate>Tue, 23 Jun 2026 11:09:55 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/46d50559-5e33-4ffd-93b5-c2919b1b4a60_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A week ago I wrote that the missing piece in the sovereign AI stack was the control and assurance layer above the model. The comments filled with builders saying they had already built it. I said a category was forming in real time.</p><p>This week it became infrastructure.</p><p>The Linux Foundation launched the Appia Foundation under its Joint Development Foundation, with founding members including Google, Microsoft, OpenAI, Mastercard, Arm, Ericsson, Siemens, Schneider Electric, and Mitsubishi Electric. Its premise is that AI trust requires verifiable proof. Its work is to build the open connecting layer between standards that set expectations and assessments that verify them, so conformity evidence produced once can be recognized across the value chain.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><br>That is the most useful contribution anyone has made in this space, and the fact that it is being built on neutral ground is exactly right. When the Linux Foundation and that roster put their names to verifiable proof of trustworthy AI, the question of whether evidence matters is settled. The category is no longer forming. It is being institutionalized.</p><h2>It proves the bigger point about independence</h2><p>Appia is structurally a neutral, openly governed standard for how a system is measured. The whole design assumes that proof has to be portable and vendor-neutral, so that a result carries the same meaning wherever it is read.</p><p>That is the same structural argument I made about platforms. A great platform can govern its own corner with real discipline. But the proof that an institution, a regulator, and a counterparty will rely on has to sit on neutral ground. Appia is the standards-level version of the independent referee.</p><h2>The one thing I would add</h2><p>The current framing is assessment-time. The example the white paper uses is a system that is scored once against criteria, with evidence that then passes downstream. That is a necessary first case. It is not the last one.</p><p>The next systems do not just get scored once. They act continuously. An agent plans, calls tools, touches data, makes decisions, and escalates inside workflows that matter. For a system like that, conformity cannot be a one-time demonstration. It has to be a standing loop. It has to hold on any given day, including the morning a model is swapped under pressure, with identity, authorization, and the audit trail intact across the change.</p><p>Evidence that was true at assessment and silently stopped being true the moment the agent or the model changed is not evidence a regulator can rely on. The conformity layer needs a way to express proof that is continuous, not a snapshot. There is a name for that standing loop: Continuous Agentic Assurance.</p><p>That is the part the agentic era forces, and it is the part the specification does not yet cover. It is also exactly buildable now while the criteria are still being written.</p><h2>What this looks like inside a bank</h2><p>Picture a regulated institution running an agent on a model from one provider, adapted by another, and wired into its own systems and data. Appia&#8217;s design lets each party demonstrate conformity for its part and pass the evidence downstream. That is real progress.</p><p>But the agent does not sit still once it has been assessed. It acts every day. When a frontier model can be pulled from the market with three days of notice, the model underneath an agent can be swapped overnight. The moment it changes, the upstream conformity evidence describes a system that no longer exists. The institution&#8217;s obligation does not pause. Under the EU AI Act, and under supervisory regimes from OSFI in Canada to peers elsewhere, it still has to show, that Monday morning, that the swapped agent operated inside policy with an unbroken audit trail.</p><p>That is what a continuous layer does. It regenerates conformity evidence as the system changes, so the pass-through stays true after the swap and not only at the moment of assessment. It is the difference between proving something was conformant once and showing that it still is.</p><h2>The voices the standard still needs</h2><p>The founding membership spans the AI value chain and multiple regions. That is the point: no one builds this layer alone. But the roster is thin where it matters most. The institutions that will have to stand behind agentic systems in front of a regulator, especially in finance and other high-stakes sectors, are barely at the table. Regulated finance appears mainly as a single payments network.