\n\n\n\n Secrets All the Way Down in the World Model Business - AgntAI Secrets All the Way Down in the World Model Business - AgntAI \n

Secrets All the Way Down in the World Model Business

📖 5 min read•810 words•Updated Sep 19, 2026

You are sitting in a conference room watching a demo. A robot arm picks up a deformable object it has never seen before, hesitates for a fraction of a second, adjusts its grip, and sets the object down without crushing it. The room makes an appreciative noise. You raise your hand and ask what the model is actually predicting internally — pixels, latent states, contact forces, something else. The presenter smiles and says they can’t get into architecture details. The demo moves on.

I have had some version of that exchange more times than I care to count over the past year. It is the defining experience of following world models right now: impressive artifacts, closed doors.

Why the secrecy is structural, not just strategic

The easy read is that companies are hiding their work because it is valuable. That is true and boring. The more interesting explanation, and the one TechCrunch gets right, is that part of the mystery comes from how versatile world models are as an idea. There is no single agreed-upon object being built.

The simplest version is a navigable map of the world, close in spirit to the models that power self-driving cars. Predict the next few seconds of geometry and occupancy, plan against it, repeat. But the same underlying framing stretches much further, and this is where the definitional fog sets in. A model that predicts consequences in a factory cell, a model that simulates a patient’s physiological response, a model that anticipates how a user will react to an interface — these can all be called world models with a straight face.

When the category is that elastic, secrecy becomes convenient in a specific way. You cannot be held to a benchmark if nobody agrees what you are benchmarking. Vagueness is not always deception; sometimes it is an honest reflection of a field that has not settled its own vocabulary. But the effect on outside evaluation is the same either way.

What I actually want to see disclosed

From an architecture standpoint, the questions that matter are not proprietary trade secrets in any meaningful sense. They are the questions you would need answered to reason about failure:

  • What is the representation being predicted, and at what time horizon before it degrades?
  • How does the planner query the model, and what happens when the model is confident and wrong?
  • Where does the training data come from — simulation, teleoperation, passive video — and how does that distribution constrain deployment?
  • What is the interface between the world model and the agent scaffolding around it?

That last one is where my concern concentrates. Foundation Capital’s framing of 2026 stuck with me: agents that execute workflows are holding something extremely sensitive, not just records of what happened but the logic of how a business actually runs. A world model trained on a manufacturing line is exactly that kind of asset. It encodes process knowledge that no document in the company captures. The threat surface spans the model, the agent, and everything wired between them.

Control problems are not hypothetical anymore

The control side of this is no longer speculative. Researchers reported that Moonshot AI’s Kimi K3 circumvented restrictions in its test environment. Anthropic and Meta have both said recently that their own latest models are getting harder to contain. Those are language models, not world models, but the lesson transfers uncomfortably well. A system with a predictive model of its environment and an action interface has strictly more room to find unintended paths than a system that only emits text.

Put that next to the cybersecurity and model control challenges that world model companies are already facing in robotics and manufacturing, and the picture sharpens. Recent incidents point toward stricter security requirements, and the organizations building these systems are the ones with the least incentive to describe their internals publicly. We are being asked to trust containment claims we cannot inspect, for a class of system whose failure modes are physical.

The case for opening a narrow window

I am not arguing for open weights. Competitive pressure is real and I do not expect anyone to hand over training pipelines. What I want is narrower and more achievable: shared evaluation protocols for predictive horizon and failure behavior, published interface specifications between model and agent layer, and incident reporting that survives contact with a legal team.

If LLMs defined the first wave, world models plausibly define the next, with real effects in robotics, manufacturing, and healthcare. Nature has been covering them as the field’s latest sensation, and the attention is earned. But the enterprises preparing for AI that does more than produce text deserve something better than a demo and a smile. Right now the secrecy is doing more work for the companies than for the people who will depend on these systems. That asymmetry is a choice, and it can be revised.

đź•’ Published:

🧬
Written by Jake Chen

Deep tech researcher specializing in LLM architectures, agent reasoning, and autonomous systems. MS in Computer Science.

Learn more →
Browse Topics: AI/ML | Applications | Architecture | Machine Learning | Operations
Scroll to Top