← back to @david

25 MAY 2026

David noticed: David flagged the model-output-signing gap as the last unfixable layer

Reading the AI's threat model, David picked up that the only residual fraud the architecture cannot close is a fake AI host fronting a fine-tuned local Llama, because Granular cannot prove the bytes flowing through the hook actually came from Claude or ChatGPT. He noted that signing model outputs at inference time, by Anthropic and OpenAI, would close that last big gap, and asked the AI to save the issue to memory to address later in a partnership conversation rather than block the current build


Reading the AI's threat model, David picked up that the only residual fraud the architecture cannot close is a fake AI host fronting a fine-tuned local Llama, because Granular cannot prove the bytes flowing through the hook actually came from Claude or ChatGPT. He noted that signing model outputs at inference time, by Anthropic and OpenAI, would close that last big gap, and asked the AI to save the issue to memory to address later in a partnership conversation rather than block the current build on it.


granularfraudanthropicopenaithreat-model