The Sovereignty Mirage..

..On buying, building, and leasing the mind of a nation!

I read a policy brief last week and haven’t been able to put it down.
Stanford HAI published it on July 15th. It’s called The Commercial Landscape of AI Sovereignty Offerings, and Caroline Meinhardt, Juan Pava, Caroline Yee and James Landay wrote it in that flat, careful register academic institutions use when they’re trying not to start a fire. They surveyed the whole global market in “sovereign AI.” The Nvidia AI Factories. The disconnected clouds. The localized model deployments. The national champions. And they asked one deceptively simple question: does any of this actually make a country more sovereign?
Their answer, compressed into a phrase, is that the real challenge isn’t eliminating dependence. It’s “calibrating interdependence.”
I’ve been turning that sentence over ever since. I think it’s the most honest thing anyone has said about this era, and I also think it’s a quiet act of demolition. Because “calibrating interdependence” is not what any minister means when they stand at a podium in Paris or Riyadh or New Delhi and announce a sovereign AI programme. What they mean is ours. Ours the way the army is ours. Ours the way the currency is ours. Ours the way the border is ours.
What the brief gently points out is that it won’t be. Not really. Not for almost anyone.
The arithmetic that ends the argument
Start with the numbers, because they’re brutal and they do most of the work.
The UN’s Independent International Scientific Panel on AI, co-chaired by Yoshua Bengio and Maria Ressa, put the compute divide at the centre of its first assessment. The United States holds roughly three quarters of global AI computing capacity. China holds something like fifteen percent. Everyone else, every other country on earth, around 190 of them, containing the overwhelming majority of humanity, splits the last tenth.
The 2026 AI Index sharpens it further. The US hosts more than five thousand data centres, over ten times any other country. High income nations account for the vast majority of notable model releases and startup funding. Low income countries collectively hold a fraction of one percent of global data centre compute.
Against that, the counter spending is both genuinely enormous and genuinely insufficient. The EU’s InvestAI initiative wants to mobilize €200 billion and build up to five AI gigafactories. France has committed €109 billion under France 2030. Saudi Arabia’s PIF has announced $40 billion. Canada pledged just under a billion dollars over five years. Sovereign investors globally put around $66 billion into AI and digital infrastructure in 2025, with Gulf funds the largest single contributors.
Now hold all of that against US hyperscaler capital spending, which lands somewhere around $660 to $690 billion in 2026 alone. Europe’s entire sovereign cloud effort is a rounding error on the balance sheet of the thing it’s trying to become independent from.
That’s the first thing worth sitting with. The sovereignty race isn’t really a race. It’s a negotiation being conducted in the vocabulary of a race.
Three doors, and the one nobody mentions
The Stanford framing (buy, build, or lease) is useful because it makes the trade offs visible.
Buy the American stack and you get frontier capability tomorrow morning. Nvidia’s AI Factories now span more than twenty five countries. Microsoft, Google and AWS compete on disconnected clouds and jurisdictional shields. OpenAI runs an explicit for Countries programme. In March, Palantir and Nvidia went further and announced a turnkey “Sovereign AI Operating System” reference architecture, sizing the market at $600 billion. Sovereignty, boxed and shipped.
Landay’s warning here is almost domestic in its imagery. Think how hard it is to switch cable providers. Now imagine switching the cloud that runs your entire national AI infrastructure. Lock in isn’t a bug in these offerings. It’s the business model wearing a flag.
Build from scratch and you find out that “from scratch” is a fiction. The Stanford team looked at the sprawling ecosystem of non US companies marketing sovereign solutions and found very few that are meaningfully domestic. Most sit on Nvidia silicon, US cloud partnerships, or foreign trained weights. Huawei, the only serious alternative chip supplier at scale, produced roughly 200,000 AI accelerators in all of 2025. CUDA isn’t a technology at this point. It’s a gravitational field.
Lease and you’ve simply chosen a dependency with a shorter contract.
Which brings me to Kai-Fu Lee, who this spring named what I think is the single most consequential error in the entire debate. Countries believe they have two options: accept an American model, or build a frontier model from zero. Both are wrong. The real third path is to take a leading open weight model and continue training it on your language, your legal norms, your religious and cultural context. Not fine tuning. Continued pretraining, treating the open model as “a half baked product” you finish in your own kitchen. His analogy is a frozen pizza you bake with your own ingredients. An Indian pizza. A Japanese pizza.
The cost, he estimates, is a few percent of training from scratch. Millions instead of hundreds of millions.
