Formerly known as Wikibon

Who Defines AI Sovereignty? The Pressure Does

Sovereign AI · September 2026

Right now, everyone. Every hyperscaler has a sovereign cloud. Every chip vendor is building sovereign AI factories. Every security vendor has a sovereign feature. The analysts are drawing their own lines too. Gartner put out a solid body of research this summer, led by its Hype Cycle for Digital Sovereignty, framing it in three domains: data, operational and technological.[14]

That’s three of the five pillars, and on those three Gartner is mostly right. The two it leaves out are the two that break first. And when everyone gets to write the definition, the buyer inherits whichever version the seller found cheapest to meet.

A definition is only worth something under pressure. A sanctions order. A subpoena. A price change on a meter you don’t own. So the question isn’t who writes the definition. It’s what holds when someone pushes.

Here’s the 5 Pillars methodology, and what each pillar looks like when the pressure arrives.

Territorial

The question. Where do your data and compute physically reside, at rest and in motion?

The story. In 2023, Samsung engineers pasted proprietary source code and internal meeting notes into ChatGPT to fix bugs and summarize meetings. Nobody breached anything. The data simply walked out the front door, into someone else’s data center, one prompt at a time. Samsung banned generative AI tools on company devices within weeks.[1] Every fab, every server, every byte at rest was in Korea. The data in motion wasn’t.

Under pressure. This is the pillar everyone sells first, because it’s the easiest to put on a landing page. In-country, in-region, under a flag you recognize. It holds as far as it goes, and every framework on the market covers data at rest. Samsung is the reminder that the prompt is data in motion, and the request path is where Territorial actually gets decided.

But push on it and it bends in two places. First, survivability, a point Gartner makes well.[14] Mandate strict local hosting, and a real emergency can still force you to offload and replicate globally just to keep the data alive. Territorial maximized can be fragile, not sovereign. Second, physics. The bottleneck for sovereign AI is increasingly the power contract, rack density and cooling, not the hardware, and plenty of “sovereign” AI factories still run on US-based NVIDIA silicon. A Territorial answer that doesn’t ask who controls your energy supply is only half an answer.

Verdict: holds, with a caveat.

Operational

The question. Who runs and secures the environment? Keys, paging, audit logs.

The story. In July 2025, ProPublica revealed that Microsoft had spent roughly a decade using China-based engineers to maintain Pentagon cloud systems.[2] The safeguard was a program of US-based “digital escorts” who typed in the commands and who often lacked the expertise to understand what they were typing. The data was in the US. The contract was with a US company. The hands on the keyboard were somewhere else. By September, the Pentagon had banned vendors from using personnel in adversarial nations on its systems.[3]

Under pressure. The best stress test here is simple, and Gartner’s healthcare guidance puts it well: make the vendor demonstrate patching, incident escalation, break-glass and privileged access without its global engineers.[14] Pull them out of the room. See what still runs.

The escorts story is why that drill matters, and why regulators are now tying system support to the citizenship and location of the engineering staff. Who holds the pager is becoming a passport question.

Verdict: holds, if you actually run the drill.

Technological

The question. Who owns the stack and the IP? Can you audit it, fork it, self-host it?

The story. On July 1, 2026, Alex Karp went on CNBC and tore into the frontier labs. His argument: they charge you for tokens, learn your business from your data, and eventually commoditize your edge.[4] Don’t let the model vendor own your alpha. I agree with every word. Then came the pitch. The answer, per Karp, is to let Palantir sit between you and the model.[5] Put your ontology, your process logic, your crown jewels, into a closed-source platform you can’t audit, can’t fork and can’t run without Palantir. That’s not taking back your alpha. That’s choosing a different landlord.

Under pressure. A single geopolitical action cuts off a vendor. If you don’t control the stack, you’re down overnight. Open source is the escape hatch, and Gartner says it plainly: the provider’s software should be open source. Their research also gives this pillar its sharpest word, “sovereign-washing”: a cloud-tethered offering parked in a local data center, branded sovereign, with the control plane still somewhere else.

Verdict: holds, when the code is actually yours to run.

The question. Which jurisdiction governs access? Which court can compel the entity that holds your keys?

This is the first pillar most definitions skip. Gartner’s three domains included. Jurisdiction shows up as a clause inside the others, data subject to local rules, operations immune from foreign interference. A modifier. Never an axis.

The story. On June 18, 2025, Anton Carniaux, Microsoft France’s director of public and legal affairs, sat before the French Senate under oath. Could he guarantee that French citizens’ data would never be handed to US authorities without the French government’s consent?[6]

“No, I cannot guarantee that, but, again, it has never happened before.”

Would Microsoft comply with a properly framed CLOUD Act request? “Absolutely, by respecting this process.”[7]

Data in France. Operations in France. Stack is the stack. Territorial, Operational and Technological all green. And a sworn admission that none of it survives a foreign statute.

