
Own the Core. Rent the Edges. Know the Difference.
The event
Stanford HAI published the first systematic survey of the commercial “sovereign AI” market (issue brief, July 15). The finding, in their words: these offerings reconfigure dependence rather than eliminate it. [1]
Three numbers to carry into your next procurement meeting:
- ~14% of NVIDIA’s revenue (~$30B) now comes from sovereign AI. [2] Sovereignty is a product line with a P&L attached.
- +35.6% growth in global sovereign cloud spend this year (Gartner). [2]
- 19 days — how long Anthropic’s newest frontier models were off the board after a US Commerce directive in June, before controls were lifted and access restored. [3]
The last one is the whole newsletter. Not an outage. A directive. The vendor could not overrule it, and nobody’s DR plan has a line item for “our model provider is legally prohibited from serving us.”
You don’t have a lock-in problem
Let me say the unpopular thing first, because it’s the thesis of this issue.
Dependency is not the failure. Unmeasured dependency is.
Every serious system depends on something it did not build. You will never own the fab. You will probably never own the frontier model. That is fine — that has always been fine. Nations run on interdependence, and so do enterprises.
There are exactly three positions you can occupy on any layer of your stack:
| Posture | What it means | Verdict |
|---|---|---|
| Sovereign | You own it, or you can leave it on your own schedule at a price you’ve written down | Fine |
| Accepted exposure | You cannot leave quickly, you know exactly what that costs, and a named executive signed for it | Fine |
| Blind spot | You have not asked | The only failure |
Two of three are acceptable. Most organizations are sitting in the third and calling it the first, because a vendor put the word “sovereign” on the invoice.
Self-awareness is the entire battle. The ostrich position — head down, procurement done, sovereignty declared — is the worst place on the board, because it’s the only one that removes your ability to make a decision. You cannot govern a risk you have not named. You cannot price an exit you have not modelled. And you will discover the number on the vendor’s timeline instead of yours.
The thing nobody sells you
No vendor sells lock-in. They sell a reference architecture — and lock-in is what the reference architecture is made of.
Lock-up is not a contract term. It’s the accumulated cost of every default you accepted because it was the fastest path to production. It compounds silently, and you only measure it on the day you try to leave.
So measure it on a day of your choosing, not theirs.
Seven layers that hold you
Score each one honestly: sovereign, accepted, or blind spot.
1. Silicon and kernels — NVIDIA
The GPU is not the moat. The moat is two decades of hand-tuned kernels, plus NVLink, Spectrum-X, NeMo, and an AI Factory blueprint that specifies the whole room. [1][2] You can buy chips from someone else. You can’t buy back the engineering years.
→ Fails Technological and Financial. Accepted exposure for almost everyone — which is fine, if you’ve said so out loud.
2. The cloud control plane — Microsoft, AWS, Google
Credit where earned: EU Data Boundary, sovereign landing zones, disconnected Azure Local, a European board overseeing EU datacenter operations. [4][5] Real improvements to Territorial and Operational.
They do not touch the control plane, the identity fabric, or the CLOUD Act. A French Senate hearing made that point plainly, and no 2026 announcement changed the statute. [6]
→ Passes Territorial. Fails Legal.
3. Models and weights
My standing rule: if a hosted frontier model sits anywhere in the request path, you auto-fail Territorial and Financial. Capping spend on someone else’s per-token meter is cost control, not financial sovereignty. June proved the Territorial half in public. [3]
4. Identity and productivity gravity
The quietest layer, and the one where blind spots cluster. Your agents authenticate somewhere. Your audit logs land somewhere. Copilot and Workspace already sit on top of the documents your agents read. Whoever owns the identity plane owns the agent estate — and nobody scores this in a sovereignty RFP.
5. Orchestration, memory, evals, tooling
Framework SDKs, context and memory stores, observability, eval harnesses. Cheapest layer to lose, cheapest layer to keep. Also where sovereignty is genuinely winnable this quarter — and where most enterprises aren’t even trying.
