Wand Blog

WAND AI adds VLNO as a Model Robustness Layer to Enable Sovereign AI on Open-Weight Models

Written by Wand Team | Aug 12, 2026, 1:14:33 PM

VLNO’s adversarial hardening technology becomes an additional security capability within Wand AI sovereign AI labor infrastructure.

Wand AI today announced the addition of VLNO to its Sovereign AI offering, enabling governments and regulated enterprises to deploy open-weight models on their own sovereign infrastructure with measurable, certified robustness. By incorporating VLNO’s security-training layer into the Wand ecosystem, organizations can operate open models on sovereign compute with a verified security and resilience posture—rather than relying on assumptions.

Nations and enterprises can run open-weight models inside their own borders on Wand’s sovereign backend, with adversarial robustness trained into the weights and re-certified on every checkpoint.

Sovereignty is pushing the market toward open models—models that can be hosted on national infrastructure and operated without dependency on a foreign vendor’s API. Cost pushes the same way, as agentic workloads multiply token volume far beyond what closed frontier models were priced for.

However, the security posture that made frontier models acceptable to enterprises does not transfer. Closed models arrive with an accountable vendor, published safety evaluations, internal and external red-teaming, and a patching path. Open weights arrive with none of that. They can be modified to embed backdoors or strip guardrails, no one is accountable for a fix, and standardized adversarial benchmarks for agentic failure modes are largely missing. In practice, this stops migrations cold: the business case for open models is approved, and the CISO blocks the move on robustness grounds.

The existing security market does not resolve this. Runtime vendors wrap the model from the outside with filters and guardrails; the model underneath stays vulnerable. Evaluation and red-team labs name the weakness in a report; the model ships unchanged. Neither changes what the model does when an agent encounters a malicious instruction in a tool result, a retrieved document, or a downstream API response.

The addition of VLNO closes that gap. Wand provides the sovereign agentic stack: country-level governance, a hybrid human and AI operating system, and certified autonomous AI labor attached to the sovereign compute base. VLNO’s security layer provides the model robustness layer. Its automated, high-scale adversarial pipeline generates attacks against the customer’s own agentic workflows, runs them at scale in sandboxed environments, and returns the result as training data—RLHF- and DPO-ready trajectories, or a hardening LoRA—that drops into the customer’s fine-tuning pipeline. The hardening lives in the weights, so it travels with the model wherever it is served, and existing filters and runtime controls stay in place on top of it. Because robustness has to keep pace with a moving target, the process is continuous rather than one-time: VLNO retests each model and agent whenever a new version or checkpoint ships, or a new benchmark of attacks emerges, and rehardens as needed, so protection stays current as both the models and the threats evolve.

“Sovereign programs have had to choose between models they control and models they can defend,” said Hertzel Kuriel, Co-founder and CEO of VLNO. “Robustness is the gate on that decision, and it has been treated as something you inspect rather than something you fix. We produce the data that makes a model stronger, so a ministry or a bank can put an open model into production on the evidence of a measured attack success rate rather than on a vendor’s assurance.”

“Wand provides the foundational infrastructure through which nations can deploy, operate, manage, and continuously evolve AI labor at scale. We are pleased to welcome VLNO into Wand’s sovereign technology ecosystem, adding a robustness capability that lets ministries, institutions, and agencies adopt open-weight models on a unified national stack without lowering their security bar,” said Cristian Felix, Chief AI Architect of Wand AI.

How It Works

The joint reference architecture supports two deployment points. Certification at admission. Wand’s Adaptive Router reduces every model call to one dispatch seam and selects models from an Open Model Registry. VLNO’s benchmark runs against candidate models before they enter that registry, producing a measured attack success rate under adaptive attacks across agentic scenarios. Robustness becomes an admission criterion of the sovereign backend rather than a property of any one deployment. Hardening in the weights. For models that fall short of the target, VLNO’s high-scale pipeline generates scenarios in the customer’s operating context, executes them with an adaptive attack model against sandboxed agentic surfaces, and returns RL trajectory data or a hardening LoRA. The customer applies it in their own environment; the artifact is data, and no weights or sensitive workflow content leave the trust boundary.

Because a robustness certificate is bound to the weights, it expires when the weights change. Every fine-tune, every version, and every newly published attack class triggers re-measurement, so a model’s posture on the sovereign backend is continuously current rather than a point-in-time report.

The capability is complementary to the inference privacy and confidential computing layers already in Wand’s sovereign ecosystem: those protect the data path around the model, while VLNO changes the behavior of the model itself.

The Wand AI and VLNO joint reference architecture is available to sovereign programs and enterprises now.

About Wand AI

Wand AI is building the sovereign infrastructure for AI labor. Wand’s operating system enables governments and enterprises to deploy, manage, govern and continuously evolve AI agents alongside humans as trusted members of the workforce, with identity, objectives, authority, security, governance and auditability built into the platform.

For nations, Wand provides a unified foundation through which ministries, public institutions, and critical national organizations can deploy AI labor while maintaining sovereign control over models, compute, data, policies and operations. Wand powers production-scale deployments with some of the world’s most consequential institutions, including leading banks, asset management firms, hedge funds, consulting firms, and system integrators. Wand exists to power the biggest transition in human history: infinite labor—so that everything humanity can imagine, we can finally build.

Founded in 2023 and headquartered in Palo Alto, California, with offices in Palo Alto, New York and Abu Dhabi, Wand is backed by world-class investors, leaders, and a tier-one research team. Learn more at wand.ai.

About VLNO

VLNO builds the security training layer for open and agentic models. Its platform generates adversarial attacks tailored to real agentic workflows, runs them at scale against sandboxed enterprise surfaces, and converts the results into training data that hardens the model itself—RLHF- and DPO-ready trajectories and hardening LoRAs that plug directly into a customer’s fine-tuning pipeline. Where evaluation labs produce reports and runtime vendors produce filters, VLNO produces the data that changes model behavior, measured by attack success rate against an adaptive attacker and re-certified on every checkpoint.

VLNO’s public robustness benchmark lets any team measure their own model for free. The company was founded by leaders in frontier-model red-teaming, adversarial evaluation, and RL-based model hardening. Learn more at vlno.ai.

 

View the full press release here.