</p><p>The criteria that will shape AI conformity for years are being drafted now, in open working groups that already include a stream on regulatory connection covering the EU AI Act. The people who live the regulator&#8217;s Monday-morning question should help write them: the operators who run agents across jurisdictions, carry model-risk obligations, and must produce evidence when something changes. The agentic, continuous dimension belongs in that work too. This is the moment to get those voices in while the pen is still moving.</p><h2>The evidence thesis is now infrastructure</h2><p>For months this series has argued that in regulated industries, the layer that proves what AI did is where trust and value concentrate. This week the most credible neutral body in open technology, alongside the largest names in the field, made that argument a standard.</p><p>The work now is to make sure the proof can keep up with systems that act on their own, and to get the operators who carry the regulatory obligation into the room while the criteria take shape. The standard is the foundation. The runtime layer that produces continuous, agentic-grade evidence is the necessary complement, and it is buildable now.</p><div><hr></div><p><em>Paul Goldman is the CEO of iTmethods, where his team builds the control and assurance layer for agentic AI: the governance, evidence, and portability that let regulated institutions run any model, swap it under pressure, and prove control. He writes The Trust Layer.</em></p><p><strong>Related reading:</strong> Canada&#8217;s Sovereign AI Stack Has One Layer Left to Build (June 17) &#183; Three Days. One Export Order. A Frontier Model Gone. (June 16) &#183; Anthropic Moved Twice. OpenAI Moved Twice. The Trust Boundary Moved With Them. (May 26)</p><p><strong>Sources:</strong> Appia Foundation, &#8220;Building the connecting layer for trustworthy AI&#8221; (white paper, June 17, 2026) and appiafoundation.org &#183; The Linux Foundation, &#8220;Linux Foundation Launches Appia Foundation,&#8221; June 17, 2026 &#183; OSFI, Guideline E-23 Model Risk Management (final, September 2025; effective May 1, 2027).</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Trust Layer&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://trustlayer.itmethods.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Trust Layer</span></a></p>]]></content:encoded></item><item><title><![CDATA[Canada's Sovereign AI Stack Has One Layer Left to Build]]></title><description><![CDATA[Canada is building sovereign AI rails. The layer that makes them safe to depend on, and provable to a regulator, is the one still left to build.]]></description><link>https://trustlayer.itmethods.com/p/canadas-sovereign-ai-stack-has-one-layer</link><guid isPermaLink="false">https://trustlayer.itmethods.com/p/canadas-sovereign-ai-stack-has-one-layer</guid><dc:creator><![CDATA[Paul Goldman]]></dc:creator><pubDate>Wed, 17 Jun 2026 12:14:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1Z2G!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe1cc5c3-2777-4a85-9b7d-db67e3a8c6c6_200x200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Canada has finally started building sovereign AI. There is a national strategy, a compute strategy, billions of dollars of domestic data centre investment, and a serious report from RBC&#8217;s Thought Leadership team mapping the whole stack. The ambition is right and overdue. But there is one more layer still to build, and the fastest way to see why it matters is to look at what happened last Friday.</p><p><strong>85%.</strong> Of Canada&#8217;s cloud spend concentrated in three U.S. firms (RBC). <strong>88%.</strong> Of enterprise foundation-model use concentrated in three U.S. firms (RBC). <strong>72 hours.</strong> From a frontier model&#8217;s public launch to its government recall, last week.</p><h2>The report gets the thesis right</h2><p>The RBC report defines sovereignty in the AI era as something other than building everything ourselves. It frames it as what it calls freedom from coercion: the ability to choose which models to run, whose hardware does the inference, which jurisdiction governs the data, and which providers you can substitute when one of them is used as leverage. That is the right definition. Sovereignty is not a data centre. It is the structural ability to not be held hostage.</p><p>And Canada is moving. The federal AI for All strategy landed on June 4, organized around trust, opportunity, and sovereignty. The Sovereign AI Compute Strategy is funding domestic capacity. Cohere is building frontier models with a federal mandate behind it. Bell and TELUS are each standing up Canadian-jurisdiction AI compute. A consortium of Canadian-owned data centre operators is assembling sovereign cloud for regulated workloads. These are real rails, built faster than the prevailing narrative admits.