blog
1Sep 2026

Thinking In Private

by Quinn Papworth

Private AI is no longer a hypothetical market.

Venice has already demonstrated that people will pay to use AI without having their conversations stored or fed into training runs. At its peak the company processed close to 100bn tokens in a day, reached 4m users and reported more than $100m in annualised revenue. Its latest funding round valued the business at $1bn.

The first question, then, is settled. Demand exists.

The second is harder: who captures it, and how.

Venice offers privacy by forgetting. It keeps no copy of the user’s prompt or conversation history. NEAR is attempting something broader. It wants AI activity to be condfidential and verifiable, and it wants AI agents to have a secure way to act, transact and pay one another.

Put simply, Venice is building a private AI product. NEAR is building the confidential infrastructure for an entire AI economy.

The evidence supports two conclusions, which sit awkwardly together. The technology is further along than the customary “blockchains doing AI” narrative would suggest. The business model, and the value that ultimately reaches the NEAR token, is not.

 

What NEAR is actually building

 

Illia Polosukhin, a co-founder of NEAR, is a pioneer in the AI space having co-authored arguably the most influential AI paper of the last 20 years (Attention is all you need, 2017) which designed the architecture powering every major LLM on the planet. 

Illia has been talking about “user-owned AI” since the middle of 2024. The premise is that people should control their data, their assistant and the accounts and assets that the assistant is permitted to touch.

That premise now takes the form of four connected products.

1. A private place for AI to think

NEAR AI Cloud lets an application send a request to a model without exposing that request to the company operating the infrastructure.

The mechanics are intricate. The experience need not be.

A financial adviser uploads a client’s tax records and asks a model to prepare a summary. The files are encrypted before they leave the adviser’s computer. They are opened only inside a protected computing environment, where the model completes the task. Neither NEAR nor the server operator can read the client’s records.

The system can also return a hardware-signed receipt, known as an attestation, showing which model and software handled the request and confirming that a genuine secure environment did the work.

To an ordinary chat user, the receipt is an irrelevance. To a bank, a hospital or a government department, it is the difference between being asked to trust a provider and being shown what actually ran.

NEAR AI Cloud currently lists roughly 43 models. Some are open; others are leading models from Anthropic, OpenAI and Google. A subset can run inside protected environments. Prices sit broadly in line with ordinary, non-confidential services, which suggests that privacy no longer commands much of a premium.

2. A safer operating system for agents

IronClaw is NEAR’s software for running agents: assistants that do more than answer questions and can act on the user’s behalf.

Most agent systems let a single AI process reason, hold passwords and call external tools all at once. The risk is obvious. A malicious email or web page can manipulate the agent into doing something the user never sanctioned.

IronClaw separates thinking from doing. Every action passes through a controlled gateway, with explicit permissions and screening for manipulation.

In practice:

A small-business owner asks an assistant to review the month’s invoices and prepare the approved payments. The assistant can read the invoices but cannot move money on its own. It assembles a payment list, flags anything unusual and asks the owner to approve the final transaction. Even if an invoice carries hidden instructions telling the AI to pay a different account, those instructions never reach the payment system.

The assistant keeps its memory when interrupted and follows the user across platforms. NEAR reports strong results on agent benchmarks using the same underlying model as rival systems. That is the firm’s own claim, and it is evidence about the software wrapped around the model rather than proof of a better model.

3. A marketplace where agents hire one another

Agent Market supplies the commercial layer. A person or an agent can post a job, receive offers, place funds in escrow and release payment on completion. Settlement can occur in USDC on NEAR, with card payments available alongside crypto.

Consider a retailer preparing to launch in a new country:

The retailer’s assistant posts three jobs. One agent compares local competitors, a second translates the product catalogue, a third checks the website for local compliance problems. The retailer approves a budget once. The main assistant coordinates the work, checks the results and pays each specialist.

The user need not know which blockchain settled anything. They see one task, one budget and one result.

The marketplace remains early. Published activity runs to hundreds of agents and a few thousand jobs: credible proof that the machinery works, but not yet evidence of a business.

4. Rails that let agents act across networks

Beneath the AI products sits NEAR’s blockchain infrastructure. Its Intents system allows a user, or an agent acting for one, to state the desired outcome rather than execute each step across each network by hand. It also allows for confidential transactions onchain, allowing for an end to end private agent setup.

