Since the consumption of LLM-based technologies sky-rocketed around early 2023, and AI entered day-to-day workplace vernacular, a couple of topics have been consistently discussed in relation to building AI-enabled applications; the high-risk concentration of dependency on a handful of frontier model providers, and the challenges or risks related to sharing and processing personal or secure information through these applications. Over the last 6-12 months, this has led to "Sovereign AI" becoming a fascinating area in relation to technology and policy, yet no two definitions of the topic are the same. The term broadly describes a nation's or organisation's capacity to develop, deploy, and control AI models and applications - but the specific definition shifts.

Meanwhile, McKinsey's December 2025 survey of 300 executives found 71% now characterise sovereign AI as a strategic imperative, projecting a $600 billion sovereign AI market by 2030. NVIDIA, arguably the company that did the most to popularise the term, frames it around national infrastructure and cultural preservation - naturally centred on the GPUs NVIDIA sells. Meanwhile, BCG argues in its 2026 analysis that full sovereignty is an illusion for most countries and advocates for "AI resilience" instead.

At the most basic level, I believe AI Sovereignty comes down to control & governance within operational boundaries, capacity to operate on sensitive data with confidence, and ownership of compute (/ hardware). In short, the facility of being able to build, deploy, and assure AI systems independently.

The UK's sovereign AI context

The UK has positioned itself as Europe's leading AI economy, backing this claim with structured public investment and private sector commitments. The AI Opportunities Action Plan, published in January 2025, laid the foundation with 50 recommendations the government accepted in full. By January 2026, 38 of 50 actions had been met, AI compute capacity had grown 10x from 2 to 21 ExaFLOPs (with a target of 420 ExaFLOPs by 2030), and over 1 million AI upskilling courses had been delivered.

The UK Sovereign AI Unit, formally detailed in November 2025, commands up to £500 million in government funding to invest in domestic AI capability, with the fund opening on 16 April 2026. Isambard-AI, launched at the University of Bristol with 5,448 NVIDIA GH200 Grace Hopper Superchips, delivers 21 AI ExaFLOPs. Private pledges include Microsoft's $30 billion UK investment (2025-2028), NVIDIA's £2 billion commitment, and Google's £5 billion pledge.

However, headwinds are emerging - OpenAI paused its Stargate UK project on 9 April 2026, citing industrial electricity prices roughly four times US levels and regulatory uncertainty. Questions about whether the £68 billion in pledged investment will fully materialise persist, and comprehensive AI legislation remains pending.

Why it matters

The drivers behind sovereign AI converge from multiple directions. Legally, the US CLOUD Act gives American authorities access to data held by US companies globally, creating what analysts call a "kill switch scenario" for nations running critical AI on platforms owned by organisations headquartered abroad. Alongside existing national data protection laws, there is an increasing amount of AI-specific guidance and policy being released and worked on that are likely to further complicate cross-border AI workloads.

Many large-scale organisations working with highly sensitive data are dependent on technology providers headquartered outside of the UK, resulting in scenarios in which control and portability are both in question. This inability to establish the required level of trust and assurance is forcing organisations to forgo the pursuit of sensitive use cases, leaving their value unrealised as a result.

Add to this the growing pressure on public bodies to demonstrate control across the AI lifecycle, evidence governance and security practices, and deliver production AI solutions, investing in Sovereign AI capabilities becomes increasingly difficult to ignore.

Some associated drivers here could be called out, such as cost or energy efficiency. I believe these may be associated factors related to sovereign AI capability, but they should not be considered as primary drivers without thorough analyses. For example, running a small custom or fine-tuned model locally for document classification costing less than a flagship model isn't like-for-like even though it is going to be cheaper.

Core components of AI sovereignty

What makes AI truly "sovereign" extends far beyond hosting workloads in a domestic data centre. While we will explore these in detail in upcoming blogs, core pillars of a comprehensive sovereignty framework include:

  • Data sovereignty - control over where training, inference, and output data resides and flows
  • Infrastructure and compute sovereignty - ownership or control of the physical compute resources on which AI workloads run
  • Model sovereignty - who controls the AI models, open and closed weight models, model provenance and portability?
  • Operational sovereignty - can we run, observe, manage, and evolve AI systems independently?
  • Security and supply chain integrity - addressing hardware and software dependencies, end-to-end security posture definition & zero-trust implementation
  • Governance, legal & Responsible AI - the jurisdictional foundation establishing governance and compliance processes, ethical control structures and enforceable control points, audit readiness
Six deployment options on a spectrum from lower to higher infrastructure sovereignty: public cloud with managed APIs, self-hosted IaaS on rented compute, sovereign cloud with a compliance layer, hybrid split workloads, on-premises dedicated hardware, and fully disconnected air-gapped
The infrastructure sovereignty spectrum, from managed APIs to fully air-gapped.

Where sovereignty increases, functionality and pace of innovation typically decrease. The strategic question is not "How do we maximise sovereignty?" but "How sovereign does this specific use case need to be?"

The technology landscape is maturing fast

In addition to NVIDIA's hardware offerings, they provide software (e.g. DGX OS, NVIDIA AI Enterprise), Inference Microservices, and deployment blueprints for local training and inference capabilities.

Hyperscalers have had sovereign cloud offerings in recent years (Microsoft, Google, AWS), but these have been focused on core platform and infrastructure offerings. Rather than being a single product offering, Microsoft's Sovereign Cloud is a combination of components and pre-packaged connections. For example:

  • Sovereign Public Cloud tier includes Data Guardian, External Key Management, the EU Data Boundary, and the Sovereign Landing Zone (an opinionated Azure Landing Zone variant with three sovereignty control levels)
  • Sovereign Private Cloud tier unifies Azure Local, Microsoft 365 Local, and Foundry Local for fully disconnected operation

In addition to Microsoft's Sovereign Private Cloud updates in February 2026, Foundry Local was also made Generally Available on April 9th. Foundry Local enables rapid local deployment of models, including open-weight models, with minimal setup, no cloud dependency, and no per-token costs. I believe this signalling is quite clear given a number of announcements and releases made in just the last 3 months.

Preparing for sovereign AI

The duration of Sovereign AI implementations or migrations are likely to be measured in years rather than months, driven not by technology limitations but by the organisational work required.

Although the starting point should always be to qualify value and for any organisation considering this, I would say there are worthwhile activities you can conduct even if a sovereign AI deployment doesn't end up being the target. For example, understanding existing AI security and governance boundaries, improving data foundations, classifying AI solutions or workloads, building governance foundations - data classification, encryption and key ownership, identity management, model risk management. This makes adopting sovereignty incremental rather than pursuing an all-or-nothing approach.

What comes next

At Actonomy, we are working on collaborative sovereign AI research projects in line with developing a practical Sovereign AI Assessment Framework, reference blueprints for sovereign AI deployments, and IP for Policy management and routing. In our future posts, we will dive deeper into the specific pillars of AI sovereignty, our assessment methodology, and the technical architecture for sovereign AI delivery across the adoption spectrum. If sovereign AI is on your horizon - we would welcome the conversation.

Originally posted on {{ post.sourceLabel }}