Button TextButton Text
Download the asset
Back
Article

A Conversation with David Bray: Trust, Sovereignty, and a World Full of Agents

A man and woman in office chairs talking while the woman holds a notebook and pen.A Conversation with David Bray: Trust, Sovereignty, and a World Full of Agents

As AI regulation shifts across states and nations, and as autonomous agents move from theory into everyday reality, one question keeps surfacing: who is actually in control? We sat down with Singularity faculty member Dr. David Bray to find out.

David brings a rare vantage point. He is CEO of LeadDoAdapt Ventures, chairs the Loomis Accelerator at the Stimson Center, and led the CDC's bioterrorism response through 9/11. Today he advises governments and Fortune 500 leaders on AI and space.

In this conversation, he unpacks what AI sovereignty really means, why leaders should verify before they trust, and the governance we'll wish we had built in 2026. We started with the most basic question of all.

SU: There are a lot of different understandings of AI sovereignty out there. What does it mean in your view?

DB: If we go to the textbook definition, sovereign means absolute rule by a king or queen. That is clearly not what people mean when they use the word now. The evolving definition is closer to this: Within whatever boundaries I have, am I able to shape things without being externally dependent on someone else?

That takes you straight to trust. One definition I find useful is that trust is the willingness to be vulnerable to the actions of an actor you cannot directly control. We all have those actors in our lives. Governments. Corporations. The decisions of certain CEOs.

So when you look at the geopolitics of AI, you have nations asking whether they can continue to carry out the rule of law inside their own borders without depending on the decisions of another nation, or a company headquartered outside those borders.

You are also seeing people use the word about organizations, which is an interesting stretch. What they mean is the same thing. You may not build your own AI, but you are now dependent on AI. So how do you keep operating, especially if you work across countries with different legal requirements?

SU: When people talk about AI sovereignty, what exactly is being made sovereign? The chips, the data centers, the models, the data, or the rules?

DB: In an ideal world, nations and large organizations would have sovereignty all the way up the stack. There are at least three layers.

The foundational layer is whether you have control and confidence in the infrastructure and the electricity your AI depends on. Most companies do not produce their own power. And while you may have fiber inside your country, the beauty of the internet, great firewall exceptions aside, is that it connects everybody. Which also means an actor half a world away can reach you.

The next layer is data, and I would include identity in that. Generative AI is very good at appearing human. There are estimates that by 2027, in the United States, one in four job applicants will not actually exist. Some of that is foreign actors trying to get inside your company. Some of it is ordinary people hiring someone else to sit the Zoom interview using a different face. They ace the questions, and the person who shows up on day one is not the person you interviewed. So can you trust the identities inside your company, and can you trust that your customers are real?

The top layer is the AI and the algorithms, and there are plenty of players there. Large US companies. Mistral in France. Open weight alternatives coming out of China. I am not sure anyone is winning at that layer.

SU: Is the hardware layer as solid as most people assume?

DB: I can share this publicly. About four years ago I got a call connected to work tied to the US Department of Defense. A company had won a competition to produce a nondestructive way of verifying that hardware really was what it claimed to be and nothing else. As a prize they were given two routers that had been in use for more than ten years in underwater nuclear environments operated by the US government. Those routers had occasionally run hot. They had been shipped back to the vendor several times, and the vendor said everything was fine.

The company ran their scan and said, "we are not getting a good score, do we have permission to open the box?" They did. Within four hours they found foreign chips attempting to phone home to another country.

You might call that a one off, or say the military was specifically targeted. So they were then given access to a US military warehouse holding 499 pieces of kit, all ostensibly from US vendors. The failure rate was 53%.

That was 2022. And recently the UK Navy found that some of the naval drones they use were attempting to ping home to that same country of 1.3 billion people, though I am *sure* they were only backing up the data as a service and nothing else untoward.

Until recently, most companies, let alone countries, never thought they had to verify that the chips were really the chips and nothing else. So when we talk about AI sovereignty, I hope people are asking what they do to verify before they trust. It is the reverse of what President Reagan said: We should first verify, then trust. Especially as we build these data centers, because the last thing you want is your most important data and your AI sitting inside a facility that was compromised from the start.

SU: Should leaders treat sovereign AI as a genuine strategic doctrine, or a procurement narrative?

DB: First, we are usually talking about generative AI, which is only one flavor of AI. There are others including Rule based systems and Computer vision, which might be poorly trained but are not going to hallucinate predictions.

With generative AI, leaders should at minimum know what it is good at and what it is not. It should not be sold to replace your humans with AI. I understand why some people pitch that. Some repetitive roles could be done by an AI. But most of us are fortunate enough to be moving up the stack toward more novel work, where you need judgment about what is good and what is valid, because the world may have changed and new judgment has to be applied.

So it is a tool that amplifies what your citizens or your employees can already do. Most people will use it well. But if you are a nation, you should not be surprised that a technology that is good at producing realistic human output gets used for fraud at scale.

I took part in an exercise about three years ago. Using ten minutes of compute using a flavor of WormGPT, a dark web tool I would not recommend anyone use, plus some plugins, you could generate a million realistic chest x-rays and physician notes supporting reimbursement claims for an upper respiratory infection at $250 each. The harder part is at that time, it cost more for Medicare in the U.S. to adjudicate whether a claim was real than to simply pay it. Submit even half of them across November and December and you walk away with $125 million.