</p><h2>Every champion is on one side of the stack</h2><p>Here is the part worth sitting with. The report names the Canadian champions available for sovereign AI procurement today, and the list is excellent. It is also lopsided. Cohere is a model company. Bell, TELUS, and the data centre consortium are infrastructure and compute. Vector, Mila, and AMII are research institutes. Every name on the list lives at the infrastructure, model, or research layer.</p><p>Map the sovereign stack honestly and one layer has no Canadian champion named on it: the control and assurance layer that sits above the model. The layer that turns freedom from coercion from a principle into something an institution can actually operate and prove. We are building sovereign rails with no sovereign control plane to run on top of them.</p><h2>Friday made the gap concrete</h2><p>On June 9, Anthropic released the two most capable models it had ever shipped. Three days later, on Friday the 12th at 5:21 p.m. Eastern, the U.S. Commerce Department issued an export-control directive barring foreign nationals from accessing them. Because ordinary cloud service cannot guarantee that no foreign national ever touches a model, Anthropic had to disable both models for every customer on earth to stay compliant. Not one enterprise customer did anything wrong. The models still vanished from all of them by Saturday morning.</p><p>Now apply the sovereign-AI frame to that event. A Canadian data centre would not have helped. A Canadian-resident copy of the weights would not have helped, because the model was withdrawn by the company that controls it, under an order from the government that governs it. The recall did not touch where the model lived. It removed the model. Sovereign infrastructure answers the question of where your AI runs. Friday asked a different question: whether you can keep running, and prove what you did, when access disappears.</p><p>That is the question the current Canadian stack does not yet answer.</p><h2>What that layer actually is</h2><p>The layer still to build is not exotic, and it is not more compute. It is governance, evidence, runtime control, and portability. Concretely, it is the ability to run a model from any source, Canadian or foreign, behind a control point you own. To swap that model under pressure without rebuilding the workflow around the replacement or losing the audit trail. To govern what the model is allowed to do at runtime. And to produce evidence, on any given day, of what ran, under what policy, on what data, and what changed when the model changed.</p><p>That is the operational meaning of the report&#8217;s own definition. Freedom from coercion is not a procurement preference for Canadian hardware. It is the ability to substitute a provider under pressure and prove the substitution to a regulator. You cannot do that from a data centre. You do it from the control layer.</p><h2>This is the Canadian opportunity, not the Canadian gap</h2><p>The good news is that this layer plays to Canada&#8217;s strengths rather than its weaknesses. It is software, not steel. Canada does not have to out-build the hyperscalers on chips or megawatts to own it. The control plane is buildable here, now, with talent Canada already has, and has too often watched leave.</p><p>And the regulatory tailwind is already blowing, which the report itself documents. OSFI and the FCAC now treat frontier AI as a financial-stability and cybersecurity concern, not merely a technology one. In April, the Canadian Financial Sector Resiliency Group convened specifically on a frontier model. The supervisory direction is clear: model risk management built for credit and market models is the floor for AI governance, not the ceiling, and the whole inference-data pathway has to be governed, not just training. That is a control-layer mandate, written by Canadian regulators, ahead of the products built to satisfy it.</p><p>The report makes one more point that should focus every Canadian software founder. What the Big Six and other major financial institutions procure in the next twenty-four months will decide whether the Canadian sovereign ecosystem reaches commercial scale. True. And the control layer is the part of the stack that makes any of those rails safe to procure in the first place. An anchor buyer cannot put a sovereign model into a material workflow without a way to govern it, swap it, and prove it. The control layer is not the last thing the sovereign stack needs. It is the thing that makes the rest of it usable.