AI · Sovereignty · Institutional Design

The Trust Layer

What Europe Should Build Instead of a Frontier Lab

Julian Gretzinger  ·  July 15, 2026  ·  Substack

Abstract

The Compute Chokepoint series diagnosed a problem this essay now tries to answer. The series located the decisive constraint of the AI age in compute rather than code, showed that regulation can localize data but not the kill switch, and argued that the games actually open to Europe are diffusion and terms-setting, not the full-stack race it keeps pretending to run. This essay draws the conclusion the series stopped short of.

The scarce resource of the digital age is not capability — it is trust between parties who cannot trust each other, and the capability race destroys it faster than it can be produced. Europe's strategic move is to build the institution that supplies it: a member-governed, Swiss-domiciled trust layer running on European compute and anchored by the European market, with frontier AI inference as its first application and not its last.

Europe has three Swiss-hosted precedents for exactly this kind of institution. It has never needed a fourth more.

The scarce resource of the digital age is not capability — it is trust between parties who cannot trust each other. Europe is the only actor that can supply it.

#AI#compute#trust#Europe#Switzerland#sovereignty

I — The Conclusion the Diagnosis Was Pointing At

The Compute Chokepoint series ended each part with a narrowing of options. Europe cannot assemble the capital, silicon, and researcher density for a frontier lab on any relevant timescale. It cannot legislate the control plane onto its own territory: the Cloud and AI Development Act can grade sovereignty into assurance levels and localize the data, but the authority to withdraw model access remains attached to foreign companies under foreign law, and no procurement rule moves it. The games that remain — diffusion, terms-setting, physical-inputs arbitrage — are real and underplayed, but they share a limitation: they are all ways of living with a dependency, not ways of changing its nature.

There is a way of changing its nature. It requires noticing what the capability race produces besides capability.

II — What the Race Manufactures

Every month of frontier progress makes the technology more valuable and its access more political. Export restrictions on advanced models, national-security reviews, alliance-management compromises, vendor safety decisions taken continents away from the users they affect — the pattern is established and accelerating. The more powerful AI becomes, the more it is treated as a weapon, and the less anyone is willing to run their model on someone else's hardware, expose their data to someone else's jurisdiction, or accept anyone's self-certified assurance that a system does what it claims.

The capability race, in other words, manufactures distrust as a byproduct, at industrial scale — and not only between the two blocs. The most instructive moment of the past two years was not American pressure on an adversary but an ally's discovery of its own exposure: Microsoft's legal director in France telling the French Senate, under oath, that no contractual arrangement could guarantee French public-sector data in French data centers against US legal process. (French Senate, June 2025) Allies do not trust allies. Enterprises do not trust their providers. Regulators cannot verify what they license. The trust deficit of the digital age is not a rhetorical flourish; it is a measurable, widening gap between what parties must rely on and what they can verify.

Capability is abundant and concentrating. Trust is scarce and eroding. Strategy begins with noticing which of the two Europe is actually positioned to supply.

III — The Institution

The proposal is an institution, not a product: a trust layer for the digital age, with three properties fixed at charter and a first application chosen for maximum pain relief.

Member-governed, controlled by no one. The institution is owned and governed by its participants — states, and potentially the regulated private infrastructures that depend on it — under a charter that no single member, bloc, or host can amend alone. Its power derives precisely from the fact that nobody commands it: a verification issued by an institution its subjects control is worthless, and a settlement layer one government can switch off is a weapon in waiting.

Swiss-domiciled, for reasons of stock rather than sentiment. Credible neutrality cannot be declared; it has to be drawn from an accumulated stock, and Europe's stock of it is domiciled in Switzerland. This is not romance about Alpine virtue. It is an observation about existing institutions. The Bank for International Settlements demonstrates the governance property: central banks did not surrender authority to Basel — they co-founded a body none of them individually controls, and use it precisely because none of them controls it. (Toniolo, 2005) CERN demonstrates the shared-instrument property: a machine no member could afford alone, hosting researchers from states that are adversaries everywhere else, which produced the World Wide Web as a byproduct of solving its own collaboration problem. The ICRC demonstrates the hardest property of all: neutrality that active combatants rely on mid-conflict. No other jurisdiction hosts all three patterns. The trust layer needs all three at once — member governance, shared instrument, neutrality under fire — and the domicile follows from the requirement.

