Skip to main content
    Back to Insights
    AI Governance

    Palantir and NVIDIA Turned Control Into a Product Category

    They are right about the problem. Owning a layer is not the same as proving an action.

    PG
    Paul GoldmanFounder & CEO, iTmethods
    July 28, 20268 min read

    Securing the Agentic Era. Article 22 · AI Governance

    An alliance of forty companies, a contract playbook, and a television appearance, all on the same day, four weeks after the partnership that set it up. They are right about the problem. Owning a layer is not the same as proving an action.

    Three things happened on Monday.

    NVIDIA announced the Open Secure AI Alliance, more than forty founding companies building open tooling for AI security. Microsoft, IBM, Red Hat, CrowdStrike, Cisco, Palo Alto Networks, Salesforce, SAP, Dell, HPE, Snowflake, Databricks, Capital One, Siemens, Hugging Face, Palantir, the Linux Foundation.

    Palantir published a long piece of contract mechanics on how a hosted model provider can quietly acquire what they call your alpha: the institutional knowledge and tradecraft embodied in the data you expose to a model and generate from using it. How to negotiate zero data retention that retains nothing. Which beta endpoints sit outside the protection you thought you bought. What happens when global inference routes your traffic into a region your regulator does not permit.

    And Alex Karp went on Fox Business and said the quiet part at normal volume.

    40+
    FOUNDING COMPANIES IN THE OPEN SECURE AI ALLIANCE
    NVIDIA ANNOUNCEMENT, JULY 27 2026
    7
    TECHNICAL CONTROLS IN A DOCUMENT ABOUT CONTRACTS
    PALANTIR GUIDANCE, READ AS A LIST

    The temptation is to read three separate items. It is one item.

    Four weeks, not one day

    At the end of June, Palantir and NVIDIA announced a sovereign AI partnership. NVIDIA’s Nemotron open models deployed inside Palantir’s AIP, Ontology, Foundry, and Apollo, running in classified and air-gapped environments, with the customer training on their own data and retaining ownership of the resulting model.

    Read the components. American chips. American open-weight models. An application layer the customer controls. Deployed where no external inference call is possible.

    Monday was that architecture acquiring a standards body, a compliance narrative, and a press cycle, all at once. Karp described the alliance as part of a broader movement that began with the NVIDIA partnership. He was not being coy about the commercial logic. He described customers who feel they are paying heavily for tokens while transferring the value of their business to a frontier lab, and he named the remedy plainly: enterprises need to own their compute and their application layer.

    That is not a convergence of independent minds. It is a campaign, executed over four weeks, by two companies with a very great deal of money at stake.

    Which does not make it wrong. It makes it worth reading carefully, because a campaign that size tends to define the vocabulary everyone else has to argue in.

    They are right about where the problem lives

    Buried in the alliance announcement is a sentence that matters more than the membership list:

    Real AI safety and security depend on the full agent stack — identity, permissions, harnesses, guardrails, logs and evaluation — not just on whether model weights are open or closed.

    Identity. Permissions. Logs. That is not model research. That is control plane.

    The contributions say the same thing in code rather than prose. HPE is bringing work on SPIFFE and SPIRE, which cryptographically verifies which workloads are permitted to talk to what. Hugging Face has given Safetensors to the PyTorch Foundation so weights can be loaded without executing arbitrary code. IBM and Red Hat’s Lightwell signs patches across the open source supply chain. NVIDIA’s own contribution is an open agent harness project whose stated purpose is making agent behaviour easier to test, trace, audit, and govern.

    Palantir’s document arrives at the same border from the legal side. Read their guidance as a list rather than as prose and something appears that the framing obscures. Maintain a living allow-list of permitted models, tools, features, and API endpoints. Automatically block calls carrying a beta header. Vet prompt-cache time-to-live before a service joins the allow-list. Fail-safe requests originating in high-accreditation environments so they cannot reach lower-accredited endpoints. Run automated alerts detecting when hyperlinked terms change. Keep observability capable of tracing which specific prompt caused a classifier to fire.

    That is seven technical controls, in a document about contracts.

    Palantir is not confused. They are being honest about a boundary. Their guidance keeps arriving at the edge of what a legal team can negotiate and stopping, because the controls sit on the other side of it, where the calls actually happen.

    And notice when their failure modes occur. A beta service auto-enabled on your tenant. A hyperlinked term updated without notice. An engineer accepting a click-through because the alternative was a blocked deploy at four in the afternoon. A model silently upgraded outside your negotiated scope. A new inference region joining the global pool.

    Not one of those happens at signature. Every one happens in production, months later, on an ordinary Tuesday, without anybody deciding anything. A contract is a point-in-time instrument. Drift is continuous.

    So the diagnosis is correct, from both directions. Safety is not a property of the model. It is a property of the layer above it, and that layer cannot be outsourced to a provider’s terms of service or to a provider’s weights.

    I have been making that argument for a year. On Monday it acquired forty founding members and a sales motion.

    What the category does not include

    Here is where I have to be careful, because the temptation is to claim more adjacency than exists.

    The alliance is scoped to cybersecurity: vulnerability remediation and disclosure, agent identity and isolation, safe weight formats, multi-model scanning, secure coding workflows. Its question is whether the system is sound. That is a real and hard question, and the contributions are serious.

    Palantir’s document is scoped to procurement. Its question is what the two parties agreed.

    Neither answers the question a regulated institution is actually examined on. Was this specific action authorized, against this business objective, within this delegated authority? Did the safeguards operate at the moment it mattered? What residual risk remains? Can you produce evidence an examiner will accept, a quarter later, for an action nobody remembers?