</p><h2>What a Canadian institution should actually ask</h2><p>For a board or a risk committee, the sovereignty question is easy to mis-frame as a buying decision about infrastructure. It is not. You cannot buy sovereignty as a data centre. You operate it as a control layer. Three questions surface whether you have it.</p><p>Can we run any model, from any source, in a workflow that matters, without re-platforming?</p><p>Can we swap that model under pressure, in a day, without losing the workflow or the audit trail?</p><p>Can we prove, with evidence rather than assurances, what the model did and that it stayed inside the lines?</p><p>If the answer to any of those is no, the sovereign data centre underneath does not save you. The model is still a single point of failure that someone else controls.</p><h2>There is a name for this</h2><p>The series has circled this discipline for months under different names: the control plane, agent operations, the trust boundary. It is worth calling it what it is. Continuous Agentic Assurance: assurance as a standing loop rather than a one-time gate. The rails Canada is building are necessary. The loop is what makes them trustworthy, and provable, on the morning something upstream changes without warning.</p><h2>The layer worth owning</h2><p>Canada is building the rails for sovereign AI, and that is the right call. Cohere, Bell, TELUS, and the consortium are doing real work, and the country is better for it. But the layer that makes those rails safe to depend on, and provable to a regulator, is the one still left to build. It is the layer where freedom from coercion stops being a slogan and becomes an operating capability.</p><p>It is also a Canadian software capability. Of every layer in the sovereign stack, it is the one an institution should least want to rent from the very providers it is trying not to depend on, and the one Canada is closest to being able to build itself. We should put a champion on that part of the map.</p><div><hr></div><p><em>Paul Goldman is the CEO of iTmethods, where his team builds the control and assurance layer for agentic AI: the governance, evidence, and portability that let regulated institutions run any model, swap it under pressure, and prove control. He writes The Trust Layer, a weekly read on governing agentic AI in regulated industries.</em></p><p><strong>Related reading:</strong> Three Days. One Export Order. A Frontier Model Gone. (June 16) &#183; Anthropic Moved Twice. OpenAI Moved Twice. The Trust Boundary Moved With Them. (May 26) &#183; SR 26-2 Just Created a Governance Gap Banks Can&#8217;t Ignore (May 12)</p><p><strong>Sources:</strong> RBC Thought Leadership, &#8220;Sovereign AI: Shaping Canada&#8217;s Next Digital Chapter&#8221; (2026), including cited figures on cloud and model concentration, AI for All (June 4, 2026), the Sovereign AI Compute Strategy, OSFI and FCAC, and the CFRG convening &#183; Anthropic, &#8220;Statement on the US government directive to suspend access to Fable 5 and Mythos 5,&#8221; June 12, 2026 &#183; McKinsey &amp; Co. sovereign-AI market estimate (via the RBC report)</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/p/canadas-sovereign-ai-stack-has-one-layer/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://trustlayer.itmethods.com/p/canadas-sovereign-ai-stack-has-one-layer/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/p/canadas-sovereign-ai-stack-has-one-layer?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://trustlayer.itmethods.com/p/canadas-sovereign-ai-stack-has-one-layer?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://itmethods.com/contact&quot;,&quot;text&quot;:&quot;Talk to iTmethods about the trust layer&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://itmethods.com/contact"><span>Talk to iTmethods about the trust layer</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://itmethods.com/insights&quot;,&quot;text&quot;:&quot;Read more at itmethods.com/insights&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://itmethods.com/insights"><span>Read more at itmethods.com/insights</span></a></p>]]></content:encoded></item><item><title><![CDATA[Three Days. One Export Order. A Frontier Model Gone.]]></title><description><![CDATA[What the Fable 5 recall tells regulated institutions about model concentration, continuity, and where the trust boundary really sits.]]></description><link>https://trustlayer.itmethods.com/p/three-days-one-export-order-a-frontier</link><guid isPermaLink="false">https://trustlayer.itmethods.com/p/three-days-one-export-order-a-frontier</guid><dc:creator><![CDATA[Paul Goldman]]></dc:creator><pubDate>Mon, 15 Jun 2026 12:36:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1Z2G!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe1cc5c3-2777-4a85-9b7d-db67e3a8c6c6_200x200.