Sovereign AI: what it really means, once you strip away the slogans
3 min read
2026 has given the word “sovereignty” a concreteness it never had before. In Washington, the government and its principal AI supplier ended up in court — and federal agencies discovered overnight what it means to depend on a technology that someone else can switch off. Chinese open-source models have overtaken 45% of global traffic, putting the mirror-image question to every company. And Europe, between the “AI Continent” plan, compute gigafactories and local champions, is trying to build an alternative. Amid all this, the company that has to decide today what to build risks mistaking a slogan for a strategy. Let us do the opposite: reduce sovereignty to a set of verifiable facts.
The four questions that define it
1. Where the data resides — legally, not just geographically. A data centre in Europe is not enough if the supplier answers to jurisdictions that can compel access to the data. The precise question is: which law applies to my data, and who can force my supplier to hand it over? For the data that matters — customers, know-how, production — the answer has to be: European legislation, full stop.
2. Who can switch off what. Take stock of your dependencies: if the model supplier revokes access tomorrow morning (for policy reasons, for political reasons, through failure), what stops working in your company? The American lesson is that this scenario is not theoretical even for the most powerful customer in the world. Open weights run in-house have their structural advantage here: they cannot be revoked.
3. What it costs to switch. Sovereignty is not about buying everything European: it is being able to change without starting over. If the model is a replaceable component — because the value lies in your connected data, in the ontology, in the processes — then you can use the best model available at any given moment, American, European or open, and switch it whenever it makes sense. If, instead, your processes are hard-wired into one supplier’s APIs, you do not have a supplier: you have a landlord.
4. Who is accountable, and under what guarantees. Contracts with explicit usage limits, guarantees on training (your data does not feed it), advance notice of changes in model behaviour, and — for regulated sectors — a documented EU AI Act/GDPR/NIS2 Directive compliance chain. Contractual sovereignty is the forgotten half of technological sovereignty.
What sovereignty is NOT
It is not autarky: giving up the world’s best models on principle is a tariff your competitors will not pay. It is not a seal of approval: “sovereign cloud” on the brochure answers none of the four questions. And it is not a public-sector problem alone: the factory that halts its production line because an external service changed its terms has a sovereignty problem identical to that of a government ministry.
The operational synthesis
The strategy we see working is layered: data and the operational model kept in-house, under European legislation, non-negotiable; models and tools chosen case by case — open and run in-house for sensitive data, frontier models via API with enterprise guarantees where maximum capability is required — behind an architecture that keeps them replaceable; and every critical action under human control, by design. It is the definition of sovereignty that still stands even when the newspaper headlines change — and over the past six months they have changed often.
Want to measure your actual dependency — data, models, contracts — and the cost of reducing it? That is the work of a first session.