6. Talent and the partner ecosystem
Your integrator’s bench is certified in someone’s stack. Certifications, co-sell incentives, and partner tiers quietly steer every architecture decision toward what the bench already knows. Sovereign design does not survive contact with a delivery team paid to reproduce a reference architecture.
7. Capital and allocation
Public-private AI factory deals, vendor-adjacent financing, GPU allocation priority. [1] When the same party supplies the compute, the blueprint, the software, and part of the funding, “strategic partnership” is a polite phrase for a single point of failure with a term sheet.
If you think this is theoretical, look at virtualization
VMware is the control group. Same shape, ten years ahead, in a market with mature alternatives and no geopolitics required.
After Broadcom eliminated perpetual licensing and moved everyone to bundled subscriptions:
- Average increases around 150%, a 72-core minimum per server license, and a 20% late-renewal penalty. [7]
- AT&T was reportedly quoted an increase in the four digits — over 1,000%. [8]
- A €500K annual bill becoming €2M at renewal, then climbing 10–20% a year. [9]
- Ingram Micro walked away from the relationship entirely. Germany’s VOICE user association filed a complaint with the European Commission. [9]
- 2026 survey data: 86% of organizations are actively reducing their VMware footprint. [10]
Nobody signed up for that. They signed up for a hypervisor in 2012 and inherited an architecture, a control plane, an API, and a partner channel. That is ecosystem lock-up, priced and invoiced.
Note what actually failed. Not the technology choice — VMware was the right call in 2012. What failed was that nobody re-scored the position for a decade. The blind spot did the damage, not the hypervisor. And the escape isn’t free either: migration break-even typically lands 9 to 14 months out, which is a number you want before the renewal letter, not after. [11]
Now re-read layer 1 and ask what that bill looks like when the ecosystem owns the accelerators, the interconnect, the compiler, and the reference architecture.
Score the deal, not the brochure
The typical “sovereign AI factory” package against the five pillars:
| Pillar | Verdict |
|---|---|
| Territorial | Pass — the racks are in-country |
| Operational | Partial — local staff, foreign runbooks and firmware |
| Technological | Fail — can’t audit, can’t fork, can’t self-host |
| Legal | Partial — jurisdiction improves, extraterritorial reach doesn’t |
| Financial | Fail — migration cost exceeds the original build |
Three of five. That’s a good deal. It is not sovereignty. Buy it if you want — just book it as accepted exposure, in writing, with a name next to it.
The exits are real
Every lock-up story above has a working counterexample. Three worth studying, with the uncomfortable parts left in.
Schleswig-Holstein — the productivity exit
The German state moved 40,000+ accounts and over 100 million emails and calendar entries off Exchange and Outlook to Open-Xchange and Thunderbird, with SharePoint→Nextcloud underway. [12] Roughly 80% of workplaces now run LibreOffice. [14]
The economics: over €15M in annual license savings against a one-time €9M investment. Payback in under a year. [13]
The honest part: opposition politicians argue the share of staff who can genuinely work in the new stack lags the 80% on the slide. [13] Exits are real, and they hurt. Budget for the friction or the friction becomes the story.
Apertus — the model exit
EPFL, ETH Zurich and CSCS shipped a genuinely open model: open weights, open training data, open recipes, Apache 2.0, 8B and 70B, ~15T tokens across 1,000+ languages. Deployed on Swisscom’s sovereign platform, downloadable from Hugging Face. [15][16] Early government deployment reported at the Canton of Ticino for official document translation, with a medical variant in hospital testing. [17]
The honest part: it trails the frontier on math and code, and hosted tooling maturity trails the big providers. [16] That gap is a number, not a verdict. Measure yours before you need it.
Triton, MLIR, ROCm — the silicon exit
Hardware-agnostic compilation stopped being a research project. Portability across accelerators is now an engineering budget rather than a bet. [18] The moat is still real. It is no longer infinite.
The pattern: every one of these exits was executed by someone who priced it before they needed it. None were forced moves. That is the entire difference between a strategy and a scramble.
The architecture: hard core, soft edges
Here’s the design principle I’d hold any sovereign program to, and it is not “own everything.” Owning everything is a fantasy that fails on contact with a budget.
