The Industry Wants a Write-Path Gate. Most Vendors Sell a PDF.
How PrimeSwarm compares to the organisations and systems the market already shortlists
A competitive white paper for general counsel, CISOs, CIOs, and boards comparing PrimeSwarm to the organisations and systems the market already shortlists.
Only Institute · PrimeSwarm · TPNN · DGV
10 September 2026
Companion papers: We Sit in Front of the Model You Already Have — keep the model you rent, bought, or run locally. Two Keys, Not a Cliché — SOC 2, ISO/IEC 42001, and the dictionary that replaces marketing adjectives with controls.
Related offer: When AI Touches the Record
House line. Statistical AI guesses. We sit in front of the write and leave a receipt.
This paper is a comparison, not a certificate. Deployment claims stay scoped to a signed SOW. DGV badges are claimed only against named cards and versions. We do not print SOC 2, ISO 42001, FedRAMP, FDA, or HIPAA as product claims. Tenant catalog and live/ready remain stubs until a swarm is actually live. HITL on send and file is live as of 11 September 2026 — see The HITL Contract. We hold ourselves to the same rule we hold incumbents to in an RFP.
Abstract
Buyers, analysts, and regulators in 2026 are asking for the same object: semantics, live operational state, and provenance — with a human who can override, and a log that reconstructs the hop. That object is a write-path gate.
The market does not sell it as one product. It sells three RFPs that got collapsed onto one slide:
- A governance programme of record (Credo AI, IBM watsonx.governance, Holistic AI).
- Runtime enforcement on agents, Copilots, and MCP (Zenity, Pillar, Speakeasy, Kosmoy, NVIDIA NeMo).
- An ontology plus operations layer (Palantir AIP).
Agent frameworks (LangGraph, CrewAI, Microsoft Agent Framework, Google ADK, OpenAI Agents) typically cover three of the twelve capabilities a GC will ask for in diligence. We architect all twelve. Some of those twelve are not live on a tenant until a swarm is stood up. This paper names both facts in the same breath.
Best organisations win programmes, models, and ontology. We should win the write. Until the workbench, the auditor letter, and the AAIF handshake are live, we lead on architecture and lag on the keys procurement already knows how to buy.
1. What the market is actually buying
Three buyer situations dominate 2026 evaluations. They are not rivals so much as jobs. Mixing them is how a vendor looks “enterprise” and still leaves an uninsured write into the record.
| Job the buyer hires | Who wins the shortlist | What they actually do | What they do not do |
|---|---|---|---|
| Programme of record | IBM watsonx.governance (Gartner Magic Quadrant Leader, June 2026); Credo AI (Forrester Wave Leader, Q3 2025; Gartner Visionary, June 2026); Holistic AI; OneTrust | Inventory, Policy Packs, EU AI Act / ISO 42001 / NIST AI RMF mapping. IBM: OpenPages + SR 11-7 heritage, FedRAMP Moderate (April 2026), air-gap on OpenShift. IBM resells Credo Policy Packs. | Sit in the request path. Credo’s own mid-2026 note still placed runtime enforcement on a roadmap. |
| Runtime / in-line control | Speakeasy, Kosmoy, Runlayer / MintMCP, TrueFoundry; security names Zenity, Pillar, Harmonic; rails NVIDIA NeMo, Bedrock Guardrails, Azure Content Safety, Lakera | Inspect or block traffic: prompts, Copilot, MCP, jailbreaks, PII classifiers. Closest architectural cousins to us. | Split act from believe. Lock a basket on residual 0.0. Quarantine a foreign GREEN. Exam a binary with hashed fail-the-cheat cards. |
| Ontology + operations | Palantir AIP + Foundry | Semantic objects, access control, federal and commercial operators, actual installs. | Treat a fact arriving from another swarm as un-admitted. Change what topology the model is allowed to know. |
| Agent runtime | LangGraph, CrewAI, Microsoft, Google ADK, OpenAI Agents | Graphs, tools, memory, developer mindshare. | Authority. Typical coverage: 3 / 12. |
| Eval / traces | Patronus, Galileo, Arize, LangSmith, Fiddler | Score answers after the fact. Useful for model-risk reports. | Block the tool call. |
| Protocols | MCP + A2A under Linux Foundation AAIF (A2A joined ~20 August 2026) | Industry plumbing. Packets move. | A handshake. Ungated A2A is TCP without TLS. |
Do not pick a fight with IBM or Palantir. A bank that already runs OpenPages will not rip it out for DGV. A ministry that already runs Foundry will not rip it out for a node map. The close is: their GREEN in watsonx is still a score. Our ADMITTED is a write that survived the gate. Their ontology object is still last-write-wins unless we quarantine.
