On the ninth of July, the prime minister of Canada stood in Riyadh and watched his country's frontier-model champion sign for Saudi megawatts. HUMAIN — Saudi Arabia's Public Investment Fund AI vehicle — committed at least 50 megawatts of AI-dedicated compute to Cohere: the company's first expansion outside North America, with sovereign Arabic models in the scope of work. Picture the room for a moment, because the room is the story: a G7 head of government travelling to the Gulf so that his national AI asset can train its next generation on someone else's electricity. Twelve days later, e& UAE and Core42 launched a sovereign GPU platform for Emirati enterprise and government — on-demand accelerators, data never leaving the UAE, zero egress fees, no capital outlay. Three days after that, India's IT Ministry tabled the IndiaAI Mission's progress in the Rajya Sabha: roughly 34,000 GPUs in a common pool, more than 93 lakh GPU-hours sanctioned across 237 projects, twenty sovereign model-building efforts backed, subsidised access reported between ₹65 and ₹150 per GPU-hour.

Underneath those three announcements, a fourth thing happened that makes the other three viable: the open-weight substrate crossed a line. Open-weight models — models whose trained parameters are published for anyone to download, run and modify — moved from a negligible share of the tokens routed through OpenRouter to roughly a third by late 2025, per the 100-trillion-token study OpenRouter published with a16z — and inside that number, Chinese open-weight models went from 1.2 per cent of weekly volume to nearly 30 per cent in a single year. On the July capability index, the best released open model sits about ten points off the best closed. A sovereign stack is only buildable at all because the model layer stopped requiring a frontier lab — you can now assemble deployable capability from weights you hold, on compute you control, in a jurisdiction you choose.

The claim of this piece is simple to state and takes the rest of it to defend: every one of these build-outs is buying a price-and-jurisdiction instrument, and sovereignty is a trust property. Compute pools compress the cost of a commodity and pin its location. Model programmes put weights into national hands. Neither buys the two layers where trust in the resulting systems is actually decided — the context layer, which governs what a system may know and on whose authority, and the evidence layer, which proves what it knew and who authorised what it did. Those layers appear in no tender in Riyadh, Abu Dhabi, New Delhi, Ottawa or Washington, because no procurement category exists for them anywhere. One regulator, alone so far, has written down the demand.

One month, four moves — and what each one is evidence of

One month, four sovereign moves July 2026: three build-outs and the substrate shift underneath them — different capital, same two layers. 9 JULY · RIYADH – TORONTO HUMAIN → Cohere At least 50 MW of AI-dedicated compute for Cohere's next-generation foundation models — operational Q4 2027, sovereign Arabic models in scope. sovereign capital · Canada's champion, Riyadh's megawatts 21 JULY · ABU DHABI e& UAE × Core42 Sovereign on-demand GPU platform for enterprise and government — data stays in the UAE, zero egress fees, no capital outlay for the customer. jurisdiction as the product · compute as a utility 24 JULY · NEW DELHI IndiaAI Mission, tabled in Parliament 34,000+ GPUs · 93 lakh GPU-hours sanctioned · 20 sovereign model efforts backed — subsidised access at Rs 65–150 per GPU-hour across 15 empanelled providers. demand-side vouchers · the only build-out with published accounting JUNE – JULY · THE SUBSTRATE Open weights crossed the line Majority of routed tokens on OpenRouter; all seven of weekly volume in a year; best released open sits about four points off best closed. the reason a sovereign stack is buildable at all Announced is not energised. The 50 MW is scheduled for Q4 2027. GPU counts are supply-side figures; utilisation is not published. Routed tokens are a developer sample, not enterprise spend — the two measures have diverged before. Different capital, same purchase: every move buys the two layers the market sells. The Sovereign Stack · sources: HUMAIN–Cohere announcement · e& UAE × Core42 · Rajya Sabha update · OpenRouter vikramjha.work

Be precise about what each announcement establishes, because they are already being quoted interchangeably as proof of the same thing.

The HUMAIN–Cohere agreement is capital finding capability. At least 50 MW of AI-dedicated capacity, expandable over five years, operational from the fourth quarter of 2027, in exchange for which the Kingdom gets a frontier-adjacent partner building Arabic sovereign models and sector-specific systems inside its perimeter. Note the direction of dependency: Canada's national AI champion will train its next generation on Riyadh's megawatts. Sovereignty, even for a G7 economy, is now brokered — through someone else's capital, someone else's grid, or someone else's silicon. Nobody holds all three.

