You can run on a sovereign cloud and still not have sovereign AI.
Residency answers where data sits. It says nothing about who holds the weights, where inference actually runs, whether the model changes under you, or what your agents are permitted to do. This is a surface, not a ladder — there are no stages and no progress, only six places where a decision about your AI can be made without you.
Model Architecture — thirty controls, five per place
Each carries the question a seller actually asks, the document it rests on, and its weight. Green traces to a primary source you can read; violet rests on a secondary reading of a paywalled analyst report and is still to be verified. ↯ marks an exposure that cannot be remediated once found — only prevented.
The Frame — your choice, made first
Sovereignty is a customer choice, not a vendor claim, so the model opens by asking for yours. The frame decides which controls are live. Controls outside it are greyed rather than hidden, so you can see what a stricter target would add.
1 · Courts you must be defensible under
Where an order against a provider of yours would have to be answered.
2 · Obligations already binding on you
These add controls rather than replacing them. The AI Act role matters most: a deployer and a GPAI provider carry sharply different duties.
3 · Substrate assurance target
These certify the cloud beneath the AI, not the AI itself — which is exactly why they are not sufficient on their own.
Self-Assessment — thirty taps, and Unknown is an answer
Rate what is true today, not what is planned. An unrated control reports as unrated — never silently scored as zero, because "we have not answered" and "we do not have it" are different findings and the difference is the point. Save a version at the midpoint: watching the score move as your team argues is the workshop's real output.
Dependency Studio
Name one thing your business could not run without. An AI drafts the parties typically behind it and which of the six places it touches — so you correct a draft rather than face a blank page. Bring your own key; nothing leaves this browser.
▸Business function
Sovereignty Register — what you know, what you have tested, what you cannot answer
There is deliberately no single sovereignty score. Compressing coverage, readiness and concentration into one number would hide the distinctions this exists to expose, and would invite benchmarking between self-reports that are not comparable. Click any figure to see its arithmetic.
The register you keep
exposure = weight × deficit × reach Grouped by what to do first, not by where it sits. Shaped so it can feed a DORA Register of Information — though the subcontracting chain still has to be enumerated by hand. This tells you where to look, not what you will find.
The plan — answer each control once
Include the functions you intend to make defensible, put them in priority order, and set how far each must go. Each control is then scheduled once, in the earliest wave that needs it — later functions inherit it rather than repeat it. The target axis is this model's own rating scale, not a maturity curve.