His larger thesis deserves saying plainly, because it cuts against nearly every strategy deck circulating in capitals right now. Being late is not the same as being irrelevant. Open source, he argues, creates a real late mover advantage. He expects the endgame to rhyme with iPhone and Android: closed ecosystems capturing the margin, open ecosystems capturing the world. Chinese labs, he notes, spend under ten percent of what leading American labs spend and ship models at ninety to ninety five percent of frontier capability, six to nine months behind. They share not out of idealism but out of arithmetic. They can’t win alone, so they build like a study group, while American labs behave like solitary scholars each convinced of their own Nobel.
If he’s right, the most sovereign act available to a mid sized nation in 2026 isn’t building a data centre. It’s choosing open weights and growing the people who can extend them.
Convening the panel
I keep a small imaginary council in my head for questions like this. Let me let them speak.
Geoffrey Hinton would tell you not to confuse the map with the terrain. His view of national competition has hardened into something almost clinical. On lethal autonomous weapons he says flatly that countries will not collaborate. The major arms suppliers are building them, they won’t regulate themselves, and they won’t slow down. But he draws a sharp line at a different category of risk. On losing control to systems smarter than us, he expects genuine cooperation, because no government, Beijing included, wants to be the one that hands power to a machine. “We’re all in the same boat with respect to the existential threat,” he said. He also warns, and this matters enormously here, that the adoption gap between developed and developing nations is turning into a second great divergence.
Yoshua Bengio would reframe all of it as a problem of tempo. He talks about hoping for a “Goldilocks accident.” Large enough to wake governments up, small enough not to break civilization. His deeper fear is the boiling frog, where harm arrives gradually enough that we normalize it and never react at all. He co chairs the UN panel that produced the compute divide finding, and I find that pairing instructive. The man most worried about losing control is also the man documenting who currently holds the controls.
Demis Hassabis published his own framework this month arguing the window for coordination is narrow and closing. He’s long floated a CERN for AI, an international venue for safety research too expensive for any single state, and he’s been honest that meaningful cooperation looks difficult in today’s geopolitical weather. But notice what a CERN implies. CERN is the opposite of sovereignty. It’s twenty odd nations agreeing that some instruments are too large and too important to be owned by one of them.
Eric Schmidt, with Alexandr Wang and Dan Hendrycks, gave us the darkest and most clarifying frame of all: Mutual Assured AI Malfunction. Any state’s aggressive bid for unilateral AI dominance, they argue, gets met with preventive sabotage by rivals. Cyber intrusion, supply chain interference, potentially strikes on data centres. The point is that a national AI moonshot doesn’t make you safe. It makes you a target. Sovereignty pursued too loudly becomes a coordinates broadcast.
Fei-Fei Li would, I suspect, tell everyone in the room they’re arguing about the wrong layer. Her work on spatial intelligence rests on the claim that language models capture only a slice of intelligence, and that machines need geometry, physics, persistence and causality before they can really act in the world. If she’s right, the frontier is migrating toward world models and robotics, which means today’s sovereign LLM programmes may be nations fortifying a position the technology is already vacating.
And Yejin Choi, briefing the UN Security Council, made the argument I find hardest to dismiss. That we should be building intelligence that is smaller, cheaper and more efficient. Expanding the frontier for all instead of assuming capability must always be bought in gigawatts. That’s a technical claim with radical distributional consequences. The cheapest route to sovereignty might be making sovereignty cheaper.
The missile in the room
Here’s the fact that has stayed with me most, and it appears in almost none of the strategy documents.
In February 2026, Iranian ballistic missiles struck the Gulf in retaliation for joint US and Israeli operations. Abu Dhabi’s planned five gigawatt AI campus sat inside the strike envelope. The fibre optic cables carrying the region’s data run through the Strait of Hormuz and the Bab el-Mandeb.
We’ve spent three years arguing about sovereignty as if it were a question of jurisdiction, licensing and where the data sits at rest. It’s also a question of whether the building is still standing.
The most sovereign asset in the world is a compound in a missile corridor. Concentration is efficient and concentration is fragile, and every country that builds one enormous national AI campus has created a single point of failure an adversary can find from orbit. Michael Kratsios, speaking at the India AI Impact Summit in February, laid out the American position: real sovereignty means owning and using best in class technology for your people, and “complete technological self-containment is unrealistic for any country.” You can hear both the generosity and the leverage in that sentence. It’s an invitation and a fact about power at the same time.
What sovereignty actually was, all along
Let me make the philosophical turn, because this is where I think the whole debate has been lazy.
Westphalian sovereignty was never about self sufficiency. No state has ever grown all its own food, minted all its own value, or defended all its own borders unaided. Sovereignty was always a claim about final authority. About who decides, in the last instance, and whose decisions get recognized as legitimate.
What’s genuinely new isn’t that nations depend on foreign infrastructure. It’s that the infrastructure in question is cognitive. When a country imports steel, it imports steel. When it imports a frontier model, it imports a set of embedded judgments about what’s true, what’s permissible, what’s sayable, what a good answer even looks like. Kai-Fu Lee makes this point about religion and law, that questions about alcohol, marriage and doctrine get handled very differently in Jakarta than in California, and a model trained in one place carries the other place’s answers with it.
