JournalAI Policy

Field guide / 6

Sovereign AI needs separate answers for compute, law, models, and data

Sovereign AI is not one architecture. Turn the label into separate, testable requirements for infrastructure, jurisdiction, model control, and data flow.

Sep 1, 20266By ISH Team
Sovereign AI needs separate answers for compute, law, models, and data
Advertisement

Sovereign AI needs separate answers for compute, law, models, and data

“We need sovereign AI” can enter a procurement document as if it described one architecture. It does not. A system might run in the buyer's country on a foreign provider's hardware, use an open-weight model controlled by a domestic operator, and still send prompts to a support system abroad. Another might keep every byte on premises while depending on a model license, accelerator supply, and update channel that the operator cannot control.

Both may be called sovereign because the label compresses several requirements into one adjective.

Kilo's recent essay What Do We Mean When We Say Sovereign AI? describes an informal LinkedIn poll split almost evenly between infrastructure ownership and infrastructure location. The poll is anecdotal rather than representative. It still illustrates the terminology problem: technically interested respondents used one phrase for different control boundaries.

A buyer does not need a universal definition before proceeding. It does need to say what must stay under whose control, and which failure, dependency, or political event that control is meant to address.

Compute: who can keep the service running?

Compute location is easy to place on a map. Operational control needs more evidence.

The European Commission's AI Continent Action Plan ties regional AI capacity to at least 19 AI factories, up to five AI gigafactories, and public plus private investment. Its published figures include €200 billion to support AI development and €20 billion for the proposed gigafactories. The program combines accelerators and data centres with talent and support services.

The live EuroHPC AI Gigafactories call makes the physical layer more specific. Each facility should integrate three to four times the number of advanced AI processors in the most powerful current European AI factories. The call also asks for adequate power capacity and practices covering energy efficiency, water efficiency, and circularity. It opened on 30 July 2026 and lists a 12 November 2026 deadline.

Regional infrastructure does not make every workload on it sovereign in every sense. An operator still needs to identify who owns the facility, who administers the cluster, where encryption keys live, which remote support paths exist, and whether firmware or accelerator software can be maintained during a supply interruption.

Jurisdiction: who can exercise authority?

A server inside one country may be operated by a company subject to another legal regime. A domestic provider can subcontract support, observability, billing, or incident response elsewhere. Data residency narrows where data is stored or processed without settling every question about corporate control, lawful access, or cross-border administration.

The European Commission's June 2026 tech sovereignty package proposes an EU framework to assess cloud and AI sovereignty. The package also includes an open-source strategy and work on sovereign AI models for the energy sector. These are proposed policy measures, not proof that a particular service meets a finished sovereignty standard.

For developers, jurisdiction begins with a systems inventory. List each legal entity that can operate the service, every subprocessor, support location, account recovery path, and actor who can change access policy. Map them to the data and control planes they can reach. This does not replace legal advice. It gives counsel and procurement a concrete system to review.

Our article on ChatGPT's EU search-engine designation showed why product category and legal scope matter independently of branding. The obligations around a supposedly sovereign system follow its actual service and actors too.

Models: what can the operator replace?

Hardware ownership does not grant model control. A hosted model may be accessed from domestic infrastructure through an external API. An open-weight model may run locally while carrying license limits, a closed training recipe, unavailable data, or a tokenizer and serving stack maintained elsewhere.

Model control can be tested with replacement questions:

  • Can the organization retain and run the exact weights it approved?
  • Does the license permit the intended use, modification, and redistribution?
  • Can the operator reproduce the serving environment and apply security patches?
  • Can prompts, tool schemas, evaluations, and safety policy move to another model without rebuilding the application?
  • Is there evidence of which model version was actually served?

Open weights do not answer all five questions. A domestic endpoint does not either.

An API compatibility layer can reduce application coupling, including a service such as api.ish.chat when it fits the workload. Compatibility can make it easier to change inference endpoints. It does not create domestic compute, alter model licenses, or prove where requests travel. Portability is one control among several.

Data: follow every copy

“Local AI” sometimes means only that the agent loop runs locally. The model may remain remote. Another provider may generate embeddings. Traces, crash reports, prompt caches, moderation calls, and support bundles can create more copies.

Draw the path of one real request. Include user input, retrieved documents, the system prompt, tool arguments, the model request and output, logs, backups, and human support access. For every hop, record its location, operator, retention, key custody, and deletion behavior. Then test network egress instead of relying on a settings label.

Our Bandura review made the smaller version of this point. “Local” describes placement rather than complete protection. A local credential can be weakly protected, and a local agent can call remote services.

Replace the adjective with tests

A procurement team can turn “must provide sovereign AI” into requirements with observable failures:

  1. During a 24-hour loss of the external model provider, an approved fallback must serve a defined workload without changing the application contract.
  2. No prompt, retrieved document, or trace may leave named regions. Controlled network tests must verify the egress policy.
  3. Only listed legal entities and support locations may administer the service, with access events exported to the buyer's audit system.
  4. The buyer must be able to export model artifacts, prompts, evaluations, tool definitions, and operational logs in documented formats.
  5. Encryption keys must remain under the named operator's control, and recovery must not depend on an undeclared foreign support path.
  6. The deployment must publish energy and water measurements relevant to its facilities rather than treating domestic location as an environmental answer.

The environmental requirement belongs here because sovereign infrastructure remains physical infrastructure. EuroHPC includes energy efficiency, water efficiency, and circularity in its call. Our SCI for AI guide describes one way to give agent workflows an emissions denominator. National control does not remove the need to measure resource use.

No deployment will maximize every kind of control. Domestic hardware may cost more. Full model control may limit access to frontier capabilities. Strict residency can complicate global support, while portability may conflict with provider-specific optimization. Those tradeoffs can be evaluated once they are stated.

A usable requirement names the compute that must remain available, the jurisdictions allowed to touch the system, the model components that must be replaceable, and every permitted destination for data. Engineering can produce evidence for those statements. It cannot test an adjective by itself.

#sovereign AI#AI infrastructure#data residency#model portability#European Union
Advertisement

Keep reading

Related stories

Browse the archive