A crypto founder telling you that AI should be a decentralised public good is easy to wave off. The pitch usually arrives attached to a token. But underneath this particular pitch sits a question that belongs on every operator's desk, whatever you make of the blockchain wrapper: who can verify what your AI actually did, and who owns the infrastructure it runs on.

The pitch comes from Jake Salerno, VP of go-to-market at 0G Labs, in an interview at EthCC. 0G is building what he calls "the world's first decentralised AI operating system." Take the product framing with the scepticism any vendor interview deserves. Keep the framing of the problem, because that part is sound.

The argument

Salerno's case is blunt. "Companies control the compute, and your data goes straight to their servers. You have to trust their privacy policy and hope they protect your data." His answer is verification: "We make AI a public good through strict verification. Decentralisation relies on verification to work effectively." His conference keynote was titled "Why Verification Should Be a First-Class Citizen in AI."

Stripped of branding, the substance reduces to three trust questions, and they are good ones:

  • Did the model compute what it claims? 0G's answer is "sealed inference" running inside trusted execution environments, hardware that attests to what actually ran.
  • Who is this agent? Their "Agentic ID" proposes a verifiable identity and passport for autonomous agents, so something acting on your behalf can prove it is what it says.
  • How was the model trained? Their answer is DiLoCoX, a 107-billion-parameter model trained across a decentralised cluster, with a paper from June 2025.
The main concern with centralisation is who has the authority to verify what happens on those servers.

The half that is genuinely right

Strip the token economics away and the concentration worry is not crypto marketing, it is close to the consensus view of competition regulators. A handful of firms control the frontier models, the cloud they run on, and the scarce accelerators underneath. When you call a model API, your prompt and your data do go to someone else's servers, and your only assurance is a policy document and a logo. For a regulated business, "trust our privacy policy" is not a control. It is the absence of one.

The verification framing is the useful export here. Can we prove what our AI computed, prove which agent acted, and prove how the model was built. Those are questions you can ask today, of any vendor, without owning a single token. Most centralised providers cannot fully answer them yet, and that gap is real. Naming it clearly is worth something, wherever the naming comes from.

The half that is still a pitch

Now the scepticism the interview does not volunteer.

"0G relies on hardware verification via trusted execution environments to entirely eliminate the need for trust," Salerno says. It does not. A trusted execution environment moves your trust from the cloud operator to the chip vendor and its firmware, and these enclaves have a long history of being broken by side-channel attacks. "Eliminate trust" is the kind of absolute claim that should make a buyer slow down, not speed up. He contrasts 0G with Bittensor, which "depends on economic incentives to keep participants honest," and argues silicon proof is stronger. Perhaps, but both are still betting that a verification primitive can stand in for an institution you can actually hold to account.

The democratisation story has texture too. 0G's flagship model was trained, by independent accounts, in partnership with China Mobile, a state-owned telecom, on the export-limited A800 GPUs Nvidia built for the Chinese market. That can be real engineering and still sit awkwardly next to the words "self-sovereign" and "public good." And decentralised training of a 100-billion-parameter model, a genuine milestone built on earlier DeepMind research, is still well short of the frontier systems your competitors actually deploy. "First mover by nine months" is a marketing line, not a moat.

So read the roadmap of weekly product launches and 350-plus integrations as what it is: momentum signals from a company that needs them, not evidence that enterprise AI moves onchain this year.

What an operator should actually do

You probably will not move your stack onto a decentralised AI operating system this quarter. You can still act on the legitimate part today. Put the three trust questions to your existing, centralised vendors, in writing, as procurement and governance requirements:

  • Computation. Can you attest, ideally in hardware, that the model and version we paid for served our request, and that our data was neither retained nor trained on?
  • Identity. When an agent acts on our behalf across systems, how is its identity and authority verified, scoped, and revoked?
  • Provenance. What can you tell us about how this model was trained and what went into it, and what are we contractually owed if that turns out to be wrong?

What we tell clients at AvantiGroup.AI

Take the problem seriously and the salesman with a pinch of salt. Concentration of AI compute, models and data is a genuine strategic risk, and verifiability is turning into a real procurement axis rather than a philosophical one. Whether your answer ends up being decentralised infrastructure, confidential computing from the cloud you already use, or simply harder contracts, the first move is the same: stop accepting "trust us" as an architecture.

The crypto industry will keep offering to sell you the radical version, token included. You do not have to buy it to take the question it is built on seriously. Ask your vendors who can verify what your AI just did. If the honest answer is no one, that is the finding, whoever you first heard the question from.