We are in the in-line control category. We win on the twelve rows, residual 0.0, and their GREEN is not our ADMITTED — not on “we also have a gateway.”
2. Spoken demand — research and public points
These are the sentences already in board packs. We did not invent them. We sit in front of the write they describe.
| Voice | What they said | What it means here |
|---|---|---|
| Gartner context layer, 2026 | AI context = semantics + operational state + provenance. Do not wrap governance on at the end. A large majority of respondents say data-governance tools are how AI governance becomes operational. | The node map, the ledger, and the PRE/POST hash are that layer. Do not sell a chatbot. |
| EU AI Act Art. 14 / 12 / 73 | Human oversight, logs, serious-incident reconstructability. The Digital Omnibus moved some high-risk dates toward December 2027 / August 2028. Boards are designing now. | HITL is a YELLOW queue with a proof id. A prompt that says “ask a human” is not Article 14. |
| Linux Foundation AAIF | MCP (agent↔tools) and Google A2A (agent↔agent) both live under AAIF. Industry will buy “we speak A2A.” | Speak the protocol. Refuse the hop without identity, capability, TPNN strip, PRE/POST. Looking anti-standard loses the platform team. |
| Forrester / Gartner 2025–26 | Credo and IBM own the programme RFP. Credo put runtime on the roadmap. | That hole is the product. Partner with GRC. |
| Kovrr 2026 buyer split | Programme vs runtime vs unified telemetry. | Do not pretend we replace OpenPages. We replace the ungated write. |
| Charlotin tracker, 5 September 2026 | 2,022 tribunal findings of hallucinated material; 805 involve a lawyer; 1,677 fabricated authorities. United States v. Heppner (S.D.N.Y., February 2026): a consumer-AI hop can destroy privilege. | Their agent in the loop is how those numbers enter your letterhead. |
| Access-control talking points, 2025–26 | Repeated claim: the large majority of AI-related breaches lacked access controls on the agent/tool path. | Missing agent_id is RED before the tool runs. |
What a GC or CISO will ask
Can you prove what the agent saw, what it was allowed to do, and what it actually did — including when the other corporation’s swarm was on the wire?
If the answer is a dashboard screenshot, they already have Credo. If the answer is a hashed receipt on the write, they do not.
What a platform team will ask
Do you speak MCP and A2A? Can we keep LangGraph / Copilot / Bedrock? Is this Helm, and does it fail closed if the catalog is missing?
Yes to sit-in-front. No to “rip out the model.” Yes to fail-closed secrets. Gated A2A, not anti-interop theatre.
3. Twelve versus three
No mainstream agent framework we measure offers more than three of the twelve capabilities a GC or CISO will actually ask for. The table is the appendix you put in the RFP. Ask them to tick theirs.
Counts below are an honest scoring of public product surface against the twelve rows in the critical-industries offer, not a vendor scorecard they would sign. Scored 10 September 2026.
| Stack | Of 12 (honest) |
|---|---|
| LangGraph / CrewAI class | 3 |
| NVIDIA NeMo / Bedrock / Azure rails | 4 |
| Credo / IBM GRC | 2 |
| Palantir AIP | 5 |
| Speakeasy / Kosmoy class | 6 |
| PrimeSwarm, claimed architecture | 12 |
| PrimeSwarm, live on a tenant today | 8 |
Do not claim 12/12 live on a tenant that has not stood a swarm up. Claim the architecture, then name the stubs.
