~/ pov

Anyone can build with AI. Trust is the differentiator.

A working thesis on enterprise AI — argued, not asserted. This is the worldview behind every engagement I take.

In an age where anyone can build with AI, the scarce skill is judgement — knowing when to trust AI, how to test what it builds, and how to make it safe, compliant, and enterprise-ready.

The model is no longer the moat. Foundation models are a commodity you rent; the demo is a weekend's work. What separates a demo from a system a business can run on is everything around the model: where the data lives, who can touch it, whether you can prove what happened, and whether anyone on the team can tell good output from confident nonsense.

This matters most in India right now. Indian enterprises lead the world on AI adoption and trail it on governance — high usage, low maturity, real penalties arriving on a statutory clock. The gap between "we use AI" and "we can defend how we use AI" is where value is won or lost over the next three years.

Judgement over output. Output is cheap now. The engineering craft that survives the AI era is the judgement layer — testing, verification, orchestration, and the taste to know what should not be automated at all.

~/ the framework

The Trust Stack.

Four layers, decided in order, at architecture time — not patched in after the pilot.

01

Residency

Where does the data physically sit, and whose laws govern it? Residency is location; sovereignty is jurisdiction. DPDP, RBI, SEBI, and IRDAI rules make this an architecture-time decision — private-cloud VPC, on-prem, or fully air-gapped, chosen by data classification, not appetite for technology.

02

Access

Who — human or agent — can touch what? RBAC gateways, consent capture, purpose limitation, and least-privilege defaults. An AI system without an access model is a breach with good intentions.

03

Audit

Can you prove what happened? Audit logging, citation grounding, deletion receipts, breach response. If an answer can't show its sources and a system can't show its history, it isn't enterprise-ready.

04

Judgement

The human layer: knowing when to trust AI, how to test what it builds, and when to keep a person in the loop. Governance frameworks fail without operators who can exercise judgement under pressure.

~/ the evidence

Why this thesis, why now.

73%

of enterprise leaders rank data privacy and security as the top AI risk — yet only 21% report a mature governance model for autonomous agents. (Deloitte, 2026)

40%

of Indian enterprises report significant or full AI usage vs. ~28% globally — while only ~23% have formal AI ethics or governance frameworks. (Deloitte India, 2026)

78%

cite integration as a top barrier to scaling AI; 53% call it severe. The blocker is plumbing, not models. (EY India, 2026)

₹250 cr

the highest DPDP penalty (~USD 30M) for failing reasonable security safeguards. Rules notified Nov 2025; full compliance by May 2027. (MeitY)

~/ put it to work

If AI adoption has to survive an audit, let's talk.

Privacy-first architecture, DPDP/GDPR-aware adoption, air-gapped where needed — and the judgement to know the difference.

Work with me