Under pressure. That’s not an accident of drafting. The CLOUD Act (2018) obliges US-headquartered providers to produce data in their possession, custody, or control, regardless of which country the bytes sit in.[8] It exists because of Microsoft v. United States, the Ireland warrant case: the government lost in the Second Circuit, and Congress passed the statute before the Supreme Court could rule.[9] It was built specifically to beat a data-residency defense.

The track record says the same thing. Amsterdam Trade Bank lost its cloud services to sanctions and went bankrupt while still solvent.[10] ICC prosecutor Karim Khan reportedly lost access to his Microsoft email after US sanctions, an account Microsoft disputes.[11] Neither was a residency failure. Neither was an operations failure. Both were jurisdiction failures. Gartner cites both cases and files them under Technological sovereignty,[14] because a three-domain model has nowhere else to put them. The CLOUD Act itself gets one line across six notes, listed as a reason to tighten operational controls.[15] To Gartner’s credit, it concedes that the “local operating entity” model regulators now mandate is untested in court. That concession is the Legal pillar. It just doesn’t get a name.

Data in region, operations locally staffed, and the legal person who can be compelled sits somewhere else entirely. Not where the data sits. Not who staffs the NOC. Who can be served, and by whom.

Verdict: breaks, unless you test for it by name.

Financial

The question. Can you leave? On your timeline, at a survivable cost, without a forced migration, without a meter you don’t own setting your gross margin three years out.

This is the second pillar most definitions skip. The standard view, Gartner’s included, treats money as the tax on sovereignty, a 15 to 20% premium for sovereign operations, a barrier to adoption.[14][16] That’s true for general-purpose cloud. It’s wrong for AI in production.

The story. In August 2026, Canva cut its revenue growth forecast for the year to 20%. The reason, per The Information: it underestimated demand for its AI features, and serving them on frontier models blew up its inference bill.[12] At 265 million monthly users,[13] a few cents per inference is the difference between a software margin and a services margin. Canva’s fix was pure Pillar 5. Route tasks away from the expensive frontier calls, push toward smaller and in-house models, and take the meter back. Cost per task dropped nearly 90% since April.[12] Nothing about Canva’s data location, operations, stack or jurisdiction changed. The only thing it didn’t control was the price of a token, and that alone rewrote the forecast.

Under pressure. Your agentic workloads leave the demo and hit production. Multistep agents keep feeding full conversation histories back into the model, and token consumption compounds. Gartner’s own infrastructure research puts the saving from repatriating high-volume agentic workloads at roughly 75% over two years.[17] The premium and the discount sit in two different Gartner notes, and they never meet.

Not a premium. A discount. Sovereignty stops being what you pay for control and becomes how you stop paying rent.

Treat money as a constraint instead of a pillar and you miss that inversion entirely. You also miss the trap: a buyer can diligence out of dependence on a foreign hyperscaler, into dependence on a small set of local providers, and score full marks on the other four.

Capping spend on someone else’s meter is cost control. It isn’t sovereignty.

Territorial, Operational, Technological and Legal all protect the asset. Financial protects the return on it. And the return is the only one of the five you can lose while every other pillar still scores green. Keys in your HSM, stack you can fork, right jurisdiction, right zip code, and a cost-per-inference curve that belongs to somebody else. When that curve moves, you don’t get to invoke your sovereignty. You get to renegotiate, absorb it, or leave. That’s a tenancy.

Verdict: breaks, unless it’s priced in up front.

The layer nobody’s pressure testing

Nearly every sovereignty framework on the market scores the data plane. Across Gartner’s 22 sovereignty profiles, the agent layer comes up exactly twice.[14] Who governs the agent’s decisions? Where does its memory live? Whose authority does the orchestration plane answer to? The research is data-plane. The next five years of risk is runtime.

The executive TCO

Sovereignty is a premium on general-purpose cloud and a discount on production inference. Which one applies depends on whether you’re demoing or in production.

Put it in the language the CFO already speaks. The Financial pillar is your unit economic alpha: the margin on each unit of work that is genuinely yours, rather than borrowed from whoever sets the price of a token. Lose it and every other pillar becomes decorative.

Hybrid is often the right architecture. Baseline on your own models, burst to the frontier when you need raw intelligence. I’d sign off on it.

On one condition: the hole gets priced, named, and owned. A hosted frontier model in the request path means your prompts, your retrieved context and your agent’s intermediate reasoning cross a boundary you don’t control, on a meter you don’t set. Write it into the risk register. Put a number on the switching cost and on what a 3x token price does to your gross margin. Then you’ve made a sound engineering decision.

What you haven’t done is achieve sovereignty. And the vendor who runs that architecture and markets the result as sovereign anyway is the one to watch.

