Skip to main content
    Back to Insights
    The Trust Layer

    The Answer Is an Estimate. Somebody Has to Check It.

    At the G20 on 2 September, Alex Karp described the one job his own sovereignty stack hands to a log.

    PG
    Paul GoldmanFounder and CEO, iTmethods
    September 9, 20269 min read

    Securing the Agentic Era. Article 25 · AI Governance

    At the G20 on 2 September, Alex Karp described the one job his own sovereignty stack hands to a log.

    On 2 September Alex Karp sat down with the US Commerce Secretary at the G20 Innovation Ministerial in Chapel Hill and told a room of ministers something most of them had flown in hoping not to hear.

    Every country outside the United States and China, he said, will have to decide which part of the AI stack is powered by American companies and which part by its own. Then it has to find the local companies and the local experts who can run that part. That expertise, he added, is very rare.

    He said the deployment path decides where a country’s knowledge accumulates, and that a firm deploying through a model vendor’s tooling is moving its alpha to that vendor without meaning to. He had a word for it. That argument is his fight with the labs and it is not this essay’s.

    He said something else that got less attention, and it is the reason for this piece.

    A model’s answer, he told the room, is an estimate. It degrades over time. Before a leader can act on it, someone has to make sure the answer is correct and take it apart so that every assumption inside it can be seen. And then the sentence that should have been the headline: whether you use Palantir’s product or not, you will need this.

    That is a description of checking the work. It was the most useful thing anyone said at the G20. It is not the same thing as sovereignty, and the difference is where an institution gets examined.

    Palantir has published the argument in full. Institutional Sovereignty in the Age of AI is a fifteen-step guide, with three layers the institution should own: compute, models, and a control layer above them. It is a serious document and it answers one question well. Who holds the asset.

    2 Sep 2026
    G20 Innovation Ministerial
    Alex Karp, Chapel Hill
    15 steps
    Institutional Sovereignty in the Age of AI
    Compute, models, a control layer above them

    The guide uses the word assurance. Read what it means there.

    "you should make your decisions based on assurance — the underlying mechanism that backs the guarantee that your data won't be retained or exposed. Assurance can be contractual or structural, the latter being stronger."

    Assurance, in that guide, appears in the compute section, and there it means the mechanism that keeps your data from being retained or exposed. That is assurance about the asset.

    The guide is not silent on checking, either. It describes an evaluation suite, output validation and regression gates before promotion, and an audit built to detect misappropriation, trigger canaries, and reconstruct which actor, which prompt, which model and which rows were touched. It is an append-only, signed log, and it is built to protect the institution from its provider.

    Those check the model, and they check it before it ships. None of them establishes whether the action the agent took met the requirement it was given, across a defined population, over a stated period, with what was not checked stated beside what was.

    Same word. Different object. Their assurance is about the asset. The examiner’s is about the work.

    Two columns. Their assurance asks whether the data was retained, whether the model passed evals, who touched what, and detects the provider. The examiner's asks whether the work met the requirement, across which population, over what period, and what was not checked.

    Sovereignty is a claim about who holds the asset. Assurance, in the sense a risk committee uses it, is a claim about what happened to it. An institution can retain every dollar of its alpha, run every weight on its own hardware, and still fail an examination, because the examiner does not ask who owns the control plane. She asks what it authorised on the fourteenth, and whether anyone checked.

    Karp’s other admissions point the same way. The question to ask of any expert, he said, is whether the expert is on the payroll. A checker that sits inside the thing it grades is on the payroll by construction. And the governments he sells to are building a Plan B, he said, because they do not want to depend on him. His words: what if I get hit by a car. That is the right question, and it applies to every layer in the stack, including the one that keeps the record.

    Two days later Geoffrey Hinton told CNN, from Toronto, that he does not think Canada can afford to get all of this technology from the States or from China. In June this series said Canada’s sovereign stack had every layer named except the one that checks the work. Karp has now told every government outside the two big producers to go and find that operator. Whether a country finds one is a different question from whether it needs one.

    The operator seam

    The layer Karp described has to be run by someone who is not the model vendor and not the platform that owns the ontology. It has to sit on the estate the institution already runs. It has to keep a record the institution owns. And it has to let the institution change the model underneath without losing either.

    That is the operator seam. We run the platform, do the work, and see whether it worked. Twenty-one years of operating delivery tooling for regulated enterprises. Named people. An agreed change process.

    That includes us. Where we build or operate the work under examination, our own assessment is evidence for the reviewer, not an opinion on it. The same test applies to us as to anyone else.

