Blog
Notes on verified AI inference, regulated industries, and the infrastructure of trust.
Subscribe via RSS-
Verifiable of What?
'Verifiable' is on every AI trust homepage now, but it hides three distinct properties: hidden (nobody saw the data), unaltered (nobody rewrote the record), and true (the computation was what the record says). Any one can hold while the others fail. A record can be perfectly hidden and unaltered and still false from the moment it was written. Only independent re-execution establishes truth without trusting the operator's hardware.
Read article → -
The Layer Nobody Bought
In nine months, roughly $40B changed hands for the layers around inference, NVIDIA taking Groq's silicon and Hugging Face's distribution, Stripe buying OpenRouter's routing. Every acquirer now has a commercial stake in what ran. Independent evidence of execution is the one layer nobody bought, and couldn't: a verifier owned by the party running the compute isn't verifying, it's reporting. Independence is a position acquisition destroys.
Read article → -
You Cannot Manage a Model You Cannot Name
Stripe's ~$7B OpenRouter deal confirmed routing as a core layer: a request goes to whichever model is cheapest, so the identity of the model that served a given call is an outcome you received, not a choice you made. But export control, federal-contract exclusions, entity listings, and sector rules all attach to which model ran. Proving a prohibited model never touched the work needs a record of what executed, not a catalog, an attestation, or a routing config.
Read article → -
Your Vendor's Model Is Now in Your Inventory
OSFI Guideline E-23 takes effect May 1, 2027 and covers every model regardless of source, including the ones you bought. You are accountable for a model you did not build, cannot inspect, and cannot re-run. Today's toolkit for that risk is the vendor's account of itself. An inventory records which model a vendor says they run; it does not establish which model actually ran on a given decision. Captured cryptographic receipts do.
Read article → -
Seven Billion for the Router
On August 19, Stripe acquired OpenRouter for a reported $7B+. Buying the router is buying a position in how AI spend flows, but a router earns its keep by choosing the model per request, which means after the fact the customer often can't say which model served it. For a contested decision (a claim, a credit refusal, a jurisdiction clause), that evidence gap is the whole question. Cheaper routing and provable execution are two halves of the same problem.
Read article → -
Which Model Decided: What LATAM Supervisors Can Already Ask For
Across Latin America, automated decisions (credit scoring, AML flags, claims triage) are the production path, and every one lands on a person who can contest it. Brazil's LGPD Article 20 already lets them demand review while protecting commercial secrets: explain the decision without opening the model. Self-attested logs fail exactly when a supervisor asks. Independent verification is how you answer both.
Read article → -
The Cheapest Watt Is the One You Do Not Spend Twice
AI's energy story is usually about scale. Underneath sits a quieter waste: to trust a result, we run it again, doubling the energy. Probabilistic verification gets the confidence without the second full run, and once a result carries proof anyone can check, the work can migrate to idle, plugged-in, low-draw phones. Neither move needs a new data center.
Read article → -
Two Proofs, One Decision
When an AI decision is questioned, three different questions get asked: was there a program (governance), was the action allowed (authorization), and did the computation happen as claimed (execution). Documentation answers the first; almost nobody can answer the other two with anything but their own logs. Two different proofs, IronProof's policy verification and Cyberian's execution receipts, close that gap, and they are not interchangeable.
Read article → -
What a DER Can Rerun: A Candidate Means of Compliance for ML in Aviation Certification
Every design assurance discipline in aviation rests on evidence a second party can independently check, not a first party's attestation. A DER can rerun a coverage report; they can't rerun a trained model. As EUROCAE WG-114, SAE G-34, and EASA's MLEAP write the rules, a cryptographic receipt per verified inference is a candidate means of compliance a DER can re-derive without taking the supplier's word.
Read article → -
The Golden Hour Problem: Escalation Chains Cannot Verify What an AI Agent Did
Two in the morning: a fraud model blocks a transaction, the ombudsman clock starts, and the on-call engineer opens the logs. Each escalation tier just re-reads the same log and adds a name to the thread: delegation of doubt, not verification. A cryptographic receipt lets the compliance officer, ombudsman, or auditor check what the agent did directly, without climbing the chain.
Read article → -
The Compute Isn't Yours. The Answer Still Is.
