Sovereignty Research

AI is usually framed as a competition for the most capable model. That framing misses a deeper transformation. As AI enters critical workflows, customers are no longer choosing only what a system can do. They are choosing who may operate it, alter it, restrict it — and ultimately stop it.

A company adopts an AI platform to summarise documents, assist developers and answer routine customer questions. The decision looks like conventional software procurement: compare capability, latency, security and price.

Then the system spreads.

It enters compliance reviews, credit decisions, industrial planning, internal knowledge systems and customer operations. Employees adapt their work to its behaviour. Applications are built around its interfaces. Evaluation suites, retrieval pipelines and approval procedures become model-specific. Business-continuity plans begin to assume that the service will remain available.

Several years later, the provider changes a model, withdraws an API or restricts a category of use. An export rule alters access to advanced compute. A regulator requires local hosting. A geopolitical dispute changes the conditions under which the service may operate.

The company discovers that it did not merely purchase intelligence as a service. It delegated part of its operating continuity to an external authority.

The original strategic question was:

What is the best AI for this task?

The question after integration is different:

Who controls the AI on which this task now depends?

This is the shift captured by the indispensability threshold: the point at which a platform transitions from a product into infrastructure. The answer will not produce one global AI market with minor regulatory variations. It is producing four distinct governance regimes: export platform, full-stack sovereignty, regulated dependence and market-conditioned access.

These regimes are not permanent national blocs. They are institutional arrangements for allocating authority over compute, models, data, deployment and continuity. A single country may use several of them at once. A single AI provider may offer all four.

The technology can remain substantially the same. The governance cannot.


Neutrality was a market condition

The first generation of commercial AI inherited an assumption from the global internet economy: software could be supplied across borders under one broadly uniform product model.

A model provider could offer the same API in dozens of countries. Customers could treat access as a private contractual relationship. Provider policies were interpreted as commercial terms rather than acts of public authority. Governments might regulate privacy, competition or consumer protection, but they did not necessarily regard model continuity as a strategic concern.

This created a form of platform neutrality.

Neutrality in this sense did not mean that providers lacked interests, policies or a home jurisdiction. It meant that those attributes were not yet decisive variables in the customer’s choice. The service could be treated as politically backgrounded because switching appeared possible and failure remained tolerable.

That arrangement works well for products. It becomes unstable for infrastructure.

Platforms scale through standardisation, discretionary rule-setting and the right to decide who can participate and under what conditions. Infrastructure is expected to provide continuity, reliability and non-arbitrary access under a recognised accountability regime. These are different governance logics. The first preserves provider flexibility. The second constrains discretion because other systems have come to depend on it.

AI currently sits between them.

For many customers, it remains a product: useful, optional and replaceable. For others, it is becoming a platform around which applications and organisational routines are built. In a smaller but growing category of deployments, it is becoming infrastructure: its absence would no longer create inconvenience but operational failure.

Neutrality is easy when exit is easy. Once exit becomes impractical, provider discretion acquires a different meaning.

A model update is no longer merely product development. A regional restriction is no longer merely compliance. A capacity allocation decision is no longer merely account management. For a dependent user, each can amount to an external intervention in its operating environment.


The indispensability threshold

AI does not become infrastructure simply because it is popular, expensive or technically sophisticated. It becomes infrastructure when its removal would require the redesign of the underlying activity.

A practical diagnostic is:

Critical workflow × external control × high exit cost × jurisdictional exposure = infrastructural indispensability

This is not a mathematical equation. It identifies four conditions that become dangerous when they coincide.

The first is criticality. The system has entered a workflow whose interruption would affect safety, public services, regulated obligations, production, revenue or institutional legitimacy.

The second is external control. Essential decisions remain with a model provider, cloud operator, chip supplier or foreign authority.

The third is exit cost. Replacing the service would require more than moving data or changing an API endpoint.

The fourth is jurisdictional exposure. Access can be changed by export controls, sanctions, localisation requirements, licensing decisions or conflict between legal systems.

Exit costs are particularly easy to underestimate. An organisation does not become dependent only on model weights. It becomes dependent on:

  • prompts and system instructions
  • retrieval and data pipelines
  • tool schemas and agent workflows
  • model-specific evaluation results
  • fine-tuning and safety evidence
  • employee knowledge of a model’s behaviour
  • regulatory approvals and validation records
  • latency, capacity and cost assumptions
  • operating procedures built around a provider’s failure modes

A customer may possess a complete copy of its data and still be unable to move the workload.

That distinction matters. Data portability is not operational portability.

The threshold has been crossed when redundancy planning stops asking, “Which alternative will we switch to?” and begins asking, “How will we continue operating while the system is unavailable?”

