The Answer Is an Estimate. Somebody Has to Check It.
At the G20 on 2 September, Alex Karp described the one job his own sovereignty stack hands to a log.
Securing the Agentic Era. Article 25 · AI Governance
At the G20 on 2 September, Alex Karp described the one job his own sovereignty stack hands to a log.
On 2 September Alex Karp sat down with the US Commerce Secretary at the G20 Innovation Ministerial in Chapel Hill and told a room of ministers something most of them had flown in hoping not to hear.
Every country outside the United States and China, he said, will have to decide which part of the AI stack is powered by American companies and which part by its own. Then it has to find the local companies and the local experts who can run that part. That expertise, he added, is very rare.
He said the deployment path decides where a country’s knowledge accumulates, and that a firm deploying through a model vendor’s tooling is moving its alpha to that vendor without meaning to. He had a word for it. That argument is his fight with the labs and it is not this essay’s.
He said something else that got less attention, and it is the reason for this piece.
A model’s answer, he told the room, is an estimate. It degrades over time. Before a leader can act on it, someone has to make sure the answer is correct and take it apart so that every assumption inside it can be seen. And then the sentence that should have been the headline: whether you use Palantir’s product or not, you will need this.
That is a description of checking the work. It was the most useful thing anyone said at the G20. It is not the same thing as sovereignty, and the difference is where an institution gets examined.
Palantir has published the argument in full. Institutional Sovereignty in the Age of AI is a fifteen-step guide, with three layers the institution should own: compute, models, and a control layer above them. It is a serious document and it answers one question well. Who holds the asset.
The guide uses the word assurance. Read what it means there.
"you should make your decisions based on assurance — the underlying mechanism that backs the guarantee that your data won't be retained or exposed. Assurance can be contractual or structural, the latter being stronger."
Assurance, in that guide, appears in the compute section, and there it means the mechanism that keeps your data from being retained or exposed. That is assurance about the asset.
The guide is not silent on checking, either. It describes an evaluation suite, output validation and regression gates before promotion, and an audit built to detect misappropriation, trigger canaries, and reconstruct which actor, which prompt, which model and which rows were touched. It is an append-only, signed log, and it is built to protect the institution from its provider.
Those check the model, and they check it before it ships. None of them establishes whether the action the agent took met the requirement it was given, across a defined population, over a stated period, with what was not checked stated beside what was.
Same word. Different object. Their assurance is about the asset. The examiner’s is about the work.

Sovereignty is a claim about who holds the asset. Assurance, in the sense a risk committee uses it, is a claim about what happened to it. An institution can retain every dollar of its alpha, run every weight on its own hardware, and still fail an examination, because the examiner does not ask who owns the control plane. She asks what it authorised on the fourteenth, and whether anyone checked.
Karp’s other admissions point the same way. The question to ask of any expert, he said, is whether the expert is on the payroll. A checker that sits inside the thing it grades is on the payroll by construction. And the governments he sells to are building a Plan B, he said, because they do not want to depend on him. His words: what if I get hit by a car. That is the right question, and it applies to every layer in the stack, including the one that keeps the record.
Two days later Geoffrey Hinton told CNN, from Toronto, that he does not think Canada can afford to get all of this technology from the States or from China. In June this series said Canada’s sovereign stack had every layer named except the one that checks the work. Karp has now told every government outside the two big producers to go and find that operator. Whether a country finds one is a different question from whether it needs one.
The operator seam
The layer Karp described has to be run by someone who is not the model vendor and not the platform that owns the ontology. It has to sit on the estate the institution already runs. It has to keep a record the institution owns. And it has to let the institution change the model underneath without losing either.
That is the operator seam. We run the platform, do the work, and see whether it worked. Twenty-one years of operating delivery tooling for regulated enterprises. Named people. An agreed change process.
That includes us. Where we build or operate the work under examination, our own assessment is evidence for the reviewer, not an opinion on it. The same test applies to us as to anyone else.