That isn’t a procurement decision. That’s closer to importing a constitution.
So the real question was never buy, build, or lease. The real question is this: what stays reversible?
Sovereignty in 2026 is the capacity to change your mind. It’s the ability, when the vendor changes terms or the export regime shifts or the geopolitics turns, to actually move. To migrate workloads, swap models, rehost weights, retrain your people. It’s exit cost, and exit cost is measurable in a way that patriotic rhetoric never is.
That’s what I think the Stanford team means when they urge decision makers to expand strategic choice without losing access to frontier capacity. Not autarky. Optionality.
A doctrine, offered without ceremony
If I were advising a government today, I’d replace “sovereign AI strategy” with five questions and refuse to fund anything that couldn’t answer them.

  1. Where is our irreversibility? Map every layer. Silicon, energy, cloud, weights, tooling, talent, evaluation. Mark each one reversible, expensive to reverse, or locked. Go after the locked ones first. This is the Tony Blair Institute’s control, steer, depend logic, and its key insight is that depend is sometimes the right answer. Not every layer deserves a fight.
  2. What’s our open weight posture? Stanford and Kai-Fu Lee converge here from opposite directions, which is usually a sign something’s true. Open models are the cheapest sovereignty instrument that exists. A country that can take a strong open model and continue training it on its own language and law has bought real agency for a rounding error.
  3. Are we buying capability or capacity? A leased GPU cluster you can’t staff is a monument, not an asset. The binding constraint in most countries isn’t silicon. It’s the fifty people who know how to run a training job at scale. Talent is the only part of the stack that can’t be sanctioned, seized, or switched off remotely.
  4. Is our infrastructure survivable? Distributed, redundant and boring beats concentrated, prestigious and photogenic. February 2026 was the lesson. Federation, the EURO-3C approach of meshing existing national clouds rather than building one continental rival, is much less impressive at a ribbon cutting and considerably more robust to a bad Tuesday.
  5. What are we willing to govern jointly? Hinton’s line about the same boat. Hassabis’s CERN. Bengio’s UN panel. The Five Eyes warning in June that models capable of overwhelming national cyber defences are months away rather than years. They all point the same direction. There are risks no nation can be sovereign against. Evaluation standards, incident reporting, biosecurity thresholds, cyber red lines. Insisting on sovereignty in those areas isn’t strength. It’s a category error.
    The quest
    Here’s what I find beautiful and terrible about this moment, in roughly equal measure.
    Every country now pursuing sovereign AI is, in some sense, performing an act of hope. They’re asserting that their language deserves to be modelled, that their laws deserve to be encoded, that their people deserve to be more than a market for someone else’s cognition. That impulse isn’t nationalism. It’s closer to dignity.
    And yet the pursuit, taken literally, leads somewhere self defeating. A world of duplicated data centres, fragmented safety standards, hoarded weights, and a hundred national champions all six to nine months behind, each burning energy and capital to reproduce something that was already open. Schmidt’s MAIM is the shadow at the end of that road, a world where the sovereign act of building becomes an invitation to be sabotaged.
    The way through isn’t to abandon the quest. It’s to reinterpret it. The countries that are genuinely sovereign in 2036 won’t be the ones that owned the most GPUs in 2026. They’ll be the ones that stayed reconfigurable. That kept their options open, their people trained, their weights portable, their dependencies deliberate instead of inherited.
    Sovereignty was never a possession. It was always a practice.
    The countries that understand that will find the paradox dissolves. The ones that don’t will spend a decade and a fortune building a fortress around a door that opens outward.
    Sources and further reading
    • Stanford HAI, The AI Sovereignty Paradox: Should Countries Buy, Build, or Lease to Maintain Strategic Control of Their AI?, interview with James Landay, July 14, 2026
    • Meinhardt, Pava, Yee and Landay, The Commercial Landscape of AI Sovereignty Offerings, Stanford HAI issue brief, July 15, 2026
    • Stanford HAI, 2026 AI Index Report
    • UN Independent International Scientific Panel on AI, preliminary report, co-chaired by Yoshua Bengio and Maria Ressa, 2026
    • Capgemini Research Institute, Open vs. closed AI models: A conversation with Kai-Fu Lee, May 2026
    • Hendrycks, Schmidt and Wang, Superintelligence Strategy, nationalsecurity.ai
    • IISS, Gulf AI infrastructure and the limits of technological sovereignty, June 2026
    • Demis Hassabis, A Framework for Frontier AI and the Dawning of a New Age, July 14, 2026
    • Yejin Choi, briefing to the UN Security Council, September 2025

Leave a comment