The e& × Core42 platform is jurisdiction productised. The pitch is not price and not capability — it is that the data never leaves the UAE and the customer never builds a data centre. That is sovereignty sold as a utility subscription, and it is a genuinely new commercial shape: the state-adjacent telco supplies the trust perimeter, the state-adjacent AI company supplies the accelerators, and the enterprise buys residency the way it used to buy bandwidth.

The IndiaAI numbers are the only build-out with published accounting. 34,000 GPUs is a supply commitment — onboarded, not necessarily utilised. 93 lakh GPU-hours sanctioned across 237 projects is the more interesting figure, because it is demand actually moving through the voucher mechanism. And ₹65 to ₹150 per GPU-hour is a transfer price, not an economy — a deliberate compression of access cost for a defined population. The Gulf announces partnerships; India tables line items. That difference in auditability is itself a strategic fact, and this piece leans on India hardest for exactly that reason: it is the build-out you can actually evaluate.

And the substrate shift is what connects them. None of these programmes assumes a domestic frontier lab. All of them assume that open weights plus sovereign compute plus local fine-tuning yields deployable capability — an assumption that was aspirational in 2024 and is arithmetic in 2026.

The substrate: open weights crossed the line, and the numbers are specific

Because every sovereign strategy now rests on it, the open-weight parity claim deserves its numbers rather than its vibes. On the Artificial Analysis Intelligence Index (v4.1, July 2026, maximum reasoning effort), Kimi K3 sits at 57 as the top open model and GLM-5.2 at 51, against a closed frontier led by Claude Opus 5 at 61, with Fable 5 at 60 and GPT-5.6 Sol at 59. Best open to best closed: roughly four points. GLM-5.2 — released 17 June under an MIT licence, roughly 750 billion parameters with 40 billion active and a million-token context — is the sharpest single artefact of the shift: a permissively licensed model inside striking distance of the frontier, which any government, bank or startup may fine-tune and own the derivative of.

The economics run the same direction harder. DeepSeek V4-Flash serves at $0.242 per million output tokens, MiniMax M3 at $1.21, GLM-5.2 at $3.31, against closed frontier models in the fifteen-to-twenty-five-dollar range — roughly two orders of magnitude of price for something in the region of four index points. And the usage follows: Qwen's family alone counts over 942 million cumulative downloads, running at more than 150 million a month, and OpenRouter's routed-token majority is the flow measure of the same shift. This is why a 50 MW commitment to Cohere, a UAE sovereign cloud and an Indian voucher pool are all rational at once: the capability layer has become somewhere between cheap and free to source, so the differentiating purchases move down-stack to compute and jurisdiction — and, as the rest of this piece argues, should be moving up-stack to trust.

One honesty note before building on this, expanded in the limits section: routed tokens measure developer flow, not enterprise spend, and the two have diverged before — enterprise dollars measured by Menlo Ventures moved the opposite way across 2024–2026. The parity index is a benchmark composite, not your workflow. The substrate claim survives both caveats; the triumphalist version of it does not.

India: the demand-side voucher, and the one portfolio position that has already paid

India's is the build-out worth the closest read, partly because it publishes the most, and partly because its design choice is the one other fiscally constrained states will copy. The Mission did not build a national supercomputer. It empanelled fifteen private providers and subsidised demand across them — vouchers, not monuments. A state-built machine is a single asset with a single procurement cycle and a single point of obsolescence, in a field where the accelerator generation turns over every eighteen months; a demand-side subsidy keeps capacity fungible, keeps providers competing, and lets the state upgrade the fleet by changing whom it empanels rather than by writing off a building. This is the digital-public-infrastructure instinct — the state as market-maker, vendors underneath — applied to compute, and it is the right instinct.

The model portfolio — twenty efforts, twelve large and eight small — has already produced the thing no other national programme has: a frontier-adjacent open-weight release. Sarvam's 105B, a mixture-of-experts model with a 128K context window and support for all twenty-two scheduled Indian languages, was trained on Mission compute and released under Apache 2.0 in February alongside its 30B sibling. Whatever its exact benchmark position, its existence changes the reference class: sovereign model-building stopped being a press-release genre the day the weights went up. And the eight small models may matter more than the twelve large ones, because fine-tuned small models are where deployable, ownable capability lives for most enterprise workloads, and Indic-language coverage is precisely the class the global frontier under-serves.

Then comes the asterisk that motivates this whole piece. Sarvam's benchmark claims remain, as the Forbes analysis in March put it, almost entirely self-attested — no major public leaderboard presence, no peer-reviewed methodology paper, headline numbers from the developer — while the models are reported in production contexts touching Aadhaar-adjacent services and a life insurer with tens of millions of customers. India has evaluation efforts, but nothing with the reach and legitimacy of a national scoreboard. A country that can train a model but cannot independently verify it has bought the commodity and skipped the trust. Hold that sentence; it is about to generalise.