The building blocks for that record are not being set by any one vendor. They are being set in the open. The Agentic AI Foundation, under the Linux Foundation, now hosts the Model Context Protocol, the interface most agents use to act, alongside the agent-to-agent standard that landed in April. FINOS hosts the AI Governance Framework the banks wrote for themselves, and on 3 September its Labs took in konspekt, a proposed open standard for a portable, human-readable record of decisions and provenance that, in its own words, lives outside any single conversation, model or platform, where a model may propose an entry and only a person may accept it. It is one maintainer and a Labs project, and it is exactly the shape Karp described. The Linux Foundation hosts the Appia Foundation, which is making verifiable proof of trustworthy AI an open standard. iTmethods is a member of all three. We do not set those standards. We sit in the rooms where they are set and we build to them, because a record that only one vendor can read is the payroll problem in a different form, and sovereign, safe and assured work needs building blocks nobody rents.
Reign Gateway is Available Today. For calls sent through it, it applies identity, access, policy and spend controls and creates a record of the request, the policy decision and the outcome. Policy-controlled failover across customer-approved models is planned. It is not shipped. Reign Factory is Available, Beta Release, and not generally available. Reign Assurance is in co-design. It is being designed to help business and risk leaders assess whether defined AI-enabled work met its intended outcomes and stayed within the requirements set for it. It is not sold. It is not an audit opinion. Reign prepares. People decide.
The same register on what we do not hold. Reign Ops holds a SOC 2 Type II. It does not extend to Gateway, Factory or Assurance. We do not hold ISO 27001, ISO 42001, FedRAMP or HIPAA. Naming a framework is not standing under it.
One aside, because the name invites it. A reign is what a sovereign does, and the product carried that name before sovereignty was a campaign. We are not claiming the word. We are saying what it leaves out.
The question a CIO will be asked twice
A board asks its CIO for the institution’s sovereignty position. That question is on every agenda in every regulated institution this autumn, and Palantir put it there. The CIO has a good answer. Data residency. Model ownership. A control layer the bank owns. A signed log.
Then the Chief Risk Officer asks the second question. On the agentic workflow that went live in May, for the actions it took in August, show me which ones met the requirement they were given, which ones did not, and what was not checked.
The first question is about the asset. The second is about the work. The sovereignty stack answers the first completely. Karp himself said the second still has to be answered, by an operator you do not rent.
Sourcing and disclosure
iTmethods sells operated engineering platforms, software-delivery capacity and AI traffic governance to regulated enterprises, and is designing an assurance offering with customers. It competes in the market this essay describes. iTmethods is a member of the Linux Foundation, FINOS and the Agentic AI Foundation. Membership of a foundation is not a claim to have authored its standards. It has no commercial relationship with Palantir. Quotations from Alex Karp are from his 2 September 2026 appearance at the G20 Innovation Ministerial and have been checked against the recording. Quotations from Palantir’s guide are verbatim, including its punctuation.
For Technology Leaders
The board will ask for the sovereignty position and the answer will be a good one. The second question is the one to prepare for, and it is about the work rather than the asset. iTmethods runs the estate, does the work inside it, and produces the record that work leaves behind.
For Technology LeadersPaul Goldman is the Founder and CEO of iTmethods. His team runs the platform, does the work, and proves it. He writes The Trust Layer at itmethods.com.
Related reading
- The Filing Is Not the Work (September 2, 2026)
- Palantir and NVIDIA Turned Control Into a Product Category (July 28, 2026)
- Canada’s Sovereign AI Stack Has One Layer Left to Build (June 17, 2026)
Sources
- CNBC, G20 Innovation Ministerial live updates, September 2, 2026
- Benzinga, Palantir’s Alex Karp warns about AI alpha leaks, September 2026
- Palantir, Institutional Sovereignty in the Age of AI, fifteen steps. Assurance defined in the compute section; evaluation suite, output validation and regression gates in the model section; audit and log in the control section
- FINOS, Portable AI Decision Records: konspekt contributed to FINOS Labs, September 3, 2026
- Linux Foundation, formation of the Agentic AI Foundation
- CNN, This city is one of the world’s most important AI hubs, September 4, 2026, via CP24
Paul Goldman
CEO, iTmethods
Founder and CEO of iTmethods, and the author of The Trust Layer. Previously published "MCP Is Exploding. Your Governance Isn’t Ready."
Continue the AI Governance series
Get Paul’s next article before it publishes
Join 500+ security leaders