Sovereignty Control Ladder

The sovereignty control ladder records one row per AI layer: data residency, compute, models, talent, and governance. Each row states the control posture, the rationale, the annual cost, and the exit or alternative if the dependency fails. The exit column is the one most often skipped and the one that matters most.

Sovereignty decisions are usually made implicitly, one procurement at a time, and only become visible when a dependency fails. The ladder makes the choices explicit and priced.

The template

Complete one row per layer. The right hand column is the one that gets skipped and matters most.

LayerControl postureRationaleAnnual costExit or alternative if dependency fails
Data residencyHold, share, or accept
Legal jurisdiction of operator
Operating personnel
Network path
Compute location
Model weights
Right to modify

Posture definitions. Hold means the state controls it directly. Share means joint control under binding agreement, including regional arrangements. Accept means external dependency with a documented exit.

How to use it

  • Complete one row per layer rather than making a single overall sovereignty judgement.
  • Price each posture annually. A posture without a cost is a preference, not a decision.
  • Complete the exit column for every row. It is routinely skipped and it is where the actual risk sits.
  • Review when a dependency changes ownership, jurisdiction, or pricing model.

Where this goes wrong

The failure modes below are the ones worth checking for first. Each describes a way this artefact stops doing its job while still appearing to be in use.

  • The ladder is treated as a ranking, so every system is pushed toward the top rung. Sovereignty is a cost, not a virtue. A system holding no personal data and no policy leverage does not need the controls that a population register needs, and spending them there means underspending somewhere that matters.
  • The rung is claimed on the location of the data centre alone. Physical hosting inside a jurisdiction means little if the operator, the key material, the model weights, or the support contract sit outside it. Each of those is a separate question and each needs its own answer.
  • Nobody names the specific dependency being removed. A rung that cannot be stated as "we no longer depend on X for Y" is a label rather than a control, and it will not survive the first procurement challenge.
  • The assessment is done once at approval and never repeated. Vendors reorganise, subprocessors change, and models get retired. A ladder position recorded eighteen months ago describes an arrangement that may no longer exist.

Common questions

How do you decide what AI capability must stay under national control?

Complete one row per layer, covering data residency, compute, models, talent, and governance. For each, record the control posture chosen, the rationale, the annual cost of that posture, and the exit or alternative if the dependency fails. The exit column is the one most often skipped and the one that matters most, because sovereignty risk becomes visible only when a dependency is withdrawn.