Monday

  • Run the drill. Patching, break-glass, incident escalation, with the global engineers out of the room.
  • Score five, not three. Add: which court can compel the key holder? And what does leaving cost, and how long does it take?
  • Follow the corporate person, not the zip code. Ask in the RFP where profits and legal liability ultimately sit. Then ask the Carniaux question, in writing.
  • Price sovereignty against the inference bill, not the cloud bill.
  • Model your unit economic alpha at 3x token prices. If your gross margin doesn’t survive it, you never had the fifth pillar, whatever the other four score.
  • Hybrid is fine. Mislabeling isn’t. Frontier model in the path? Name the exposure, price it, own it. Just don’t call the result sovereign.

So who defines AI sovereignty?

Not the vendor. Not the analyst. The pressure does.

The ICC prosecutor didn’t lose access because his data moved. The Amsterdam Trade Bank didn’t fail an operations audit. And no residency guarantee survived a sworn hearing in Paris. They were beaten by a jurisdiction and a bill, the two things you can lose while every other pillar still scores green.

Three out of five ain’t bad. Until someone serves you a subpoena and a bill.

If you want your vendor estate pressure tested on all five, that’s what an Agentcy Labs Sovereignty Assessment does. Get in touch.

Amit

References

Gartner, The Future of AI Infrastructure, G00849023, June 24, 2026. on Sovereign AI.

Bloomberg, “Samsung Bans Staff’s AI Use After Spotting ChatGPT Data Leak,” May 2, 2023. https://www.bloomberg.com/news/articles/2023-05-02/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak

ProPublica, “Microsoft Says It Has Stopped Using China-Based Engineers to Support Defense Department Computer Systems,” July 18, 2025. https://www.propublica.org/article/defense-department-pentagon-microsoft-digital-escort-china

Nextgov/FCW, “Pentagon bans tech vendors from using China-based personnel following a ProPublica investigation,” September 2025. https://www.nextgov.com/defense/2025/09/pentagon-ban-tech-vendors-using-china-based-personnel-following-propublica-investigation/408281/

Forbes, “Karp Says Frontier AI Labs Are Stealing Enterprise Value And VCs Are Listening,” July 2, 2026 (on Karp’s July 1 CNBC Squawk Box interview). https://www.forbes.com/sites/josipamajic/2026/07/02/karp-says-frontier-ai-labs-are-stealing-enterprise-value-and-vcs-are-listening/

SiliconANGLE, Dave Vellante, “Alex Karp, frontier models and the real fight for enterprise AI,” July 5, 2026. https://siliconangle.com/2026/07/05/alex-karp-frontier-models-real-fight-enterprise-ai/

The Register, “Microsoft exec admits it ‘cannot guarantee’ data sovereignty,” July 25, 2025. https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/

Forbes, “Microsoft Can’t Keep EU Data Safe From US Authorities,” July 22, 2025. https://www.forbes.com/sites/emmawoollacott/2025/07/22/microsoft-cant-keep-eu-data-safe-from-us-authorities/

US Department of Justice, CLOUD Act Resources. https://www.justice.gov/criminal/cloud-act-resources

Supreme Court of the United States, United States v. Microsoft Corp., No. 17-2, dismissed as moot, April 17, 2018. https://www.supremecourt.gov/opinions/17pdf/17-2_1824.pdf

Global Trade Review, “Solvent but bankrupt: how sanctions felled Amsterdam Trade Bank.” https://www.gtreview.com/news/europe/solvent-but-bankrupt-how-sanctions-felled-amsterdam-trade-bank/

heise online, “Criminal Court: Microsoft’s email block a wake-up call for digital sovereignty,” May 2025 (reporting the Associated Press account and Microsoft’s denial). https://www.heise.de/en/news/Criminal-Court-Microsoft-s-email-block-a-wake-up-call-for-digital-sovereignty-10387383.html

The Information, via Dealroom, “Canva Hits AI Speedbump on Costs, ChatGPT Competition,” August 6, 2026. https://dealroom.co/news/info-19trz12-canva-hits-ai-speedbump-on-costs-chatgpt-competition/

Value Add Pulse, “Canva cuts 2026 revenue forecast to 20% on AI costs,” August 10, 2026. https://valueaddvc.com/pulse/canva-cuts-revenue-forecast-ai-costs-2026

Gartner, Hype Cycle for Digital Sovereignty, 2026, G00846342, June 25, 2026.

Gartner, Digital Sovereignty Across Data, Operations, and Technology, G00859739, July 11, 2026.

Gartner, Sovereign AI Series: Checklist for Enterprise AI Strategy, G00845631, July 9, 2026.

Article Categories

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.
"Your vote of support is important to us and it helps us keep the content FREE. One click below supports our mission to provide free, deep, and relevant content. "
John Furrier
Co-Founder of theCUBE Research's parent company, SiliconANGLE Media

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well”

Book A Briefing

Fill out the form , and our team will be in touch shortly.
Skip to content