The Credibility Wars

The Credibility Wars

Credibility is the one asset that never appears on a balance sheet and never transfers with the deal. You can buy the customer list, the patents, the engineers, and the office, and still find that the thing which made all of it valuable stayed behind in a building you no longer own. That is the lesson underneath a forty-year-old acquisition, and it is the same lesson underneath every security alliance and model launch being announced in AI this month. The base layer of any durable system is not code or capital. It is the willingness of other independent parties to treat you as something they have to reason with rather than something they have to contain.

IBM bought Rolm in 1984 because it believed that acquiring a smaller company’s resources would extend its own reach into a growing market, which was a perfectly coherent thesis on paper. What the deal made plain afterward was that nothing in Rolm’s tangible pool could simply be carried across the desk. The value lived in relationships, in a particular institutional rhythm, and in a kind of credibility that cannot survive the moment of acquisition because it was never really Rolm’s to own in the first place. It was held by the people on the other side of those relationships, on loan, and revocable at any time. IBM got the assets. It did not get the thing that had made the assets matter, and there was no clause available that could have delivered it.

What IBM Bought When It Bought Rolm

The reason this failure repeats is that credibility looks like a property of the company holding it, when it is actually a property of the relationship. It is a judgment other people are making about you, refreshed continuously, and an acquisition is exactly the kind of event that prompts everyone to refresh the judgment at once. The counterparties who trusted Rolm were not trusting a legal entity. They were trusting a set of expectations about how that entity behaved, expectations built over years of small interactions, and the acquisition invalidated the evidence those expectations were standing on.

Democracy operates on a similar logic, on a longer timescale and with considerably higher stakes. It is not the most efficient form of government, and it does not reliably produce the strongest technocratic outcome on any given policy question. What it produces instead is trust distributed horizontally among people who do not have to agree on much else, plus a mechanism for correction that does not require collapse first. That is the actual product, and legislation is a byproduct. Because the crises that surface when the trust erodes are expensive and highly visible, it is easy to mistake the whole arrangement for something fragile. In practice it has proven the most capable of absorbing shocks without breaking, precisely because it does not depend on any single person or faction holding the center together. Distributed trust is slower to build and much harder to destroy than the concentrated kind.

How Square Borrowed Credibility from Apple and Visa

Square is the clean commercial version of the same mechanic, and its early years are more instructive than the usual retelling allows. It entered a payments market where trust was already thin and where the barriers to entry were mostly regulatory and perceptual rather than technical. The early questions about security were not minor irritants to be messaged around. They were existential for a company trying to convince small merchants to hand over card data to a startup they had never heard of.

What changed the trajectory was not a marketing pivot or a shift in messaging. It was Apple agreeing to stock the reader in every store for ten dollars, and Visa making a strategic investment. Both of those were credibility transfers from institutions that already commanded enough trust to lend some of it out, and the loan did something no advertising budget could have done: it moved the question a merchant had to answer from “should I trust this company” to “why would Apple and Visa be wrong.” Square did not buy those endorsements. It earned them by building something that could not be explained away, which is the only currency that works in this market. The borrowed legitimacy bought time, and the time was spent building legitimacy of its own.

Why Nvidia and Microsoft Opened a Security Alliance

That pattern runs through any system that has to survive contact with other systems, which is why it explains the current posture in AI security better than the press releases do. When Nvidia and Microsoft announced an open AI security alliance, the meaningful content was not the alliance itself. It was the tacit admission underneath: security can no longer be asserted unilaterally and simply believed. It has to be verified by competitors, standardized enough to be legible to outsiders, and made durable enough that other independent interests start aligning with yours instead of organizing against you. An alliance is what that admission looks like when it is written down by lawyers, and the reporting around the announcement reads very differently once you take the admission as the news.

The product side is doing identical work in a different register. Microsoft’s first cyber model and new agentic security system shift the pitch from “trust us” toward “check this yourself,” which is a considerably weaker claim and therefore a considerably more credible one. Put the two announcements side by side and the friction between them is the interesting part. The alliance concedes that no single vendor’s assurance is sufficient anymore, while the product is still a single vendor’s assurance, just one built to be inspected. Both are answers to the same problem at different altitudes, one at the industry level and one at the code level, and neither would exist if unilateral assertion still worked.

The discipline is consistent across all of these domains. You are building a stack whose base layer is the willingness of other independent systems to treat you as part of the environment they must account for. Democratic systems rely on elections, courts, and a free press to do that work. Companies rely on partnerships, security audits, and open standards. Platforms rely on developer ecosystems and genuine interoperability. None of these mechanisms are fast. Every one of them is slower than an acquisition, slower than an announcement, and slower than anything money can buy outright, which is exactly why they are worth what they are worth.

The Test Is Whether the System Can Correct Itself

There is a practical and thoroughly unglamorous test for whether any of this is real: can the system correct itself without an external force breaking it open? A democratic system can, sometimes, barely, when the institutions are intact and the habits still hold. A well-secured platform can patch itself before a breach forces the question into public. A company with genuine credibility can change direction and take its users with it rather than hand them to a competitor at the moment of maximum doubt.

The organizations that fail this test share a profile. They accumulated resources while skipping the trust-building step, usually because the trust-building step is slow, has no attributable owner, and never shows up in a quarter where things are going well. They tend to last exactly as long as the next market cycle allows, and their collapse gets narrated as a shock even though the missing layer was visible the whole time. The gap between having resources and having legitimacy is where most of the genuinely interesting failures live, and IBM buying Rolm is simply the oldest well-documented version.

The present moment in AI is dense with announcements, model releases, and funding rounds, all of which are resources. The winners over the next decade will not be whoever posted the best benchmark score on a given Tuesday, because benchmark scores are exactly the kind of asset that transfers, commoditizes, and expires. They will be the ones that made their systems legible to regulators, auditable by competitors, and trustworthy enough that the broader market stops treating them as hazards to be contained and starts treating them as infrastructure to be built with. That shift is the whole game, and everything else is noise.

Leave a Reply

Your email address will not be published. Required fields are marked *