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On Friday a frontier model that hundreds of millions of people were using disappeared. Not throttled. Not degraded. Withdrawn from the entire market by the next morning. The cause was not an outage, and it was not a business decision. It was a letter from the United States government.</p><p><strong>3 days.</strong> From Fable 5&#8217;s public launch to its government recall. <strong>5:21 p.m. ET, Friday June 12.</strong> When the export-control directive reached Anthropic. <strong>Hundreds of millions.</strong> Users on the two models pulled worldwide.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I have spent the last month of this series tracking one question: where the trust boundary in enterprise AI actually sits, and who keeps moving it. In May the answer was the vendors. Anthropic moved twice. OpenAI moved twice. Each pushed forward-deployed engineering and self-hosted runtime toward the customer, because the regulated enterprise would no longer accept the vendor&#8217;s perimeter as its own.</p><p>On Friday the boundary moved again. This time a vendor did not move it. The government did. And the mechanism was not relocation. It was deletion.</p><h2>What happened</h2><p>On June 9, Anthropic released two new models, Fable 5 and Mythos 5, the most capable it had ever shipped and, by independent benchmark, the most capable models available to the public. Three days later, on Friday June 12 at 5:21 p.m. Eastern, the Commerce Department sent the company a directive. Citing national security authorities, it barred every foreign national, inside or outside the United States, including Anthropic&#8217;s own foreign-national employees, from accessing the two models.</p><p>Ordinary cloud service cannot guarantee that no foreign national ever touches a model. So to comply, Anthropic had to disable Fable 5 and Mythos 5 for every customer on earth. Access to its other models was untouched.</p><p>The stated trigger, as Anthropic understands it, was a claimed method of jailbreaking Fable 5: prompting the model to read a codebase and identify software flaws. Anthropic disputes that this warrants recalling a model deployed to hundreds of millions of people. It notes the same capability is widely available in other public models, including OpenAI&#8217;s GPT-5.5, and is used every day by the defenders who keep systems safe. The company is complying with the order. It also called the order a misunderstanding and said it is working to restore access.</p><p>I am not going to relitigate the security question here. Reasonable people will argue it for weeks, and the facts are still moving. The lesson does not depend on who is right.</p><h2>The vendor did not move the boundary this time</h2><p>In May, the trust boundary moved because vendors relocated it. The model still ran. You could still call it. What changed was where the runtime and the engineers sat. That is an architecture problem, and architecture problems have architecture answers.</p><p>On Friday nobody relocated anything. The model was removed from the market. That is a different failure mode, and a worse one. You cannot govern, encrypt, or self-host your way around a model that no longer exists for you to call. A relocated boundary is a design question. A deleted model is a continuity question.</p><p>And notice what triggered the deletion. Not what any customer did. Who might use it. Not one enterprise customer did anything wrong, and the model vanished from all of them anyway. Dependency risk you did nothing to incur is the hardest kind to plan for, and the easiest to ignore until the morning it arrives.</p><h2>A bank should read this differently than a startup</h2><p>For a consumer app, a model going dark is an inconvenience. Switch providers, move on. For a regulated institution, it is a supervised event.</p><p>When I wrote about SR 26-2 last month, the point was that the Federal Reserve now expects banks to govern AI models the way they govern any model that touches a material decision: inventory it, validate it, plan for its loss, and be able to show your work. A model that a third party can withdraw overnight is, in supervisory language, concentration risk and third-party dependency risk in a single object. European institutions already carry the same expectation under DORA&#8217;s third-party rules. The examiner&#8217;s question after Friday is short. If a model in one of your material workflows is unavailable tomorrow morning, what happens, and can you prove the answer before it happens.