    The building blocks for that record are not being set by any one vendor. They are being set in the open. The Agentic AI Foundation, under the Linux Foundation, now hosts the Model Context Protocol, the interface most agents use to act, alongside the agent-to-agent standard that landed in April. FINOS hosts the AI Governance Framework the banks wrote for themselves, and on 3 September its Labs took in konspekt, a proposed open standard for a portable, human-readable record of decisions and provenance that, in its own words, lives outside any single conversation, model or platform, where a model may propose an entry and only a person may accept it. It is one maintainer and a Labs project, and it is exactly the shape Karp described. The Linux Foundation hosts the Appia Foundation, which is making verifiable proof of trustworthy AI an open standard. iTmethods is a member of all three. We do not set those standards. We sit in the rooms where they are set and we build to them, because a record that only one vendor can read is the payroll problem in a different form, and sovereign, safe and assured work needs building blocks nobody rents.

    Reign Gateway is Available Today. For calls sent through it, it applies identity, access, policy and spend controls and creates a record of the request, the policy decision and the outcome. Policy-controlled failover across customer-approved models is planned. It is not shipped. Reign Factory is Available, Beta Release, and not generally available. Reign Assurance is in co-design. It is being designed to help business and risk leaders assess whether defined AI-enabled work met its intended outcomes and stayed within the requirements set for it. It is not sold. It is not an audit opinion. Reign prepares. People decide.

    The same register on what we do not hold. Reign Ops holds a SOC 2 Type II. It does not extend to Gateway, Factory or Assurance. We do not hold ISO 27001, ISO 42001, FedRAMP or HIPAA. Naming a framework is not standing under it.

    One aside, because the name invites it. A reign is what a sovereign does, and the product carried that name before sovereignty was a campaign. We are not claiming the word. We are saying what it leaves out.

    The question a CIO will be asked twice

    A board asks its CIO for the institution’s sovereignty position. That question is on every agenda in every regulated institution this autumn, and Palantir put it there. The CIO has a good answer. Data residency. Model ownership. A control layer the bank owns. A signed log.

    Then the Chief Risk Officer asks the second question. On the agentic workflow that went live in May, for the actions it took in August, show me which ones met the requirement they were given, which ones did not, and what was not checked.

    The first question is about the asset. The second is about the work. The sovereignty stack answers the first completely. Karp himself said the second still has to be answered, by an operator you do not rent.

    Sourcing and disclosure

    iTmethods sells operated engineering platforms, software-delivery capacity and AI traffic governance to regulated enterprises, and is designing an assurance offering with customers. It competes in the market this essay describes. iTmethods is a member of the Linux Foundation, FINOS and the Agentic AI Foundation. Membership of a foundation is not a claim to have authored its standards. It has no commercial relationship with Palantir. Quotations from Alex Karp are from his 2 September 2026 appearance at the G20 Innovation Ministerial and have been checked against the recording. Quotations from Palantir’s guide are verbatim, including its punctuation.

    For Technology Leaders

    The board will ask for the sovereignty position and the answer will be a good one. The second question is the one to prepare for, and it is about the work rather than the asset. iTmethods runs the estate, does the work inside it, and produces the record that work leaves behind.

    For Technology Leaders

    Paul Goldman is the Founder and CEO of iTmethods. His team runs the platform, does the work, and proves it. He writes The Trust Layer at itmethods.com.

    Sources

    • CNBC, G20 Innovation Ministerial live updates, September 2, 2026
    • Benzinga, Palantir’s Alex Karp warns about AI alpha leaks, September 2026
    • Palantir, Institutional Sovereignty in the Age of AI, fifteen steps. Assurance defined in the compute section; evaluation suite, output validation and regression gates in the model section; audit and log in the control section
    • FINOS, Portable AI Decision Records: konspekt contributed to FINOS Labs, September 3, 2026
    • Linux Foundation, formation of the Agentic AI Foundation
    • CNN, This city is one of the world’s most important AI hubs, September 4, 2026, via CP24
    PG

    Paul Goldman

    CEO, iTmethods

    Founder and CEO of iTmethods, and the author of The Trust Layer. Previously published "MCP Is Exploding. Your Governance Isn’t Ready."

    Continue the AI Governance series

    Get Paul’s next article before it publishes

    Join 500+ security leaders

    The Trust Layer.

    A weekly essay on governing agentic AI in regulated industries. No product pitches.

    Talk to the team behind the Trust Layer.

    We run the platform, do the work, and prove it. Reign Ops operates the engineering toolchain your teams already use. Reign Factory, Gateway and Assurance sit inside that boundary, each at its own stated stage. Tell us what you are solving for and we will route it to the people who own that work.

    Start a conversation