model releaseObservedPublished: 13h ago

What do we mean by sovereign AI?

Everyone, it seems, now wants "sovereign AI". The UK government has launched a £500m Sovereign AI fund to back British artificial intelligence (AI) startups. Cloud providers advertise it . Industry analysts expect sovereign cloud and AI services to take-off this year. Yet in conversations with senior leaders over recent months, I have noticed something odd. Ask five people what AI sovereignty means and you will get five different answers. Some talk about where data is stored. Others talk about building British AI models. A few mean something closer to national security. Most, if pressed, admit they are not quite sure. That vagueness matters. A term that means everything ends up justifying anything, from a major public investment to a vendor's rebranded hosting package. So it is worth slowing down and asking what we are really talking about. One word, five issues Sovereignty is not a single property. When people use the word, they are usually mixing together at least five different ideas. Ownership is about who holds the asset - the data, the servers, the model. Control is about who can operate it, change it or switch it off. Jurisdiction is about whose laws apply and whose courts can compel access. Capability is about whether you have the skills to build or run it yourself. Optionality is about whether you can walk away and use something else without serious damage. These are relatively independent. Storing your data in a UK datacentre may give you a sense of ownership, but it does not settle the question of jurisdiction. The US Cloud Act , passed in 2018, allows US authorities to seek data held by US-based providers wherever it happens to be located. That is not a theoretical concern. In 2025, Microsoft's legal director for France told a French Senate inquiry that the company could not guarantee French public-sector data would be shielded from such demands, while noting that no such demand had in fact been made. Location, in other words, is not the same as control. Why this matters to you It is tempting for leaders in banks, local authorities, universities or NHS trusts to treat AI sovereignty as a matter for ministers. That would be a mistake. The same questions apply to every organisation that is now building AI into how it works. The difference is one of scale, not of kind. When I look at the AI deployments organisations are making, I see five layers where important choices are being made, and where sovereignty is won or lost: Data: where it lives, who can access it, and under whose rules. Infrastructure: the compute, cloud and chips your services run on. Models: whether you can inspect, adapt, move or replace the models you depend on. Governance: whether you set the rules for how AI is used in your organisation or simply inherit them from a supplier's terms of service. Capability: whether you have people who understand what they are buying and running. Each of the five ideas above can be tested at every one of these layers. Who owns our data? Who controls our models? Whose law governs our infrastructure? At national level there are further layers, such as where the economic value of AI ends up and whether models reflect our languages and institutions. But for most organisations, these five are where the practical decisions have most impact. When 'sovereign' is just a label This matters because the market has already noticed the demand. Suppliers large and small now attach the word "sovereign" to their cloud and AI offerings, and analysts expect the trend to accelerate. IDC, for example, forecasts that by 2028, 60% of organisations with digital sovereignty requirements will have migrated sensitive workloads to new cloud environments. That is a forecast rather than a fact, but it shows the direction of travel. “AI sovereignty is not about independence from the world. It is about knowing which dependencies you have, choosing them deliberately, and keeping a credible way out” Alan W. Brown The risk for senior leaders is buying the label rather than the substance. A "sovereign" service may keep your data in the UK while the encryption keys, the support engineers and the contracting legal entity sit elsewhere. It may run a model you cannot move, on terms you cannot influence. So, when a supplier offers sovereignty, the right response is to ask which of the five layers it actually covers. Who holds the keys? Who can access the system, and from where? Which law governs the contract? What happens to your data, your prompts and any models tuned on your information when the contract ends? The answers will tell you far more than the brochure. The silent lock-in trap Yet, we also need to be realistic. Full sovereignty across all five layers is unaffordable for almost every organisation, and for most countries too. Dependence on large technology suppliers is not a failure - it is a condition of using AI at all. However, there is a world of difference between dependence you have chosen with your eyes open and dependence you have drifted into. In my book, Making AI work for Britain , I describe this drift as silent lock-in. It does not arrive through a single dramatic contract. It accumulates, one pilot and one integration at a time, until an organisation discovers it can no longer leave. As I argued in Computer Weekly when the book launched, "No market stays plural on its own. Left to itself, enterprise AI will concentrate." This is why I think the most useful test of sovereignty is not ownership but optionality. Can you leave? How long would it take? What would you lose? The book's answer is to design exit in from the start - what I call exit-by-design - and to invest in being a smart buyer by having, as I put it in that same piece, "a small core of people who can sit opposite a vendor and know what they are looking at." A message for policymakers For those in government, the lesson is uncomfortable. National AI sovereignty is not only built through flagship announcements. It is built, or eroded, through thousands of procurement decisions made across the public sector every year. The UK government's Sovereign AI Unit is a welcome signal of intent. But in my most recent Computer Weekly column , I pointed out a gap - the state "is buying capability it will not own and has not secured the means to leave." Supporting British AI firms is valuable. Yet unless contracts secure data portability and transition arrangements, the state may simply be swapping one form of dependence for another. The book's position is clear - the UK does not need to build its own foundation models to exercise sovereignty over AI. It needs to consolidate demand and diversify supply, using its buying power to keep the market open. Others are pressing the same point. The Open Rights Group has urged the government to adopt a digital sovereignty strategy, warning that over-reliance on US technology companies carries risks comparable to depending on a single country for energy. You do not have to agree with every part of that argument to recognise the underlying concern. What matters now AI sovereignty is not about independence from the world. It is about knowing which dependencies you have, choosing them deliberately, and keeping a credible way out. I am pleased to see this framing gaining ground. A forthcoming book from Public Digital, Digital sovereignty: The power to decide , defines digital sovereignty as "the agency to make deliberate choices about your digital future, and the capacity to follow through on them." I look forward to reading it. So, rather than asking whether your organisation is "sovereign", I would suggest asking three sharper questions: Which AI services would we struggle to operate if a supplier changed its terms, prices or availability tomorrow? Whose law, in practice, governs our data and the models we rely on? If we needed to switch supplier, could we, how long would it take, and who in our organisation would know how to do it? If the answers are uncomfortable, that is useful. It means the conversation about sovereignty has finally moved from slogans to decisions. Alan W. Brown is Professor of Digital Economy at the University of Exeter Business School and research director at the Digital Policy Alliance. He is the author of Making AI Work for Britain (London Publishing Partnership, 2026).

Download social card
Copy launch post

Why this byte is shareable

Signal quality

observed

Confidence badge and source context included.

Entity anchor

AI News

Clear company or model context for distribution.

Export ready

1200 x 630 card

Optimized for X, LinkedIn, and chat previews.

Why it matters

AI News can change capability, routing, cost, or product scope for builders shipping against current model APIs.

Suggested launch post

Use this in X threads, community posts, internal team chats, or launch recaps.

What do we mean by sovereign AI?

Why it matters: AI News can change capability, routing, cost, or product scope for builders shipping against current model APIs.

Source: Techtarget
https://a2zai.ai/bytes/what-do-we-mean-by-sovereign-ai-2c6a0f18
Post to X
Copy text

Permalink: https://a2zai.ai/bytes/what-do-we-mean-by-sovereign-ai-2c6a0f18

Social card: https://a2zai.ai/bytes/what-do-we-mean-by-sovereign-ai-2c6a0f18/opengraph-image

Social and community

Discussion