Over the past six months, three of the most strategically consequential companies in enterprise infrastructure — Nvidia, Cisco and CrowdStrike — have each published their own AI safety playbook. The coverage has been respectful, bordering on reverent, treating these documents as evidence that the industry is finally maturing. I read the news differently. In 2017, I led a six-month audit of SWIFT's legacy messaging protocols against early Ethereum-based settlement layers in Geneva. I interviewed forty migrant workers in Zurich and documented how 35 percent of their remittances evaporated into hidden intermediary fees — not because anyone was malicious, but because every correspondent bank maintained its own compliance manual, its own security posture, its own idea of what a safe transfer looked like. The system was not broken by bad actors. It was broken by the seams between well-intentioned standards. When I see three companies building three separate playbooks for AI safety, I do not see initiative. I see the same seams being sewn back into a new fabric.

The broader context matters, because the companies themselves are not interchangeable. Nvidia builds the silicon beneath most of the world's frontier model training; its dominant position in accelerators means its safety assumptions become physical constraints for every model that trains on its hardware. Cisco owns the connective tissue through which model weights, training datasets and inference requests traverse enterprise networks; a compromise here is not a single-company event but a mass exfiltration event. CrowdStrike sits at the endpoint, ingesting a telemetry river of machine-executed decision-making and catching the moment autonomous agents begin to act beyond their declared permissions. Each company's vantage point is legitimate. Nvidia cares about alignment and weight theft. Cisco is haunted by the prospect of poisoned inference traffic moving laterally through infrastructure it once calmly defended. CrowdStrike watches software make legally consequential choices at machine speed, and its threat model has shifted from intrusion detection to intent uncertainty. Each playbook addresses real attack surfaces, and each is technically sound within its own domain. Yet the aggregate effect only resembles safety the way a pile of driftwood resembles a bridge. Adding a third independent playbook cannot remediate the absence of a shared foundation; it only adds another architectural voice to an argument with no arbiter.

The deeper problem surfaced during the 2020 DeFi Summer. I spent that season analyzing over 5,000 transactions inside Curve Finance's liquidity pools to understand stablecoin peg stability, and what I discovered was uncomfortable then, and more uncomfortable now: protocol after protocol had independently designed elaborate defense mechanisms, and all of them collapsed onto the same handful of vulnerabilities. Oracles were shared. Validators were concentrated. Audit firms were few. Externally, DeFi looked like a variegated ecosystem of competing approaches to the problem of trusted settlement. Internally, it was a monoculture wearing a diversity costume. When the liquidity freeze arrived in 2022 and approximately $40 billion in stablecoin liquidity evaporated from cross-border payment protocols within a matter of weeks, the withdrawal was not triggered by any single technical failure. It was triggered by the sudden recognition that trust had never been a protocol feature. It had always been a fragile social agreement disguised as code — and everyone realized it at the same time.

Corporate AI playbooks will replicate this trajectory if they remain orphaned from one another. Training data provenance, the single most urgent technical deficit in artificial intelligence, currently lacks credible attestation for roughly seventy percent of datasets. I flagged this repeatedly at the 2026 roundtable in Geneva where I facilitated discussions between EU regulators and AI developers on aligning decentralized compute markets with the transparency requirements of the EU AI Act. Nvidia's playbook cannot fix provenance. Cisco's playbook cannot fix provenance. CrowdStrike's playbook cannot fix provenance. They can describe the risk in sophisticated language, and they can each prescribe mitigations at their own layer, but none of them constitutes a shared substrate for external verification. No AI safety playbook that lacks an external enforcement mechanism can be described as a safety playbook at all — it is marketing with technical vocabulary.
There is a counterargument, and it deserves a fair hearing. Perhaps independent playbooks are the correct response to an uncertain environment: a portfolio of experiments, each generating data, each testing a distinct hypothesis. Perhaps the market should let the strongest safety practices win through competition rather than settling on a premature standard that cements yesterday's thinking. I have heard this logic applied to crypto's consensus mechanisms, and it sounds reasonable — until the moment the market actually fails. The uncomfortable truth about standards competition is that the market does not converge on the safest standard. It converges on the cheapest standard that can still pass regulatory inspection, because that is the standard which generates the highest short-term returns. The hollow resonance of digital ownership in art taught us this with devastating clarity: when ownership protocols competed in the NFT era, the most exploitable versions won, and ordinary collectors paid the difference in lost restitution and legal ambiguity. We are about to repeat that sequence with national infrastructure at stake, and the hollow resonance has grown louder at a scale no art market ever reached.
The decoupling thesis — that independent playbooks insulate each vendor from the other's failures — inverts under pressure. Suppose the first serious AI incident occurs. It will not occur neatly inside Nvidia's domain or Cisco's domain or CrowdStrike's domain. It will occur at the interface between two of them, in the gap where no playbook has authority. In every distributed system I have audited, the decisive vulnerability has never been the center. The seam between centers is the only geography that matters. This is true for cross-border payments, where regulatory disconnects between jurisdictions tax the poorest remitters most heavily. It will be true for artificial intelligence, because both are networks of trust, and trust is not a company-level property — it is a network-level property. In a crisis, fragmented playbooks do not distribute risk across the participating parties. They concentrate it into the ungoverned spaces each playbook disclaims.
So what would constitute an adequate response? Something with the verifiable truth function that zero-knowledge proofs were meant to supply to this sector: a way of proving that a model trained on declared data, that an incident was honestly disclosed, that a mitigation step actually executed. At the Geneva roundtable, the most substantive demand from the regulatory side was not for more sophisticated safety frameworks. It was for a minimum viable audit layer — interoperable, machine-readable, externally verifiable. None of the three vendors has yet delivered that. The vendor list is less interesting than the audit question. Whoever publishes a safety playbook tells us how they wish to be seen; whoever audits the playbooks tells us what actually protects the public. The company with the best playbook remains irrelevant if the market lacks a common measure of safety. We have been here before. We watched $40 billion disappear because trust turned out to be a social agreement dressed as code. We watched a generation of autonomy promises dissolve when the incentives stopped. The question I carry into my own work is direct: are we willing to build the verification layer first, to pursue verifiable truth in an increasingly opaque world — or will we again mistake coordinated documentation for actual coordination?