# The Sovereign Frontier Enterprise

Adoption is universal and impact is concentrated. The difference is what a company owns around the models.

- Published: 2026-09-12
- Type: Perspectives
- Topics: sovereign-ai, transformation
- Canonical: https://hellofig.io/blog/the-sovereign-frontier-enterprise

**In short.** Adoption of AI is near universal, but only a small share of organizations see significant performance gains, and the firms pulling ahead use several times more AI capability per worker. The difference is what the company owns around the models: custody of its data, its accumulated knowledge, its context, its choice of model, and oversight placed outside the model. Fig is built so those five stay with the enterprise.

---
Two numbers describe the state of enterprise AI in September 2026. The first is from [Glean's Work AI Index](https://www.glean.com/work-ai-institute/work-ai-index): 87 percent of digital workers now use AI at work, and three quarters say it makes them more productive, but only 13 percent say their organization performs significantly better because of it. The second is from [OpenAI's Enterprise Signals](https://openai.com/signals/enterprise-data/): the firms in the top decile of AI usage now generate 8.3 times as many output tokens per active user as typical firms, up from 2.6 times in January, and message volume explains only about a third of that gap. The rest comes from richer, more complex use.

Put the two together and the picture is clear. Adoption is universal. Impact is concentrated. And the concentration is not explained by who has the best model, because everyone has the same models. It is explained by what a company has built around them.

We call the companies that are pulling ahead Frontier Enterprises, and we think the thing they have in common is ownership. This piece is about what they own, why the incentives of the AI industry make that urgent, and what it takes to get there.

## Renting intelligence

Every company starts by renting. That is correct. The frontier moves too fast for any institution to build its own models, and it should not try. The mistake is letting the rental define the whole system.

A rented setup has three tells, and they are easy to check.

First, the know-how the organization creates through use lives inside a provider's product. The prompts that work, the corrections people made, the examples that taught the model what "good" looks like for this company: they exist as chat history and preferences that do not export in any usable form.

Second, switching models means starting over. So nobody switches, and the provider's roadmap quietly becomes the company's roadmap. When the provider raises prices, changes retention terms, or falls behind a competitor on the tasks that matter, the company discovers how deep the dependency runs.

Third, the controls that matter, who can act, on what, with whose approval, exist as prompt instructions and good intentions rather than as a system. That works until the first time a model is talked into doing something it should not, which the [OWASP Top 10 for Agentic Applications](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/) now lists as the number one risk in the category, under the name agent goal hijack.

None of this shows up in year one. It shows up when the price changes, the model changes, a regulator asks a question, or a better model appears somewhere else.

## Why the incentives make this urgent

A model provider's business improves when more of a customer's work flows through its models and more of the customer's know-how shows up in its usage data, its evaluations, and eventually its weights. That is not a conspiracy. It is how the business works, and Palantir made the point bluntly in its own sovereignty guide this summer: the provider's incentive is to migrate as much intelligence from the enterprise into its model as it can.

An institution's business improves when the opposite happens: when the know-how it creates stays in a form it holds, and the model underneath it stays replaceable. Every month of use pushes value in one direction or the other. A Frontier Enterprise makes sure it compounds inside the institution.

This is not an argument against frontier models. It is an argument about where the compounding happens.

## The five things a Frontier Enterprise owns

<figure><img src="/assets/images/blog/five-things-you-own.svg" alt="Five circles around a central core labeled the enterprise: data, knowledge, context, model choice, and oversight."><figcaption>The five things that compound inside a Frontier Enterprise. Own all five and the frontier works for you.</figcaption></figure>

**Data, meaning custody.** Not a region on a map but a path that can be traced end to end. Where each copy of a record is processed, stored, and retained, including prompts, retrievals, outputs, logs, and support access. A no-training clause is necessary and not sufficient; it says nothing about logs, safety classifiers, or subprocessors. Custody is proven by tracing every copy and exercising deletion, not by reading a security page.

**Knowledge, meaning what a year of work produces.** Records, decisions, corrections, evaluation cases, and the criteria for what counts as done. Kept in a form that outlives the model and the platform that first captured it. The test is not an export button. The test is moving one workflow into a second environment, restoring its permissions, running the same cases, and measuring what was lost.