Running on European compute, anchored by the European market. Switzerland supplies the charter and the credibility; it cannot supply the physics or the leverage. The infrastructure — the data centers, the firm power, the network — sits in the EU, at the hydro, nuclear, and solar sites where compute belongs. And the enforcement mechanism is the European market: 450 million consumers and the world's most-copied regulatory template are what convert the institution's standards from suggestions into conditions. A verification regime nobody must pass is a website. A verification regime that gates access to the largest coordinated demand pool outside the two blocs is a standard.

There is a fourth element, less discussed than the other three and arguably the most durable. Europe's structured data estates — in health, industry, energy, and public administration — are the one asset class where the continent holds something the blocs cannot simply outspend it to acquire, because the asset is a function of universal health systems, deep industrial history, and administrative order rather than of capital or silicon. The European Health Data Space, legislated but not yet operational, is the first attempt to make such an estate usable at continental scale. (Regulation (EU) 2025/327) Governed correctly — federated, standardized, made available to models under terms that keep it under European legal control while letting it create value — this data becomes gravity. Capability travels to where the valuable data is governed; it does not wait for the data to be shipped to it. A trust layer with the data is a destination. A trust layer without it is a room that nobody has a reason to enter.

Governance in one jurisdiction, infrastructure in another, enforcement in a third mechanism — no leg of the tripod can capture the others.

The division is the design. The governance cannot seize the compute; the compute host cannot rewrite the charter; the market cannot override the neutrality. Distributed control is not an unfortunate compromise on the way to the institution. It is the institution.

IV — The First Application

Frontier AI inference is the beachhead, because it is where the trust deficit currently costs the most, and because the enabling technology has quietly become deployable.

Confidential computing — hardware-attested trusted execution environments, commercially available today on Intel, AMD, and ARM silicon — allows a frontier lab to load its model weights into an enclave on infrastructure it does not operate, where the operator can verify the enclave but cannot extract the weights, and users can query the model without the lab seeing who is asking or what. (Intel SGX; AMD SEV-SNP; ARM CCA) The weights leave home physically while never leaving the enclave logically. The lab keeps its crown jewel; the host keeps physical control; neither trusts the other, because the hardware and the charter carry the terms. Under the trust layer's governance, the arrangement acquires the property neither a national law nor a bilateral contract can supply: withdrawing access stops being a unilateral decision taken inside one company under one government, and becomes an institutional act under a charter that the withdrawing party co-signed.

Honesty about the limits belongs in the proposal, not in the rebuttals. The technology is not invulnerable — the side-channel literature against trusted execution environments is active, including physical attacks demonstrated against Intel SGX attestation as recently as last year, and any deployment is defense-in-depth, not a single-layer guarantee. (ACM CCS, 2025) The open-hardware exit from dependence on American chip attestation — RISC-V trusted execution — is a research ecosystem today, not a product, and remains five to seven years from production. (Keystone, EuroSys 2020; Orange Research, 2026)

There is a dependency beneath the dependency. Today's trusted execution environments are attested by firmware supplied by Intel, AMD, and ARM — all American companies, all subject to the same jurisdiction the trust layer is designed to insulate against. A European enclave whose guarantee of integrity rests on an American attestation root has not escaped the jurisdictional problem; it has moved it down one layer of the stack. The RISC-V path is the eventual exit, but "eventual" means the trust layer's first five to seven years operate with this dependency acknowledged, mitigated by defence-in-depth and multi-vendor attestation, and not denied. That is an honest engineering position. It is not the clean break the architecture promises at maturity, and a serious interlocutor will notice the gap immediately.

The deepest limit, however, is legal rather than technical: American export-control law attaches to entities and relationships, not to enclaves, which means a genuinely bloc-neutral institution serving both Washington's and Beijing's spheres would likely be classified out of existence on its first day. The trust layer's realistic scope, at birth, is the democratic world — the trusted ground on which allies protect themselves from each other's overreach, enterprises from their providers' discretion, and citizens from everyone's surveillance. That is a narrower claim than Switzerland-between-superpowers. It is also, on the evidence of the French Senate testimony, a market with no shortage of demand.