So for a nation, AI can simultaneously enhance the productivity of your citizens and challenge your ability to carry out the rule of law and defend yourself, both in parallel. For a company, it is a chance to empower employees and deepen customer relationships, while also being used to undermine your cybersecurity, your reputation, or, in more benevolent terms, to let a competitor eat your lunch.

SU: You testified before Congress last year. Where is Washington getting this right, and where is it dangerously wrong?

DB: For some mysterious reason, when they wrote the Constitution, the founding fathers forgot to mention who gets to regulate AI. So by default it is a state right.

For this reason, as well as the challenges of building any consensus in our polarized times, we have not seen much federal legislation. We have seen executive orders from multiple presidents, but those are executive orders vs. literal “Acts of Congress”. Meanwhile there are more than 1,200 pieces of passed or draft AI legislation across the fifty states, which means, only half joking, that we are going to need AI to navigate AI policy at the state level.

All politics is local. If we tried a single umbrella policy tomorrow, what works for Colorado will not work for Alabama and will not work for New Hampshire. So what I recommended in my testimony was something different. We already have sector specific laws. Healthcare. Banking. Commerce. Defense. Go through them and ask where the speed and scale of generative AI breaks them, then upgrade those laws, rather than writing new AI policy from scratch.

I worry about attempting to craft “one ring” in terms of AI policy to rule them all. A single AI policy over everything will strangle innovation and the things that make individual communities and individual companies distinct. And the honest difficulty is that AI policy has to answer two questions first: which flavor of AI is being employed as they have different risks, and in what context, as this also informs the policies. Generative AI recommending what I might want to buy online is one risk calculus. Generative AI making decisions about my healthcare, or on a battlefield, is another entirely.

If the federal level cannot get traction on AI policy, then what I would like to see is ten or twelve states, deliberately from both sides of the aisle, reaching consensus on a bare minimum. That can effectively become federal policy by bubbling up.

One thing worth watching. California borrowed from what Europe did with GDPR and said you must treat a Californian digitally as a Californian, whether they are in New York or overseas. Nobody has really tested it. Yet I do joke with both my European and my Californian colleagues, are you trying to accelerate the end of sovereignty-defined-by-geography? Because that is what you have just done with these extraterritorial policies.

SU: Five years out, what is the thing we will wish we had built the governance for in 2026?

DB: Within about two years there will be at least ten times as many digital agents on the planet as there are humans. That points somewhere unfamiliar for the human species on Earth. We’ll need better ways to navigate a world awash with agents producing, consuming, and interpreting information. 

One approach involves an existing IEEE protocol, the hyperspatial transport protocol, that lets you bound things by space and time. You could say, here is my one meter bubble, and here is what I consent to happening to my physical persona and my digital one. You can collect my biometrics, or you cannot, or you can because I am at an airport. It can be conditional.

I would not call that a social contract. I would call it choice architecture between individuals and providers of community or company-based services. For example: If you want to board this flight, you can choose to share limited information and go through the additional screening line, share more information and thus do rapid boarding, or if you choose to share no information you cannot board. Several European countries already do a version of this with individual taxes. Share your data and we will tell you what we think you owe and you can correct us. I’d like to see something similar where folks can pick that path or choose not to share information upfront, and thus file manually.

That is sovereignty at the level of one. If everyone has that capability, it is genuinely good. However if only a few do, it is dangerous because there are missing checks-and-balances given the scarcity. In my opinion, the most dangerous stretch will be “the power law” period, when a small number of actors hold significantly outsized sovereignty relative to everybody else, because that reliably ends in power grabs by the few.

Which is why we should be moving faster to distribute the ability to do AI in ways that are privacy-preserving, less energy-intensive, and supportive of individual human choice and agency. You should be able to run it locally if you want. You should be able to use federated learning approaches, where the algorithm comes to you and learns from your data with your permission without taking your data sets away.

It is worth remembering that sovereignty by geography, the Treaty of Westphalia, arrived roughly two hundred years after the printing press. It would be a mistake to assume the internet, smartphones and generative AI together will not call us toward a new way of organizing as humans locally, regionally, and globally. I would rather we choose the future by building and co-creating it today because otherwise you can imagine worse versions of the future. For example: social media is almost perfectly designed to produce a kind of neo feudalism, lords and ladies with their vassals and the rest of us as serfs. You can also imagine someone arguing that the world is dangerous and your job is at risk, so accept total surveillance and we will keep you safe and employed. People will sell that. I do not want either because they end up with a net loss of choice and agency for most people.

And here is the statistic that makes both governments and corporate boards sit up. By 2030, more than 40% of the data on the face of the planet will have been produced by AI. So how do you make decisions at a corporate level, let alone carry out the rule of law at a national one, if you cannot be sure the data underneath the decision is legitimate and not synthetically produced to make you think and act differently than you would if you had better, high-quality data?

‍

Singularity

Singularity's team of internal thought leadership works to develop interesting resources, articles and insights about our core areas of expertise, programs and global community.

Unlock Access