| # | Capability | Typical agent stack | GRC (Credo / IBM) | Rails (NeMo / cloud) | Us |
|---|---|---|---|---|---|
| 1 | Streaming with PII per chunk | No | No | Partial (PII detect) | Yes — TPNN on the wire |
| 2 | Sessions with retention / decay | External store | Inventory only | No | Designed; operate per tenant |
| 3 | PII / PHI sanitization | Rare | No | Yes (classifiers) | Yes — L0 to the model, L2 to the human |
| 4 | Injection defense + SIEM | Plugin | No | Yes (jailbreak) | Yes — plus SIEM forward |
| 5 | Fairness gate that can block | No | Eval report | No | Topology demonstration — not a lending engine |
| 6 | Cryptographic receipts | Prompt log | Factsheet | No | Helix SHA-256 / PRE-POST |
| 7 | SIEM (Splunk / Datadog) | Enterprise add-on | GRC export | Cloud-native logs | Designed; wire per install |
| 8 | Zero-trust JWT + RBAC | API key | SSO to the GRC app | IAM on the model | Capability on every call |
| 9 | Hardened, capability-gated sandbox | Bare Docker | No | Tool rails (NeMo) | execute:sandbox or it does not run |
| 10 | A2A with strip + handshake | Direct JSON / open A2A | No | No | Gated A2A — must still speak AAIF |
| 11 | Declarative agent catalog | Hidden in code | System inventory | No | YAML catalog — stub until live swarm |
| 12 | Hashed independent exam | Policy Packs / ISO mapping | No | 89-card DGV — first-party, not a notified body |
4. Where we lead the best of class
Lead means: a serious organisation cannot buy this object from NVIDIA, IBM, Palantir, or LangChain today. Not “we have more features.”
Act is not believe. GREEN on a tool call is not ADMITTED on a fact. Same identity, different title — quarantine, not last-write-wins. No GRC platform, no guardrail library, and no Palantir ontology ships this split as two permissions with two proofs. Foreign GREEN is not our ADMITTED. That sentence is the Federation product.
In the write, not after it. IBM and Credo win the programme RFP and still do not sit in the request. NeMo filters the prompt. Patronus scores the answer. We refuse undeclared write, missing agent_id, and sandbox without execute:sandbox before the side effect exists. Closest cousins do in-line enforcement without PIR residual, TPNN L0/L2, or a 89-card hashed exam.
Residual 0.0 is a lock, not a vibe. Only OS / PIR treats arithmetic equilibrium as the pass condition for the signed basket. Model confidence is not that number. Honest limit: residual 0.0 is not Reality. Unsigned or missing fields can sit at 0.0 while the world moved. Correspondence to the live record is a different claim. We will not collapse them.
The model never sees the chart. TPNN strips to L0 for the agent and keeps L2 for the clinician or solicitor. Bedrock Guardrails redact strings. We change what topology the model is allowed to know. Palantir access control still wants the object in the ontology.
Exam with teeth. DGV is 89 cards, including nine designed to fail a cheating system, with SHA-256 settlement. IBM Factsheets and Credo Policy Packs map controls to law. They do not fail your binary on “HITL cannot be bypassed.” We must never call this a notified-body certificate.
The door is the map, not the agent. Node Exposure Assessment names cognitive, record, identity, external, execution, memory, and human nodes before anything is turned on. LangGraph starts with a graph. Palantir starts with an ontology you already bought. We start with ungated writes. That picture is usually the close.
5. Where we lag — and what “improved” looks like
Best organisations beat us on trust theatre we have not earned yet. IBM has FedRAMP Moderate, OpenPages, and air-gap. Palantir has federal installs. NVIDIA has every platform team’s email. LangGraph has the developers. We have the better object and almost none of the procurement keys.
The letters themselves are the subject of the companion paper. The rest of the list is product and distribution.