What all four build-outs buy — and the two layers none of them cover

Here is the distinction that does the work. Access sovereignty is the ability to reach the commodity on your own terms: your jurisdiction, your pricing, your allocation rules, your residency guarantees. Verification sovereignty is the ability to prove, to your own institutions and on your own evidence, that what the commodity produced is fit to act on. Every July announcement purchased the first. No tender anywhere on earth currently purchases the second.

What Rs 10,372 crore bought, layer by layer The IndiaAI Mission's July numbers, mapped onto the four layers a sovereign AI stack needs. LAYER 4 · EVIDENCE NOT FUNDED What did it know, who authorised it, prove it Appears nowhere in the progress report — no procurement category exists LAYER 3 · CONTEXT NOT FUNDED Whose knowledge, under whose entitlements, with what provenance No line item, no tender, no empanelment — the market does not sell it LAYER 2 · MODELS FUNDED 20 sovereign model efforts backed — 12 large, 8 small Sarvam 30B and 105B trained on Mission compute, released under Apache 2.0 LAYER 1 · COMPUTE FUNDED 34,000+ GPUs · 93 lakh GPU-hours sanctioned · 237 projects 15 empanelled providers · subsidised access at Rs 65–150 per GPU-hour THE DEMAND EXISTS DPDP Act, 2023 Purpose limitation makes context scope a statutory question, not a design taste. RBI draft MRM guidance 24 June 2026 Autonomy is a tiering axis. Kill-switch and override arrangements mandated. Accountability cannot be outsourced to the vendor. Both point at layers three and four. Read the counts as supply-side figures. GPU numbers are onboarded capacity — utilisation is not published. Prices are subsidised transfer rates, and reported figures span Rs 65 to Rs 150 per GPU-hour depending on accelerator class and source. The market sells layers one and two. Sovereignty is decided in three and four. The Sovereign Stack · sources: Rajya Sabha progress update, 24 Jul 2026 · Sarvam AI · RBI draft guidance vikramjha.work

The figure uses India's numbers because India publishes them, but the four-layer reading applies to every build-out in this piece. Layers one and two — compute and models — are where all the capital lands: the GPU pools, the vouchers, the 50 MW, the model grants. Layer three is context: whose knowledge a deployed system acts on, under whose entitlements, with what provenance. Layer four is evidence: what did it know, who authorised it, prove it after the fact. Those two layers are where a bank's model-risk committee, a ministry's procurement officer or a foreign counterparty actually decides to trust a system — and they appear in no progress report, no platform launch and no bilateral agreement, because the market does not sell them and no procurement category exists to demand them.

Run the test across each build-out. Sarvam's models reach production on the developer's own benchmarks — verification gap. Cohere will build sovereign Arabic models inside HUMAIN's perimeter — evaluated by whom, against what harness, on whose evidence? The e& platform guarantees where data sits, which is layer-one residency; it says nothing about what a system running on it may know or how its actions are attested, because that is not what a GPU utility is for. And the honest asterisk under all of it: every accelerator in every one of these pools is NVIDIA silicon, so compute you can access is not compute whose supply chain you control — access sovereignty itself is bounded by a single upstream vendor, everywhere, equally. The build-outs differ in capital structure and rhetoric. In stack coverage they are identical: layers one and two, funded lavishly; layers three and four, absent.

One quarter, three regulatory postures — and only one demand signal

One quarter, two opposite answers What the US revision and the RBI draft say about AI systems that act — issued 68 days apart. 68 days UNITED STATES · 17 APRIL 2026 Fed SR 26-2 / OCC Bulletin 2026-13 Supersedes SR 11-7 and SR 21-8; rescinds OCC 2011-12. “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” No enforceable standards, no prescriptive requirements. Separate AI guidance promised — no date attached. A DEFERRAL, NOT AN EXEMPTION INDIA · 24 JUNE 2026 RBI draft model risk management guidance All models in scope — internal or third-party, whether or not the bank calls them models. Foundational and frontier AI expressly named. Autonomy is a risk-tiering axis, beside materiality and complexity. Kill-switch, override and suspension mandated. Third-party accountability stays with the bank. Comment window closed 24 July 2026. SYSTEMS THAT ACT ARE IN SCOPE Neither supervisor is handing anyone a control specification. One declined to write it. The other has drafted the demand for it — and asked the industry to comment. Honest limit: the RBI text is a draft; obligations and dates may move before final issuance. The Sovereign Stack · sources: OCC Bulletin 2026-13, 17 Apr 2026 · RBI draft MRM guidance, 24 Jun 2026 vikramjha.work

If the market will not sell the trust layers, the other force that could summon them is supervision — which is why the most important sovereign-AI documents of 2026 are not the compute announcements at all, but two regulatory texts issued sixty-eight days apart.

