TGG/RESEARCH/SOVEREIGN AI

Sovereign AI: beyond hosting models locally

TGG RESEARCH AUGUST 2026 SOVEREIGN AI 12 MIN

"Sovereign AI" has become shorthand for buying GPUs and hosting a model inside national borders. That satisfies the press release. It rarely satisfies the requirement — because the requirement was never about where the servers sit. It is about who can access, alter, observe and switch off the system, and whether those answers hold under pressure.

The comfortable definition

Location is the easiest property to procure and the easiest to photograph. A data center is tangible; a ribbon can be cut in front of it. But a locally hosted model whose weights arrive from an uncontrolled source, whose updates are pushed by a foreign vendor, whose telemetry leaves the building, and whose operators depend on remote support has the sovereignty of a rented apartment: you live there, someone else holds the keys.

The inverse is also true, and less popular to say: a workload on hyperscale infrastructure, wrapped in customer-held keys, contractual jurisdiction, verified data paths and an exit plan, can be more sovereign in practice than a national data center run on foreign support contracts. Sovereignty is a property of the architecture, not the address.

Four properties that actually decide it

When we assess an "AI sovereignty" program, we test four properties. Each is checkable with evidence; none is satisfied by geography alone.

01 MODEL
Provenance of weights, right to evaluate, right to refuse an update, ability to reproduce or replace.
02 DATA PATHS
Every route data can travel — including telemetry, logs and support channels — enumerated and controlled.
03 ACCESS
Who holds keys, who can reach production, which jurisdiction can compel whom — answered with names, not diagrams.
04 OPERATIONS
Can your people run, patch, extend and recover the system if every external party disappears tomorrow?
FIG. 1 — THE FOUR SOVEREIGNTY PROPERTIES, EACH VERIFIABLE WITH EVIDENCE

The dependency ledger

The practical instrument is a dependency ledger: one line per external dependency — weights, hardware support, orchestration software, monitoring, expertise — with three columns. What breaks if this dependency is withdrawn? How long until it breaks? What is the substitution path? Most programs discover their real sovereignty posture in the second column. A ledger with honest entries is worth more than any architecture diagram, because it converts a political ambition into an engineering backlog.

Sovereignty is measured in the second column: how long until it breaks.

What to do on Monday

Three questions to put to any sovereign-AI proposal, internal or vendor-supplied. First: which of the four properties does this investment actually improve, and what is the evidence? Second: what does the dependency ledger look like the day after go-live? Third: what is the exit path from every component named in the proposal? If the answers are geographic, the proposal is about real estate — not sovereignty.

None of this argues against local infrastructure. It argues for buying the property you intend to buy. Location is one input among several — and on its own, the weakest.

TGG RESEARCH · DISCUSS THIS PAPER: DEV@TGG.GROUP ← ALL RESEARCH