| Priority | Gap | Why it loses deals | What improved looks like |
|---|---|---|---|
| P0 | No auditor letter for SOC 2 or ISO 42001 | The questionnaire dies before the twelve-row table is read. | Type I on hosted Guard. AIMS scoped to the gate, not the lab. See companion paper. |
| P0 | Tenant catalog and live/ready still stubs until a live swarm. HITL send/file is live as of 11 September 2026. | A GC who logs in and sees a laboratory will not believe Art. 14. | One design-partner swarm. Screenshot of a YELLOW resume with two names on the receipt. See The HITL Contract. |
| P0 | Public site still sells the laboratory | Industry demand is write-path governance. | Public narrative = node map, act vs believe, /quote. Lab stays for researchers. |
| P1 | Ungated-A2A refusal without a first-class AAIF handshake | Platform teams hear “we don’t do A2A” and pick Google. | Gated A2A that speaks AAIF messages + identity, TPNN, PRE/POST. Demo two named entities. |
| P1 | DGV is a first-party exam | “Certified” in our mouth sounds like their Factsheet until a third party signs. | Keep the honesty line. One external lab or design-partner attestation on a named card set. |
| P1 | Fairness gate is a topology demonstration | A lender will ask for SR 11-7-grade model risk. IBM already owns that sentence. | Do not sell Four-Fifths as a credit engine. Complement OpenPages. |
| P2 | Distribution and integrator channel | NeMo is a pip install. Bedrock is a checkbox. Palantir has SIs. | Helm + MCP allowlist in front of LangGraph. One SI playbook. Do not build a new runtime. |
| P2 | Marketplace $49 / $499 unlinked from Guard / Estate / Federation | Confused SKU kills the motion. | One funnel: assessment → SKU. Tokens always customer-paid. Marketplace is not PrimeSwarm. |
Do not try to beat them on token throughput (NVIDIA), model-risk heritage (IBM / SR 11-7), federal ontology installs (Palantir), developer default (LangGraph), or EU AI Act Policy Pack libraries (Credo).
Beat them on: missing agent_id is RED before the tool; a foreign fact is quarantined until admitted; sandbox JWT is not execute:sandbox; Art. 14 is a queue with a proof; an A2A hop has PRE/POST and a TPNN strip.
6. How to promote this without lying
Industry demand already matches the product. The failure mode is claiming certificates, Reality, or a live tenant PMO we do not have.
| Say this | Never say this |
|---|---|
| Statistical AI guesses. We sit in front of the write and leave a receipt. | We determine Reality. Residual 0.0 means the world is true. |
| They have a programme of record. We have the hop. Use both. | We replace watsonx.governance / Credo / Palantir. |
| We speak MCP and A2A. Ungated A2A is TCP without TLS. | A2A is unsafe; we do not interoperate. |
| Twelve vs three. Tick the appendix. | We are 12/12 live on every tenant. |
| SOC 2 is the letter on the service. ISO 42001 is the AIMS of the gate. Mapped today; certified when the auditor signs. | We are SOC 2 / ISO 42001 / FDA / HIPAA / FedRAMP certified. |
| Node Exposure Assessment first. Agents last. | Buy a swarm and we will govern it later. |
| Guard / Estate / Federation. Humans bind send and SOW. | An agent emails the buyer. Marketplace $49 is PrimeSwarm. |
If a word is on the cliché list in the companion paper, use the control sentence or cut it.
7. What to put in the room
Board pack (one page). Charlotin 2,022. Art. 14 / 73. AAIF A2A. Twelve vs three. Act vs believe. CTA: Node Exposure Assessment, then /quote.
Platform pack. Helm, fail-closed secrets, MCP allowlist, sit in front of LangGraph / Bedrock, gated A2A demo, SIEM to the SOC they already have.
Proof we still owe. One live design-partner YELLOW resume. SOC 2 Type I kickoff on Guard scope. ISO 42001 Statement of Applicability that names product objects. One AAIF-speaking Federation handshake. Then the twelve-row table stops being a claim.
Close
Every critical organisation is already running AI against nodes it cannot name. The next wave is those agents talking to someone else’s agents. The question is not whether to adopt swarms. The question is whether the next write to the record — yours or theirs — is proposed or executed, and whether you can reconstruct the hop when Article 73, the inspector-general, or the court asks.
Best organisations win programmes, models, and ontology. We should win the write.
Only Institute | PIR Research
PrimeSwarm · TPNN · Only OS · DGV
Design-partner and enterprise briefings: research@only.institute
Website: only.institute
Quote: /quote
This document is a competitive briefing and a description of architecture. It is not a SOC 2 report, an ISO 42001 certificate, legal advice, or a notified-body conformity assessment. Figures are from named public sources as of the dates given. SKUs and rates live in /quote and stay off this paper.
Published by Only Institute