Suppose an institution downloads a model and runs it in its own building. Does it now own the intelligence it uses? It has custody of weights and hardware, but a second public model port could bypass its policy. A connector could quietly reinterpret “customer” after a mapping edit. A workflow could repeat a payment after a timeout. An agent could report its own advice successful without observing the outcome. Ownership in this setting is a chain of control and evidence, not one item in an inventory.

That was the problem before Regnant's current products had names. The company record frames it through three fronts: working-language models, decision systems and infrastructure that stays within the institution's perimeter. The repositories show why these fronts cannot be collapsed into one feature. Each has a different trust boundary and a different kind of proof.

1
Figure 1. Model, server, sources, approvals and audit form a connected control path.

Control begins at the request path#

Cordon demonstrates the first distinction. A local model server is insufficient if callers can reach the runtime around the gateway. Cordon supervises its own llama-server on loopback, gives it a per-boot key, and applies identity, permissions, token budgets and output policy at the only intended entrance. It writes an audit record before inference and signs the response. Its streaming filter holds back enough text to catch a sensitive pattern that spans chunks. When timing normalization is enabled, it refuses streaming rather than claiming the timing signal is hidden while releasing token-by-token intervals.

The limit is equally relevant. Sealed model bundles are staged briefly as plaintext for a runtime load; disk-backed staging is not enclave-resident decryption. Hardware attestation support has documented synthetic tests, but a claim about protection from a hostile host administrator must be verified on the target hardware. The word “local” does not settle the threat model by itself.

Meaning and authorization need their own boundaries#

Matta addresses a different weakness: an organization may control every source database but still lack one governed interpretation of its records. Its mapping and SHACL validation path can reject malformed or semantically incompatible RDF before it enters the asserted graph. Separate named graphs retain ontology, asserted facts, inferred facts, audit and quarantine. A mapping suggestion from a model is not allowed to become a continuous sync job until a steward reviews it. A full-snapshot connector can remove absent records only when the source contract says the inventory is complete. Without that contract, “missing” could mean “filtered out.”

Knott and SeeP show two forms of authorized action. Knott keeps workflow state durable across a restart and exposes error branches and human tasks in the graph the author saved. It avoids retrying side-effecting timeouts by default because a remote provider may have performed the action before the timeout. SeeP starts from a narrower agent capability: investigation tools are read-only. A proposed plan passes policy and approval, and the executing node verifies the signed plan, resolved targets, expiry and one-use run marker. A gateway's claim that someone approved is not enough for a node that can check independently.

2
Figure 2. Mapping review, durable workflow review and node verification form separate control points.

A working language and a measured consequence#

KW5 is a research response to the language part of ownership. The weights were trained from scratch for Kiswahili rather than reaching it only through translation. Its open releases include model artifacts and evaluation records. They also include limits: strong held-out text compression is not a demonstration of reading comprehension or factual safety. The later 149M work recovered a model initially thought unusable after finding that the loader tied embeddings a TPU training run had left separate. That incident is a reminder that custody of a checkpoint is not proof one can reconstruct the trained model faithfully.

Wallgarden addresses what happens after a system influences a business decision. A recommendation becomes a claim tied to a metric, baseline, direction and horizon. A later observation, not the model's account, determines the verdict. Where there is no reading, the case remains unmeasurable and outside the value ledger and learning loop. This is necessary if a track record might someday justify more automation. A system cannot earn trust by counting its own unknowns as successes.

IIN supplies a useful boundary case. It connects plant readings, asset records, predictions, approvals and work orders, but its September assessment calls the build an engineering candidate. Tests using synthetic readings and mocked database grants establish parts of the implementation. They do not establish prediction quality on plant failures, production tenant isolation or a recoverable full deployment. An installable Windows client does not contain the server stack. Ownership includes the discipline to withhold a release claim until those tests exist.

Two other workspaces illustrate the human scale of the same principle. Kairos is designed for teachers preparing Tanzanian curriculum material on school computers with a local model. It can generate and export, but a teacher must inspect the lesson or marking result before using it. Weave retains a research project's sources, datasets and task evidence across chats. Its bounded analysis sandbox and persistent developer workspace have different permissions; confusing them would turn a safe data experiment into a file-system editing path. Bubbly makes a related separation for engineers: the desktop and terminal are two views of one backend thread, while provider choice determines whether code context goes to a local model or an external service. In each case “runs locally” is a property to specify for the actual component and configuration, not a blanket claim about every optional path.

3
Figure 3. A checkpoint and outcome have verification records, while a plant prediction awaits validation.

This is not one completed proof shared by every product. A deployment would still need the actual hardware and network boundary, reviewed source mappings, key custody, recovery drills, user testing in the working language, and observed outcomes on the relevant tasks. The practical test of ownership is whether an institution can inspect and operate those boundaries without relying on a vendor's uncheckable assertion. The following product and research posts examine where the current implementations meet that test and where evidence is still owed.