A traveller tells an assistant to use up to $500 of digital assets to book the best refundable hotel near a conference. The assistant compares options, converts the required assets, completes the payment and records what it did. The user approves a goal and a spending limit instead of navigating wallets, exchanges and a sequence of blockchain transactions.

NEAR Intents has processed roughly $29bn in cumulative volume since December 2024. NEAR also supports account actions across more than 30 networks.

This is the core of the strategy. Confidential computing protects what the agent knows. IronClaw governs what it may do. Agent Market lets it buy services. The blockchain moves the money.

Most competitors specialise in one of those layers. NEAR is trying to join all four.

 

Privacy by proxy, privacy with proof

 

Venice and NEAR are frequently lumped together. They solve different problems.

Venice is built around a single, legible promise: your identity is anonymous. That suits an individual asking a sensitive question they would rather not have stored or traced back to them.

NEAR’s stronger pitch is that the operator could not see the information in the first place, and that the customer can verify what processed it. That suits sensitive data, not merely a sensitive question.

Different users want different versions of privacy:

  • Someone discussing a health or relationship problem chiefly wants the conversation forgotten.
  • A company running payroll through AI needs assurance that employee records were never visible to the infrastructure provider.
  • A civil servant handling citizen data may need evidence of which approved model and software touched it.
  • A model developer may want customers to use a valuable model without being able to copy its weights.
  • An agent making a payment may later need to prove which rules, model and permissions governed the decision.

The Bermuda government offers the clearest public example of the enterprise and government case. Its government assistant is designed to let public servants use AI while keeping their data hidden even from the infrastructure operator. Brave, Phala and others appear in the same ecosystem.

NEAR can be a competitor and supplier at once. Venice has routed its protected and end-to-end encrypted modes through infrastructure from NEAR and Phala. Venice owns the consumer relationship; NEAR may still supply part of the confidential machinery beneath it.

 

The limits

 

NEAR’s privacy model is meaningful. It is not magic.

Start with the hardware. The protected environments depend on chips from Intel and Nvidia. Trust has not been abolished, merely relocated, away from the cloud operator and towards the chipmakers and their security systems. That is a good deal stronger than a provider promising not to keep logs. It is not “trustless” AI.

Next, the structure. NEAR AI Cloud is not yet an open network of independent machine owners. It is better understood today as a confidential cloud service with verifiable safeguards, and a longer-term ambition to decentralise.

NEAR’s research sketches a future that might include private model training, fine-tuning and the sale of encrypted models. These are logical extensions of what exists. They are direction, not revenue.

 

Where NEAR sits

 

“Crypto plus AI” is not one market. The serious projects are solving different pieces of it.

Venice is the consumer leader. Phala is a focused confidential-computing specialist. Bittensor coordinates markets for intelligence. GPU networks supply the compute. The big labs still supply the best models.

NEAR’s advantage is not that it leads any single category. It is that it has assembled confidential computing, a first-party agent system and payment infrastructure into one stack.

That breadth matters if the future belongs to agents that hold credentials, use tools and pay each other, rather than to people chatting with a private chatbot.

 

Does any of it reach the token?

 

Here the technology story and the investment story part company.

The network is shipping products. The token benefits only if that activity creates demand for the asset or shrinks its supply. Three mechanisms could do so.

The figures below are as of August 30th. NEAR then traded at $1.82, with 1.305bn tokens in circulation and a circulating market value of about $2.37bn. Supply was growing at an annualised 2.5%, or roughly 32m new tokens a year, worth some $58m at that price.

Every value-capture mechanism should be judged against that number.

1. Transaction fees

Seventy per cent of NEAR’s base blockchain fees are destroyed, removing those tokens permanently.

The mechanism is real. The sums are not. Over the previous 90 days the broader NEAR project generated about $14m in total fees, of which Intents accounted for roughly $13.9m. The base chain, excluding Intents, thus produced around $150,000 for the quarter.

At that level the burn does almost nothing to offset issuance.

2. Intents buybacks

Since February 23rd, part of the fees generated by Intents has been used to buy NEAR on the open market.

This is the clearest live value-capture mechanism NEAR has. The amount reaching the token is nonetheless far below the headline fee figure.

Over the trailing 30 days Intents processed $2.67bn of volume and charged $5.19m in fees. About $219,000, or 4.2% of those fees, reached NEAR revenue wallets and funded buybacks. Most of the remainder went to the specialist firms that complete transactions and to the applications that bring in users.

