The data sovereignty question Palantir didn’t ask.

franklin discovery

Palantir’s new paper outlines 15 ways for institutions to protect their knowledge from the AI models they use. The better question is why it needs protecting at all.

Palantir has published a 28-page paper titled “Institutional Sovereignty in the Age of AI.” It’s addressed to every government and company running frontier models, and the argument is blunt—your institution’s knowledge is being pulled into predictive AI models you’ll never own, and the companies doing the pulling have structural reasons to keep at it. Palantir’s answer is a fifteen-step defense covering contract terms, architecture, hardware, and auditing, all meant to keep what your institution knows inside your institution.

The paper is worth reading in full, because the diagnosis is careful and mostly right. Model providers, Palantir writes, have “a structural incentive to migrate as much intelligence from enterprises into their model weights” as they can. Weights (the internal numbers that predictive AI models like OpenAI’s learn during training) hold everything a model knows, and nobody can open them to read what’s stored there, not even the company that built the model. That means the judgment your organization spent decades building flows out through everyday prompts, into systems that learn from what they take in, unless you’ve negotiated otherwise. Once that know-how is in the weights, it isn’t yours anymore. It can be leased back to your competitors as generic capability.

Most companies still think of their model provider as an ordinary vendor. You pay for a service, and the service improves your business. Palantir asks a simple question. If your incentives were aligned with your model provider’s, why do they charge per token instead of taking a share of the value they help you create? Every prompt your team sends is revenue for them, whether or not it produces anything for you.

Almost nobody has thought through where that arrangement leads. Palantir follows the logic to its end. A provider that holds your operating knowledge can charge more for your highest-margin workflows, and in the most extreme case it can step into your market and, in the paper’s words, “completely replace you.” It’s already happening. As revenue pressure builds, model providers have begun competing directly with their own enterprise customers.

    Fifteen steps to IP “security.”

    The steps themselves are a defense-in-depth approach: zero data-retention agreements with every provider, model agnosticism so no single lab can hold your data hostage, granular permissions, audit logs, owned compute for the most sensitive work, and an ontology of your own knowledge under your control. Taken together, they describe how a serious institution builds walls around a technology it can’t see inside.

    Read closely, though, and the paper keeps conceding how much those walls depend on bargaining position. Zero data retention “must be negotiated with model providers,” and “negotiation requires both initial and continued leverage.” It must be renegotiated with each provider separately and held up over time against a counterparty with every incentive to erode it. The audit section is even more candid. A provider’s SOC 2 report “does not say anything about whether and how your data may have entered a training pipeline.” The reasoning tokens models display are “more user explainability theater than any genuine visibility into why a model reaches its final output.”

    That’s Palantir writing about the technology its own platform orchestrates.

    The most interesting concession comes in the paper’s final step. Institutional knowledge, it argues, must be captured in an ontology that exists “independently of the model intelligence layer.” If your only assets are prompts combined with hidden model weights, “the know-how is trapped inside this single model relationship rather than owned by your institution.” Models should be modular and swappable, treated as commodity intelligence. The knowledge layer is yours.

    Take things one step further.

    Follow that logic one step past where the paper stops, and you arrive at a question it never asks.

    If the closed model is the thing you need fifteen defenses against, why does your knowledge have to live inside one at all?

    Every step in the paper rests on the same assumption—institutional knowledge will live in, or pass through, systems whose inner workings nobody can inspect. And what can’t be seen can’t be verified, so every defense reduces to trust. You trust a retention clause to mean your data was never stored. You trust an audit report the provider itself commissioned. And you trust that a provider with every reason to use what it collects never will. Trust stacked on assumptions is a bad combination in business, and here it’s the entire foundation. The defenses are elaborate because what you’re defending is invisible.

    Another way to protect IP.

    But the assumption is a choice. Weights are one way to hold knowledge in a machine. There’s another: store it as concepts, the way a dictionary stores meanings, with each idea written down and connected to the ones it relates to. Knowledge stored that way is something you can look at. You can check what the system believes and correct it when it’s wrong. None of it asks for blind belief, because none of it is hidden.

    This is how Franklin Discovery™ by entigenlogic® works. Go back to the paper’s final step. Palantir says institutional knowledge should be captured in an ontology, an organized map of concepts, and that the map must exist outside the model itself, or else everything you know is trapped in a single vendor relationship. Franklin Discovery is built on exactly that map. entigenlogic spent roughly ten years constructing it, and your documents are read into it. What you get is a record of what your organization knows that you can open and read.

    Palantir says your data should never be used to train someone else’s model. Nothing you put into Franklin Discovery ever does. Palantir says every model interaction should be auditable. Every answer arrives with its source attached, so verifying one takes a glance rather than an audit. That’s the point. With Franklin Discovery, you don’t need the fifteen steps, because your data never leaves your control in the first place.

    The bigger question.

    Palantir’s paper will get filed as procurement guidance. It’s bigger than that. Where an institution’s knowledge lives, and in what form, is becoming one of the defining decisions of the decade, and it’s being made right now, mostly by default, workload by workload.

    For institutions that keep running their knowledge through closed models, the fifteen steps are the right playbook. But the paper’s own logic stops short of solving the real problem. Contracts and audits are what sovereignty costs when your knowledge flows where you can’t see it. Keep information in a form you can see and own, and there’s nothing left to negotiate.