The Six Dimensions of AI Sovereignty
- 18 hours ago
- 7 min read

AI sovereignty has moved to a boardroom imperative faster than most organisations anticipated. Regulatory pressure, geopolitical volatility, and the rapid operationalisation of agentic AI have together made a sovereignty strategy necessary. Most organisations have one. Few have one adequate for the environment they now face.
Managing AI sovereignty is a multidimensional game of chess. Most organisations are playing on one board while their exposure accumulates across five others. The framework set out here is drawn from what enterprises are wrestling with on the ground. These include the decisions being made under pressure, the assumptions being tested by geopolitical events, and the new vulnerabilities being discovered.
Agentic AI is also changing the nature of sovereignty itself. Enterprises are no longer protecting data alone. Increasingly, they are protecting the institutional knowledge, decision logic, workflow logic, and operational intelligence accumulated by AI systems.
Six Actions for Minimum Viable Sovereignty
Complete independence is neither practical nor necessary. Organisations can instead pursue a minimum viable sovereign posture aligned to their risk appetite and operational requirements. The six dimensions below set out where that posture needs to exist, and the actions that help build it.
Strengthen data sovereignty. Identify your most sensitive data assets, including personal information, financial records, AI training data, governance evidence, and strategic intelligence. Apply controls based on sovereignty sensitivity rather than treating all workloads equally.
Understand jurisdictional exposure. Map every critical technology provider, identifying where it is incorporated, which laws govern it, and which governments may have legal authority over the data, systems, or communications it handles.
Reduce operational dependency. Assess the dependency of critical business processes on specific vendors. Develop fallback options, portability plans, and contractual protections that allow operations to continue if a key supplier becomes unavailable.
Protect model and IP sovereignty. Identify where organisational knowledge, decision logic, workflows, model weights, and AI-generated intellectual property are accumulating. Ensure these assets remain portable and are not irretrievably embedded within a single platform.
Prepare for political disruption. Assess exposure to sanctions, regulatory interventions, executive orders, and other government actions that could affect access to critical technology services. Develop contingency plans.
Strengthen technical sovereignty. Prioritise technologies that can be inspected, modified, deployed, and migrated without requiring vendor permission. Technical flexibility reduces dependency and improves resilience as AI ecosystems evolve.
None of these actions delivers complete sovereignty in isolation. Together, they establish a practical foundation for participating in the global AI ecosystem while maintaining control over major risks.
The Residency Fallacy
Most enterprises believe sovereignty is addressed through local data centres, sovereign cloud offerings, and compliance with local regulations. While all three may be true, none necessarily changes the legal authority over the systems and data on which the organisation depends.
A server in Singapore running on AWS infrastructure is not sovereign from US law. A Microsoft Azure deployment in a Frankfurt data centre is not insulated from US government access. A Google Cloud workload in a Sydney availability zone is not outside the reach of US legal instruments because of its physical location.
Data residency, where data physically sits, is different from data sovereignty, which is about who has legal authority over that data. An organisation can have complete data residency in any jurisdiction while having limited sovereignty if the infrastructure provider is incorporated in a country whose laws permit or compel government access.
In 2025, Microsoft France acknowledged before a French Senate inquiry that it could not guarantee that data stored in France would be beyond the reach of US authorities. That highlights the distinction between data residency and legal sovereignty. Most enterprises have invested in sovereignty initiatives that improve data residency without materially changing their underlying legal exposure.
Jurisdictional Foundations
Jurisdictional sovereignty addresses the laws that govern technology providers and the extent to which governments can force access to data, systems, or communications. In the United States, legislation including the Cloud Act, FISA 702, and the Patriot Act creates legal pathways through which authorities can compel access to data or communications handled by US-incorporated providers, regardless of where that data is stored. For enterprises running critical workloads on US technology platforms, the implication is straightforward. Data residency does not remove legal exposure.
Many organisations assume that acting as the data controller provides meaningful protection. In practice, a provider that possesses and can access data remains subject to legal orders directed at it. For this reason, customer-managed encryption is often a more effective control than contractual language alone.
China presents similar considerations. The National Intelligence Law requires Chinese organisations to support and cooperate with state intelligence activities, while other laws governing data security, cybersecurity, and personal information create additional obligations around government access, data localisation, and cross-border transfers.
The purpose of this analysis is not to pass judgement on any jurisdiction. It is to understand which governments have legal authority over critical technology providers and how that exposure contributes to an organisation’s overall sovereignty posture.
The Political Layer
The legal instruments described above are structural and relatively permanent. Political risk is different. It is the additional exposure that comes from a government’s demonstrated willingness to use its influence over technology companies as an instrument of policy beyond conventional law enforcement.
Structural legal risk can be managed through architecture and contracts. Political risk requires a different kind of preparation. Political sovereignty is not unique to any one country. It arises wherever governments use legal or regulatory authority in ways that affect access to critical technology services.
