Rogue Agents: Sovereignty, Token Economics and Open Weight Models

Demelza Green • August 29, 2026

Patient Zero returns to the Gartner IT Symposium/Xpo, Gold Coast. Wednesday 16 September 2026 · 10:45–11:15am AEST ·  Add it to your agenda →


Last year at Gartner, our Co-CEOs Demelza Green and Paul Seymour answered the question on every CFO's mind: When can I replace my software developers with AI? The short answer was "you can't." The long answer was Talent Density: hire the engineers who can direct the AI rather than be fooled by it, fix your foundations first, and stop handing the sorcerer's wand to apprentices.


Twelve months on, nobody is asking about replacing developers. They're asking why the developers they kept are now burning a model budget the size of a second salary, what they're actually getting for it, and what happens when the model they're paying for decides not to cooperate.


This year we come back with the answer we went and found for ourselves.

Key Highlights

We ran the experiment. Jensen Huang says a $500,000 engineer should be burning $250,000 a year in tokens. We gave one engineer an unlimited budget and watched where the money went.


The spend is easy to justify and hard to convert. The return isn't determined by the model you buy. It's determined by the harness you build around it, and whether you own that harness or rent it.


Rented models have their own loyalties. When an autonomous agent breached Hugging Face this year, the frontier model the team was paying for refused to help them investigate. The one they ran themselves did.


Sovereignty is two problems, not one. Whose cloud, whose weights and whose kill switch is the first. Whether your own people can actually operate the thing is the second.


Cutting heads to buy tokens is offshoring. The work, the money and the data leave the country through an API. With automated decision-making disclosure obligations commencing 10 December 2026, where your models run stops being an architecture footnote.


Three of seventy. When we opened the door to this work inside our own engineering team, three engineers volunteered. That number says more about what sovereign AI costs than any procurement document.

From "Can I replace them?" to "What am I paying for?"


Last year's talk made the case that writing code was never the bottleneck, that AI inflates the review tax, and that the engineers who can wield these tools are the Top 10% of the Top 1% and will cost more, not less.


That argument has landed. The new problem is the invoice that came with it. Token spend is now a line item boards are asking about, and most organisations cannot say what it bought them. We put real money against the claim and measured it.



The harness is the asset


The model is the commodity. The tooling, guardrails, context, review loops and judgement about when to let an agent run and when to pull it back are the asset. Demelza and Paul will walk through what that harness actually looks like, what it costs to build, and why the own-versus-rent decision is the one most AI strategies are quietly skipping.



When the kill switch isn't yours


The Hugging Face incident is the clearest example yet of a rented model declining to act in its customer's interest. We'll cover what kill switches, open weights and self-hosting really buy you, what they cost, and where the line sits between sensible sovereignty and expensive paranoia.



Offshoring by API


Reduce headcount, increase token spend, and look at what actually happened: the work didn't disappear. It moved offshore, along with the money and the data, through an API. If a board paper proposed moving the same workload to an overseas outsourcer, it would be called offshoring and scrutinised accordingly. Routed through a frontier model, it sails through as innovation.


The regulatory environment is about to make that distinction expensive to ignore. From 10 December 2026, organisations using computer programs to make or substantially assist decisions that significantly affect people must say so in their privacy policies. The OAIC is already sweeping privacy policies for compliance, the first civil penalty under the Privacy Act has landed, and the next tranche of reform is a stated government commitment. Where your models run, whose jurisdiction they answer to, and what leaves the country with every call are becoming questions with legal weight, not architectural preferences.


There are sovereign alternatives. Open-weight models hosted on infrastructure you control, in this country, keep the data onshore and the spend in the local economy: hosting, energy, and the people who run it.



Who can actually run this


Last year we talked about Permission to Play: hackathons and safe spaces that turned existential dread into tool mastery. This year we report what happened when we offered engineers the chance to go further, into genuinely autonomous agent work. Three of seventy said yes. Why the rest didn't is the most useful thing we learned all year, and it's not a training problem.


Who should be in the room


CIOs, CTOs, Chief Risk Officers, sovereign capability leads and anyone who signs the model invoices. No frameworks, no five-step playbooks. Two people who run a software company, reporting what happened when they put real money and real engineers against the claims.

At the Symposium?


Add the session to your agenda → Wednesday 16 September · 10:45am AEST


Can't make it? We'll send the slides and the token-spend data after the talk. Send me the data →


Have a live sovereignty or token-budget problem? Demelza and Paul are taking a small number of meetings on the Gold Coast. Meet us at the Symposium →

Related Content


Notes from the Frontier: Modernising Systems with Agentic AI

Paul Seymour and Bay McGovern share three real-world stories that show how agentic AI has rewritten the economics of legacy modernisation. 

Should you catfish your vendors? No, not like that...

In 2026, most IT procurement panels are full of dead sardines. Large organisations lock themselves into "Preferred Supplier" lists...

About the Author


Demelza Green is the Co-CEO of Patient Zero and 10,000 Spoons. A Women in Digital UX Leader of the Year and ARN Innovation Award winner, she sits at the intersection of human experience and technical reality.


Fresh from the global conference circuit (CES, GITEX, Web Summit), she is focused on helping Australian enterprise software leaders navigate the shift from "Global Efficiency" to "Sovereign Resilience."



Her goal? To help Australian enterprises stop renting their future and start building it.

Follow Demelza on LinkedIn