The contradiction should be stated rather than hidden: this essay invokes the BIS, CERN, and the ICRC as precedents, and those institutions derived their credibility from serving all parties, including adversaries. A trust layer scoped to the democratic world is not neutral in that sense — it is allied infrastructure with a neutral charter. The honest answer is that this is a phasing constraint, not a design choice. The charter should be written to admit wider participation as the legal landscape permits, because the institution's long-term credibility depends on the same universality that made its analogues credible. But at birth, export-control law draws the boundary, and pretending otherwise — designing as if the institution could serve Beijing on day one — would be the surest way to ensure it never opens at all. The tension between universal aspiration and democratic-club feasibility is real. It is also the tension every one of the cited analogues navigated: the BIS began as a European reparations mechanism and took decades to become global; CERN began as a Western European response to American and Soviet science and admitted non-aligned and Eastern Bloc members only later. Universality was the destination, not the founding condition.

V — Not the Last Application

The reason to charter an institution rather than launch a service is that the trust deficit is general, and the same machinery serves every domain where the bottleneck is trust between adversaries rather than capability.

Cross-border settlement of tokenized assets needs a finality layer no single central bank or depository controls — the fragmentation the IMF now warns about in formal scenario language is precisely a trust-layer vacancy. (Adrian, IMF, 2023; 2026) Competing firms need data clean rooms where pooled information trains a shared model without any contributor exposing raw data to another: fraud consortia, rare-disease research, supply-chain intelligence, all currently blocked by "I will not show you mine." Carbon markets, provenance claims, and model-safety certifications need an auditor whose judgment is credible because no interested party governs it. Cross-border digital identity needs a root of trust no single government owns. At the far edge, future agreements on AI capability itself will need what arms control has always needed — a verifier both sides accept — and confidential computing is the first technology that lets a party prove compliance without exposing the secret being verified.

Money was merely the first thing civilization needed a neutral layer for, which is why the Basel institution exists. Digitization is converting every high-value cross-border interaction into a who-controls-the-switch problem, and weaponized interdependence is teaching every participant that the switch can be thrown on them. The number of domains requiring neutral, verifiable, adversary-proof infrastructure is not stable. It is compounding.

VI — The Politics, Honestly

Nothing in this essay is technically blocked. All of it is politically blocked, and the blockages deserve naming.

The European Union does not currently want neutral infrastructure; it wants sovereign infrastructure it commands — the entire framing of its new cloud legislation is European control, not shared control. Member states with national champions will resist ceding the trust layer to a charter, and France will say so first. Switzerland's neutrality stock is itself depreciating — its adoption of EU sanctions in 2022 spent credibility with one side of the world that a trust institution would eventually want back. Swiss direct democracy can veto any treaty that reads as integration wearing a neutrality costume — and on 27 September 2026, Swiss voters will decide a popular initiative to constitutionalize "perpetual and armed" neutrality, a vote whose outcome will directly shape the feasibility of any new institution requiring international engagement. And the two parties' own history is the strongest counterargument: a decade spent failing to agree an institutional framework over far lower stakes.

The sharpest cautionary precedent is not a failure but a success that was later spent. SWIFT routed the world's interbank messages for four decades precisely because it was nobody's instrument — a Belgian cooperative, owned by its members, politically inert by charter, and therefore trusted by parties who trusted little else about one another. Its exclusion of Russian banks in 2022 was defensible on every ground except one: it demonstrated, to every state watching, that the neutral layer had an owner after all. The lesson is not that neutrality is worthless. It is the opposite — the weaponization worked precisely because SWIFT's neutrality had accumulated so much systemic power that revoking access was devastating. But the same act taught every future participant to price the possibility of revocation, and the search for alternatives to SWIFT dates from that week. Neutrality is not a static property conferred at founding. It is a discipline that has to survive exactly the pressure its own importance attracts, and it must therefore be bound into the charter deeply enough that no member — including the host, including a future European government that has changed its mind — can override it unilaterally. A trust layer that can be weaponized once will be trusted only until the day it is.