Own the core. Stay movable at the edges. Know precisely where the line sits.
The core — the crown jewels. You own this outright.
- Identity and authorization for every agent and human in the estate
- Audit logs and the evidentiary trail
- Agent memory and context — the accumulated institutional knowledge your agents run on
- Evals, policy, and the control plane that decides what runs where
- The data itself, and the schema it lives in
This is the layer that is expensive to build once and catastrophic to rent. It is also, conveniently, the cheapest layer on this list to own outright — and the one layer where “we’ll build it for you, you own it” is a coherent sentence. Nobody is going to hand you a fab. Anyone can hand you your own control plane.
The edges — deliberately interchangeable.
- Models: swappable behind an interface you control, with a measured quality delta per swap
- Accelerators: portable through the compiler layer, not hand-tuned into a single vendor’s kernels
- Inference venues: in-country, on-prem, or hosted — a routing decision, not an architecture
- Point tools: assumed disposable from day one
If swapping a model provider is a config change plus a regression run, you are sovereign at that layer. If it’s a project, you are not. That single test is worth more than any vendor’s sovereignty certification.
The failure mode I see most: enterprises fighting hard for sovereignty at the edges — arguing about which region the GPUs sit in — while handing the core away for free because it arrived bundled.
Five rules
- Own the crown jewels. Rent capability. Never rent control.
- Keep the request path portable. Abstract at the boundary you control, not inside someone’s SDK.
- Run two of everything that matters — not for redundancy theatre, but so the second option stays warm and priced.
- Contract for the exit, not the honeymoon. Hard uplift caps, co-terminus dates, defined swap rights, export in open formats, no punitive renewal penalties. [11] A BATNA you haven’t priced is a wish.
- Fund the exit muscle. A standing budget line for portability, and a named owner per layer. Sovereignty without an owner is a slide.
Your next 90 days
Days 1–30 — Inventory. Map every dependency by layer. Score each: sovereign, accepted, or blind spot. Name an owner. Price the exit for the top three. Written numbers, not adjectives.
Days 31–60 — Run the drill. Pick 72 hours. Assume your primary model provider is not down but prohibited. What still ships? Then run your top three workloads on self-hosted open weights and record the quality delta as a number. June was the unscheduled version of this exercise. Run the scheduled one.
Days 61–90 — Convert it. Renegotiate one contract with real exit clauses. Move one workload onto a portable path. Put a one-page five-pillar scorecard in front of your board, with the exit cost per layer on it — and get the accepted exposures formally signed, not assumed.
Ninety days will not make you sovereign. It will convert your blind spots into accepted risks, which is the only move that was ever available to you — and the one number you currently don’t have.
The reframe
Stanford’s conclusion is that full self-sufficiency is a myth and the real work is calibrating interdependence. [1] Correct — and incomplete.
Calibration without a rehearsed exit is a slogan. And diversification isn’t sovereignty either: two dependencies you can’t exit is just two landlords.
Sovereignty is not zero dependency. It is dependency you can price, govern, and terminate on your own schedule.
Exit cost is the only honest measure. Everything else is marketing with a flag on it.
Your turn: run the 72-hour drill this quarter and reply with the pillar you failed. I’ll publish the aggregate — anonymized — in a follow-up issue, because the failure distribution across this industry is the most useful thing none of us currently has.
And if the drill tells you the core is the part you don’t own: that’s what we build at Agentcy Labs. We architect and deliver the crown jewels layer — identity, audit, agent memory and context, evals, control plane — and the customer owns it outright. Not licensed, not hosted on our terms, not a dependency swapped for a friendlier one. Hard core, soft edges, and a number next to every dependency.
Action item
Adopt a “Hard Core, Soft Edges” architectural framework by taking full ownership of your core identity, audit logging, agent memory, and evaluation control planes while decoupling edges like frontier models, GPUs, and point tools behind provider-agnostic abstraction layers. Standardize model routing and context pipelines so that switching model providers requires only a configuration update and regression run rather than a major code refactor. Finally, execute a scheduled 72-hour portability drill this quarter—simulating the immediate loss of your primary hosted model—to benchmark system resiliency, quantify quality deltas using self-hosted open-weight alternatives, and prove your stack’s exit path before renewal deadlines arrive.
