Every sovereign AI plan needs an exit it has actually tested
A woman can type a question to a government help service in the Arabic dialect she speaks at home, using the same words she would use with a clerk at a counter, and get back a confident reply to a question she never asked. A man can find his bank transfer held because a screening system fails to recognise that two spellings of his name belong to the same person.
There is no reason to wonder where the software behind those services came from, who trained it, or who decides whether it improves. Both are living with the consequences of those decisions all the same.
According to Muhammed Shabreen, CTO, CNTXT AI, both problems start in the same place. General-purpose AI models, trained mostly on English and Mandarin, struggle with Arabic as people actually use it. For example, words change form, writers routinely leave out vowel marks, speakers move between languages in a single sentence, and one dialect can sit a long way from the next. “These are not cosmetic issues,” he said. “They can cause a public-service assistant to misread a citizen’s request, or a financial-crime system to mishandle Arabic name variants during sanctions screening.”
Sovereign AI exists to prevent failures like these, the idea is that a system serving citizens, checking financial transactions and handling state records should understand the people it serves and answer to the country it serves them in.
However, few national programmes build such a system from the ground up. They start with a model that a developer in another country has trained and released openly, with its workings published so that anyone can download, run and modify it. They then adapt it for their own languages, services and data centres.
“Training a competitive foundation model from scratch is unrealistic for almost every government,” said Andre Troskie, EMEA Field CISO at Veeam, referring to the large general-purpose systems that everything else is built on. He sees no failure in the borrowing. “That is a rational division of labour, provided it is recognised as adaptation.”
“An open-weight model already in your hands cannot be taken away from you, but its future can,” Shabreen said. The country keeps a working copy, and that copy stays as it is unless the country changes it. Everything after that point is decided by someone else: the corrections, the security fixes, the next and better version, even the terms under which the model may be used. “Improvements, security fixes and the next generation are all decisions made in someone else’s boardroom,” he added.
Veeam’s research across EMEA found that 49% of surveyed organisations already run a mixed arrangement. They keep sensitive data on local or sovereign models and send more general work to global ones. That is a reasonable answer to the cost of building everything at home. It also spreads an organisation’s reliance on outsiders across more places, and many organisations have no clear record of where those places are.
A server at home proves very little
“The common misconception is that residency equals sovereignty. It does not,” Troskie said. “Data may be hosted within a national border while the infrastructure, operational access or contractual control still sits elsewhere.” The question he asks is whether an organisation still holds the controls when circumstances turn against it. “Sovereignty is whether you can keep operating, governing and reversing the system under your own rules when a vendor, court or outage disagrees.”
“At the infrastructure layer, sovereignty means workloads run in-region under enforceable local jurisdiction. That is necessary, but it is table stakes,” Shabreen said. The model is the harder test. It requires an organisation to “inspect, adapt, evaluate and, if needed, replace the model without asking a foreign vendor’s permission”. Of those four verbs, replacement is the one both men keep coming back to. It is also the one an organisation finds hardest to prove until the day it has to.
“The strengths are real and we should be honest about them,” Shabreen said of building on open models. They offer “capability close to the frontier, at a fraction of the cost of training from scratch”, and they can run entirely inside a country’s borders. “Dismissing that would be posturing.” Troskie agreed that the approach lets a national programme “concentrate on local language capability, domain expertise, public sector requirements and deployment within controlled environments”. The alternative is spending years and fortunes recreating what already exists.
“Access to weights should not be confused with complete independence,” Troskie said. The weights are the settings a model learns in training, the part that makes it behave as it does. Holding them is a little like holding a finished building without the architect’s drawings, the builder’s methods or the team that knows how to put up another one. A programme may have the model and still not have “access to the original training data or the expertise required to reproduce the model independently”.
He offered a test that any minister or chief executive could put to their own team. “The real test is whether an organisation can continue operating if the original developer changes the licence, stops publishing updates or moves the model in a different direction. If the answer is no, the programme has achieved a degree of control, but not complete sovereignty.”
“While the strength of the approach is speed, the risk is that speed is borrowed,” Shabreen said. Borrowing time is sensible as long as the lender stays generous, and nothing obliges the lender to do so. He said organisations should put that time into what they can keep when the model changes. “What converts borrowed capability into a durable position is owning the data, the adaptation process and the evaluation, because those are the assets that transfer when the underlying model changes.”
