
Share
As enterprises demand AI models run on their own servers, model builders lose control over the intellectual property they license. OPAQUE's new custody protocol offers a technical answer to a problem contracts alone can't solve.
The AI industry has a custody problem, and it has been managed mostly through legal paper rather than technical enforcement. OPAQUE, the confidential computing company born out of UC Berkeley's RISELab, thinks it has a better answer. On September 10, the company launched Weight Custody Manifest (WCM), an open standard and developer-preview SDK designed to give AI model builders verifiable, revocable control over where and when their model weights can be unlocked once deployed on infrastructure they do not own.
The problem WCM addresses is structural, not incidental. Enterprises are fine-tuning open models on proprietary data. AI labs and software vendors are being pushed, increasingly as a deal condition rather than a preference, to deploy their most valuable models directly into customer, sovereign, and on-premises environments. That shift hands physical control of the weights to someone else's machines. Once that happens, the model builder's only real leverage has been a signed contract, which is a poor substitute for a technical guarantee.
WCM's pitch is straightforward: keep the weights encrypted until the receiving infrastructure proves it satisfies conditions set by the model builder in advance. Even after a key is released, access can be revoked at any time if conditions change or if proof of compliance lapses. That revocability matters. It converts a one-time trust decision into an ongoing, enforceable relationship.
Existing key brokers handle release mechanics but don't tie that release to the model's actual identity or usage terms. WCM closes that gap. A jointly signed manifest, co-signed by the model builder and a custodian (OPAQUE by default, or self-hosted for sovereign customers), can encode the model's identity, license, permitted uses, jurisdiction, approved software, and custody requirements before any weights are unlocked.
The system also tracks fine-tuned derivatives back to their parent models and supports revocation down that entire chain. That's a meaningful design choice given how often derivative models proliferate inside enterprise environments without clear lineage tracking. Either party, builder or customer, can trigger an emergency revocation. Sovereign deployments can require a quorum, so no single actor can unilaterally switch a model off. Manifests can be recorded to a public, append-only log, a requirement OPAQUE says sovereign deployments already demand.
Imran Siddique, OPAQUE's Chief Platform Officer, framed the shift in blunt terms: "Today's Confidential AI protects the customer from the model. WCM protects the model from the customer." He added that written contracts have limited reach once models move onto infrastructure their builders don't control, and that builders need proof, not promises, that their intellectual property will only unlock under agreed conditions.

The standard is positioned as complementary to OpenSSF Model Signing rather than competitive with it. Signing verifies a model is genuine. WCM determines whether that genuine model can actually be unlocked. Together, the two address different halves of the same trust problem.
OPAQUE is releasing WCM under an Apache license as a developer preview, with a published specification, a defined data format, a working reference library, and 91 public test cases. That's a meaningful degree of transparency for a security standard at this stage, and it invites scrutiny: model builders, customers, and infrastructure providers can independently evaluate the threat model rather than take OPAQUE's claims on faith. As a preview, the specification and interfaces remain subject to change ahead of a stable release, which is worth flagging for any team considering early production use.
The validation data is where the claims get concrete. OPAQUE reports the build is reproducible: two independent builds produced byte-identical results across 5,948 files, verified automatically. WCM has been tested on an NVIDIA H100 in confidential mode, along with AMD and Intel confidential servers on Azure and Google Cloud. In its most recent test, a CPU and GPU had to prove themselves together against a fresh, one-time challenge before the model key was released as sealed ciphertext. Attempts to substitute either proof were rejected, and the full test suite passed. That's a reasonably rigorous bar for a preview-stage product, though independent third-party audits have not yet been reported.
WCM arrives at a moment when sovereign AI deployment is shifting from edge case to default requirement for a growing share of large enterprise and government deals. The tension between model builders wanting to protect valuable IP and customers wanting full control of their own infrastructure isn't going away. It's arguably intensifying as models grow more capable and more expensive to build.
What OPAQUE is offering isn't a finished product so much as a proposed rulebook, open-sourced so the market can stress-test it before anyone commits production workloads to it. That's a sensible approach given the stakes: a custody standard that fails under adversarial conditions is worse than no standard at all, because it creates false confidence.
The open questions are adoption and interoperability. A standard is only as valuable as the number of model builders, cloud providers, and sovereign customers willing to build against it. OPAQUE has the pedigree to get a hearing, with founders Ion Stoica and Raluca Ada Popa carrying credibility from Databricks and DeepMind respectively, but pedigree doesn't guarantee ecosystem buy-in. Watch for whether major model providers beyond OPAQUE's own customer base adopt WCM, and whether the 91-test suite expands into something closer to a formal security audit before the stable release ships. For now, this is a credible technical answer to a real commercial standoff, not yet a proven industry standard.
Tags
Original Sources
OPAQUE Launches Weight Custody Standard for Sovereign and On-Premises AI - BigDATAwire
↗ https://www.hpcwire.com/bigdatawire/this-just-in/opaque-launches-weight-custody-standard-for-sovereign-and-on-premises-ai
About the author
Marcus began tracking AI's market implications in 2016, noticing AI-related patent filings accelerating ahead of earnings upgrades before most of the sell-side had caught on. A former fixed-income quantitative analyst, he spent two decades building models that priced risk across emerging markets before pivoting to cover the economic impact of AI full-time. His writing translates opaque technical developments into clear risk/reward terms — and he's rarely diplomatic about the gap between AI valuations and underlying fundamentals. He believes most market participants still underestimate AI's long-run deflationary effect on knowledge work.
More from The Analyst →This Week's Edition
11 September 2026
33 articles
Related Articles

Health Wildcatters Names 14th Startup Cohort Ahead of INVEST Digital Health
Products & Applications · 5 min

Inova Health Taps Anomaly Insights AI to Recover $10.4 Million in 90 Days on Payer Claims
Products & Applications · 5 min

Interra Health Links E-Prescribing Platform to CMS GLP-1 Bridge Program
Products & Applications · 6 min
Related Articles

Health Wildcatters Names 14th Startup Cohort Ahead of INVEST Digital Health
Products & Applications · 5 min

Inova Health Taps Anomaly Insights AI to Recover $10.4 Million in 90 Days on Payer Claims
Products & Applications · 5 min

Interra Health Links E-Prescribing Platform to CMS GLP-1 Bridge Program
Products & Applications · 6 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.