Capability

Sovereign & open-weight AI

Owning the intelligence and the context, rather than renting both and hoping.

Data and model sovereignty
Residency and cross-border inference
Open-weight evaluation
Local and air-gapped inference

The problem

This lane is usually argued as ideology — open versus closed, one country's models versus another's — and that framing is why serious institutions discount it. The durable argument is narrower and much harder to dispute: in an incident, the capability you can actually rely on is the one you control. A governed model inside your boundary does not rate-limit you, does not refuse you, and does not phone home. That is a resilience property before it is anything else, and it is the same property that lets you prove afterwards exactly what touched your data.

Where it breaks

Failure pointWhat actually happens
Inference crosses borders invisiblyProvider routing moves a prompt between regions with no signal at your layer. Most architectures have never traced where a prompt physically goes, which makes a residency assurance an assumption.
The refusal you cannot appealA hosted safety filter reads what is being asked, not who is asking or under what authority. During an intrusion the most valuable queries are exactly the ones most likely to be refused.
Capability withdrawn underneath youA model version is retired, a rate limit changes, a term is amended. Nothing in your change control fired, and behaviour moved anyway.
Sovereignty asserted, not evidencedA contractual residency clause is not a traced request path. The two are routinely treated as the same thing until an examiner asks.
Open-weight adopted without evaluationRunning a model locally proves control, not fitness. Without a parity evaluation against the workflow it replaces, sovereignty is bought with a quality regression nobody measured.
No exit that has been runAn exit path in a contract is a promise. An exit path that has been executed once is a control.

Standards and regimes named on this page were last checked against their primary sources on . Instruments move — several cited here changed inside the last year — so verify against the source before you rely on one. If you find something stale, tell me and I will correct it.

The work

What this actually consists of

  • Where the sovereignty line actually falls for your obligations — and where it does not need to
  • Traced inference paths, so residency is evidence rather than assurance
  • Open-weight evaluation against the specific workflow, so a sovereign option is chosen on measured parity and not on principle
  • Local, air-gapped and hybrid deployment patterns, including which workloads genuinely warrant them
  • Tested exit and fallback from a hosted provider — run once, not merely drafted

The test

The question is not open or closed. It is: if the provider refused you tomorrow, mid-incident, what would you still be able to do — and can you show it, rather than believe it?

Next step

Where does this sit in your estate?

The useful version of this conversation is specific — one workflow, one deadline, one thing you are not sure you could evidence. That is usually twenty minutes.