Flagship essay · The spine
The Three Layers
Trust in AI is treated as one problem. It is three: whose values the system runs on, who decides when it should not decide, and what actually happened. Values, judgment, evidence. Why I am building all three.
Ask a room of serious people what it would take to trust AI and you will get one word, governance, doing the work of three different jobs. Pull the word apart and the jobs separate cleanly. Somebody has to decide what the system should want: whose values it runs on, and whether the people it runs on had any say. Somebody has to own the calls the system should not make alone: a human with a name, reachable at the moment it matters. And somebody has to keep the record of what actually happened: what the system was, when it changed, what the human did. Values, judgment, evidence. I build trust infrastructure for AI, and this essay is the map of it: three layers, one argument.
Layer one: whose values
Every model is an opinion. Somebody chose its data, its objectives, its refusals, and those choices govern everyone the model touches, almost none of whom were consulted. The first layer of trust is making that opinion legible and contestable: values decided in the open, by the governed, not baked in by whoever got to the training run first. That is Sanctity, the values layer. It answers the question that comes before any deployment: what should this system want, and says who.
Layer two: whose judgment
No matter how good the values, some calls should not be made by a machine alone: the irreversible ones, the ones that touch a life, the ones the model itself is least certain about. The second layer is a working path from an AI agent to a qualified, accountable human, with expertise weighted and the person named. Not a confirm button, which I have argued is liability laundering, but an actual consult: the hard call reaches someone answerable, in time to matter. That is HumanChain, the judgment layer. It answers the question during the deployment: who decides, when the system should not.
Layer three: what actually happened
And underneath both sits the layer almost nobody builds, which is why I did. Values you cannot verify are marketing. Judgment you cannot evidence is a story. The third layer is the independent record: which model was actually serving, whether it changed, what the human was shown, what they did about it. Measured by a party that is neither the vendor nor the buyer, continuously, on a record that cannot be quietly rewritten. That is Modelometer, the evidence layer, live in beta: serving identity checked daily, behavior measured weekly, every run hash-chained in public. It answers the question that arrives after everything else: prove it.
Any two without the third collapse
Here is why this is one architecture and not three products that happen to share a founder. Values plus judgment without evidence is a church: sincere, unverifiable, and helpless in a dispute. Judgment plus evidence without values is a bureaucracy: everything documented, nothing worth documenting, the machinery of accountability aimed at goals nobody endorsed. Values plus evidence without judgment is a museum: principles beautifully recorded while the system decides alone in the back room. Each layer keeps the other two honest. The record proves the judgment happened; the judgment enforces the values; the values give the record something worth proving.
The order of building
I am building the evidence layer hardest and first, and the reason is unromantic: it is the layer the other two need on day one, and the layer nobody else has an incentive to build. Vendors will not fund their own witness. Buyers cannot run one credibly. The values conversation and the judgment market both stall the moment somebody asks, how would we know, and the honest answer industry-wide is that we would not. Fix that, and the other layers stand on ground instead of air. If you want the argument for the evidence layer in full, start with Your AI Changed Last Night, Prove It and The Model on the Invoice.
What this means if you are buying
You do not have to care about my company names. Care about the three questions. When a vendor says trustworthy, ask: whose values, decided how? Ask: which decisions reach a named human, and how fast? Ask: who keeps the independent record, and would it survive your lawyer? Any AI deployment that can answer all three is defensible. Any that cannot is running on vibes, and vibes, as I keep writing, do not survive a dispute. The trust stack is not a slogan. It is a checklist, and it has exactly three lines.
Read on
The evidence layer in full: Your AI Changed Last Night. Prove It. and The Model on the Invoice. The judgment argument: human oversight is mostly theater. The values premise: every model is an opinion.