    A sound system can still take an unauthorized action. A well-drafted contract can be honoured perfectly while an agent does something no one approved. Soundness and agreement are both necessary. Neither is authorization, and neither is proof.

    That gap is not a criticism of either party. It is what is left after both of them have done their work.

    The word doing the most work is “own”

    Karp is right that you have to own the application layer. The unresolved part is what owning it means when the layer is somebody’s product.

    An enterprise that moves off a frontier lab and onto a vendor’s application layer has changed counterparty. It has not necessarily changed posture. The dependency is now on a different company, with different commercial incentives, and the same structural property: the record of what your agents did, and the authority under which they did it, lives inside something you license.

    The test is simple and nobody markets against it. Does your authorization policy survive a decision to change models? Does your action log survive a decision to change vendors? Can you hand an examiner a complete, ordered, attributable account of what an agent did and what it was permitted to do, in a quarter when you did not plan to change anything and then had to?

    If the answer is no, the risk has been relocated and renamed sovereignty.

    Ownership of a layer is a commercial arrangement. Proof of an action is an artefact. Only one of them is admissible.

    The question worth sitting with

    An agent in your environment does something on a Friday that nobody sanctioned.

    By Monday, can you produce an ordered, attributable record of every action it took, the authority under which each was permitted, and the point at which it exceeded that authority?

    Not whether you would eventually piece it together. Whether you can produce it.

    If the answer is that nobody knows, the controls you have are describing a protection you have never tested. The difference only becomes visible under examination, which is the worst possible moment to discover it.

    Monday was a good day for this industry. Two of the largest companies in it told several thousand enterprises that the control layer is theirs to hold, and put engineering behind the claim. The part still open is who produces the proof for the specific action, on the specific day, that a regulator is going to ask about.

    Sourcing and disclosure

    NVIDIA announced the Open Secure AI Alliance on the NVIDIA blog on July 27, 2026, with more than forty founding members. The alliance describes itself as building on the Linux Foundation’s Akrites initiative and OpenSSF community work. It is an NVIDIA-led alliance rather than a Linux Foundation project, and no charter or governance documentation had been published at the time of writing. NVIDIA’s announcement cites an autonomous agent breaking containment during a benchmark and reaching a third party’s production systems earlier in the month as part of the motivation for the alliance.

    Palantir Technologies and NVIDIA announced their sovereign AI partnership at the end of June 2026, covering the deployment of NVIDIA Nemotron open models within Palantir AIP, Ontology, Foundry, and Apollo in classified and air-gapped environments.

    Palantir Technologies published “AI Sovereignty is Your Alpha: How to Avoid Transferring Your Alpha to a Hosted Model Provider” on the Palantir Medium publication on July 27, 2026. Palantir states the document is not legal advice and creates no attorney-client relationship. Nothing here is legal advice either.

    Alex Karp’s remarks are paraphrased from a Fox Business interview broadcast on July 27, 2026, and are not presented as direct quotation.

    This article takes no position on export controls, on the regulation of open-weight models, or on the national origin of any model.

    Several parties described here build and sell in this market. So do we. iTmethods is a Silver Member of the Linux Foundation, which is an inaugural partner in the alliance described above, and a member of FINOS and the Agentic AI Foundation. We build runtime governance software for regulated enterprises. Our interest in the conclusion is not hidden.

    AI governed. Outcomes assured.

    If the honest answer to the Friday question is that nobody knows, that is the conversation to have with your board and your audit committee before an examiner has it with you. iTmethods governs enterprise AI and assures its outcomes, and Reign delivers that assurance: the authorization policy, the action record, and the evidence that survive a change of model and a change of vendor, because they are yours rather than a feature of the layer you licensed.

    Request a Board and Audit Briefing

    Paul Goldman is the CEO of iTmethods, where his team builds the control and assurance layer for agentic AI: the governance, evidence, and portability that let regulated institutions run any model, swap it under pressure, and prove control. He writes The Trust Layer at itmethods.com.

    Sources

    • NVIDIA, Open Secure AI Alliance launch announcement, NVIDIA blog, July 27, 2026
    • Palantir Technologies, “AI Sovereignty is Your Alpha: How to Avoid Transferring Your Alpha to a Hosted Model Provider,” Palantir Medium publication, July 27, 2026
    • Alex Karp, Fox Business interview, July 27, 2026 (remarks paraphrased, not direct quotation)
    • Palantir Technologies and NVIDIA, sovereign AI partnership announcement, end of June 2026
    • HPE, SPIFFE and SPIRE workload identity contributions to the alliance
    • Hugging Face, Safetensors contribution to the PyTorch Foundation
    • IBM and Red Hat, Lightwell supply chain patch signing
    • The Linux Foundation, Akrites initiative and OpenSSF community work
    • EU AI Act
    • OSFI Guideline E-23 Model Risk Management (effective May 1, 2027)
    PG

    Paul Goldman

    CEO, iTmethods

    Creator of Reign and Forge. The platform and operational substrate for AI governance in regulated industries. Previously published "MCP Is Exploding. Your Governance Isn’t Ready."

    Continue the AI Governance series

    Or share your thoughts here

    Your comment will appear on this page. The best insights may be shared in the LinkedIn discussion.

    Get Paul’s next article before it publishes

    Join 500+ security leaders

    The Trust Layer.

    A weekly essay on governing agentic AI in regulated industries. No product pitches.

    Talk to the team behind the Trust Layer.

    Reign: AI Governance Platform. Forge: Managed Runtime + DevOps Tooling. Reign governs. Forge runs. Tell us what you're solving for and we'll route your request to the right team.

    Talk to Us