On 17 April, the US banking agencies issued their revised interagency model risk guidance — Fed SR 26-2, OCC Bulletin 2026-13 and the parallel FDIC issuance — superseding SR 11-7 after fifteen years. It states that generative and agentic AI models are novel and rapidly evolving and, as such, are not within its scope, with separate AI guidance promised and no date attached; it also sets no enforceable standards. That is a deferral, not an exemption — every obligation attached to the underlying action still binds — but the practical consequence is that no US institution will be handed an agent-control specification any time soon, and the eventual guidance will be written against whatever the industry has already built.

On 24 June, the Reserve Bank of India published its draft Guidance on Regulatory Principles for Model Risk Management, comments closed 24 July. Its scope provision is the most consequential sentence any regulator has produced on this subject: all models a regulated entity relies on — internal, third-party, or combinations, irrespective of whether the institution recognises them as models — with foundational and frontier AI expressly named. Risk tiering must weigh materiality, complexity and the degree of autonomy placed on model outputs: autonomy as a first-class risk axis, which reaches agentic systems without needing the word. Kill-switch, override and suspension arrangements are mandated. Accountability for third-party models stays with the bank, independent validation is required regardless of vendor assurance, and models lacking explainability draw enhanced controls rather than exemptions.

Hold each RBI requirement up and ask what it consumes. Tiering by autonomy consumes a record of what a system is entitled to do and on whose authority — the context layer. A kill-switch drill consumes a defined point of action where authority can be severed — the context layer at its enforcement edge. Independent validation consumes evaluation evidence the vendor did not produce. Every after-the-fact obligation consumes a record of what the system knew and who authorised the act — the evidence layer, precisely. The draft never names the layers. It simply describes a supervisory posture that cannot be discharged without them. The Gulf, meanwhile, runs a third posture: SAMA and the CBUAE's conservatism, plus the partnership perimeter itself — who may build with whom, under what export and audit conditions — functions as de facto governance while formal AI frameworks mature. Three postures, one practical convergence: in every market, the institution ends up owning the trust layer itself, either because no specification is coming, because a draft one already arrived, or because the perimeter demands evidence before formality does.

The protocol-layer wager, generalised

There is a template for what happens next, and it is Indian, though its application is now global.

UPI did not win by building a state bank The sequencing that made digital public infrastructure work, held against the AI stack in 2026. PAYMENTS · THE 2016 PLAY 1 · The state standardised the protocol identity · addressing · settlement grammar · consent 2 · The market competed underneath banks, payment apps, devices — all interchangeable 3 · Trust became a property of the rails not of any single vendor's promise AI · THE 2026 STATE OF PLAY 1 · The state subsidises the commodity compute vouchers · model grants — layers one and two 2 · The protocol layer is unwritten entitlement grammar · provenance format · attestation record 3 · So trust is re-argued, deployment by deployment agency by agency, bank by bank, review by review The AI protocol layer is not the model, and it is not the data centre. It is the layer that records who may know what, who may act, and what happened — in a form a regulator can replay. The parallel is an argument, not a proof. Payments had one clearing problem; AI systems have many. What carries over is the sequencing — standardise the trust layer first, and let the market build everything else on top of it. The Sovereign Stack · the DPI sequencing argument, applied to the four-layer AI stack vikramjha.work

India's digital public infrastructure did not win by building a state bank, a state phone or a state app. It won by standardising the protocol layer — identity, addressing, settlement grammar, consent — and letting the market compete underneath it, which turned trust into a property of the rails rather than of any vendor's promise. Run that template over AI in 2026, in any of the four jurisdictions this piece has visited: the state is subsidising the commodity, and the protocol layer — the shared grammar everything else plugs into — is unwritten. The AI equivalent of the settlement grammar is not the model and not the data centre. It is the grammar that says this system, acting for this principal, may know this and do this, and here is the record — an entitlement grammar, a provenance format, an attestation record, standardised so a regulator can replay any consequential action without a bespoke investigation.