— Amit
References
[1] Zhang, Wald, Adeli, Cryst et al., The Commercial Landscape of AI Sovereignty Offerings, Stanford HAI issue brief, 15 July 2026. https://hai.stanford.edu/policy/the-commercial-landscape-of-ai-sovereignty-offerings
[2] Big tech sovereign AI tools promise control, but drive lock-in, CIO Dive, July 2026. https://www.ciodive.com/news/big-tech-sovereign-ai-tools-promise-control-drive-lock-in/825958/
[3] Anthropic, statement on Claude Fable 5 / Mythos 5 access. https://www.anthropic.com/news/fable-mythos-access
[4] Microsoft strengthens sovereign cloud capabilities with new services, Microsoft Azure Blog, April 2026. https://azure.microsoft.com/en-us/blog/microsoft-strengthens-sovereign-cloud-capabilities-with-new-services/
[5] Microsoft’s Sovereign Cloud in 2026: How Far Does It Go in Addressing Sovereignty Risks?, KuppingerCole, April 2026. https://www.kuppingercole.com/blog/small/microsofts-sovereign-cloud-in-2026
[6] Microsoft Cloud sovereignty in 2026: ambition and reality, Databalance, February 2026. https://www.databalance.eu/en/microsoft-cloud-sovereignty-2026/
[7] VMware Price Increase: What You Need to Know in 2026, Firmographic, May 2026. https://firmographic.co/blog/vmware-price-increase
[8] Broadcom VMware Pricing Changes — Understanding the Licensing Crisis Driving Migration, SoftwareSeni, December 2025. https://www.softwareseni.com/broadcom-vmware-pricing-changes-understanding-the-licensing-crisis-driving-migration/
[9] VMware Licensing Costs 2026: What Changed and What Enterprises Must Do Now, Clouditiv, March 2026. https://www.clouditiv.com/blog/vmware-licensing-costs-2026-broadcom-changes
[10] VMware 2026 Price Increases: Broadcom Licensing and Options, The IT Vortex, June 2026. https://www.theitvortex.com/vmware-broadcom-changes-2026-cost-risk-private-cloud/
[11] Broadcom VMware Pricing Report 2026, Redress Compliance, March 2026. https://redresscompliance.com/broadcom-vmware-pricing-report-2026
[12] Schleswig-Holstein waves auf Wiedersehen to Microsoft stack, The Register, 15 October 2025. https://www.theregister.com/2025/10/15/schleswig_holstein_open_source/
[13] Goodbye, Microsoft: Schleswig-Holstein relies on Open Source and saves millions, heise online, December 2025. https://www.heise.de/en/news/Goodbye-Microsoft-Schleswig-Holstein-relies-on-Open-Source-and-saves-millions-11105459.html
[14] German state replaces Microsoft with open source, saves millions each year, Cybernews, December 2025. https://cybernews.com/news/schleswig-holstein-germany-microsoft-open-source/
[15] Apertus: a fully open, transparent, multilingual language model, ETH Zurich press release, September 2025. https://ethz.ch/en/news-and-events/eth-news/news/2025/09/press-release-apertus-a-fully-open-transparent-multilingual-language-model.html
[16] Apertus Review (2026), Kompozy, June 2026. https://kompozy.io/reviews/apertus
[17] Apertus: the Swiss open source AI model challenging the giants, P. Pillitteri, March 2026. https://pasqualepillitteri.it/en/news/443/apertus-ai-swiss-open-source-language-model
[18] The Next Wave of AI Infrastructure Must Target NVIDIA’s CUDA Moat, Built In, January 2026. https://builtin.com/articles/nvidias-cuda-future-ai-infrastructure
Further reading: Sovereign AI promises independence, but often deepens reliance on US vendors, Stanford report says, DigiTimes, July 2026. https://www.digitimes.com/news/a20260723PD208/nvidia-data-microsoft-technology-openai.html

