Enterprise AI

Who Owns Trust? The Missing Layer in Sovereign AI 

By Zak Doffman, CEO, Pairpoint 

Governments are racing to make AI sovereign. They are regulating models, requiring data to remain within national borders, investing in domestic computing capacity and building sovereign clouds. These are necessary but they are not sufficient. None of them answer the most important question:  

Who owns the trust? 

Who decides whether a user, device, workload or AI agent is genuine? Who controls the identity infrastructure behind that decision? And under whose jurisdiction does that trust operate?  

If the answers ultimately point to a small number of global technology platforms and cloud providers, then sovereignty remains incomplete. Data may be local and infrastructure may be nationally hosted, but the mechanism determining who and what can be trusted still sits elsewhere.  

Sovereignty must include the trust layer  

Trust is often reduced to a technical feature such as a certificate, login, token or security check, when in reality it is a far more fundamental layer that underpins every digital interaction. 

Every AI system depends on trust across hardware, firmware, software, models, agents and the provenance of data and outputs. Carriers do not own all of that trust, nor should they. But they can anchor one critical layer – network-validated identity for the devices and systems connecting AI to the real world.  

The sovereign AI debate therefore needs to move beyond where data is stored or where a model is trained. A country cannot claim full digital sovereignty unless it has meaningful control over how identities are established, authenticated and authorised. Today, much of that power rests with cloud and technology platforms which are enormously capable, but built around their own architectures, commercial priorities and jurisdictions, not the nation’s. That said, there is another option and it is already deployed.  

The world’s largest trust platform already exists  

Telecom operators manage one of the largest distributed trust ecosystems ever created. Every SIM, eSIM or iSIM contains cryptographic credentials used to establish trust with a mobile network. Before a device is allowed to connect, the network authenticates it through a standards-based process proven across billions of mobile connections.  

This trust relationship operates across phones, vehicles, smart meters, payment terminals, industrial machinery and an expanding range of connected infrastructure. It is standards-based, proven at global scale and deeply embedded in regulated telecommunications frameworks. It is also largely invisible to the enterprise systems and public services that could benefit from it.  

For decades, operators have used this capability primarily to provide connectivity. They authenticate billions of devices every day but capture relatively little of the value of that trust beyond connectivity. Pairpoint believes that needs to change.  

Carriers should not be the supporting cast in sovereign AI. They are best placed to become its trust layer. Operators are already being asked to provide the land, power, fibre, connectivity and data-centre capacity behind sovereign AI. Those assets matter. But their most differentiated contribution may be the one least visible – trust. They operate critical national infrastructure, understand regulated identity and lawful accountability, and maintain direct cryptographic relationships with devices across long operational lifecycles.  

Cloud platforms can host sovereign workloads. Governments can define sovereign policy. But carriers can provide carrier-rooted trust, governed within national and regulatory frameworks, connecting devices, people, systems and AI agents to those environments.  

AI makes the question urgent  

Traditional digital identity was largely built around people logging into applications. AI changes the model. Autonomous agents will initiate transactions, access sensitive information, operate machinery and communicate with other agents. Decisions that once required a human click will increasingly take place machine-to-machine and in real time. But it will not be sufficient to ask whether an agent has the correct password or token.  

Enterprises and governments need confidence that an AI agent is who it claims to be, that it is operating through a trusted device or workload, and that it still has the authority to carry out the action it is attempting. This becomes especially important when agents start interacting with connected infrastructure and real-world systems.  

In that environment, trust cannot be established with a single login or authentication check. It must be continuous, contextual and constantly verified as conditions change.  

Network-rooted identity is not a silver bullet. It cannot tell you whether software has been compromised, whether an AI model is producing accurate outputs, or whether an agent is making the right decision. Those issues still depend on application security, governance frameworks and policy controls. 

What it can provide is something fundamental: strong, independent evidence that a device, connection or workload has been verified through a trusted, regulated carrier relationship. 

That trusted signal creates a solid foundation for higher-level decisions about access, authority and risk, helping organisations act with greater confidence in an increasingly autonomous world. 

Quantum safety cannot wait for the next device cycle  

There is a second reason why trust may need to move closer to the network. Many connected devices deployed today will still be operating in a decade or more. Some may remain in service for thirty years, long after current cryptographic standards have been superseded by the realities of the quantum era. 

Replacing every endpoint is not a credible option. Many devices simply will not have the processing power, memory or upgrade capability needed to support future security requirements. 

The network offers a more practical alternative. By embedding trust services within managed infrastructure, security capabilities can evolve over time without forcing organisations to replace millions of deployed devices. Networks, of course, will also need to modernise their own cryptography, and SIMs are not magically quantum-safe. But infrastructure provides a scalable point of control where new protections can be introduced and strengthened as threats evolve. 

In a world of long-lived connected assets, that flexibility may prove just as important as the technology itself. 

From connectivity provider to trust provider 

This is the role Pairpoint is helping to enable. Every SIM or eSIM already has a cryptographic relationship with its network operator. Pairpoint extends that capability beyond connectivity, enabling operators to deliver identity, verification and assurance services to enterprises, governments and digital platforms.  

The goal is not to replace existing security controls, but to add a carrier-rooted foundation that strengthens them. For operators, this is a major opportunity. Connectivity is increasingly commoditised, while assurance is becoming more valuable as connected devices and autonomous systems proliferate.  

By expanding their role, operators can become key enablers of the next digital economy, offering services built around identity, security, verification and AI. Having already connected billions of people and devices across borders, they are uniquely positioned to support secure digital interactions at global scale while respecting local governance and regulation.  

Related Articles

Back to top button