B
Research
What the team found, and what I did with it
I put the regulatory side with one researcher and market and cost with another. What came back is below, along with what I decided each part meant for the service.
The four numbers I pulled out for the pitch
A synthesis board this dense does not survive a presentation, so I reduced it to four figures a room could hold.
- 415 TWhGlobal data-centre electricity in 2024, about 1.5 percent of all electricity on earth.
- 0.24 Wh · 0.26 mLA median Gemini text prompt, which is 240 kWh and 260 litres once you multiply by a million prompts. Gemini is a default rather than a choice, which is the point.
- $1.32 to $2.00Take-home hourly wage for the Kenyan workers who read the worst text on the internet so the model could ship safely.
- 10 of 13Companies in Stanford's Transparency Index disclosing no energy, carbon, or water data at all.
The full audit boundary
Boundary definition turned out to be the core finding of the audit, not a preliminary to it.
- In scopeInference footprint, data-centre build-out, labelling labour, behavioural design, and disclosure quality.
- Out of scopeChip fabrication, enterprise API workloads, benchmark quality, and copyright licensing. Those matter, but auditing them properly was a different project and saying so protected the credibility of what we did claim.
- Unit of analysisOne median text prompt, multiplied by volume, multiplied by default distribution, to reach the system-level effect. Without that ladder every statistic the team found would have been an anecdote.
- Objects of studyChatGPT, Claude, and Gemini. Three different corporate shapes doing the same job, a capped-profit lab, a public-benefit corporation, and a division of a trillion-dollar advertising company.
Starting from GDPR rather than from scratch
I did not want to invent governance principles. GDPR already defines them and companies already have to follow them, so I used its three pillars as the frame and asked what each would look like if it paid the user back.
- PrivacyProtects personal data and secure handling across the whole lifecycle, from collection through deletion. "Data protection should be integrated into technology design from the beginning." Art. 25 and Recital 78
- ConsentRequires clear permission before collection and use, and the right to withdraw at any time without penalty. "The data subject shall have the right to withdraw his or her consent at any time." Art. 7
- ControlGives people the right to access, change, and delete their data, putting the individual at the centre of governance. "Controller means the natural or legal person which determines the purposes and means of the processing of personal data." Art. 4(7)
Reading them this way changed my mind about the project. Consent and control are already legally guaranteed, but nothing in the law says the value has to come back. That gap is where I decided TokenTrust would sit.
The market numbers that made this a business case
The cost research I assigned is what moved the argument from ethics to economics, and it is the section I leaned on hardest when presenting.
- 24% CAGRGlobal sovereign cloud market growing from $129B in 2025 to $572.3B by 2032. MarkNtel Advisors via PR Newswire, March 2026
- 84%of business leaders say data sovereignty and repatriation rules mattered more this year than last. Kyndryl via PR Newswire, March 2026
- 75%of consumers will not buy from an organisation they do not trust with their data. Cisco 2024 Consumer Privacy Survey
- +36%Rise in average enterprise monthly AI spend, from $63K in 2024 to $85.5K in 2025. CloudZero State of AI Costs, 2025
- 2×The number of organisations spending over $100K a month on AI doubled in a year, which is why cost governance is now a board-level line item. CloudZero State of AI Costs, 2025
Four signals I used to time the opportunity
I sorted what we found into signals and marked how strong each one was, because a weak signal you can see early is worth more to a service proposal than a strong one everyone is already acting on.
- Signal I · StrongAI-generated noise and model collapse. As synthetic content fills the training pool, companies face real risk from degraded data. Trustworthy models need trustworthy inputs, which raises the value of data with a known origin.
- Signal II · StrongCopyright litigation. Suits over training data keep multiplying. Harm reaches past individuals to organisations, and generative systems can produce false claims at scale.
- Signal III · WeakRegulatory pressure toward compensation. Reward can work as an institutional tool for accountability and consent. Rather than blocking information, it sets the conditions under which data can be shared and valued.
