Small models, trained for the work — and kept current. Baru and Nabu do not run one general model over everything. They run customised language and perception models — open-weight bases adapted, quantised and distilled for a specific job, on the specific tier where that job runs.
foundation models pre-trained. Every model starts from a strong open-weight base
steps from base to fielded model: start strong, tune efficiently, fit the tier, shrink the hot path
size bands, defined by deployment tier rather than parameter count
rule for promotion, shared with personas and skills: nothing that passed before may fail now
Source: S1, S5.
A radar return, an RF signature, a Quebec formal notice, a clinical screening flag: each has a vocabulary a general model has seen rarely and a failure mode it cannot recognise. The work that matters most is where a model trained on the open internet is least prepared.
A carried node has a power and memory budget a frontier-scale model cannot enter. A model that only runs at the centre stops when the link does — and in Baru’s environments the link is the exception. Size is what the tier permits.
The material that would make a model good at the job is the material not permitted to leave the building. Adaptation has to happen where the data is, on hardware the operator controls, under the same custody as everything else.
A fielded model drifts: the vocabulary moves, the sensors change, the base is superseded. Capability is moving into small open-weight models faster than any one vendor’s roadmap. The value of a platform is moving from the model to the lifecycle around it.
Four steps, one model per job, sized to where it runs. Enkidu does not pre-train foundation models; it makes strong open bases excellent at your task. Start strong — the strongest open-weight base for the job. Tune efficiently — parameter-efficient fine-tuning, so the adaptation is small, auditable and cheap to re-issue as the mission changes. Fit the tier — quantised to the deployment tier’s memory and power envelope. Shrink the hot path — a student distilled from a larger teacher where single-digit-millisecond inference is required.
On Baru — the trusted intelligence-fusion platform — this means one specialist per modality: vision, RF, acoustic, LiDAR, text, each tuned to its telemetry vocabulary and served where the data is. On Nabu — the trusted investigation & discovery platform — the reference deployment runs a reasoning model, retrieval and embedding models, a speech model and a safety-screening model as co-resident services, each a separate custody item that can be adapted, replaced or rolled back on its own.
| Band | Where it runs | What it does | How it is made |
|---|---|---|---|
| Micro | Node tier — Jetson Orin class; a team, a vehicle, an autonomous platform | One modality, one job, on the hot path: signature classifiers, RF and acoustic specialists, safety screens | Distilled student of a larger teacher; quantisation-aware; validated on the tier |
| Small | Hub tier — Jetson Thor class; fuses a cluster | Per-modality specialists with more context; drafters for speculative decoding; embedding and retrieval | PEFT adaptation of an open base; quantised to the hub envelope |
| Medium | Centre tier — Grace-Blackwell class; Nabu reference node — DGX Spark class | Domain-adapted reasoning; the verifying target in speculative decoding; interview and narrative models | PEFT adaptation of a strong open base; quantised where the envelope requires |
Source: S2, S3, S5.
A model is only as defensible as the data that shaped it and the record that carries it. Every training corpus passes an anti-poisoning ingestion gate — provenance-checked sources, integrity controls, documented lineage — the same policy decision point that admits an observation into Baru or a document into Nabu, because training data is operational data. Every model shipped is versioned, signed and entered into the chain of evidence; every deployment is reproducible from the recorded recipe. The registry entry carries the parent model, the build recipe, the evaluation gate it passed and the transfer path it took to the node, and Kittu’s pre-flight check reads that entry before the model may run.
Movement is logistics; the gate decides. Weights move across a fleet by whatever path is fastest and permitted, but movement is never trust: every install is verified against the registry and recorded into custody, and loading fails closed. What may be distributed is exactly the set the registry has activated. A reviewer who asks “which model produced this?” gets not a version string but a chain — the base and its licence, the corpus and its gate, the adaptation and its recipe, the evaluation and its threshold, the person who activated it and the policy under which they did.
A model is never finished. It is current, or it is superseded — and the record shows which, for every node, at every moment. Drift monitoring runs alongside operational metrics so degradation is caught, not discovered. Telemetry is de-identified before it is used to improve a model. Failures are mined and each becomes a golden task — a case the next version must get right. Retraining re-issues the adaptation from the same base and recipe, which is what makes it small, auditable and cheap enough to do often.
