What Sovereign AI Cannot Buy

Sovereign AI is sold as independence. No country achieves that, including the largest. What is achievable is managed dependency, and it is cheaper than the version being marketed.

What Sovereign AI Cannot Buy

Published 2026-09-04 · By Shahzad Asghar

Sovereign AI is usually sold as independence. Build the data centre, train the model, keep the data at home, and the country stops depending on anyone else.

No country achieves that, including the largest. What is achievable is something narrower and more useful: managed dependency — knowing precisely what you rely on, what it would cost to lose it, and how quickly you could switch. That is a different objective, and it leads to different spending.

This is the counterpart to sovereign AI: what it means and what it costs. That page sets out the layers you can hold and what each costs. This one sets out what stays out of reach regardless of budget, because a strategy that quietly assumes otherwise fails at the point it is tested.

What stays dependent, whatever you spend

Silicon. Leading-edge fabrication exists in a handful of places and cannot be replicated by national will or budget. A country can own a data centre; it cannot make the accelerators inside it. Those arrive through supply chains subject to export controls that change with foreign policy rather than with your procurement cycle. A "sovereign" facility full of imported chips is sovereign in the way a rented flat with your own furniture is.

Frontier model training. Training a leading general model costs more than most national AI budgets in their entirety, requires hardware that may not be exportable to you, and produces something outdated within a couple of years. Very few states will ever do this, and for almost all of them it would be a poor use of the money regardless.

The research frontier. The science is published and therefore available, but availability is not capability. Reading a paper and reproducing the result at scale are separated by infrastructure and people, and the people are internationally mobile.

The software stack. The frameworks, libraries and tooling everyone builds on are largely open source, which feels like independence and is not quite. Governance of those projects sits with foreign foundations and companies. You can fork; almost nobody can maintain a fork.

Talent. This is the binding constraint nearly everywhere, and the one least amenable to procurement. It is also the only dependency that can walk out voluntarily.

Nothing here argues against sovereign AI. It argues against a version of it that promises independence, because that version sets a country up to spend heavily and still discover, at the first disruption, that the dependency was never removed.

What sovereignty genuinely can buy

The achievable list is shorter, cheaper, and worth more than the aspirational one.

Control over data. Where it sits, who processes it, what leaves the country, what may be used for training. This is largely a matter of policy, contracts and architecture rather than capital expenditure, and it delivers most of what people actually mean when they say sovereignty.

Control over the application layer. The system that decides who gets a benefit, how a case is triaged, what a citizen sees — these can be built and owned domestically even when the model underneath is not. This is where the consequential decisions live.

The ability to switch. If your systems are built so a model can be replaced in weeks rather than years, a supplier's price rise or withdrawal becomes an inconvenience instead of a crisis. Portability is the most under-purchased form of sovereignty available, and among the cheapest.

Continuity under disruption. Can essential services keep running if a foreign provider becomes unavailable? Answering that honestly usually reveals which workloads genuinely need to run locally — and it is a much shorter list than a full sovereign stack.

The right not to automate. No external provider can make a state deploy AI in a given process. Declining is itself an exercise of sovereignty, and it is free.

The reframe worth adopting

Stop asking "how do we become independent" and start asking three questions instead.

Which dependencies could we survive? A model provider withdrawing is survivable if you can switch. A chip embargo is not, on any timescale that matters. Sort them.

How fast could we switch? Measure this concretely. If the answer is "we have never tried", the honest answer is that you do not know, and that is the finding.

What breaks first? Usually not the technology. Usually the people who understand the system, or the contract that quietly permits something you assumed it did not.

That reframing turns sovereignty from a construction project into a risk position, which is what it actually is. The sovereignty control ladder is the artefact for recording it layer by layer.

The expensive mistake

The most common failure is buying compute as a sovereignty gesture.

A national data centre is visible, announceable, and satisfying. It is also, on its own, close to meaningless: imported accelerators, a foreign-built model running on them, foreign-trained staff operating it, and a support contract with a company on another continent. Every dependency that mattered survived the purchase. What changed is that the electricity bill is now domestic.

The cheaper and more effective sequence runs the other way. Establish data rules first, because they cost policy rather than capital. Build the application layer domestically, because that is where decisions about people are made. Engineer for portability, so the model underneath is replaceable. Then, and only then, ask whether any workload genuinely requires local compute — and buy for that specific workload rather than for the general idea of sovereignty.

Small models running on ordinary hardware make this more achievable than it was even two years ago. A system that works on a modest local machine, as in running AI locally without a GPU, is a more genuine form of sovereignty than a large facility running somebody else's frontier model.

If you are a smaller state

Most sovereign AI writing implicitly addresses countries with capital, engineers and negotiating weight. The advice changes considerably without those.

Concentrate on data governance and the application layer, and accept the model layer as procured. That is not surrender; it is the same decision every organisation makes about the software it does not write.

Buy portability explicitly. Put exportability, exit terms and data deletion in the contract rather than assuming them, using the vendor assurance questions. A supplier who will not commit in writing has told you something.

Pool where you can. Shared regional infrastructure and joint procurement give smaller states leverage none of them holds alone — a dynamic I have written about in AI governance in the Arab region.

Invest in the people who can evaluate what you are buying. The scarcest capability is not building models; it is the ability to tell whether a vendor's claims are true. That is cheap relative to compute and it compounds.

The honest position

Sovereignty in AI is a spectrum of dependencies, not a state to be achieved. The countries that will handle the next decade well are not the ones that spent most on looking independent. They are the ones that know precisely what they depend on, have priced what losing it would cost, and can move faster than the disruption.

That is less satisfying than a ribbon-cutting. It is also achievable on a realistic budget, which the alternative is not.

For the full layer model and its costs, see sovereign AI and the sovereign AI strategy playbook. For the governance that has to sit around any of it, AI governance for government.

Frequently asked questions

Can a country be fully independent in AI?

No. Leading-edge chip fabrication is concentrated in a handful of locations, frontier model training exceeds most national AI budgets, and the required expertise is internationally mobile. What is achievable is managed dependency: knowing what you rely on, what losing it would cost, and how quickly you could switch.

Does sovereign AI require building a national data centre?

Usually not, and buying one first is a common and expensive mistake. Data governance and the application layer deliver most of the practical benefit at a fraction of the cost. Local compute is worth buying for specific workloads that genuinely cannot run elsewhere, identified after those first steps rather than before.

What is the difference between data sovereignty and sovereign AI?

Data sovereignty concerns where data sits and which laws govern it. Sovereign AI is broader, covering data, compute, models, applications and expertise. Data sovereignty is the layer most achievable through policy alone, which is why it is the sensible place to start.

What can a small country realistically control in AI?

Its data rules, its application layer, its contracts, and its ability to switch suppliers. Those cover the decisions that affect citizens directly. The model layer can reasonably be procured, provided portability and exit terms are secured in writing.

Is using a foreign AI model a loss of sovereignty?

Not necessarily. Sovereignty is compromised by being unable to leave, not by the supplier's nationality. A foreign model you can replace in weeks poses less risk than a domestic system nobody can maintain or modify.

What is the cheapest meaningful step toward sovereign AI?

Write down what each system depends on and what switching would take. Most organisations have never done this, and doing it usually reveals that a few dependencies carry most of the risk — and that some of them can be removed cheaply.

Written by Shahzad Asghar — Head of Data and Digital Solutions at UN-ESCWA, with 20+ years building AI and data systems across UNHCR, UNICEF, and UNOCHA. His team built UNHCR’s first global IVR appointment system, serving 700,000+ refugees. He created the Last-Mile AI Framework. Read more about this UN AI expert

← All articles