- Signal IV · WeakAn interplatform token economy. If AI tokens became tradeable, fragmented platform ecosystems could consolidate into one network. This was the weakest signal we found and the one I built the service on.
C
Strategy
The framework I built, and why it is shaped this way
The obstacle to paying people for data was never really technical. It was that nobody agreed on how to measure the thing being paid for. Once I saw that, the design problem became a measurement problem, and DQI became the exchange rate the rest of the system runs on.
What changes on each side
I argued the case twice, once for the person handing over data and once for the company collecting it, because a proposal that only helps one side does not get adopted.
- Visibility · UserFrom no view of how data is used, to ownership you can see and act on.
- Compensation · UserFrom data taken with nothing in return, to token rewards sized by DQI.
- Agency · UserFrom vague unease, to direct control over how much you share.
- Risk · CompanyFrom unauthorised collection and the litigation that follows, to consent-based collection that protects against liability.
- Quality · CompanyFrom inconsistent inputs, to data you can select on a known standard.
- Reach · CompanyFrom a limited collection scope, to wider reach earned through trust.
This is the slide I used to open every review. When data is given willingly, liability turns into protection and collection grows on trust instead of resistance, and that reframing is what made the enterprise side of the argument work.
Component I: DQI, the Data Quality Index
Four dimensions decide what a contribution is worth, with privacy sitting outside them as a gate rather than a score.
- AccuracyData has to match the real world. Errors here trigger regulatory penalties directly.
- CompletenessRequired fields and records must be filled. Gaps in an audit trail are compliance violations on their own.
- ConsistencyThe same data point holds the same value everywhere. Discrepancies between sources do not survive review.
- FreshnessHow current the data is, and whether the latest updates were actually applied.
- Privacy gateSeparate from the score. If it trips, DQI output is blocked entirely until encryption, anonymisation, and user notification are resolved. Making this a gate rather than a weighted factor was a deliberate choice, since a high score should never be able to buy its way past a privacy failure.
Component II: Reward Token
The part that closes the loop between giving something and getting something back.
- User sidePeople contribute data and receive token refunds they can spend on the service or carry as value across the platform.
- Company sideCompanies validate what they received and train on data they know is good, which is what they are paying for.
- The loopCirculation that pays both sides, grounded in consent and exchange rather than extraction.
Component III: Data Credit
A trust rating for companies. I added this last, after realising the system had no way to hold the enterprise side accountable for keeping its end.
- Corporate credibilityA benchmark for how credibly a company uses data, tied directly to data sovereignty.
- Audit transparencyHow far consent boundaries were respected, checked through internal and external audit.
- Reward fulfilmentWhether promised tokens were actually paid out, and whether they are usable once received.
- DQI accuracyWhether value was assessed fairly and every factor was applied the same way.
- Consent complianceWhether the company disclosed how data was used and kept people properly informed.
Who sits where
I mapped participants into three rings so the team could argue about influence without arguing about org charts. Governing bodies at the core, regulated companies in the middle, affected parties on the outside.
- Layer I · GoverningGovernment of Canada, EU AI Act, OECD AI Principles, ISO/IEC 42001, NIST AI Framework.
- Layer II · RegulatedOpenAI, Google DeepMind, Anthropic, Amazon, Meta AI.
- Layer III · AffectedContent creators, healthcare providers, financial institutions, academic researchers, enterprise data teams.
Partnerships follow the same three layers. Safe Superintelligence Inc. as technical advisor, Okta for identity and access, and GPAI to support entry into other markets. Government bodies stay informed and consulted while keeping regulatory authority. AI companies gain unified token management and access to consent-sourced data.
Four markets where nobody was standing
Competitors run on use then deplete. I positioned TokenTrust on use, refund, recirculate, which is what put us in open space on both value return and portability.
