Skip to content

Digital Sovereignty and National AI Strategies

4 min read · updated August 3, 2026

“Sovereign AI” is used for four different capabilities that are only loosely related. Separating them is the whole analysis, because a strategy that buys one and was justified by the threat model for another is a strategy that will not deliver what it promised.

Four claims in one phrase

MeaningDescription
data sovereigntyData about residents stays under domestic jurisdiction — residency requirements, local processing, restrictions on transfer.
compute sovereigntyPhysical machines located domestically and, in the stronger version, domestically owned and allocated by a domestic body.
model sovereigntyModels trained domestically, on domestic data, in the national language, with content policy set domestically.
supply chain sovereigntyDomestic ability to design, fabricate, package and power the hardware. The strongest form and the one almost no state possesses.

They are not a ladder. A country can have data residency with no domestic compute, or a national model trained entirely on foreign hardware in a foreign cloud. Announcements routinely use one word for all four.

Matching each to a threat model

Data sovereignty

The threat is foreign legal process reaching data about residents, and foreign intelligence access. The important and frequently missed point: the threat is legal, not geographic. Several jurisdictions assert extraterritorial reach over data held by companies subject to their laws regardless of where the servers sit, so a local data centre operated by a subsidiary of a foreign parent may not defeat the process it was built to defeat. What resolves that is corporate structure, operational control and key custody — a sovereign cloud arrangement in the substantive sense — rather than the coordinates of a building. Residency also does nothing about a supplier withdrawing a service.

Compute sovereignty

The threat is denial of capacity: export controls, allocation decisions made abroad during shortage, price shocks, or a supplier declining to serve a particular workload. Domestic compute genuinely addresses these, and it addresses none of the others — a domestic cluster full of imported accelerators remains dependent on the supply chain for replacements, and running a model whose licence can be revoked on domestic hardware does not confer control over the model.

Model sovereignty

Two distinct threats here, worth separating. One is content and behaviour policy set elsewhere — refusals, framing of contested history, values embedded through alignment choices made in another society. Domestic models genuinely address this and it is a legitimate public interest rather than a protectionist excuse. The other is language and cultural under-service: models trained predominantly on a few languages are measurably worse for the rest, and no foreign provider has a strong commercial reason to fix that for a small language community. This is a well-evidenced gap and one of the better arguments in the whole area. Neither threat is addressed by owning hardware.

Supply chain sovereignty

The threat is total denial in a serious geopolitical event. This is the only version that answers it, and the reason it is rare is arithmetic: the fixed costs of a leading-edge fab and the accumulated process knowledge behind it are not purchasable on a national budget in a single cycle. Partial versions — packaging, mature nodes, domestic design with foreign fabrication — are achievable and are often what a “semiconductor sovereignty” programme actually means.

The cost side nobody puts in the announcement

Frontier training costs are set globally and do not scale down with the size of the country doing it. A state with a small domestic market pays approximately the same fixed cost as a large one and spreads it over far fewer users. That is a hard economic constraint and it is the main argument made by economists who are sceptical of national model programmes.

The counter-argument, made by proponents, is that capability retention is the point: a programme builds people, institutions and evaluation capacity that persist after the model is obsolete, and that capacity is what makes a state an informed buyer, regulator and negotiator. That is a real benefit and it is not captured by comparing the model to what could have been bought.

There is also a recurring finding in the technology diffusion literature worth putting on the table without overstating it: for most economies, the returns to adoption capacity — skills, data infrastructure, process change — have historically exceeded the returns to domestic production of the technology itself. Whether AI follows that pattern is an empirical question that is not settled, and both sides of the sovereignty debate cite the diffusion literature for opposite conclusions.

Instruments and their failure modes

  • Public compute facilities. Address compute sovereignty and researcher access. Failure mode: capital funded, operations underfunded, resulting in underutilised hardware and no budget for the staff who would make it usable. Recurrent cost is the thing to check.
  • National language corpora and evaluation suites. Low cost, high leverage, and useful to domestic and foreign models alike. The most reliably worthwhile item on this list and the least announced.
  • Procurement preferences. Fast to implement. Failure mode: protecting a domestic supplier from the competition that would have made it good.
  • Residency requirements. Address a legal threat only partly, as above, and impose real costs on domestic firms that then cannot use the cheapest capable service.
  • National model programmes. Address model sovereignty. Failure mode: a single expensive training run that is obsolete within a year, with no sustained programme behind it. A strategy that funds one model rather than a capability is the pattern to be sceptical of.

Assessing a strategy

Three questions. Which of the four is it actually buying? What threat was used to justify it, and does the instrument address that threat or a different one? And is there a recurrent budget, or only a capital announcement? A great deal of what is published under this heading fails the second question, and most of the rest fails the third.

Nothing here describes what any particular government is currently doing; national programmes change with budgets and administrations. Check the current strategy document for the country you care about.

A note on the word itself. “Sovereignty” imports a claim of ultimate authority, and very little of what is discussed under the heading amounts to that; most of it is dependency management, which is an ordinary and legitimate objective that industrial policy has pursued for centuries under less charged names. Using the stronger word makes partial measures sound like independence and makes disagreement sound unpatriotic, which is precisely why it is chosen. Reading a strategy with the word mentally replaced by “reduced dependency on X” usually clarifies both what is being proposed and what it will achieve.

Digital Sovereignty and National AI Strategies · Multigrid