**Context, meaning the model of how the business works.** [Connectors](/platform/connectors) to the systems of record with their permissions intact, the [skills and packaged expertise](/platform/plugins) a team has built up, and the structure of who decides what and who approves it. Context is what makes an agent yours rather than generic. It has to remain portable, or it is not yours.

**Model choice, meaning liquidity.** The ability to [route each task](/blog/flash-or-thinking) to the best model from any lab and to change that routing when the frontier moves, without changing the system around it. Switching should be a setting, not a migration. The companies pulling ahead in OpenAI's data are not the ones with one model; they are the ones using more capability per worker, and that is only affordable when routine work runs on routine models.

**Oversight, meaning authority outside the model.** Approval before anything irreversible, bound to the exact operation. Credentials scoped to the task. A record of every action that an auditor can replay. A kill switch that stops work without leaving partial state behind. A model can be persuaded; the system around it must not be.

Own all five and the frontier is leverage. Own three and you are renting with extra steps.

## What changes when you own them

The payoff shows up in four numbers a board already tracks, and a Frontier Enterprise measures each against a baseline taken before the work started.

<figure><img src="/assets/images/blog/four-outcomes.svg" alt="Four tiles: revenue, cost, time, and control, each with the measure it is tracked in."><figcaption>Four outcomes, each measured against a baseline taken before the first workflow changed.</figcaption></figure>

- **Revenue.** Faster pipelines and higher-quality work, because the agents doing the work know the company's context and not just the language.
- **Cost.** The bill goes down, not just the number of steps. Routine work runs on efficient models, frontier reasoning is reserved for where it earns its price, and the spend is visible per team and per workflow.
- **Time.** The waiting comes out. Handoffs, approvals, and re-keying between systems are the days between steps, and they are where most cycle time lives.
- **Control.** A pulse on cost, usage, and adoption across every team, with people approving anything irreversible and a record of what ran and why.

The 13 percent in Glean's data are not measuring differently by accident. Glean's own analysis of what those organizations do differently comes down to four things: measurement, governance, context, and work design. Three of the four are ownership questions.

## How you get there

Nobody owns all five on day one, and no platform purchase delivers them. The path is a sequence, and the first few workflows teach an organization how to run it for the rest.

1. **Pick one consequential workflow** and write its charter: what the agent may touch, what it may do, what quality is accepted, what happens when it fails, and who owns each of those answers.
2. **Route the workload, then choose the model.** Decide how isolated the workload has to be from what it has to survive, then compare models on your own cases rather than on public benchmarks.
3. **Put the controls in the system**, not the prompt. Permissions inherited from the source systems, approval before irreversible actions, an audit trail in a form your own tools can query.
4. **Rehearse the exit** before you need it. Move the workflow to a second environment and measure what was lost. An exit clause that cannot be executed is not protection.
5. **Price accepted outcomes**, including the cost of control, and decide on evidence whether to release, restrict, or stop.

That sequence is a ninety-day program. Our research team published the full [operating playbook](/blog/sovereign-ai-the-operating-playbook) this week, with a worked example and the four tests that prove each step. Bringing it to a security review is its own piece: [Getting the CISO to yes](/blog/getting-the-ciso-to-yes).

## Where Fig fits

Fig is built so that the five things stay yours. Every frontier model from multiple labs, [routed per task](/platform/auto-routing) and switchable by policy. [Enterprise context](/platform/enterprise-context) that connects to the tools you already run, with permissions intact and everything exportable. [Governance](/platform/security) that lives in the system: approvals, scoped credentials, and [Command Center](/platform/command-center) for what ran and why. And a [transformation team](/transformation) that runs the ninety-day program with your owners and your evidence, then hands you the keys.

## Key takeaways

- Adoption is universal and impact is concentrated; the gap is explained by what a company owns around the models, not by model access.
- A Frontier Enterprise owns five things: custody of its data, its accumulated knowledge, its context, its model choice, and oversight outside the model.
- Provider incentives push know-how toward the model; ownership makes it compound inside the institution instead.
- The path is a sequence: charter one workflow, route it, put controls in the system, rehearse the exit, price accepted outcomes.

The frontier is available to everyone. What you build around it is not. Build a Frontier Enterprise. Own what compounds.

*Sources: Glean Work AI Index 2026; OpenAI Enterprise Signals, August 2026; OWASP Top 10 for Agentic Applications, 2026; Palantir, Institutional Sovereignty in the Age of AI, July 2026.*
