I had wanted to talk to Illia Polosukhin again. I had met the former Google Brain researcher and co-author of the seminal 2017 paper, Attention Is All You Need, that introduced the Transformer architecture that now underpins today’s AI models, at Nvidia’s GTC conference two years ago. We spent nearly an hour talking on a couch tucked into a noisy corner of a hotel bar amid the chaos of the conference, and I felt lucky to find anything that wasn’t the floor to sit on.
Unfortunately, the interview—which focused on Polosukhin’s work as founder of NEAR Protocol, a public blockchain designed to serve as open infrastructure for the emerging “agent economy” and user-owned AI—never fit into anything I was writing at the time. But I filed it away, knowing I wanted to circle back.
These days, Polosukhin’s ideas about “democratic AI”—and his argument that the technology’s future shouldn’t be controlled by a handful of tech giants—suddenly feel very relevant. Over the past month, the AI industry has been consumed by debates over Anthropic's Mythos and Fable models, export controls, open versus closed AI, and, last week, the growing geopolitical competition with China over frontier AI with the release of Moonshot AI’s Kimi K3. Many of those debates ultimately come down to the same question: Who should control AI? It's a question Poloshukhin has been thinking about for years.
Polosukhin’s views are shaped in part by his own experience. He grew up in the former Soviet Union, in Ukraine, before building his career at Google Brain. He told me that perspective informs his skepticism of concentrated power—whether in governments or corporations—and helps explain why he believes AI should be built on open, verifiable infrastructure rather than controlled by a handful of institutions or by the government.
In our Ground Level AI Podcast conversation, we discuss how those experiences shaped his thinking, why he believes AI sovereignty has become one of the industry’s defining issues, and what recent debates—from Anthropic’s Mythos and Fable controversy to the broader geopolitical competition over frontier AI—say about where the technology is headed.
Inside my conversation with Illia Polosukhin: Four ideas about AI verification, privacy, and user ownership
(Quotes have been lightly edited for clarity.)
AI should be aligned with the user—not the company
Ever since Polosukhin left Google Brain to found NEAR Protocol in 2017, he has been focused on democratic technology, privacy and ownership of data.
He said that part of the reason he is so devoted to that is being from the former Soviet Union:
“Privacy and sovereignty, was something that you grew up fighting for and you definitely don’t want a government that can effectively dictate what you should think and how you should do things. Some of the core values are coming from that.”
But he added that it’s also because technology has become an interface — it’s how we perceive information and interact:
“This was true even before LLMs. Your Twitter feed, your Facebook feed, Instagram feed, it’s all machine learning. It’s all an AI model. The goal of that AI model is not to make you smarter, to make you a better person. It’s to make more money for the company. That incentive drives all kinds of disruptive behavior underneath.”
That means it’s even more critical that AI is aligned with individuals, something which Polosukhin insists blockchain and decentralization can help with:
“Blockchain actually offers an alternative which says this is an open ecosystem. Everybody joins and contributes. There is an economic engine underneath, but it’s not an extractive engine.”
User-owned AI is not about open versus closed
Most of today's AI debate assumes the key question is whether models should be open or closed. Polosukhin thinks that the real issue is whether users can verify what AI they're actually interacting with:
“Right now, even if you’re using an open-weight model, you’re hitting an endpoint by some provider, you actually have no idea what you’re using. They can be providing you whatever they want. They can be rewriting prompts. If it’s not on your laptop, you actually don’t know what’s happening.”
User-owned AI, then, is really about control, he said, particularly for businesses:
“I don’t want anyone to be in between me and the computing. In the business context, you can start changing how a company makes decisions because you just change how the information is presented by rewriting a little bit of a system prompt. And so it’s really important to have this verifiability on top of privacy.”
Businesses or governments may also care about what is in the model itself, he added:
“There can be a lot of bias. There can be sleeper agents, which is like a special way to train a model so that it activates specific behavior only under certain conditions. This would be a way to effectively inject malicious code into code bases. You need the process itself to be verifiable.”
Verification has to extend beyond the output
Polosukhin argues that verifying an AI model's answer isn't enough. To truly trust an AI system, he says, users should be able to verify the entire chain—from the model and prompt to the hardware it ran on. In practice, that means being able to verify not just the answer, but the model, prompt, training data, and hardware used to produce it.
“It’s verifying inputs and outputs. NEAR’s modern hardware has a confidential computing mode, which effectively locks it inside a computer, like a Swiss vault in which you can authorize that a specific code will run on specific inputs, and this is outputs. You do need a lot of cryptography around that to actually pass it through, run it on different devices, et cetera.”
“This gives you the ability to know that with this model, and my prompt or my system prompt or my training data, tthis is the produced outcome. And it was run on this hardware, on this specific GPUs, on this specific CPUs. So you get full authentication of that.”
Restricting AI is restricting knowledge
Much of today's AI policy debate centers on restricting access to powerful models in the name of safety and national security. Polosukhin argues that approach misunderstands the problem. Rather than limiting access to knowledge, he believes society should focus on regulating harmful actions:
“I hope most Americans and most of the world want to promote self-sovereignty and the ability for everyone to express themselves and do things. We have already laws around unlawful behavior. So designing and doing bio-weapons and bombs, et cetera, all of that is already preventable. Someone can study nuclear physics without AI. It's not that AI suddenly makes people smart and therefore we should limit who gets to be smart. That’s the same thing as saying like, hey, some people should not go to the library or enroll in some university.”
Polosukin insisted the issue goes back to freedom of speech:
“It’s the same components. It’s literally text, right? It’s speech in a very principled way. And so if you’re limiting that, instead of limiting the actions, instead of limiting the outcomes, you are kind of censoring at the core of the knowledge. As soon as you start censoring speech — we’ve been down this road. It ends up being kind of a losing game.”
This can lead to censoring learning, he explained:
“Jakob Uszkoreit, one of the co-authors of Attention if All You Need, launched a company that designs mRNA sequences. I wanted to learn more about how it works. But I’m afraid to ask OpenAI or Anthropic models because they’re going to ban me if this goes sideways. Not because I’m trying to design something, but because I’m trying to learn.”
What he’s excited about
Despite his concerns about centralization and censorship, however, Polosukhin remains optimistic. He believes today's models are already powerful enough to dramatically expand what individuals can accomplish—and that the next challenge isn't making AI smarter, but making it verifiable, user-controlled, and trustworthy.
“There’s never been a more fun time to build. When I was 14 and I was learning about all of these things, this was exactly what I wanted. I want to talk to a computer and build stuff and move really quickly. So I’m really excited by the potential this opens up. You have a model that can, by talking to it, you can learn anything in the world, so the kind of human enablement that this leads to is insane.”




