The IoT Frontier Model
Large language models read what people wrote. The next generation must understand what machines live through.
Every battery, pump and microgrid records experience that could help the next machine like it. TLAY trains industry frontier models on that experience across fleets and owners, inside attested enclaves, with differential privacy proven on every release. The data never leaves its owner’s control.
Watch the film (4:52) →Read the thesis →User guide →
Built on the confidential federated learning design from Google Research, Toward provably private learning from federated data. The frontier model is our roadmap; the sealed pipeline already runs in our pilot.
The film · 4:52
From the three locks to the architecture, the running pilot and the road ahead: the whole story in one film.
A new device starts with its own short history and a spec sheet, while machines like it have already met every problem it is about to face, somewhere else.
Operating records reveal a plant’s output, customer habits and asset health. A meter reading shows when a home is empty. “We anonymize it” is a promise no one can check.
Key: confidential computing and differential privacy
“Temperature” comes from different sensors with different precision; a stop may be a fault or a schedule. Without identity and context, more data is more noise.
Key: trusted provenance from the device
Good data costs connectivity, upkeep, labeling and consent management. If all the value stays with the model builder, owners have no reason to stay in.
Key: rewards tied to contribution
Why now
In October 2026 Google Research showed confidential federated learning training Gboard’s English and Japanese models. Devices upload encrypted data; only publicly logged, attested programs can decrypt it.
Source: Daly et al., arXiv:2609.31494. The A/B test ran about 3.5M devices per arm with user metrics neutral.
AMD SEV-SNP and Intel TDX machines rent on demand, and sign an attestation of exactly which program runs inside.
TLAY’s BoAT brings identity, signing, consent and payment to the device; HashAnchor gives machine events a verifiable integrity record.
The paper proved the architecture and the cloud supplies the hardware. TLAY connects them, end to end, for machine data.
An IoT Frontier Model learns what many devices in many conditions have in common, then carries that experience to new devices and new tasks. The large model serves from the cloud; skills are distilled down to the edge.
From battery state, temperature, load and dispatch: earlier anomalies, longer asset life, better scheduling.
From vibration, current and maintenance outcomes: unplanned downtime turned into planned maintenance.
From actions, environment and task feedback: faster ramp-up on every new site.
“Frontier” is earned by capability, not parameter count.
Confidential federated learning
Classic federated learning trains on each device and trusts the operator to add the privacy noise. In the design Google Research describes, devices upload encrypted data, and only publicly logged, attested programs may decrypt it. TLAY applies that design to machine data.
IoT is the most natural home for this architecture.
Classic federated learning needs devices that can train, stay online for round after round, and run shared code. Meters, gateways and sensors can’t. Here a device only collects, signs and encrypts, then goes offline. The bar to join industry learning drops from “can train a model” to “can encrypt a record.”
The cloud protects the computation, but it cannot say where the input came from. A model worth relying on knows which device produced a record, how it measured, and whether the record was sent twice.
Runs on the machine today; extends to encrypted upload and policy checks for TLAY Confidential Compute.
Links tasks, data commitments and result receipts, so every party can check the record was not altered.
Devices with secure boot and attestation give stronger evidence; constrained devices state their tier. Trainers filter, weight and trace by it.
What changes hands is the right to use data for one task, plus the model service built on it. Never an unlimited right to copy. Rules are written down before anyone joins.
Not for bytes, which rewards junk, and never for what the data says, which leaks it. The pilot pays the same for every contribution that passes validation.
Devices receive income within the permissions their owner grants, and pay for forecasting and diagnostic services in return.
Less downtime, longer asset life, better energy use. That is what keeps the flywheel turning.
Export a result bundle and verify it on your own machine, with no network. Pin the public keys from a source you trust, such as the cloud key service, rather than taking them from us.
Output from a release in our Oct 7 cloud pilot run.
$ python -m tlay_client.verify_receipt \ --bundle result_bundle.json \ --anchors pinned.json Security mode: attested_pilot Trust anchors: pinned PASS release_commit_signature PASS attestation_record_signature PASS attestation_verdict PASS workload_candidate_signature PASS layer_consistency NOT_CHECKED result_commitment PASS transparency_inclusion NOTE: sealed result. The buyer's result key opens it and checks the commitment.
We label every result by what was actually proven: synthetic data, simulated payments and hardware-attested compute are kept apart and never blurred.
Energy is where we start: continuous, time-ordered data and forecasts that can be tested on concrete tasks. Every gate asks two questions: did capability improve, and do participants still control how their data is used?
Consent, confidential compute, privacy budget, signed receipts and settlement work end to end.
Gate: consent and privacy limits hold as agreed
Joint data against one operator training alone, tested on new sites that took no part in training.
Gate: collaboration brings measurable gains
Root and worker TEEs, a public transparency log, open source and reproducible builds.
Gate: privacy budget and model utility still hold at larger scale
More device types and operators, many tasks on one shared industry foundation model.
The full argument behind the IoT Frontier Model, and a role-by-role walkthrough of the pilot.
Why machine experience has not become shared intelligence, why now, and how confidential federated learning changes that.
Read the thesis → User guideTenant admins, the key authority, device owners, buyers and auditors: what each one does, with screenshots from the pilot.
Open the guide →We are looking for our first fellow travelers.
Or write to info@tlay.io.