At that point, authority mismatch becomes visible. The customer is accountable to shareholders, regulators, patients, citizens or industrial operators, but may not control model availability, version changes, inference geography, capacity priority or acceptable-use boundaries. One actor possesses the control surface. Another bears the consequences.


The AI control stack

For governance analysis, the AI stack should be read in terms of where concrete decision rights reside.

LayerWhat is controlledThe decisive question
ComputeChips, data centres, energy and scarce capacityWho receives capacity, and who may be denied it?
CloudHosting, identity, networking and service continuityIn which jurisdiction may the system operate?
ModelWeights, APIs, versions, safeguards and behaviourWho may alter or withdraw the capability?
DataTraining, retrieval, retention and cross-border movementWhich information may be used, stored or transferred?
WorkflowAgents, tools, procedures, evaluations and human routinesCan the function be moved without being redesigned?
AuthorityFinal operating boundaries and crisis decisionsWho can ultimately say “yes,” “no” or “stop”?

The last layer is often absent from technical architecture diagrams, but it governs all the others.

Technical control alone is not sovereignty. A provider may be technically able to disable a service without possessing legitimate public authority to determine the customer’s policy. Conversely, a government may claim sovereign authority without possessing the technical means to exercise it.

A more useful definition of sovereignty has three elements:

  1. Decision finality: someone has the recognised right to make a binding decision.
  2. Boundary control: that authority can determine access, continuity, geography and shutdown conditions.
  3. Accountability coupling: the authority bears responsibility for the consequences.

Where these elements are separated, sovereignty is weak or mismatched. The Starlink–Starshield analysis identifies precisely this problem: systems can be expected to provide infrastructure-grade continuity while remaining governed through platform-style discretion.

This is also why local hosting does not, by itself, create sovereign AI. A model can run inside a national data centre while its updates, licensing, capacity allocation, encryption hierarchy or critical software dependencies remain controlled elsewhere.

Data residency is not decision finality.


From one market to four regimes

The usual account of AI fragmentation focuses on regulation, protectionism or strategic competition. All matter, but none fully explains the direction of the market.

The deeper mechanism is dependency.

As AI becomes embedded in critical workflows, external control becomes politically and organisationally visible. Customers demand continuity guarantees, audit rights, local operating authority and credible exit options. Governments become less willing to tolerate an unaccountable external veto over public administration, defence, finance, healthcare or industrial capacity.

Providers respond by creating separate deployment, contractual and control arrangements. Markets that were unified at the model layer begin to fragment at the governance layer.

The causal sequence is:

Adoption → integration → rising exit cost → indispensability → visibility of external control → demand for assurance → regime separation → market fragmentation

The four resulting regimes are analytical ideal types. They describe where control resides and how access is made legitimate.

RegimePrimary locus of controlCore propositionPrincipal risk
Export platformProvider and its home jurisdictionRapid access to a globally scaled AI stackExternal policy and continuity dependence
Full-stack sovereigntyDomestic or sovereign institutionsControl across compute, cloud, models, data and operationsCost, duplication and capability gaps
Regulated dependenceLocal law and procurement layered over an external stackGlobal capability subject to graded local assuranceFormal control may exceed technical control
Market-conditioned accessLarge buyer, public procurer or local consortiumAccess granted on locally negotiated termsComplexity, inconsistency and partial localisation

1. Export platform

The export-platform regime treats AI as an integrated stack that can be deployed outward: chips, data centres, cloud services, models, applications, standards and financing.

Its advantage is scale. Customers receive advanced capabilities without reproducing the whole supply chain. Providers gain global reach, network effects and ecosystem lock-in. The exporting state extends its technical standards and commercial influence.

The United States made this logic explicit in a July 2025 executive order creating an American AI Exports Program centred on full-stack packages that can include hardware, cloud infrastructure, data pipelines, models, security measures and sector-specific applications. The order also asks consortia to identify target countries and explain who will build, own and operate the associated infrastructure. (The White House)

The export platform is not simply a commercial channel. Control follows the stack.

A customer may host data domestically and employ local operators while remaining dependent on foreign-origin chips, software licences, model updates and export permissions. U.S. guidance issued in May 2026 clarified that licensing requirements for certain advanced computing items can follow the headquarters or ultimate parent of an entity even when that entity is located elsewhere.

This does not make export platforms inherently unreliable. For many countries and companies, they will remain the fastest and most economically rational route to advanced AI. The regime becomes problematic when the customer confuses access with control.

A contract may guarantee service under ordinary conditions. It cannot necessarily neutralise the provider’s home-state law, sanctions obligations, export policy or emergency authority. The relevant purchasing question is therefore not merely whether the exporter is a trusted partner today. It is whether continuity remains governable if the relationship changes tomorrow.

2. Full-stack sovereignty

Full-stack sovereignty seeks control over the complete operating chain: compute, cloud, models, data, engineering capability and final authority.

