The AI governance certification market has reached its breaking point. A $300M Y Combinator company fabricated compliance. Enterprise trust infrastructure collapsed overnight. The market now demands what Lunara has been building from the beginning: constitutional governance with public accountability.
Delve, a Y Combinator backed company valued at $300M, built its business on a simple promise: AI compliance certifications. Organizations paid for the badge. The market assumed the audits were real.
They were not. Context AI and LiteLLM both suffered major security incidents after Delve certified them. When scrutinized, the certifications could not withstand inspection. The company disabled bookings in March 2026.
This is not an isolated failure. It is a structural one. When a single entity controls both the standard and the certification, the incentive to maintain rigor collapses under commercial pressure. The badge becomes the product, not the audit.
The market now has empirical proof that centralized AI certifications cannot be trusted. The question is not whether this will happen again. It is who will build the alternative.
These numbers are not abstract risk. They are procurement, accreditation, and regulatory liability. The EU AI Act enforcement date passed on August 2. NIST Q3 guidance is pending. Joint Commission is expanding AI governance review for accredited hospitals. State clinical AI transparency laws are multiplying.
Organizations that cannot demonstrate governance are losing contracts. The gap between having AI and governing AI is where liability lives.
The AI governance market is fragmenting into three categories. Each addresses a real need. None of them is a constitutional authority.
Cryptographic identity, issued and attested. It answers who is this with certainty, and stops there. Identity is a fact about an agent, not a judgement about whether it should be trusted with anything.
DigiCert AI Passport and the certificate authorities. Well capitalised. Largely solved.
Permissions, lifecycle, credentials and enforcement at runtime. It answers what may this agent do right now. This is the layer consolidating fastest, and the one attracting infrastructure-scale capital. It is control, not obligation: an action can be perfectly permitted by policy and still be unlawful.
Okta, SailPoint, ServiceNow and the agent-identity entrants. Converging on the same primitives.
Evidence normalised across every vendor, mapped to the obligation that governs it, with a named owner and the gaps stated plainly. It answers is this defensible, and who is accountable. No tool in the first two layers produces this, because each sees only its own estate — and an obligation does not stop at a vendor boundary.
This is where Lunara Society operates, and it is the layer no incumbent owns.
The first two layers are being built well and funded heavily. Neither interprets. A permission engine can tell you an agent was allowed to act; it cannot tell you whether Article 50 required that agent to disclose itself first, whether anyone owns that obligation, or what evidence you would produce if asked. That distance — between a control that passed and an obligation that holds — is where liability accumulates.
| Provider | Approach | Constitutional Authority | Public Auditability | Revocability |
|---|---|---|---|---|
| Lunara Society | Constitutional governance | Yes | Yes | Yes |
| DigiCert AI Passport | Cryptographic identity | No | Limited | No |
| Delve (collapsed) | Centralized certification | No | No | No |
| SailPoint / Entro | NHI discovery tooling | No | Vendor locked | No |
| Okta Cross App | Protocol level access | No | Vendor locked | No |
| ServiceNow | Vertical governance tooling | No | No | Internal |
DigiCert launched an AI Trust Architecture that gives agents cryptographic passports. This is valuable infrastructure. But identity without governance is a badge, not a standard. DigiCert can tell you who an agent is. Lunara tells you whether that agent is governed.
SailPoint, Okta, and ServiceNow are building governance tooling. They are plumbing. They help organizations manage access and workflows. They do not establish constitutional standards. They do not publish public registries. They do not revoke certifications when trust is broken.
Lunara Society is the only entity that provides constitutional governance authority. Everything else is a tool.
The Lunara Constitution establishes seven pillars of AI governance. Each pillar is mapped to specific regulatory requirements in each certification track.
Healthcare Track: HIPAA, FDA medical device guidance, Joint Commission standards, EU AI Act Annex III, state clinical AI transparency laws.
Financial Services Track: FINRA, CFPB, SR 11-7 model risk management, EU AI Act credit scoring rules, GLBA Safeguards Rule, NAIC AI guidelines.
Government Track: Federal procurement readiness, NIST AI Risk Management Framework, CISA guidance, FedRAMP alignment.
Every certification is published in a public registry. Every certification is revocable. Every audit trail is accessible. This is not a product. It is a standard.
The EU AI Act Article 50 enforcement date passed on August 2, 2026. NIST Q3 procurement guidance is pending. The competitive window to establish constitutional authority before the market commoditizes is 6 to 9 months.
Tailscale Aperture, the closest shadow AI governance competitor, is still in alpha. Isometric, Portal26, and Compuvi have raised capital but are building tools, not standards. The constitutional governance position is unoccupied.
Organizations that establish their governance credentials now will be positioned ahead of the regulatory enforcement curve. Those that wait will be responding to enforcement actions instead of preventing them.
Founding pilot seats are open. Five per track. Priority processing, founding certification status, and preferred pricing locked for 36 months.
View Certification TracksNew: Healthcare Vertical
The first compliance risk scoring platform built for healthcare organizations deploying AI. HIPAA plus EU AI Act unified framework.
Learn More