← Back to TIL
First Gear / July 27, 2026

Model Choice Needs Custody

Aggregation

World

2 critical / 2 happenings

Aggregation

Tech

2 critical / 1 happenings

Ideation

Ideation

Idea 1 Model Custody Firewall

Sell regulated enterprises a control plane that treats every AI model like a supply-chain component: provenance, jurisdiction, weights lineage, hosting location, policy exposure, benchmark fit, and hot-swap substitutes are tracked before a request is routed. The primitive is not cheaper routing. It is auditable custody for model decisions when the cheapest capable model may also be the one procurement, regulators, or customers later force you to remove.

Source Signals

Why Now: Model cost is dropping fast, open-weight Chinese models are good enough for real workloads, and U.S. policy is moving from abstract safety debate into procurement risk. Existing gateways optimize price, latency, fallback, and logs. The new pain is proving why a model was allowed, where it ran, what it could leak, what policy changed, and which substitute will keep the product alive tomorrow.

First Wedge: Start with banks, defense-adjacent SaaS companies, and healthcare vendors that already route across multiple LLMs but cannot answer a customer security review cleanly. Version one sits beside their AI gateway, inventories every model/provider path, assigns a custody score, blocks disallowed routes, and generates audit packets for security questionnaires and procurement renewals.

Commercial Model: The buyer is the CISO or AI platform lead with legal/procurement pulling budget. Charge an annual platform fee based on model routes and governed applications, with paid compliance packs for SOC 2, HIPAA, defense-contractor, and regional data-residency reviews. The budget exists because one blocked enterprise deal or forced model migration costs more than the tool.

Defensibility: The compounding asset is a live map of model lineage, hosting providers, sanctions/entity-list exposure, customer policy outcomes, eval substitutions, and migration playbooks. Cloud gateways can add a checkbox, but they are conflicted if they also sell model traffic; the neutral system of record for model custody can become the audit layer customers and insurers trust.

Technical Risk: The hard part is proving lineage and policy exposure when weights, fine-tunes, distillations, and hosted endpoints are intentionally opaque. The product needs a mix of provider attestations, hash/signature registries, behavioral fingerprinting, static policy rules, and reproducible evals that show a replacement model is safe enough for the same workflow.

Market Expansion: After LLM routing, expand into embedded models in devices, vendor AI features inside SaaS tools, call-center agent stacks, and regulated supply-chain software where customers need to know which autonomous system touched their data or made a decision.

Self-Critique: This could collapse into a feature of Cloudflare, Kong, Datadog, OpenRouter, or an enterprise GRC suite. It also depends on buyers caring before a major enforcement action or public breach. The wedge has to be custody evidence that wins security reviews, not another dashboard for model ops teams.

Next Experiment: In two weeks, interview 15 AI platform/CISO buyers at regulated companies and collect the exact model-provenance questions from their security reviews. Build a thin scanner for one gateway log format that flags Chinese/open-weight/unknown-hosted routes and produces a one-page audit packet. Try to get three buyers to pay for a private beta tied to an active enterprise customer review.