Its objective is not simply to keep data inside national borders. It is to ensure that no external actor possesses a unilateral veto over a critical capability.

This can involve domestic chip programmes, state-supported data centres, national model development, public data resources, local software ecosystems and government-controlled deployments. China represents the clearest large-scale example of this direction, although no country is completely self-sufficient.

China’s rules for public generative-AI services place those services within a framework of national security, public interest, data governance and provider obligations — encouraging innovation in foundational algorithms, frameworks, chips, software platforms and shared compute infrastructure, as well as the use of secure and trusted technology resources. (China Anti-Corruption Website)

The attraction is decision finality. A full-stack sovereign system can align technical control with domestic political authority. It reduces exposure to foreign export controls and creates greater freedom to establish local operational boundaries.

The costs are substantial. Frontier compute is capital-intensive. Domestic ecosystems may duplicate global investment. Smaller markets may struggle to sustain model development, tooling, talent and specialised infrastructure. Sovereign systems can also become less competitive if protection from external dependency turns into insulation from external innovation.

Full-stack sovereignty is therefore most plausible where the stakes are exceptionally high, the market is large, or the state is willing to absorb significant inefficiency in exchange for control. It is unlikely to be the default regime for every workload.

3. Regulated dependence

Regulated dependence accepts that the most capable or economical technology may remain externally supplied. Instead of replacing the stack, the jurisdiction attempts to domesticate its operation through law, audit, procurement and graded assurance.

This regime can require local data processing, transparent software supply chains, local key custody, independent operators, change-control rights or restrictions on foreign legal interference.

The European Union’s proposed Cloud and AI Development Act offers a clear expression of this model. Published in June 2026, the proposal combines greater European capacity with a single sovereignty-assessment framework and a common public-sector procurement mechanism. It defines four assurance levels, ranging from EU-based data processing to stronger requirements concerning third-country independence, EU ownership and control, software-supply-chain transparency and protection from external interference — while the Commission states that the wider market should remain open to partners. (Digital Strategy)

That is not autarky. It is differentiated dependence. The same underlying technology can be admitted under different conditions according to the consequences of failure.

The strength of this regime is proportionality. It avoids the expense of rebuilding every layer while making governance requirements visible.

Its weakness is the possibility of sovereignty theatre. A service may receive a sovereign label because it runs in a local facility, while the foreign provider retains decisive control over model updates, capacity, software maintenance or suspension. Legal restrictions can improve accountability, but they cannot manufacture technical independence where none exists.

Regulated dependence succeeds only when assurance claims correspond to real control surfaces.

4. Market-conditioned access

Market-conditioned access relies on bargaining power rather than complete ownership.

A large country, public procurer or industrial consortium offers providers access to demand in exchange for local capacity, partnerships, investment, language support, public-sector commitments, data boundaries or some transfer of operating control. The objective is not to build every component domestically. It is to prevent foreign capability from entering solely on the provider’s terms.

India’s public compute programme illustrates one component of this model. The IndiaAI Mission announced more than 18,000 affordable compute units through an empanelment process involving local and international technologies supplied by multiple cloud, managed-service and data-centre providers. The state aggregates demand, subsidises access and creates a domestic allocation mechanism rather than relying exclusively on individual customers negotiating with global vendors. (IndiaAI)

This regime can coexist with an export platform. At the 2026 India AI Impact Summit, the United States described a model in which partner-country “national champions” would be incorporated into customised American AI export stacks, promoting strategic autonomy without requiring full self-sufficiency. (The White House)

Market-conditioned access is especially attractive to countries that possess significant demand but cannot economically reproduce the frontier stack. Its strength is leverage. Its weakness is fragmentation at the operating level: every market may require different partners, entities, contracts, hosting arrangements and compliance layers.

For providers, the world becomes more expensive to serve. For buyers, it becomes more governable.


Fragmentation without different models

AI fragmentation does not require every country to develop a distinct frontier model.

The same model family can operate through several institutionally different products: a global public API; a locally hosted commercial instance; a sovereign-cloud deployment; a government-controlled version; an open-weight model operated by a national provider; a joint venture in which keys and control planes are held locally; a regulated instance with separate logging, retention and update rules.

The technical core may be similar. The surrounding rights can differ substantially.

One deployment may permit unilateral provider updates; another may require customer approval. One may use provider-controlled encryption keys; another may require local key custody. One may receive best-effort capacity; another may have contractual priority. One may operate under general terms of service; another may specify crisis authority, rollback rights, audit access and suspension procedures.

As a result, price and performance will diverge by jurisdiction. A sovereign or highly assured deployment will often cost more, update more slowly and offer fewer features than the global product. Those differences are not necessarily technical inefficiencies. They are the cost of a different authority structure.

