AI value is moving above the model. The layer it moves to is unowned.
Models are converging; the durable advantage is shifting to whoever holds the institution's accumulated state — the evidence, decisions, and governance history behind its AI work. Rosetta is the protocol layer for that state: reviewable before action, tamper-evident after it, portable across model families, and owned by the institution.
AI-agent pilots that never reach production; top blockers are evaluation gaps (64%) and governance friction (57%).
Forrester / Anaconda, 2026Organizations with governance maturity adequate for the agents they already deploy.
McKinsey AI Trust Maturity Survey, 2026Projected global enterprise AI-agent spend by 2027.
IDC / McKinsey, 2026EU high-risk AI obligations, now fixed; transparency obligations began Aug 2026. Fines to €35M or 7% of turnover.
EU AI Act & Digital Omnibus, 2026Palantir's Alex Karp, channeling what he calls the private fury of enterprise CEOs: customers want control of their models, their data, and their edge — to “own the means of production.” CNBC interview, July 2026
Microsoft's Satya Nadella, more quietly: a company that is only a consumer of a foundation model will struggle to retain the learnings — and the enterprise value — created by using it. Stanford remarks, 2026
Both are buyer-side demand for the same missing object: a record of the institution's AI work that it owns, that any model can read, and that no one can quietly rewrite.
Everyone else records the agent. Rosetta's review is part of the decision.
Twenty-plus vendors sell observability — a camera pointed at the cockpit, a trail you could delete without the agent noticing. Here the Rosetta Review participates in the decision before action; any prior state is reconstructable, and alteration is detectable at the exact entry. The live case answers the buyer's question —show me the trail behind the decision — in sixty seconds.
The Review is the door. The larger asset is governable state: what the system knew, what remained unresolved, what it learned, and which pressures shaped action. What stays hidden cannot be governed.
Run the answer yourself →A protocol company, on the SOC 2 pattern
Protocol layers are winner-defined markets: the first adopted specification is the one everyone else conforms to. The commercial motion follows the attestation pattern — reference implementation, conformance criteria, certification — with the protocol as the defensible core: patent filings on record, mechanism under NDA, specifications shared with partners under license.
Technical detail — defensibility, precisely
The public site demonstrates behaviors: pre-action review that changes outcomes (the counterfactual), exact reconstruction and tamper-evidence (the record test), and cross-model portability (the handoff, read from the institution's own database). The mechanisms producing those behaviors — representations, mutation discipline, verification model, arbitration — are deliberately absent from this site and constitute the filed IP. Model vendors face a structural conflict in replicating the layer: its core property, portability, dissolves the lock-in their positions depend on; trust layers historically had to be neutral to be adopted. And an intermediary that holds everyone's institutional memory merely relocates the dependency — an intermediary is a new landlord; a protocol is a deed.
The demonstrations are public behavior. The mechanism is filed and under NDA. If the layer thesis is right, the open question is who defines the layer — and protocol windows, historically, are short.
Above board: all market figures are third-party and named on screen — verify them independently. Named executives are cited as buyer-side demand signals, not as endorsements of this product. Demonstrations show behaviors; scenario content is fictional and labeled; the persistence, verification, and handoff machinery is real.