A joint SentinelLABS and Censys research project scanned 175,000 publicly exposed Ollama hosts across 130 countries over 293 days, revealing a vast, unmanaged AI compute layer operating outside platform guardrails. The ecosystem is bimodal: a transient majority and a persistent core of ~23,000 hosts generating 76% of activity. Nearly half of hosts advertise tool-calling capabilities, enabling code execution and API access. Model adoption is highly concentrated around Llama, Qwen2, and Gemma2 in Q4_K_M quantization format, creating a software monoculture vulnerable to systemic exploits. Key threats include resource hijacking (free compute for spam/disinformation), prompt injection against RAG deployments, identity laundering via residential IPs, and governance gaps where attribution and enforcement mechanisms break down. The research frames this as a 'governance inversion': accountability is diffused across thousands of home networks while functional dependency concentrates in a handful of model lineages from a few labs.