revolut.hotIndependent thought experiment · not affiliated with Revolut Ltd · no non-public information used
Working note v3 · 11 Sep 2026

The attested key base is the asset. The governed node is the unit.

Revolut does not own a fleet of AI computers, and buying one is not the hard part — compute is rentable. What it already owns is harder to build and impossible to rent: a device-bound, attested key on tens of millions of phones, issued under a banking licence, revocable centrally, and already trusted for strong customer authentication. Enrolment at scale is the bottleneck in every sovereign-AI proposal. Here it is already solved, for a different purpose.

80m+
retail customers, each with an attested app instance
Revolut Annual Report 2025 site, “as of today”; the FY25 PDF text says over 70m. Re-date before publishing.
~767k
business customers, up ~33% year on year; company target 1m
Revolut Annual Report 2025. Do not round to 800k.
~18.5k
employees, March 2026 — the internal sandbox, and larger than usually assumed
Revelio Labs workforce estimate. The “13k” figure circulating from LinkedIn is a follower-adjacent count, not headcount.

What changes when the unit changes?

A home lab is not evidence that a bank can run its risk stack on one mini-PC. It is evidence about a different unit: a local, revocable, policy-bound node that does private work close to the data and escalates what it cannot or must not decide.

Can Revolut replace central AI with millions of local machines?

Better question

Can Revolut issue bounded, revocable, independently verifiable authority to software acting on a customer’s behalf — and have a third party who banks elsewhere accept the proof?

Where the previous drafts break

Four independent drafts of this thesis all placed identity, permissions and revocation in a central Revolut registry with a compliance dashboard on top. That is the standard enterprise identity answer and it works perfectly — inside the perimeter.

It stops working at the first company boundary. When a node at an SME acts toward that SME’s auditor, its non-Revolut bank, a supplier or a tax authority, the counterparty cannot query Revolut’s registry. “Revolut says this node was authorised” is a claim, not evidence. The counterparty must be able to verify, offline and after the fact, that a specific action fell inside a specific mandate that was valid at that moment — without being a Revolut customer and without trusting a dashboard.

Consequence

A central registry makes this an internal control. A verifiable credential makes it a product that works where Revolut’s customers are not — which is the only version with a network effect.

The architecture is the product — not the box

Local node

Private work stays close

Local model, OCR, retrieval, drafting, bookkeeping, document processing. Hardware varies: phone secure element, laptop, workstation, appliance. The root of trust is the attested key, not the silicon class.

→
Authority pack

The mandate is signed and bounded

Signed, versioned, expiring: what may be done, on what facts, to what cap, until when, what must be recorded, when to escalate. Solvers are implementation detail — no claim that law is fully formalisable.

→
Overflow

Hard work can leave the node

Memory spilled locally where the machine allows; selected tasks routed to an approved pool when it does not. Routing is itself policy-controlled — where a task may go is part of the mandate, not a scheduler decision.

→
Proof

Third parties verify without asking

Every action carries a credential chain: who issued the mandate, to which key, under which policy version, revoked or not. Verifiable by a counterparty with no access to Revolut and no access to the node.

One architecture, three different units

Employees

The clean sandbox

Tens of thousands, inside one legal entity, on managed devices. One authority pack, one escalation path, no external customer risk. This is where failure modes are discovered cheaply.

Unit: managed laptop, optional desk appliance
Business

The strategic middle

Where the thesis either earns money or dies. These customers already have documents, payroll, vendors and accounting to process, and they already deal with counterparties who are not Revolut — so they are also the first population that needs the proof layer.

Unit: one office machine, pre-approved
Retail

Not a hardware market

Do not extrapolate a £2–4k workstation to tens of millions of people. The mass node is the phone that is already in the customer’s hand and already holds the key. A dedicated box is a premium slice, not the plan.

Unit: phone secure element + NPU

What the thesis does — and does not — solve

It helps with

  • keeping sensitive working data on-device;
  • making an agent’s mandate explicit, bounded, expiring and revocable;
  • letting a counterparty verify that mandate without trusting the issuer’s dashboard;
  • shipping identical policy semantics across heterogeneous hardware;
  • producing a machine-readable audit trail that survives the node being wiped;
  • turning future compute capacity into overflow rather than the only place work can happen.

It does not solve

  • legal interpretation, or whether the policy encodes the law correctly;
  • accountability: moving execution to the customer’s device does not move regulatory responsibility. Under outsourcing and critical-third-party rules the regulated firm still answers for the function;
  • fraud detection, which needs cross-customer signal by construction and belongs in the centre;
  • support economics across hundreds of thousands of businesses;
  • model weight security once weights reach an uncontrolled device;
  • truth of the input facts.

The scale ladder

The route from an N=1 experiment to a product proposition is a sequence of increasingly expensive falsification tests, not a jump.

01

N=1 · dogfood the node

One knowledge worker or small regulated operator. Test authority packaging, local execution, logging, revocation, overflow — and whether an outside party can actually verify a trace.

Proves the loop works — not that anyone wants it
02

N=10–30 · controlled pilot

Employees, or a handful of business accounts. One workflow, one authority pack, one hardware profile.

Measures support cost, failure modes, operator trust
03

N=100–1,000 · distribution test

Over-the-air policy updates, telemetry minimisation, mixed devices, rollback, revocation latency, real service economics — and the first counterparty who is not a customer accepting a proof.

Tests whether distribution becomes a channel
04

Product scale

Only then: segmented rollout by jurisdiction, workflow and risk class.

Scale is earned, not inferred from customer count

Four questions that can kill this — usefully

Verification

Will any counterparty outside the issuer’s ecosystem actually accept a credential-backed trace, or do they demand a human signature anyway?

Economics

Is local plus overflow cheaper or more valuable than cloud-only after support, updates and hardware?

Governance

Can authority be versioned, signed, revoked and audited without turning every policy into a brittle formalisation project?

Demand

Does sovereignty, privacy or latency create willingness to adopt — or is this elegant and commercially unnecessary?