the category · measured compute, now for AI

Measured AI

AI whose every output ships with a signed record of exactly how it was produced — who asked, which model answered, on what hardware, from what materials — so trust becomes a decision you make on evidence, not a promise you accept on faith.

Everyone else asks you to trust the box. We measure the manufacture and sign the receipt.

The trusted-computing world never actually trusted anything. The TPM measured — took a hash — and signed the measurement. Trust was a separate policy decision made on top of the evidence. Measured AI applies that one primitive to AI: we don’t assert a model is safe, aligned, or trustworthy — we measure how each answer was manufactured and sign the measurement. Whether to trust the answer is then your call, made against real evidence instead of a vendor’s word.

Not “trusted AI.” Not “safe AI.” Not “confidential AI.” Measured AI. The confidential-computing camp powers on measurement only to unlock a secret, then throws it away — because they only wanted privacy. We keep the measurement, sign it, and bind it to the output. Retained-and-signed measurement is message integrity — the durable, portable receipt regulated and defense buyers are actually asking for.

Measurement is a level, never a boolean

The fatal error in every “trust” pitch is the green-checkmark lie — verified ✓ as if it were binary. Measurement has depth, and we state it honestly on every proof. A weak measurement is not a fake measurement: weak-but-real beats strong-but-asserted. The level is the product ladder and the pricing ladder at the same time.

LevelWhat is measuredStatus
L0Nothing signed — today’s default AI. No receipt, no recourse.baseline
L1Attested transport — the prompt is signed at the source, the output is signed, and the two are cryptographically bound into an ownable data wallet.Live today
L2GPU attests the loaded weights — real hardware TEE (Intel TDX / AMD SEV-SNP + NVIDIA CC) proves which model actually ran.pilot
L3Measured weights bound to a declared corporate identity, anchored on-chain — the exact model, from a named owner who stands behind it.pilot
L4Fleet of signed receipts → backward traceability, forward recall, and statistical process control. A manufacturing quality system for knowledge.enterprise

Adopt at L1 today; deepen for assurance. Each rung is a licensable product — the full ladder lives at measured.rootz.global.

What gets measured — the manufacturing record

Prompt → output, through a known plant, from known raw materials. Complete provenance is bilateral — and the half everyone else skips is the work order, which is where ownership comes from.

Work order
Signed intent
The prompt + terms, signed by the customer’s key. The demand side nobody else measures — the root of title.
Plant · iron
Attested hardware
CPU + GPU in confidential mode, hardware-attested. Genuine silicon, genuine fabric.
Plant · code
Measured stack
The inference stack measured to an auditable build. Known code, no silent drift.
Raw materials
Declared model
The exact weights, bound to a declared corporate identity — anchored, reputational.
Title
Bound output
One signed receipt ties {plant, materials, work order, output} together — authenticity and ownership.

It all collapses to one atom: a signed manifest of hashes — an SBOM + shipping manifest for every AI message. See the manifest demo →

Why “measured” wins

It’s honest — it promises evidence, not virtue, so it survives contact with a skeptic and a regulator. It’s a category the incumbents can’t claim — “confidential / safe / trusted AI” all assert an outcome; measured describes a method, and their method throws the measurement away.

It has a 25-year sworn pedigree — TCG / TPM is measured computing (Wave Systems, Rivetz). This is not a new buzzword; it is a standardized discipline, extended to the ownership of AI output. Patent US 2025/0112783 A1.

Verify it, don’t take our word

The L1 primitive is live and breakable right now — sign a prompt, get a signed answer bound to it, then hit Tamper and watch the proof turn red:

Proof of Origin (humans↔AI) →  ·  Signed Manifest (context custody) →  ·  Signed MCP (AI↔services) →

Standards this aligns to: Five Eyes “Careful Adoption of Agentic AI Services” · NSA MCP Security notice · requirement-by-requirement map →