Sovereignty now means which models you’re allowed to run

Checked 22 Sep 2026 · By Luke Czak

ArticleAI & SocietyFree to read

The question of who controls a country’s AI capability is quietly becoming a question about which models it is allowed to run at all, not which ones it chooses to.

The word sovereignty used to mean, in the context I first heard it applied to computing, something closer to data residency — where the servers physically sit, which jurisdiction’s courts can compel access. That framing is already out of date for the frontier of AI, because the more consequential question is no longer where a model’s outputs are stored but which models a country, a company, or an individual is even permitted to run in the first place.

That shift matters because access to a frontier model is not a commodity in the way most software has been. A capable model is closer to a strategic asset — export controls on the chips that train it, licensing terms on the weights that decide who can use it, usage policies enforced by a handful of providers who can revoke access unilaterally. None of that is hypothetical; it describes the actual mechanics of how the current generation of frontier models reaches anyone at all. The list of entities capable of training something at the frontier is short and getting shorter relative to the number of entities that depend on the output, which is exactly the asymmetry that makes the word sovereignty apply at all — dependency without control is the condition the word has always described.

The practical consequence I think about most is what happens to a person or an organisation that has built real capability on top of a provider’s model, when the terms of that access change and there was never a version they controlled. This is not a new pattern — it is the same dependency that platform businesses have lived with for two decades, rebuilt at a layer that now sits underneath almost everything else. The difference is how much more of the stack now runs through that single dependency. A platform losing access to a distribution channel can usually route around it, however painfully; an organisation losing access to the model it built its actual product logic on top of often cannot, because there may be no comparable substitute to route to.

Open-weight models are the closest thing to a hedge against this that currently exists, and I think that is the actual reason the debate about releasing weights openly versus keeping them behind an API is a policy question and not just a competitive one. A weight you can run yourself is not revocable by anyone else’s decision. It may be behind the frontier, and it usually is, but it is the version of the technology that cannot simply be turned off from outside your own control.

Whether any of this resolves towards more openness or less is not something I think is settled, and I am wary of anyone who states it with confidence in either direction — the incentives run in both directions at once, towards control because capability is genuinely dangerous in the wrong hands, and towards openness because concentrated control over something this consequential is its own kind of danger.

What I do think is settled is that the old framing of sovereignty, about where a server sits, is answering a question that stopped being the important one. The question that matters now is closer to a supply chain question than a data protection one — who can build the thing, who can run the thing, and who can be cut off from the thing by a decision made somewhere else entirely.

I do not think most people building on top of frontier models today have priced this risk correctly, mostly because the terms have been stable enough for long enough that stability feels like a property of the relationship rather than a temporary condition of the market. It has not been tested yet at the scale that would reveal whether it holds.

Comments (0)

Sign in to comment.