A new version is promoted only if every prior golden task still passes, the pass rate strictly increases, and at least one mined failure resolves — the same zero-regression rule the persona and skill libraries use. Activation is a person’s decision, recorded in the registry per tier and continuum.
Nusku — fleet control, one of the four Ekur capabilities — is how the declaration becomes true across the fleet. Fleet state, meaning which model versions run on which nodes under which conditions, is declared at the centre, signed, and pulled by nodes. A node dark for a day converges to the same model set as one that never lost its link. Control never carries data. Updates are staged, health-gated and A/B per zone, with automatic rollback if the health gate fails; the fleet reports by exception, so an operator sees departures from the declaration, not a stream of confirmations.
Enkidu commits to keeping fielded models current: monitored for drift, retrained against mined failures, re-evaluated under the zero-regression rule, and redistributed under Nusku — as an operating practice of both platforms, not as a project.
Both platforms can be fielded with a variety of models. Which one runs, where, and under which conditions is the end user’s declaration — held as policy, distributed by Nusku, admitted by the gate on each node. A model selection is a policy binding, not a rebuild.
| Condition | On Baru | On Nabu |
|---|---|---|
| Normal operation, link present | Hub specialists fuse the cluster; the forward centre runs the medium reasoning model | The domain-adapted reasoning model; retrieval and speech models co-resident |
| Link lost | Nodes continue on micro specialists; abstentions queue for reconciliation on return | Local models only; the aperture is closed; the deliverable discloses what could not be checked |
| Envelope reduced | A smaller quantised build declared for the tier takes over; the swap is a custody event | Speech deferred; reasoning continues on the quantised build |
| Regulated-practice task | — | Only the adaptation fenced for that tier is admitted; it cannot be replaced by configuration |
| New sensor or jurisdiction | A new specialist is adapted, evaluated and activated; the old one is superseded, not deleted | A new adaptation is registered beside the existing one; the operator declares which continuum uses which |
| A base model is superseded | Adaptations re-issued on the new base under the same recipe; the operator decides when each tier moves | Same rule; the golden tasks decide whether the move is a promotion |
Illustrative policy bindings — the shape of the declaration, not a configuration. Source: S5, S6.
A small drafter proposes; the authoritative target verifies every token, so acceleration cannot alter assured behaviour. Enkidu is evaluating it on Baru’s own sensor-fusion prompts, not public prompt sets.
Speculative decoding→Holding a student’s accuracy through the quantisation the node tier requires, so the micro band is a real model rather than a degraded one.
Quantization-aware distillation→Peer-to-peer transfer within zones, a governed depot across them, the install gate deciding what may serve.
NVIDIA ModelExpress→Adaptations fenced to a tier and benchmarked against external judgments.
Evaluation and prototyping activity — no availability, customer, or performance claims.
No number on this page is an Enkidu measurement of an Enkidu model. Baru is in prototype; Nabu’s Legal implementation is specified to a build-book whose figures are planning envelopes measured at named validation gates. The one performance figure cited in this programme — a 3.43× decode gain from speculative decoding on Jetson AGX Thor — is NVIDIA’s measurement on the hub-tier silicon Baru specifies, not Baru’s, documented with its regressions on the smallest nodes and under batching.
Exact model selections and quantisation budgets per tier are left to detailed design; per-tier speech sizing is open research. Size bands describe tiers, not parameter counts, and will be revised as the open-weight landscape moves. Activation is a human decision; no model self-promotes.
S1 — Enkidu. Baru — Intelligence Fusion: models built for the mission.
S2 — Enkidu. Enlil Conceptual Architecture, v0.16. 2026 — internal record.
S3 — Enkidu. Dinanu Conceptual and Technical Architecture, Rev B. 2026 — internal record.
S4 — Enkidu. Speculative Decoding in Baru, ENK-WP-2026-002.
S5 — Enkidu. Model Training & AI Research, technical whitepaper ENK-TWP-2026-005, September 2026.
S6 — Enkidu. Nusku — Fleet Control.