Whichever jurisdiction standardises that layer first becomes the reference implementation for sovereign AI — the thing the others license, imitate or quietly adopt, exactly as UPI became the artefact every payments delegation now visits. The candidates each have an edge and a gap. India has the institutional muscle memory and a regulator already drafting the demand, but no procurement category yet. The Gulf has capital that could simply buy the buildout, and supervisors whose conservatism would adopt it fast, but its build-outs are currently importing capability rather than specifying trust. North America has the deepest engineering bench and the strongest market incentive — its supervisor has explicitly declined to write the spec, leaving it to whoever ships one — but no national programme to anchor it. The wager is open. What is not open is the direction: every regulated deployment in every one of these markets, from a Mumbai bank to a Riyadh ministry to a Toronto insurer, currently re-argues trust from scratch, and that cost compounds with each deployment until someone standardises it away.

Honest limits — where this argument is weak

Six places I would not lean hard, stated before someone else states them.

Announced is not energised. The HUMAIN–Cohere capacity is scheduled to be operational in Q4 2027, and announced megawatts have a long history of arriving late or smaller. India's GPU counts are onboarded supply-side figures; utilisation is not published, and reporting has flagged it as a live concern. The ₹65–150 price band reflects source and accelerator vintage — a band, not a point.

Routed tokens are not enterprise spend. OpenRouter measures a developer-weighted flow; Menlo's enterprise-spend measurement moved the opposite direction over the same period. The substrate claim I am making — open weights are now sufficient for sovereign stacks — survives on capability and price evidence alone, but the majority-share figure should not be quoted as market share.

The parity index is a composite under specific settings. The four-point gap is measured at maximum reasoning effort on one index; the setting is load-bearing, and index points are not your workflow. Anyone adopting an open model on this argument still owes themselves a blind evaluation harness on their own tasks.

The RBI text is a draft. Obligations, thresholds and dates may move before final issuance. I am relying on its direction — autonomy in scope, evidence obligations, non-delegable accountability — which comment processes rarely reverse, not its letter, which they often soften.

The DPI parallel is an argument, not a proof. Payments had one clearing problem; AI systems have many heterogeneous trust problems, and one protocol layer may fragment into several. What I am confident carries over is the sequencing — standardise the trust layer, let the market build on it — not the claim that one artefact serves every domain.

And the verification critique cuts everywhere, including at the frontier. Self-attested benchmarks are the industry norm, not an Indian or Gulf deviation; frontier system cards are vendor-reported as a rule. The difference is that a sovereign programme's entire justification is public trust, which raises the standard its outputs must meet. A critic who says the whole industry has this disease is right; this piece is arguing the sovereign build-outs are where the cure is both most needed and most fundable.

Monday, in three chairs

Nothing above argues for waiting, and each chair this piece is read from has a concrete next move that costs engineering, not tenders.

If you run AI in a regulated institution — in any of these markets — build the four artefacts every posture converges on: a model inventory that includes every third-party and foundation model you touch, whether or not anyone called it a model; a tiering memo that scores autonomy explicitly — what each system may do without a human, in business terms; a kill-switch drill with a named owner, a real severance point and a measured time-to-halt; and an evidence record captured at the point of action — what the system knew, from where, under which authority — because it cannot be reconstructed later. If the RBI draft applies to you, this is the final's direction. If SR 26-2's deferral applies to you, this is what the eventual guidance will be written against. Either way it is the same work.

If you shape policy — in Delhi, Riyadh, Abu Dhabi or Ottawa — the single highest-return line item the next tranche could fund is the national scoreboard: a standing, adversarial, blind evaluation harness for the models your programme backs, run by an institution with no stake in the results, publishing methodology and refreshing continuously. It costs a fraction of one GPU tender and it converts a model portfolio into an adoptable one. The second line item is the attestation standard — the record format a regulator can replay — drafted with your supervisor rather than around them. First mover here wins the reference-implementation wager outright.

If you build, the gap between this summer's compute announcements and this summer's regulatory texts is a product specification nobody has claimed, in four markets simultaneously: the entitlement grammar, the provenance format, the evaluation harness, the attestation record. The build-outs have guaranteed that models and compute will be abundant, cheap and jurisdictionally pinned. The regulators have guaranteed that institutions will owe proof of what those models do. Between abundance and obligation sits the entire missing market. The audit is the product.

The July announcements settled the question nobody was really asking — whether states can buy the commodity layers. They can, in three different currencies. The question that decides which of these programmes becomes a reference implementation and which becomes a very large customer is whether anyone funds the layers no tender yet names — and unlike the megawatts, that race has no incumbent. I work on exactly this seam — entitlements, governed context, attestation — across North America, the Gulf and India; if a sovereign-stack decision with your name on it is waiting on the trust question, vikramjha.work is the place to start that conversation.