Almost no regulated AI team runs its own inference. It sits with a hyperscaler or a managed endpoint. The machine belongs to a vendor; the output, the consequence, and the regulator's question belong to you. An API log, an invoice line, a dashboard screenshot all describe what the vendor's system reported about itself. None is something the person asking can check. A cryptographic receipt is.
Read article → -
When an Agent Takes the Action, Its Own Logs Are Not the Proof
A chat agent that only produces text has weak felt pain. It concentrates where an agent takes a consequential action, moving money, denying a claim, filing to a regulator. Then the question stops being 'what did the model output' and becomes 'what did this agent actually do, and on what basis.' Observability is the system's word about itself; an independent receipt is something a third party can check.
Read article → -
You Have Logs. Logs Can Be Edited.
In Mobley v. Workday a court let discrimination claims proceed against the AI vendor itself, on what the model actually did. Every AI vendor in a regulated industry now has to prove what its model ran, on which input, producing which output. Self-kept logs, SOC 2, and contracts all collapse the moment it turns adversarial. The fix is a tamper-evident receipt verified by a party that never ran the job.
Read article → -
The Trust Mark of Independent Compute
Billions are flowing into AI compute, but almost none of it buys a guarantee about the work performed. Independent providers are cheaper, yet serious buyers default to the incumbents because they cannot check the work, so they buy the reputation instead. A verifiable receipt, produced by a prover separate from the executor, lets independents sell proof instead of a name.
Read article → -
When the Sign-Off Stops Being the Last Line of Defense
A compliance officer or ISO 42001 assessor signs off on an AI system's outputs after reading a model card and a sample of predictions. That signature has carried the trust for years, but a reviewer who attests to correctness without a way to independently check the computation is holding liability they cannot discharge. Separating the executor from the prover turns the sign-off into something anyone downstream can check.
Read article → -
The Executor Runs the Model. The Prover Answers for It.
Across the regulated AI sector, production inference runs on managed cloud the company doesn't operate, yet the compliance obligation stays with the licensee. The human-review tier that used to close that gap attests but never reproduces. A cryptographic receipt from a prover separate from the executor does.
Read article → -
Inference Has No Controller
Kubernetes learned a decade ago that a system cannot be trusted to report its own state, so the controller sits outside the object. AI inference never learned it: the operator runs the model, writes the log, and vouches for itself. The executor cannot be the prover.
Read article → -
The Reviewer and the Reviewed Cannot Be the Same Agent
Separation of duties (the party doing the work can't be the only one checking it) is load-bearing in every GRC framework. When an AI agent acts and another AI reviews, that independence is cosmetic. What agentic systems do to one of the oldest controls in the book.
Read article → -
What ISO 42001 Asks For, and What It Cannot Give You
ISO 42001 asks you to measure, monitor, and keep records of how your AI behaves. None of those clauses, on their own, proves what the model did on one specific decision. That is the difference between a record and a proof, and where it starts to matter.
Read article → -
Cheaper Compute, Borrowed Trust
Moving inference off the hyperscalers is cheaper, but the trust model changes. When the hardware isn't yours, a cryptographic receipt (not the provider's word) is what makes the result usable for regulated work.
Read article → -
The Four Questions I Ask Every AI Vendor Before Signing
I sign the vendor contract and I answer for it later. Four questions, none of them technical, that decide whether I can prove what an AI model did, or only repeat what the vendor told me.
Read article → -
The Regulator Is Already in the Building
While most of the AI industry watches the EU AI Act's deadlines slide into 2027, insurance examiners in twelve states are already asking carriers to account for their AI. The instrument exists, it is in use, and your vendor cannot answer it for you.
Read article → -
I'm Not the Engineer. I'm the One Who Has to Defend It.
The people who actually decide whether an AI tool gets bought look more like me than the people pitching it. An operator's view of the gap between a vendor demo and what a compliance team can defend.
Read article → -
The EU Just Blinked. The Trajectory Didn't Change.
A delay is not a reprieve. It is extra time to build what every version of these rules converges on: proving which model made a decision, on what data, and how you know.
Read article → -
$100 Billion of AI Inference Runs on Blind Trust
Every AI model powering insurance pricing, fraud detection, and clinical decisions today produces outputs that no third party can independently verify. That era is ending.
Read article →