The competitive market therefore begins to reward more than model quality. Providers must increasingly sell continuity, jurisdictional assurance, auditability, local operating authority, change control, supply-chain transparency, and credible exit and migration support.

Capability remains essential. But in critical markets, it becomes the entrance ticket rather than the final differentiator.

Governance becomes part of the product.


The institutional-separation pattern

The likely response to market fragmentation is not a choice between one universal platform and complete national self-sufficiency. It is institutional separation.

The Starlink–Starshield case provides an early design pattern. A common technical foundation can be divided into services with different authority, accountability and compliance regimes once commercial platform governance can no longer carry the obligations of critical use.

AI providers are likely to follow a comparable pattern:

Commercial AIRegulated or sovereign AI
Standard terms of serviceExplicit authority and accountability
Provider-directed updatesNegotiated change and rollback rights
Shared global control planeJurisdiction-specific control plane
Provider-controlled keysCustomer- or state-controlled keys
Best-effort capacityContracted or prioritised capacity
Standard audit evidenceSector-specific assurance and chain of custody
Provider-defined suspensionPredefined crisis decision procedures

Institutional separation can protect both sides. Critical customers receive a governance regime appropriate to their dependency. Providers avoid imposing the cost and rigidity of infrastructure-grade obligations across their entire commercial market. High-stakes decisions become procedural and contractual rather than improvised.

But separation can also be cosmetic. A “sovereign” AI service is weak if the same external actor can still withdraw the model, deny replacement hardware, control all updates, revoke licences or reallocate the necessary compute. A local control plane is valuable, but it does not neutralise every upstream dependency.

The purpose of separation is not to eliminate dependence. It is to make the allocation of dependence, authority and accountability explicit.


Five questions for the board

The practical implication is that potentially critical AI should no longer be procured capability-first. Governance should be established before deep integration, accounting for the loss of future options while those options still exist.

1. Who can stop it?

Identify every actor capable of suspending, constraining or materially altering the service: the model provider, cloud operator, chip supplier, software licensor, export authority, regulator and local infrastructure partner. The answer should describe technical power, legal power and contractual power separately.

2. How long can we operate without it?

“High availability” is not an answer. The organisation should know when absence progresses from inconvenience to process degradation, contractual breach, regulatory exposure or inability to perform the function. This is the real measure of criticality.

3. Can we move the workload, not merely the data?

A credible migration plan must include prompts, tools, agents, evaluations, integrations, fine-tuning assets, safety evidence, user procedures and performance assumptions. An untested alternative is not an alternative.

4. Who bears accountability?

Compare the actor that controls the system with the actor responsible for the outcome. The greater the distance between control and accountability, the greater the authority-mismatch risk.

5. What option space are we losing today?

Every new integration should be evaluated for its effect on time-to-exit, number of credible substitutes, retraining cost, revalidation requirements and bargaining power. Dependency often becomes dangerous gradually. No single decision creates lock-in; each decision removes another future alternative.


What would weaken the argument?

Fragmentation is not inevitable in every part of the AI economy.

Neutrality can remain stable where AI is peripheral, failure is tolerable and switching is credible. Common interfaces, open weights, portable evaluations and genuinely tested alternatives can slow the transition to indispensability. International agreements could also align continuity expectations across jurisdictions.

Nor should every localisation policy be interpreted as evidence of governance fragmentation. Data protection, cybersecurity, industrial subsidies and ordinary protectionism can produce similar-looking outcomes.

The mechanism proposed here is present when localisation is accompanied by demands for crisis decision rights, control over model changes, continuity guarantees, capacity priority, jurisdictional assurance, explicit suspension conditions, and credible functional substitution.

The thesis would be weakened if globally governed AI platforms remained indispensable to critical processes for an extended period without producing institutional separation, governance-based procurement, sovereign capacity investment or recurring conflict over decision rights. That outcome is possible. It is simply not the direction in which the strongest current signals point.


The market after capability

There will not be four perfectly bounded AI worlds. The regimes will overlap, combine and compete.

An American export platform may incorporate a local national champion. A European buyer may use an American model under a high-assurance EU operating regime. India may combine foreign chips, domestic data centres and public allocation. China may use foreign technology selectively while maintaining sovereign authority over public deployment.

The decisive division is therefore not between open and closed countries, or between domestic and foreign models. It is between different answers to four questions:

Who controls the stack?
Who guarantees continuity?
Who may change the operating boundaries?
Who is accountable when the system fails?

AI began as a market in which customers compared models.

It is becoming a market in which they compare governance regimes.

The most capable model will not always win. In critical environments, the winning system will be the one that can be deployed under an acceptable allocation of access, authority and risk.

One technology will support four governance regimes because capability can be globalised more easily than control.