- AI Token Market
TAM $30B+Existing tokens are useful only inside their own ecosystem, so cross-platform refund and conversion is untouched. Ours would be the only one with a refund mechanism.
- Cross-platform Interoperability
TAM $15B+Integration platforms move data, not value. This sits at the point where iPaaS shifts from data pipes to value pipes.
- Data-as-a-Service
TAM $12B+DaaS is built around companies buying and selling data, with no return to the person who produced it. Consent-based compensation is the difference.
- AI Regulatory Compliance
TAM $5B+Everyone else treats compliance as penalty avoidance. Framing it as user reward is the position nobody had taken.
Three horizons to market
I sequenced it so trust gets built before tokens circulate, because launching an open token economy without an audit trail would have been the fastest way to fail.
- H-I · Y0 to Y1Build the governance core. DQI implementation and consent logging, audit-ready collection records, no open token circulation, rewards limited to internal credits in a controlled pilot.
- H-II · Y1 to Y3Pilot with selected AI companies, adapt DQI to sector needs, validate consent and reporting workflows, and audit internally whether the reward structure holds up under real use.
- H-III · Y3+Scale through standardisation, expand audit partnerships, add certification and reporting, and extend the governance framework across jurisdictions.
"Beyond simple redemption or transactional utility, TokenTrust carries an inter-platform character that guarantees user autonomy and expands service accessibility for AI enterprises." This is how I closed Phase I, presented March 23, 2026 as Group 14 of the AI Data Governance Society.
D
Blueprint
Phase II, where I made it operable in one country
Phase I left us with a framework that worked in the abstract. For Phase II I narrowed it to Canada on purpose, because a governance proposal that names no jurisdiction cannot be checked, and I wanted the team's second submission to be checkable.
Services like OpenRouter, Perplexity, Cursor, and Copilot already let you reach several AI providers from one place. What none of them give you is any say over your data once it moves. That distinction, access versus value, is what Phase II is organised around.
What changed between the two phases
- Phase I gave usThe global picture and the token economics, with DQI, Reward Token, and Data Credit named as the service components.
- Phase II had to giveA Canadian operating blueprint. We knew data had value. What we had not shown was which laws, which filings, and which accountable people would let anyone actually run it.
Four axes, and the order they switch on
I structured Phase II around four value axes and, more importantly, around their sequence. Getting the order wrong is how projects like this stall.
- Axis I · TraceabilityDQI gives data a measurable identity. Without it there is no refund, no compensation, and nothing to hold anyone to.
- Axis II · RefundA circular model replaces one-way consumption. No refund mechanism exists anywhere in the current AI token market.
- Axis III · InterplatformThe way VISA unified payments across banks, this unifies token value across AI platforms.
- Axis IV · RegulatoryRegulation is not the cost of doing this, it is the precondition. Without it the other three carry no legal weight.
Traceability comes first because everything else is calculated from it. Regulation runs underneath all of them from day one. Refund starts at pilot. Interplatform only opens once cross-border governance is settled, which is why it is a year three item and not a launch feature.
Axis I, before and after
- TodayData goes untraceable the moment it is submitted. Once it enters a platform, nobody can follow its path, its use, or its worth, so there is no way to compensate anyone for it.
- With DQIAccuracy, completeness, consistency, and freshness leave a fingerprint on every contribution. Measurable data carries traceable value, and traceable value can be paid for.
Axis II, before and after
- Existing modelUse, then deplete. Tokens are spent, the value is gone, and the person who supplied the data keeps nothing.
- Our modelUse, refund, recirculate. Contribution is scored by DQI, paid in Reward Token, converted to Data Credit, and put back into service access.
Axis III, before and after
- Existing platformsAggregate services. OpenRouter and Copilot move data between providers, unifying access but not worth. Token value stays siloed and cannot cross a platform boundary.
- Our positionConsolidate value. A unified exchange layer where tokens carry measurable worth across platforms, get priced by demand, and stay portable.