The one asset that gains value
“The data layer is where I see the most substance today, for the simple reason that it is the only layer where the asset appreciates,” Shabreen said. Models are upgraded and replaced, and computing power keeps getting cheaper. Carefully governed data, along with the tests built on it, follows a different path. “It becomes more valuable with every model generation, because it is what allows you to adopt each new generation on your own terms.”
This brings the argument back to language. CNTXT AI’s datasets were built with native linguists, cover more than 25 dialects and are checked by people against regional requirements, Shabreen said. That work outlasts any particular model, and it measures things the industry’s public rankings ignore. “Public leaderboards will not tell you things that would be especially pertinent to your business, such as how a model handles a Gulf-Arabic customer request.” Arabic is one case of a problem any country with its own languages, dialects and naming customs will face. A model can score well in public comparisons and still misunderstand the people it was brought in to serve.
“Relatively few organisations can own every component of an AI stack, but they can control which data a model sees, which identities can access it, what actions can be performed and whether changes can be audited and reversed,” Troskie said. For him, control over data and day-to-day operations is where sovereignty is most real today. It is also where an organisation is most likely to notice when it has lost control.
The exit nobody rehearses
“The starting consideration should be reversibility,” Troskie said. “An organisation should understand whether it can replace the model without rebuilding the applications, security policies, retrieval systems and business processes around it.” Here the quiet dependency becomes concrete. A model that cannot be removed without dismantling everything built around it binds an organisation as tightly as any closed product, whatever its licence says. “A model dependency becomes an operational risk when the organisation cannot see it, isolate it or replace it.”
“The fallback should exist before the model enters production,” he added. In practice, that means keeping the model files and settings an organisation is legally entitled to hold, keeping the model separate from the applications and data that depend on it, and maintaining a tested alternative. The cost of skipping these steps is easy to miss at the start. “If changing a model would require rebuilding the whole service, the architecture has created lock-in even if the original weights were described as open.”
Shabreen called this the least discussed part of any sovereign strategy: “a tested ability to move workloads, data and adapted models to a different provider or foundation”. The key word is tested. Many organisations have an exit plan on paper. Far fewer have checked whether it works before they actually need it.
Accountability has no supplier
“An organisation may work with partners to deliver them, but it cannot outsource accountability for them,” Troskie said of the capabilities a sovereign strategy has to keep in-house. His list covers who can see which data, who holds the encryption keys, what AI systems are running, who decides during an incident, and how the organisation recovers and eventually leaves a supplier. These are questions of command, and they stay with the organisation however much of the technology underneath is bought in.
“The ability to independently measure model behaviour against your own benchmarks, in your own languages and use cases, rather than taking a vendor’s word for it,” was how Shabreen described one of the four capabilities he believes must be held at home. The others are control over the full life of the data, governance with answerability to the country’s own regulators, and the exit path. Chips, computing capacity, base models and software tools can safely come from outside. CNTXT AI builds on infrastructure from Oracle, NVIDIA and AWS. “Our role is building the controlled layer above that substrate,” he said.
“The real distinction is between a consciously managed dependency and a dependency the organisation discovers only when something fails,” Troskie said. Every country and company relies on others somewhere. What separates them is whether they know where those dependencies are and have decided, in advance, what they will do when one gives way.
A few will still start from nothing
“The economics rarely justify it, but the strategic logic can,” Shabreen said of training a national model from scratch. He expects the market to divide over the next two to three years. A small number of entities, mostly nation states, will build their own base models from start to finish. “It is insurance against release risk, it builds a national talent pipeline, and it guarantees that a floor of capability exists under domestic control, regardless of what foreign labs decide.” Most enterprises will keep adapting what others release, though that work is becoming more demanding. “The sophistication is moving into the layers around the model.”
“An organisation may use a locally controlled model for sensitive or regulated workloads, a specialised model for a particular industry and a global model for lower risk general tasks,” Troskie said. The difficult part will be deciding which work goes where, and keeping track of it once it does. “Organisations will need to route workloads according to data classification, risk, jurisdiction and performance without losing visibility or control.”
The woman typing her question and the man waiting on his transfer will never see any of this. Whether those services understand them next year depends on decisions made long before either of them types a word: who owns the data the system learned from, who tests it in the way they speak and write, and whether the organisation behind it could switch to another model if the one it relies on stopped improving. “Sovereignty is the ability to keep making your own decisions as the technology underneath you changes,” Shabreen said. “The models will change. The infrastructure will change. What has to stay yours is the data, the evaluation and the right to walk away, because that is what lets you adopt whatever comes next on your own terms.”