Recent events illustrate how political decisions can have operational consequences for organisations that depend on global technology platforms. Following US government sanctions against the International Criminal Court’s (ICC) chief prosecutor, he lost access to his Microsoft email account. The ICC subsequently migrated away from Microsoft’s software, moving to an open-source sovereign alternative developed under a German government digital sovereignty initiative. The migration cost time, money, and operational continuity because a US government executive order threatened any company with fines and prison time for providing technological support to a sanctioned individual.
Separately, the US government imposed sanctions on a United Nations Special Rapporteur in July 2025, shortly after she published a report naming major US technology companies in relation to their activities in conflict zones. The same executive order mechanism applied. Any US company providing technological support to a sanctioned individual faces legal jeopardy. Every enterprise needs a contingency plan in case of unexpected sanctions, including those operating within the United States.
The Alternatives That Now Exist
Until recently, enterprises seeking frontier AI model capability outside US providers had no credible alternatives, but that position has changed significantly.
Mistral AI, the French company founded in 2023 with backing that includes explicit European sovereign AI ambitions, has built a family of open-weight large language models that are competitive with US alternatives for a range of enterprise use cases. Mistral models can be self-hosted on non-US infrastructure, fine-tuned on proprietary data without that data ever touching a US-controlled system, and deployed entirely within jurisdictions of the enterprise’s choosing. For workloads where sovereignty is critical, Mistral represents a credible European alternative at the model layer, even if it is not a universal replacement for every frontier capability.
DeepSeek’s open-weight model releases demonstrated that frontier-level AI capability is achievable outside the US, at dramatically lower cost. The strategic implication extends beyond the specific models. The era of US monopoly at the frontier model layer is ending. Enterprises now have genuine architectural choices that did not exist eighteen months ago.
China’s domestic AI ecosystem represents the most complete sovereign AI infrastructure built by any non-US actor. Enterprises should understand it as a structural development in the global AI landscape while applying thorough jurisdictional analysis to Chinese vendors. China’s National Intelligence Law creates equivalent Chinese state access obligations to those the Cloud Act creates for US providers. Substituting US dependency for Chinese dependency does not solve a sovereignty problem. Instead, it trades one geopolitical exposure for another.
The practical implication for enterprises is a portfolio approach: US frontier models where capability justifies the jurisdictional trade-off; European sovereign models where jurisdictional independence matters more than absolute capability; and self-hosted open-weight models for the most sensitive workloads. The goal is not independence from all external AI infrastructure, as this is neither practical nor necessary. The goal is deliberate interdependence, which allows enterprises to know where dependencies sit, understand the exposure each one creates, and determine that the trade-off is acceptable.
Singapore as a Model
Singapore offers a useful operational model of deliberate AI sovereignty, and the lessons translate directly to enterprise practice.
Singapore uses US cloud infrastructure extensively and engages deeply with Chinese technology ecosystems. It has not attempted to build a fully sovereign domestic AI stack, because full-stack sovereignty is neither practical nor necessary. Instead, it has pursued deliberate interdependence with explicit governance.
The Infocomm Media Development Authority’s (IMDA) Model AI Governance Framework, expanded in early 2026 to address agentic AI, establishes operational accountability, oversight requirements, and risk management standards for autonomous AI systems. It allows Singapore-based organisations to deploy global AI capabilities within a governance architecture they control.
The principle is directly applicable at the enterprise level. An organisation does not need to own its own models or build its own cloud infrastructure. It needs to govern how those external capabilities operate within its own boundaries, covering what they can access, what they can do, what audit trail they leave, and what the exit options are if the relationship needs to change.
Sovereignty as Strategy
Sovereignty is not the same as independence. Most mature organisations are not attempting to disengage from the global AI ecosystem. Instead, they are attempting to participate in it on their own terms.
Passive dependency is a choice made by default. Deliberate interdependence is a choice made by design. The difference between them is not the technology stack. It is whether the organisation has thought carefully about what it depends on, understood the exposure that dependency creates, and taken deliberate steps to manage it across all six dimensions.
Most enterprises have addressed one dimension and left the others largely unexamined. The framework set out here is a starting point for changing that. The organisations that work through all six will be significantly better positioned than those that discover their exposure after the fact.
Andrew Milroy is the founder of Veqtor8, a Singapore-based global technology advisory firm. He advises enterprises, governments, and technology vendors on agentic AI governance, cybersecurity, and technology strategy across the United States, Europe, and Asia Pacific. If your organisation has not yet assessed its AI sovereignty exposure, it is probably overdue.
Disclaimer: This article reflects the author’s opinion and analysis based on publicly available information and professional conversations. It is not legal, regulatory, or investment advice.




Comments