
Weight Custody Manifest ends the standoff that keeps the best models out of customer-controlled environments: builders get verifiable control over where their weights are unlocked, and customers keep control of their own machines
SAN FRANCISCO, Sept. 9, 2026 /PRNewswire/ -- OPAQUE, the Confidential AI company, today introduced Weight Custody Manifest (WCM), an open standard and developer-preview SDK that gives AI builders verifiable control over when and where their model weights can be unlocked when deployed on customer-controlled infrastructure.
WCM extends OPAQUE's Confidential AI infrastructure to protect the actual models running on sensitive data, not just the data itself. AI models are increasingly moving beyond the infrastructure of the companies that built them. Enterprises are fine-tuning open models on proprietary data, while AI labs and software companies are being asked to deploy increasingly valuable models directly into customer, sovereign and on-premises environments. This shift creates a new trust problem for model builders. As model weights are deployed on someone else's machines, builders lack the technical controls required for effective protection. For a growing number of sovereign and on-premises deals, deploying into the customer's environment is now a precondition of the deal rather than an option.
WCM directly addresses this challenge by keeping model weights encrypted until the new infrastructure proves it meets the conditions approved by the model builder. Even after the key is released, if those conditions change or the required proof is not consistently met, access can be revoked at any time.
"Today's Confidential AI protects the customer from the model. WCM protects the model from the customer," said Imran Siddique, Chief Platform Officer at OPAQUE. "The terms of a written contract have limited reach as AI models increasingly move onto infrastructure their builders don't control. Builders need proof that their intellectual property will only be unlocked in an environment that meets agreed-upon conditions. WCM gives all parties verifiable proof instead of asking either side to simply trust the other."
Unlike existing key brokers, WCM connects key release to the model itself and the terms governing its use. A jointly signed manifest can define the model's identity, license, permitted uses, jurisdiction, approved software and custody requirements before its weights are unlocked. WCM also tracks fine-tuned derivatives back to their parent models and supports revocation down the chain. The manifest is co-signed by the model builder and the custodian, OPAQUE by default or self-hosted by a sovereign customer. Either side can trigger an emergency revocation, and sovereign deployments can require a quorum so no single party can switch the model off on its own. Manifests can be recorded to a public, append-only log, which sovereign deployments require. It complements OpenSSF Model Signing where signing proves the model is genuine, while WCM determines whether it can be unlocked.
WCM is being released as an open, Apache-licensed developer preview with a published specification, defined data format, working reference library and 91 public test cases. The specification, threat model and tests are public so model builders, customers and infrastructure providers can independently evaluate and implement the protocol. As a developer preview, the specification and interfaces may change based on implementer feedback ahead of a stable release.
OPAQUE has validated WCM end-to-end on real hardware. The build is reproducible, with two back-to-back builds producing byte-identical results across 5,948 files, verified automatically. WCM has been validated using a NVIDIA H100 in confidential mode, as well as AMD and Intel confidential servers on Azure and Google Cloud. In its most recent validation, a CPU and GPU proved themselves together against the same fresh, one-time challenge before the model key was released as sealed ciphertext. Attempts to substitute either proof were refused, and the full test suite passed.
Developers can access the WCM specification, reference implementation and test suite at https://agentrust-io.com/wcm.
About OPAQUE
OPAQUE is the Confidential AI company. Born from UC Berkeley's RISELab (now the Sky Compute Lab), OPAQUE lets organizations run AI models, agents, and workflows on their most sensitive data with hardware-rooted isolation and verifiable evidence that approved governance policies were actually enforced. Founded by Dr. Ion Stoica (co-founder of Databricks; co-director, UC Berkeley Sky Compute Lab), Dr. Raluca Ada Popa (ACM Grace Hopper Award winner; Senior Staff Research Scientist at Google DeepMind, where she leads AGI security research), and Rishabh Poddar (CTO); Imran Siddique, creator of the open-source Agent Governance Toolkit (AGT), is Chief Platform Officer. OPAQUE created the Confidential Computing Summit.
Media contact: [email protected] and [email protected]
SOURCE OPAQUE
Share this article