AI Sovereignty: Definition, the Four Layers, and Why Compute Is the Hard One
AI sovereignty is the capacity of a state to develop, deploy and govern artificial intelligence systems without depending on infrastructure, models or rules controlled by another state. The term entered mainstream policy vocabulary around 2023 and has since been applied to national compute programmes, domestic model development, data residency law and regulatory regimes. It is used loosely, and that looseness matters: the phrase bundles together at least four distinct claims with radically different price tags and success rates. A country can achieve three of them within a single budget cycle. The fourth is available to roughly four jurisdictions on earth.
The Four Layers
Compute sovereignty is control over the physical substrate: semiconductor fabrication, lithography equipment, advanced packaging, memory, data centre capacity and the electrical generation required to run it. This is the capital-intensive layer, measured in decades and hundreds of billions of dollars, and it is the layer where dependency is hardest to disguise.
Model sovereignty is the ability to train, own and modify frontier or near-frontier model weights domestically, rather than accessing them through a foreign provider’s API. Because training a competitive model costs a fraction of building a fab, this layer is achievable on a national budget. That asymmetry explains why dozens of states have a national model programme and almost none has a domestic lithography capability.
Data sovereignty is jurisdictional control over the data used to train and query AI systems, including residency requirements, cross-border transfer restrictions and rules on what may be used as training material. This strand predates AI entirely and inherits its legal architecture from earlier data protection regimes. It is largely a construct of law rather than of engineering.
Governance sovereignty is the right to set binding rules for AI systems operating within a jurisdiction, and — in the more ambitious versions — to project those rules extraterritorially onto foreign developers seeking market access. This is the layer available to a bloc that has lost the first three but retains a market large enough to make compliance mandatory.
Conflating these produces most of the confused commentary on the subject. A government that has built a national data centre, trained a domestic model on domestic data and passed an AI act has achieved three layers while remaining entirely dependent on foreign silicon for all of them.
The Compute Stack and Its Chokepoints
Compute sovereignty fails or succeeds at a small number of specific bottlenecks, roughly in descending order of difficulty.
- Extreme ultraviolet lithography. A single supplier, ASML, produces EUV scanners. Export controls have kept them out of China entirely. No second source exists at any price.
- Immersion deep ultraviolet lithography. The most advanced tooling available to restricted buyers, printing 28nm-class features in one exposure and reaching finer nodes through multipatterning at a cost in yield. ASML holds the overwhelming majority of the installed immersion base. China began mass-producing a domestic immersion system in 2026, at initial volumes of roughly five units per year — a genuine milestone in kind, and a rounding error in quantity.
- High-bandwidth memory. HBM is the binding constraint on AI accelerator supply and is produced at scale by three firms, all in the United States and South Korea. Export controls bar HBM sales into China.
- Advanced packaging. Chip-on-wafer-on-substrate capacity, hybrid bonding and die stacking sit between wafer output and shippable accelerators, and have repeatedly been the actual limiting factor on delivery.
- Electrical power. The newest constraint and the only one on this list a mid-sized state can realistically build rather than buy. Gigawatt-scale campuses now compete directly with national grids, and siting decisions increasingly follow generation rather than fibre.
Servicing rights sit underneath all of this. Installed equipment requires continuous calibration and parts supply from the vendor, which means an export control regime that reaches servicing can degrade capacity a country already owns. This makes the installed base a persistent point of leverage rather than a one-time transaction.
Sovereign AI as a Commercial Category
The gap between what states want and what they can build has produced a commercial product. Accelerator vendors and cloud operators now sell “sovereign AI” as a packaged offering: hardware installed on national territory, operated under domestic law, with data never leaving the jurisdiction. Nvidia has reported sovereign demand as a distinct revenue stream, and national programmes in Europe, Japan, India, the Gulf states and Southeast Asia have been announced on this model.
What this delivers is real but bounded. The buyer gains jurisdictional control over data and inference, insulation from foreign subpoena, and domestic capacity that cannot be switched off remotely by a cloud provider’s terms of service. What it does not deliver is independence from the supply chain that produced the hardware, from the export licences that permitted its sale, or from the vendor’s software ecosystem. The arrangement is better described as sovereignty over the top of the stack, leased from the bottom of it.
National Approaches
United States. Sovereignty pursued through denial rather than autarky: export controls on advanced chips, lithography tools and HBM; pressure on allied suppliers to align licensing regimes; and domestic fabrication subsidies. The strategy assumes continued leadership and works by widening the gap rather than closing one.
China. The only programme seriously attacking the bottom of the stack, driven by necessity. Domestic lithography, domestic memory expansion, domestic accelerator design and state capital deployed at scale. Progress has been real at mature nodes and in conventional DRAM, and remains constrained at the leading edge and in high-bandwidth memory. The 2026 listing of the country’s largest DRAM producer, and the parallel emergence of domestic immersion tooling with that same producer named as an early customer, illustrate the strategy: build capacity at the accessible tiers, then work upward.
European Union. Governance sovereignty as the primary instrument, exercised through the AI Act and its extraterritorial reach, supported by a much weaker compute position concentrated in equipment supply rather than chip production. Europe manufactures the machines that make advanced chips without manufacturing the chips.
Middle powers. Japan, South Korea, India, Taiwan, Israel, the Gulf states, Singapore, Canada and France each hold one or two layers strongly and import the rest. Korea and Taiwan hold irreplaceable positions in memory and foundry respectively while depending on foreign design tools and equipment. The Gulf states convert energy abundance into data centre capacity while importing everything installed inside it.
Developing and emerging economies. For most states the realistic ambition is data and governance sovereignty, plus fine-tuning of open-weight models on local languages and domestic datasets. The wide availability of capable open-weight models — many of them released by Chinese labs — has made this tier substantially more attainable than it was, which is itself a form of soft-power projection by the releasing parties.
Criticisms and Limits
The concept attracts three recurring objections.
The first is that sovereignty at the model and data layers is comparatively cheap and therefore over-claimed, producing announcements that describe procurement as independence. The second is that AI sovereignty is often a rebranding of industrial policy, with the security framing used to justify subsidies that would otherwise face scrutiny — and that the resulting spending is unusually insensitive to return on investment, because it is defended politically rather than financially. The third is measurement: the same hardware order is frequently announced by the vendor, the sovereign wealth fund and the relevant ministry, which inflates aggregate figures for national AI investment and makes independent verification difficult.
A fourth and more structural criticism is that full-stack autonomy may be economically irrational even where it is technically achievable. The semiconductor supply chain is the most specialised production system ever built, and replicating it nationally means accepting materially worse tools at materially higher cost. States pursuing it are making a security argument, not an efficiency one, and the trade is only rational under an assumption that access will eventually be withdrawn.
Related Terms
- Sovereign AI — used interchangeably with AI sovereignty, but more often in the commercial sense of nationally-hosted infrastructure sold as a product.
- Digital sovereignty — the broader parent concept covering cloud, data, payments and communications infrastructure.
- Technological decoupling — the deliberate separation of two economies’ technology supply chains, of which AI sovereignty programmes are one expression.
- Export controls — the primary policy instrument by which one state limits another’s compute sovereignty.
- Chokepoint — a stage in a supply chain with few enough suppliers that control of it confers leverage over everything downstream.
- Open-weight models — models whose parameters are publicly released, enabling model sovereignty without frontier training capacity.
- Compute divide — the widening gap between states with domestic accelerator capacity and those without.
The practical test of any AI sovereignty claim is a single question: if the supplying jurisdiction withdrew licences, parts and servicing tomorrow, how long would the capability keep running? Answers range from indefinitely to a matter of months, and almost no public announcement specifies which.