</p><p>There is a sharper edge for global banks. The order did not turn on geography. It turned on nationality. It barred foreign nationals from the model wherever they sit. A global institution runs its operations with people of many nationalities in many countries. An access rule written that way does not close an office. It can fracture a workflow across the very people who run it. Sovereignty stopped being a principle on Friday. It became an operational variable.</p><h2>Three things that stopped being hypothetical</h2><p><strong>Single-model dependency is a single point of failure.</strong> It does not matter whether the model disappears by export order, by a vendor&#8217;s own safety call, by an outage, or by a lapsed contract. If one model sits in a material workflow with no tested alternate, you have built a single point of failure and called it a capability.</p><p><strong>The control layer outranks the model.</strong> &#8220;We use the most capable model&#8221; is a procurement preference, not an architecture. On Monday Fable 5 was the most capable public model in the world. By Saturday it was unreachable. What survives a week like that is not the model. It is the layer that decides which model runs, watches what it does, and can move you to another one without losing the thread.</p><p><strong>Sovereignty is now operational.</strong> Access can be cut by nationality, by decree, between a Friday evening and a Saturday morning. For any institution that operates across borders, where a model can legally run, and for whom, is now a live design constraint, not a policy footnote.</p><h2>What good looks like</h2><p>The institutions that will absorb a week like this without a board incident share a short list of properties. Their AI runs behind a control point they own, not one the vendor owns. Every model call produces evidence: what ran, under what policy, on what data, and what changed when the model changed. No single model sits in a material workflow without a tested alternate. And model substitution is a drill they have run, not a paragraph they have written.</p><p>None of that makes a model immune to recall. Nothing does. It changes the consequence of a recall from an outage you explain afterward into an inconvenience you planned for.</p><p>This is the discipline the series has circled for months under different names: the control plane, agent operations, the trust boundary. Friday is the cleanest argument yet for treating them as one practice, and for calling it what it is: Continuous Agentic Assurance. Not assurance as a one-time gate, but assurance as a standing loop. Fable passed every safety gate it was given, and then it was gone anyway. The gate is not the control. The loop is.</p><h2>What to do this week</h2><p>This week, inventory the models in your material workflows and mark every one that has no tested alternate. That list is your concentration risk, written down.</p><p>This month, make model portability and per-call evidence a requirement, not a preference. If you cannot switch models without losing your audit trail, you do not yet have a control plane. You have a dependency with good intentions.</p><p>This quarter, run the drill. Pull a model out of a non-production workflow and prove you can fail over with governance intact. The first time you do this should not be the morning a government does it for you.</p><p>On Friday, the most capable model in the world had its launch and its recall in the same week. The model was the headline. The dependency was the story.</p><div><hr></div><p><em>Paul Goldman is the CEO of iTmethods, where his team helps enterprises build and govern AI-native platforms, from model and agent control planes to the evidence and continuity that regulated industries require.</em></p><p><strong>Related reading:</strong> Anthropic Moved Twice. OpenAI Moved Twice. The Trust Boundary Moved With Them. (May 26) &#183; 15 Days. Six Vendor Moves. Three Breaches. One Threat Actor. (May 21) &#183; SR 26-2 Just Created a Governance Gap Banks Can&#8217;t Ignore (May 12) &#183; When Your Vendor&#8217;s AI Ambitions Become Your Governance Problem (April 23)</p><p><strong>Sources:</strong> Anthropic, &#8220;Statement on the US government directive to suspend access to Fable 5 and Mythos 5,&#8221; June 12, 2026 &#183; TechCrunch, June 12, 2026 &#183; Bloomberg, June 13, 2026 &#183; CNBC, June 12, 2026 &#183; Fortune, June 13, 2026</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/p/three-days-one-export-order-a-frontier?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Trust Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://trustlayer.itmethods.com/p/three-days-one-export-order-a-frontier?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://trustlayer.itmethods.com/p/three-days-one-export-order-a-frontier?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div>]]></content:encoded></item></channel></rss>