What changes this is what always changes it: a shock that converts "we want to command it" into "we need it to be trusted more than we need to command it." The founding members of every Swiss-hosted institution arrived by that road — the BIS out of reparations chaos, CERN out of a continent's scientific collapse, the ICRC out of a battlefield. The access cutoff that actually bites, the settlement freeze that strands a member state's assets, the AI incident nobody can independently verify: one of these arrives on every plausible timeline. The institution cannot be built in the week after. The architecture, the charter drafts, the enclave standards, and the coalition can all be built in the years before — which are now.

There is a plausible objection that the multilateral institution described here never arrives — that what actually happens is a proliferation of bilateral and small-club arrangements: France contracting directly with a specific lab for sovereign inference, a Nordic consortium pooling compute under a specific treaty, Japan and the EU signing mutual recognition for AI safety certification. These are already happening, and each one solves a real problem without requiring the institutional leap of faith a chartered trust layer demands. The question is whether they converge. The historical answer is that they do, because bilateral arrangements do not scale — each new pair requires its own negotiation, its own audit, its own legal basis — and clubs fragment, creating interoperability gaps that eventually cost more than the institution they were avoiding. The BIS did not replace bilateral central-bank relationships; it absorbed them, because the bilateral lattice became unmanageable. The trust layer may well begin as the coordination point for a set of bilateral arrangements that already exist, rather than as a replacement for them. That is a less dramatic founding story than a charter signed in Geneva. It is also a more likely one.

There is one more temptation to resist, and it is linguistic. The moment this project describes itself as a bloc, it becomes one, and invites the treatment blocs receive. The model is the opposite: boring, plumbing-grade, institutionally dull by design. The most powerful neutral infrastructures in history were invisible until the day someone tried to weaponize them — and their invisibility was the power.

The obvious tension: this essay frames the trust layer as Europe's strategic alternative to the frontier race, which is a visible, deliberate geopolitical choice — and then argues the institution must be invisible plumbing. Both cannot be true at the same time, unless the distinction is drawn precisely. The decision to build is visible; the institution that results is not. The BIS was founded by a geopolitical act — the Young Plan, the Hague Conference, a treaty — and the founding was as public as any event in interwar diplomacy. The institution that emerged has been boring for ninety-six years. Politicians take credit for the founding; the institution survives by ensuring no politician takes credit for its operations. That is the model: a celebrated strategic choice that produces an uncelebrated institution. The danger is not the announcement. It is the politician who, having announced, continues to treat the institution as a trophy rather than as plumbing. The charter's job is to make that politician irrelevant to the institution's governance from the day it opens.

The Fourth Institution

Europe has spent a decade measuring itself against a race it cannot win and does not need to. The blocs are building capability; capability is not scarce where it matters — it is merely withheld. What is scarce is the thing the race burns for fuel: the ability of parties who distrust each other to transact, verify, and rely. That resource has to be supplied by an institution that no participant controls, domiciled where neutrality has stock, running on infrastructure with real physics behind it, enforced by a market too large to ignore.

Europe is the only actor that can assemble all four elements — and only if it stops trying to be a competitor long enough to become the ground. It has built this institution three times before, in Basel and Geneva, each time after a catastrophe made the need undeniable. The fourth time, the need is already visible in sworn testimony and export ledgers. The honest prescription is not "build the institution now" — the political preconditions are not met, and the piece has said so. It is: draft the charter, publish the enclave standards, assemble the coalition of the willing among the member states and firms that already feel the pain, and run the first confidential-computing pilots under a provisional governance framework that can be upgraded to treaty status when the crisis arrives. Pre-positioning is not the same as founding, but it is the difference between standing up an institution in months and standing one up in years. The only question is whether the architecture is ready before the catastrophe or has to be improvised after it.

The model is not the prize. The trust is. Build the layer that carries it.

This essay builds on The Compute Chokepoint series (Parts I–IV), which diagnosed the market structure, bloc formation, regulatory limits, and strategic options this proposal responds to. The views expressed are the analytical position of the author in a personal capacity and do not constitute investment, legal, or policy advice.

Sources

Julian Gretzinger

Investor and writer on monetary history, real wealth mechanics, and financial markets. substack.com/@juliangretzinger