Logo
FrontierNews.ai

Governments Are Building Their Own AI Control Layers. Here's Why That Matters for Your Data.

Governments and enterprises are now investing in dedicated infrastructure to control which AI systems can access sensitive data and when. A London-based startup called Valarian just closed a $50 million Series A funding round to build what experts call a "sovereign AI control layer," a governance layer that sits between AI tools and the sensitive systems they touch, enforcing rules at the infrastructure level rather than hoping vendors behave responsibly.

What Is a Sovereign AI Control Layer?

A sovereign AI control layer is not another AI model. Instead, it's software infrastructure that governs how AI systems and other high-consequence applications access data, communicate with each other, and operate. Think of it as a security checkpoint between your AI tools and the sensitive information they're allowed to touch.

Valarian, founded by Max Buchan and Josh McLaughlin, closed its Series A on July 13, 2026, led by New Enterprise Associates (NEA). This marks NEA's first defense and dual-use investment in Europe. The round also included backing from Lightbank, XTX Markets, Sequel, LitVC, and angel investors Gokul Rajaram and Nikesh Arora, bringing Valarian's total funding to $70 million.

The startup operates on two tracks: one for enterprise customers and one for defense applications. The underlying problem it solves is straightforward but urgent. Most companies today grant broad API access to AI vendors and hope for the best. Once AI systems start acting autonomously instead of just answering questions, that approach becomes untenable.

Why Are Governments Suddenly Concerned About AI Data Access?

The timing of Valarian's funding reflects a broader shift in how institutions think about AI governance. The startup has visible support from the UK government, signaling that "hope for the best" is no longer acceptable policy when it comes to AI access to sensitive data.

Consider the practical reality: most mid-size companies already run five or six AI-enabled HR tools. Each one potentially has access to employee salary bands, medical leave records, and other sensitive information. Without a control layer, there's no unified way to audit or restrict what each vendor can actually see or modify. Valarian's bet is that this gap will become a regulatory and security imperative, not just a nice-to-have feature.

The problem extends beyond HR. A recent case at Montefiore Medical Center in the Bronx illustrates the stakes. The hospital eliminated 12 utilization-review nursing positions this month, handing the work of confirming that patient care is medically necessary to AI software from Datavant. The New York State Nurses Association flagged the move as a violation of AI-protection language the union won after a 41-day strike, and raised concerns about data exposure risks.

How to Assess Your Organization's AI Governance Readiness

  • Data Access Audit: Ask your HR software vendors a direct question: what data does your AI feature actually have write access to, and who audits it? If nobody at the vendor can answer quickly, that's a red flag that your organization lacks visibility into AI permissions.
  • Vendor Accountability: Determine whether your vendors have published policies on what AI systems can and cannot access. Look for explicit documentation of data retention, deletion, and third-party sharing practices, not just general privacy statements.
  • Infrastructure-Level Controls: Evaluate whether your current tech stack allows you to enforce rules about AI access at the infrastructure level, or whether you're relying on each vendor to self-regulate their own systems.

The Skills Gap Is Making Governance Harder

Ironically, the very infrastructure that could solve the AI governance problem is competing for scarce talent. A new OECD policy paper titled "Skills in the AI age" found that firm-level AI adoption across member countries roughly tripled between 2021 and 2025, rising from about 7 percent to 20 percent of businesses. Yet workers with advanced AI skills, including machine learning and data science expertise, still make up only around 1 percent of the workforce.

The OECD warns that without stronger training systems, this gap will widen inequality. Large firms will continue pulling away from small ones, and high-skill roles from routine ones. For organizations trying to build out AI governance functions, this means competing for the same scarce talent pool that every other company wants.

What Does This Mean for AI Automation in Sensitive Roles?

Utilization review, the work Montefiore handed to AI, is exactly the kind of judgment-heavy, rules-based task that AI vendors pitch as ready to automate right now. It's also the kind of work where a wrong call delays someone's care. The Montefiore case previews the sovereign AI control layer question every workforce will eventually face: who decides when AI gets the final say, and who double-checks it.

The broader research community is taking this question seriously. An analysis of 170,927 arXiv papers posted between January 2025 and June 26, 2026 found that agentic AI evaluation, AI-assisted scientific discovery, and autonomous research capability are among the fastest-growing shares of research output in the first half of 2026. In plain terms, AI researchers are now spending more time asking "does this agent actually work" than "how do we build a bigger model." That's a healthy sign that AI agents pitched for HR workflows and other sensitive applications are getting more scrutiny before they ship.

The infrastructure of AI oversight is being built right now, and most HR teams are watching from the sidelines. Whether your organization is ready to participate in that conversation depends on whether you can answer basic questions about what your AI vendors can actually touch, and who's checking their work.