AI Sovereignty Model · Where you can be reached, by whom, and how fast you could do without them

In review No frame set
1AI Sovereignty Model
2Model Architecture
3The Frame
4Self-Assessment
5Dependency Studio AI
6Sovereignty Register
Six places, all live at once

You can run on a sovereign cloud and still not have sovereign AI.

Residency answers where data sits. It says nothing about who holds the weights, where inference actually runs, whether the model changes under you, or what your agents are permitted to do. This is a surface, not a ladder — there are no stages and no progress, only six places where a decision about your AI can be made without you.

6
Places
30
Controls
Live under your frame
You can answer
Your frame· nothing set yet
Agency ↑
↓ Substrate
Least replaceable ↑
↓ Most substitutable

Model Architecture — thirty controls, five per place

Each carries the question a seller actually asks, the document it rests on, and its weight. Green traces to a primary source you can read; violet rests on a secondary reading of a paywalled analyst report and is still to be verified. ↯ marks an exposure that cannot be remediated once found — only prevented.

Six places · thirty controls

The Frame — your choice, made first

Sovereignty is a customer choice, not a vendor claim, so the model opens by asking for yours. The frame decides which controls are live. Controls outside it are greyed rather than hidden, so you can see what a stricter target would add.

1 · Courts you must be defensible under

Where an order against a provider of yours would have to be answered.

2 · Obligations already binding on you

These add controls rather than replacing them. The AI Act role matters most: a deployer and a GPAI provider carry sharply different duties.

3 · Substrate assurance target

These certify the cloud beneath the AI, not the AI itself — which is exactly why they are not sufficient on their own.

Self-Assessment — thirty taps, and Unknown is an answer

Rate what is true today, not what is planned. An unrated control reports as unrated — never silently scored as zero, because "we have not answered" and "we do not have it" are different findings and the difference is the point. Save a version at the midpoint: watching the score move as your team argues is the workshop's real output.

UnknownWe cannot say who holds this, or how long we would need without it.
KnownWe can name the holder and estimate the time — but it has not been tested.
RehearsedWe have done it, or tested it end to end, within the last 12 months, and evidence exists.

Dependency Studio

Name one thing your business could not run without. An AI drafts the parties typically behind it and which of the six places it touches — so you correct a draft rather than face a blank page. Bring your own key; nothing leaves this browser.

Business function
This produces a hypothesis, not a finding. Anything drafted here lands as Unknown until a human confirms it. The model may never auto-rate a control — an inferred answer becoming a “Known” would destroy the only thing that makes this register defensible.

Sovereignty Register — what you know, what you have tested, what you cannot answer

There is deliberately no single sovereignty score. Compressing coverage, readiness and concentration into one number would hide the distinctions this exists to expose, and would invite benchmarking between self-reports that are not comparable. Click any figure to see its arithmetic.

Ranked by exposure

The register you keep

exposure = weight × deficit × reach  Grouped by what to do first, not by where it sits. Shaped so it can feed a DORA Register of Information — though the subcontracting chain still has to be enumerated by hand. This tells you where to look, not what you will find.

Three bands · ordered by exposure
Driven by the Dependency Studio

The plan — answer each control once

Include the functions you intend to make defensible, put them in priority order, and set how far each must go. Each control is then scheduled once, in the earliest wave that needs it — later functions inherit it rather than repeat it. The target axis is this model's own rating scale, not a maturity curve.