Sovereign AI Strategy: A Practical Playbook

Last updated: 2026-08-14

Your government or institution has committed to sovereign AI. You now have to decide what that means in practice, what it costs, and what you build first.

Sovereign AI Strategy: A Practical Playbook

The decision this page helps you make

Your government or institution has committed to sovereign AI. You now have to decide what that means in practice, what it costs, and what you build first.

Sovereignty is not a single thing you either have or lack. It is a ladder of specific controls, each with a price and each independently achievable. Most states can afford two or three rungs. The strategic question is which ones, and the honest answer usually surprises the people who commissioned the strategy.

Rules of thumb

1. Name the layers you intend to control. There are seven, and they are separable: data residency, model weights, compute location, network path, operating personnel, legal jurisdiction of the operator, and the ability to modify the system. Write down which of the seven you will hold, which you will share, and which you accept as external dependency. A strategy that does not make this table explicit has not made a decision.

2. Do not open with a national language model. It is the most visible option and almost never the highest return. Training costs recur, the result is obsolete within two model generations, and you will have solved a problem that commercial providers also solved. Open instead with the data estate and the procurement rules, because both compound and neither depreciates.

3. Sovereignty over data is achievable. Sovereignty over frontier capability is not, for most states. Be precise about the goal. Controlling where your citizens' records live, who can read them, and under whose law is realistic and defensible. Matching frontier training capability is a different order of expenditure. Conflating the two produces strategies that fail publicly.

4. Budget operating cost, not build cost. Over five years, run cost typically dominates. Plan for total cost of roughly three times the build figure over that period, covering power, cooling, hardware refresh at three to five years, network, licensing, and staff. Capital appropriation without a matching operating line produces a facility that degrades from the day it opens.

5. Retention beats recruitment. You will not out-pay the private market and you should stop trying. Compete on the things you can offer: problems of national consequence, access to data nobody else holds, authority to decide, and predictable career progression. Then fix the two things that actually drive exits, which are procurement latency and the inability to get a development environment.

6. Build the procurement rules before the infrastructure. Every AI system your state acquires for the next decade will pass through procurement. A clause set that mandates data residency, sub-processor disclosure, model change notification, exit and portability, and audit rights will shape more of your sovereign position than any single data centre. It also costs almost nothing to write.

7. Fix identity, registries, and interoperability first. AI applied to a fragmented data estate produces fragmented results at higher cost. Population registry quality, a working identity layer, and enforced interoperability standards are the precondition. They are unglamorous, they take three years, and skipping them is the most common cause of stalled national programmes.

8. Choose the compute posture deliberately, in three tiers. Sensitive workloads on domestic infrastructure under domestic control. General workloads on commercial cloud under contractual residency terms. Frontier experimentation on whatever is available, accepting the dependency, because you will not be training frontier models. Publishing this three-tier posture ends most internal arguments about where a given system should sit.

9. Regional pooling beats national duplication. Compute, evaluation infrastructure, language resources, and specialist talent all reward scale. Neighbouring states with a shared language or shared legal tradition duplicate the same investments repeatedly. Pooling is politically harder and economically obvious. Raise it early, before capital is committed.

10. Treat language as infrastructure, not as an application. If your working language is under-resourced, the useful investments are corpora, evaluation benchmarks, tokeniser quality, and public domain data release. These raise the ceiling for every system built afterwards, including systems you did not fund. Training one model does not.

11. Set an exit plan for every external dependency you accept. Accepting a dependency is legitimate. Accepting one with no documented alternative, no portability provision, and no estimated switching cost is not. For each external layer, record the alternative, the time to switch, and the cost. Review annually.

12. Publish measurable commitments on a fixed schedule. Strategies without dated deliverables become documents. Commit to a small number of observable outcomes with named owners and quarterly reporting. Three real commitments outperform thirty aspirations, and they survive a change of minister.

The artefact: sovereignty control ladder

Complete one row per layer. The right hand column is the one that gets skipped and matters most.

LayerControl postureRationaleAnnual costExit or alternative if dependency fails
Data residencyHold, share, or accept
Legal jurisdiction of operator
Operating personnel
Network path
Compute location
Model weights
Right to modify

Posture definitions. Hold means the state controls it directly. Share means joint control under binding agreement, including regional arrangements. Accept means external dependency with a documented exit.

The artefact: national AI strategy test

Run any draft strategy against these ten questions. A draft that fails more than three is not ready for cabinet.

  1. Does it state which sovereignty layers are held, shared, and accepted?
  2. Does it carry a five-year operating cost, not only a capital figure?
  3. Does it name an accountable institution for each commitment, with an individual title?
  4. Does it identify the data estate work that precedes the AI work?
  5. Does it commit to procurement clause reform with a date?
  6. Does it state what the state will not do?
  7. Does it include an exit or alternative for each accepted external dependency?
  8. Does it define measurable outcomes reportable quarterly?
  9. Does it address who is accountable when a public sector system harms a citizen?
  10. Does it survive a change of minister, meaning are the commitments institutional rather than personal?

The artefact: five-year cost model structure

Build the model with these lines. Understating any of them is the standard failure.

Capital. Facility, power distribution, cooling, compute hardware, network hardware, initial software licensing.

Operating, annual. Power at realistic utilisation. Cooling. Hardware refresh provision at 20 to 33 percent of compute capital per year. Software and support licensing. Connectivity. Facility operations.

People, annual. Platform engineering, security operations, data engineering, model operations, governance function. Cost these at retention-competitive rates, not at standard public scale, then state the gap explicitly rather than hiding it.

Programme, annual. Evaluation and benchmarking, corpus and dataset development, training and capability building, external assurance.

Contingency. Not less than 15 percent. Power costs and hardware availability have both moved sharply and will again.

Failure signals

  • The strategy names capability targets but no institution owns them.
  • Capital is appropriated and the operating line is not.
  • A flagship model is announced before the data estate work is scoped.
  • Sovereignty is claimed while inference runs in another jurisdiction under another law.
  • The talent plan consists of a recruitment target with no retention mechanism.
  • No document states what the state has decided not to attempt.
  • Neighbouring states are building the same facility for the same purpose and no one has convened the conversation.

What this does not cover

This page addresses strategy formulation and the control choices underneath it. It does not cover national security applications, defence procurement, export control regimes, or the specific technical design of data centre and network infrastructure. It also does not cover the domestic political economy of where facilities are sited, which frequently determines outcomes more than any analysis here.

Download this playbook as Markdown · All playbooks