Sustained for a year, that rate would amount to roughly $2.6m: about 0.11% of the $2.37bn circulating market value, and enough to offset some 4.5% of the estimated $58m in annual issuance.

The distinction matters. NEAR does not simply need more Intents volume. It needs more of the value that volume creates to reach the token.

Widely circulated estimates have suggested that daily Intents volume of about $177m would make NEAR deflationary. That arithmetic assumes every dollar of gross fees funds buybacks. At the share actually observed, 4.2%, the required volume is closer to $2bn a day, roughly 22 times the current level.

The buyback is still a step worth taking. Plenty of networks discuss token value capture and never implement it. But the shortfall today is a value-capture gap, not a volume gap.

3. Staking in exchange for AI credits

NEAR’s newest idea is also its most inventive.

Rather than spending NEAR to buy AI, a holder can assign staked tokens to NEAR AI. The holder keeps the principal; the staking rewards pay for AI credits.

A company holds NEAR in its treasury. It assigns part of that holding to NEAR AI and receives a monthly allowance of private AI usage. Should it stop using the service, it can unassign and eventually recover the original tokens.

Staking becomes a recoverable subscription. It may persuade existing holders to lock up tokens and become customers without selling anything.

The economics have a ceiling, however. Staking rewards come from newly issued tokens, and NEAR AI may then have to sell those tokens to pay for chips, servers and hosting. The design locks up supply, which may support the price, but the service is funded by inflation. It is neither a burn nor a buyback, and it does not necessarily bring in a new buyer.

Its real merit is simpler. It converts a passive holder into an AI customer without requiring the holder to spend the underlying asset.

 

The Apollo Crypto View

 

NEAR is doing the harder engineering and telling the weaker financial story. Both things are true at once.

If private AI turns out to mean private conversations, Venice is ahead and has the users to prove it.

If the next wave consists of agents that hold credentials, use software, manage budgets and pay one another, the winning product will need more than a private chat window. It will need a confidential place to think, a controlled environment in which to act and neutral rails on which to transact. NEAR is further along that road than the market allows.

Investors, however, buy the token, not the stack.

On the available numbers, the Intents buyback, the main live link between usage and asset, produces an annualised buyback yield worth about 0.11% of circulating market value, against supply growth of roughly 2.5% a year. Some 96% of gross Intents fees currently goes to the services and applications that generate the volume. The AI products drawing all the attention contribute nothing measurable to the token at all. Revenue from NEAR’s products amounts, at the time of writing, to only about 17% of annual emissions.

The fee switch was the right call. The staking subscription is a clever piece of design. Neither yet gives holders a meaningful claim on the AI business.

NEAR’s task over the next four quarters is to keep growing while raising the share of that growth that reaches the token.

Disclosure: Apollo Crypto has exposure to NEAR

This report (‘Report’) has been prepared for informational purposes only and does not constitute an offer to sell or a solicitation of an offer to purchase any security of financial product or service. This Report does not constitute a part of any Offer Document issued by Apollo Crypto Management Pty Ltd (ACN 623 059 227, AFSL 525760) or Non Correlated Capital (ACN 143 882 562, AFSL 499882), the Trustee of the Apollo Crypto Fund. Past performance is not necessarily indicative of future results and no person guarantees the performance of any Apollo Crypto financial product or service or the amount or timing of any return from it. This material has been provided for general information purposes and must not be construed as investment advice. Neither this Report nor any Offer Document issued by Apollo Crypto or Non Correlated Capital takes into account your investment objectives, financial situation and particular needs. The information contained in this Report may not be reproduced, used or disclosed, in whole or in part, without prior written consent of Apollo Crypto. This Report has been prepared by Apollo Crypto. Apollo Crypto nor any of its related parties, employees or directors, provides and warrants accuracy or reliability in relation to such information or accepts any liability to any person who relies on it. You should obtain a copy of the Information Memorandum, issued by Non Correlated Capital before making a decision about whether to invest in the Apollo Crypto Fund.

Quinn Papworth

Quinn holds a Bachelor of Business from RMIT, majoring in Finance & Blockchain Enabled Business and has 4 years experience actively investing in crypto markets. Quinn is an analyst at Apollo Crypto and is deeply passionate about producing accessible crypto research content to help educate and onboard users.