ZillaAI

The position

Several lit channels converging on one bright junction in otherwise black terrain, seen from the air at night.

Most AI arrives as somebody else's service

The model lives elsewhere. Your data travels to it. The terms, the retention, the pricing and the deprecation schedule are all set by whoever owns the endpoint. For a great many organisations that is not a deployment option. It is a reason not to start.

So they don't start. Not because the technology doesn't work, but because the only shape it is offered in is one they cannot accept.

"Private" usually isn't, and "local" usually is a toy

Private AI, in practice, tends to mean being a tenant in somebody else's cloud with a stronger contract. Better, but the data still leaves, and the dependency is still total.

Local AI, in practice, tends to mean a chatbot on a workstation. Genuinely private, and not operations. It answers questions. It does not do work, carry responsibility, or leave a record anyone could audit afterwards.

Between those two there is a gap, and the gap is where most real work lives.

Capability is the easy half

The hard part was never getting a model to produce something. It is everything that has to be true before you can let it act: knowing what it did, on whose authority, and being able to show your reasoning to somebody who was not in the room.

That is not a feature. It is the difference between a demonstration and a system you can put your name to.

Authority is a process, not a size

There is an assumption that this kind of rigour belongs to large organisations, because only they can afford the committee. We think that has it backwards. Authority comes from a governed process, and a process can be small. What it cannot be is absent, or improvised each time, or dependent on somebody remembering.

A small organisation running a disciplined process is more trustworthy than a large one running none. Size is not the qualification. The process is.

What this site is for

This is where that thinking gets written down, in public, with dates on it. Not a product tour and not a status board - the arguments, the problems worth solving, and the principles we keep arriving back at.

A zero is not a calm

Silence is reported as a finding.

Most monitoring is built to read quiet as good news. That is the failure worth designing against, because the controls that hurt you when they stop are exactly the ones that stop without saying anything.

So every control declares the cadence it is supposed to keep, and is graded against its own promise rather than against a global threshold. A control that has never produced a single record is not healthy and is not broken — it was never wired, and that is its own status.

Not an illustration: A system that cannot tell you it is broken — the incident this describes, written up in full.

Read the third row again. Armed, unverified is the subtle one. That control may be working perfectly; nothing has happened that would make it act, so nothing proves it would. Showing it green would let an unverified control borrow the colour of a verified one, and that is how a system ends up reporting health it has not earned.

The first row is the one that matters most, and it is the easiest to miss. Nothing has ever been written there. It will never alarm on age, because age needs a first entry to count from.