@Visa and @Mastercard just went live with agentic commerce in Europe. Real transactions, real merchants.
Both rivals reached the same conclusion: agents need verifiable identity before they can spend.
Next question: does that identity travel beyond one network?
The real conversation we need isn't "should the US gatekeep Sol."
It's "who else should be in the room when frontier model access gets decided."
What do you think?
If frontier AI access is gated by one government's national security calculus, every other country becomes a downstream user of decisions they had no say in.
That's not global governance. That's one country writing the rules for everyone else's future.
The EU has the AI Act.
Singapore has its own framework.
The UAE, India, and Japan are all racing to build sovereign AI capacity.
A single-nation approval gate for frontier models doesn't reflect how AI actually gets used, or who actually gets affected by it.
Here's the question nobody's asking:
Why does ONE country get to decide who on Earth can access the most capable AI model?
The US didn't build AI alone. It won't deploy it alone either, whether it admits that or not.
OpenAI's most capable model ever just launched.
Almost nobody can use it.
Sol is gated behind US government approval. ~20 companies. Everyone else waits.
This isn't a product launch anymore. It's a geopolitical clearance process.
Aravind Srinivas is betting on orchestration as the moat.
Orchestration still needs a foundation under it: verified ID, attributable action, & proof that holds up after the model is forgotten
If the model isnt the product, accountability is
What replaces "the model" as the moat?
Once agents run continuously, act autonomously, and execute real tasks, on their own, the question stops being "which model is smartest."
It becomes: which agent did this, can you prove it, and who's accountable when it's wrong.
That's an identity problem. Not a model problem.
If he's right, every founder building "on top of a model" needs a new answer to one question:
What's actually defensible once the model underneath you is interchangeable?
Compute isn't it. Orchestration alone isn't either.
Aravind Srinivas just said the quiet thing out loud.
The model is no longer the product.
$20B valuation. 400 people. 1B+ searches a month.
His thesis: model = commodity. Bottleneck = memory and power. Orchestration = where the money actually is.
Genuine question for builders:
When your agent acts autonomously β what actually proves to a regulator or auditor what it did, and why it was allowed to?
Not "we log everything."
The actual mechanism. Cryptographic or structural.
How are you solving this?
Today, on my own machine:
An agent spawned β got issued a cryptographic identity β acted β had that identity revoked the second its task ended.
Zero cloud dependency.
This is where the industry converges in 2 years.
Mental model for agent identity:
A human has a passport. Proves who they are, where they can go, who's accountable.
Agents need the same.
Not a log. A cryptographic credential: this agent, this scope, this owner, this expiry.
Local models aren't a downgrade from the cloud.
For regulated workloads, sensitive data, anything that can't leave your network, local inference is the only correct architecture.
Future isn't cloud vs local.
It's both, switchable, one identity layer underneath.
"AI governance" gets used like it means one thing.
It doesn't.
Filtering outputs after the model speaks β structurally blocking an agent from acting outside scope.
One's a guardrail. One's enforcement.
Most products sell the first, market it as the second.
Built a universal model gateway this week .One API β Claude, GPT, local Llama. Same identity layer. Same audit trail. No matter which model does the work.The model is becoming a commodity.Identity is where the value sits now.
New "agentic AI" launch this week. Bigger autonomy claims.
Same unanswered question: how do you prove what the agent did, and on whose authority?
A timestamp isn't proof. A log isn't a signature.
Autonomy is shipping faster than accountability.
Most "AI agents" can't answer a basic question:
Who authorized you to do that?
We optimized for capability. We forgot accountability.
An agent moving money or writing code needs what a new hire needs day one β verified identity + defined scope.