Axis IV, before and after
- Every competitorCompliance as penalty avoidance, a cost to keep as low as possible.
- Our reframingPIPEDA, FINTRAC, CBPR, and ISO/IEC 42001 as infrastructure to build on. The same framework that satisfies a regulator is what generates user trust, and it is what lets DQI carry legal weight.
What has to be in place before any of it runs
The team pulled the regulatory instruments and I mapped each one to the horizon where it becomes binding. This is the section that took the longest and the one I am most confident in.
- PIPEDA
Primary · H-IPersonal Information Protection and Electronic Documents Act. It applies at every layer: collection, valuation, compensation, and transfer. Our scope reaches past ordinary consent obligations because the DQI-to-token pipeline itself decides what counts as collection under federal law.
- FINTRAC MSB
Required · H-IMaking tokens exchangeable triggers money services business classification. Registration is a precondition, not a choice, and Okta's authentication defines which transactions are reportable.
- CIPP/C
Required · H-IA certified privacy professional inside the compliance team, so PIPEDA alignment is structural rather than a document produced at review time.
- OPC & PACC
Advisory · H-IIThe Privacy Commissioner advises on the data-token exchange model and receives annual transparency reports. PACC gives access to Canada's privacy governance community.
- Global CBPR
Global · H-IIICross-border transfer is structural once the ecosystem spans jurisdictions, and CBPR is the legal route. This is what unlocks Axis III.
- ISO/IEC 42001
Certification · H-IIICertifies the AI governance standard internationally, which is the credibility enterprise partners ask for before they sign anything.
Three horizons, one question each
I gave every horizon a single compliance question, because a milestone list nobody can remember is a milestone list nobody follows.
- H-I · Y0 to Y1Can we legally operate? PIPEDA framework and consent logging, a CIPP/C-certified Data Protection Officer, FINTRAC registration as a money services business. Execution stays internal, with the CTO and Okta consulted.
- H-II · Y1 to Y3Who governs our governance? Apply to the OPC regulatory sandbox, activate PACC for government access, build the advisory relationship with the Privacy Commissioner, consult GPAI on precedent while ISED is kept informed.
- H-III · Y3+Can our data cross borders? ISO/IEC 42001 certification, Global CBPR for transfer legitimacy, SSI Inc. and GPAI advising jointly, and AI companies entering as direct participants.
Who is accountable for what
As lead I wanted names against responsibilities, not a diagram of boxes. We used RACI and let the matrix grow with each horizon.
- InternalCEO and founder accountable throughout. Legal and compliance responsible for execution. CTO consulted. The DPO starts responsible and becomes accountable from H-II as the data protection scope widens.
- RegulatorsOPC consulted from H-II. FINTRAC and ISED informed from H-II onward. None of them are engaged at H-I, which is deliberate: we have nothing to report until consent logging exists.
- PartnersOkta and SSI Inc. consulted at every horizon for authentication and identity. GPAI joins as a consulted party from H-II for cross-jurisdiction alignment.
- AI EnterprisesInformed only at H-III, entering as direct ecosystem participants once the governance layer can actually hold them to something.
R is responsible and does the work, A is accountable and owns the result, C is consulted for input, and I is kept informed.
Four questions the interface has to answer
I translated the governance model into wayfinding, since none of it matters if a person cannot find their own position in it.
- Where am IDashboard. Token balance, value status, portfolio. The entry point, and an immediate read of where you stand.
- Where did it goData Flow. Destination, usage path, transfer history, so you can follow your contribution through the system.
- What came backReturn. Refund history, compensation records, earned value. The record of what the system paid you.
- How do I control itSettings. Privacy level, consent boundaries, reward rate. The governance layer, handed to the user.
"This positions AI token commerce not merely as an exchange mechanism, but as infrastructure that requires compliance as its base layer before value can flow." Phase II closed on April 5, 2026, with pilot operations and market validation as the next step.