01 Independence
Insurance against the platform grading its own homework.
When one vendor is the agent, the enforcer, and the auditor of record at once, an outside auditor or regulator needs proof from a party that is not the one being judged.
Independent, neutral, verifiable
The backstop no platform can be for itself.

Who has to trust it later
The decision takes a second, and everyone who has to answer for it shows up later.
They all need the same record, and the only one that exists is kept by the company with the most to lose if it looks bad.
Almost nobody who has to trust an AI-assisted decision was in the room when it was made.
Four different jobs, four sets of pressure, one thing none of them can get. The problem was never how carefully the record is kept, but who keeps it.
That gap cannot close from the inside. It closes from outside, or it stays open.


The problem
AI is moving into decisions that carry real consequence: the trade that executes, the claim approved or denied, the action an agent takes at 2am with nobody in the building.
Ask a model the same question twice and it can answer two ways, but even a model that never did that would still be the player grading its own play.
The proof has to come from somebody who is not in the game, and that is the receipt we keep.
Claim. The model can't be its own proof.
1. NOT REPEATABLE BY DEFAULT One prompt run 1,000 times at temperature 0 produced dozens of different outputs, caused by how requests batch on the graphics processing unit (GPU), floating-point order, and model routing, not by sampling randomness.
2. DETERMINISM IS ACHIEVABLE, AND BESIDE THE POINT It can be forced with batch-invariant kernels and pinned hardware at roughly 34 to 62 percent throughput cost, and it is neither the default nor available in shared cloud serving.
3. THE MODEL IS STILL THE THING BEING CHECKED Reproducibility was never the requirement, and independence was.
Source: Thinking Machines Lab, "Defeating Nondeterminism in LLM Inference," September 2025.
One incident
02:14, a Tuesday in March
Representative scenario. No client named.

Direct loss
$780,000
Sequence of events
02:14
An AI agent approves 1,900 claims in nine minutes. Nobody is watching.
That night
A model update shifts how one field, the date of loss, is read.
Undetected
Forty-one claims fall outside their coverage window. Approved anyway.
On review
The platform re-runs the prompt. Same input, different output.
Too late
By the time a person notices, the money is gone.
3 weeks later
The regulator asks who approved these, and on what basis. No independent proof exists.
Every action was logged and every log said ALLOW, but none of them said why and none could be replayed.
When the insurer asked the platform to prove the decision, it re-ran the prompt and got a different answer, and nothing had broken: the system behaved exactly as designed.
The direct loss was $780,000, and the larger cost was the answer nobody had to who approved these and on what basis, because the insurer held a complete record of what happened and no independent proof of why.
That is the failure that matters. Not a breach, not an outage, but a quiet and fully authorized decision that nobody can stand behind.
An independent receipt cannot stop a model from drifting, but it catches the drift, ties it to an identity, and produces proof every side can trust.
The one held picture, sharpened
The card network is trusted by both sides for exactly one reason: it is neither of them, so neither the merchant nor the bank grades its own transaction.
AI acts now, and the platforms are trying to be merchant, bank, and referee at once, which is why somebody has to be the neutral party for what AI does.

The category
What we actually sell, three insurances

01 Independence
Insurance against the platform grading its own homework.
When one vendor is the agent, the enforcer, and the auditor of record at once, an outside auditor or regulator needs proof from a party that is not the one being judged.
02 Continuity
Insurance against the platform as a single point of failure.
If identity, policy, audit, and enforcement all live in one vendor's stack, an outage or an acquisition takes your whole governance posture down with it.
03 Sovereignty
Insurance against lock-in.
The record of what your AI did should be portable, held under your own keys, and verifiable outside any vendor's tenant.
Independence, continuity, sovereignty. Three things no platform can provide about itself.

How it works
01
Tie every action to an identity that can be held to account.
02
Check the action against fixed policy before it executes.
03
Preserve a signed receipt of what happened, held under your keys rather than the platform's, and verifiable outside NMSG and outside your tenant by a party that holds no account with either.
An auditor opines and an underwriter prices on the artifact, while counsel defends and a lender explains from the record rather than from a reconstruction.
Who it is for
This is for the person carrying liability for outcomes produced by AI systems they did not build, and for anyone who has learned that the failure that matters happens off-hours and at volume, when a control that only probably fires proves it was never a control at all.
It is not for developers evaluating an application programming interface (API), buyers shopping for a governance tool, or anyone looking for a demonstration, and they will know within a line.


Why me
I did not come to this from AI. I came from security, writing up other people's breaches for the people who had to act on them, and the same shape kept turning up.
The control fired or it did not, and either way the evidence went nowhere. By the time anyone needed to know what happened, the only record left belonged to the party being asked about it.
Platforms will keep getting better at enforcement, and none of it produces evidence an outsider can rely on, because a check on a system cannot be the system.
So I took the seat that is left. Infrastructure means the ordered assembly laid beneath, and what nobody sees decides what can stand above it. That is the whole job, and I intend to do only that.
W
Founder, Nine Mile Security Group
A platform can't be the independent check on itself, and we are that check: the neutral proof layer for regulated AI.
We are building the layer beneath the AI economy, the independent conscience that keeps power honest, and the agent economy does not have one yet.
