Governments are increasingly talking about “sovereign AI” as if sovereignty can be achieved by building a national model, keeping data inside national borders or purchasing a domestic cloud service. However, beneath those visible measures lies a harder question: when a critical AI system fails, changes behaviour or becomes dependent on an external supplier, who can actually inspect it, intervene and demand accountability?
A new paper, “Credible Sovereignty: Operationalizing AI Governance Across Infrastructure, Data, and Models: A Systematic Review” published in the journal AI by Raghu Raman and Prema Nedungadi of Amrita Vishwa Vidyapeetham, argues that the emerging AI sovereignty debate has focused too heavily on declared autonomy and too little on whether control can be demonstrated in real deployments.
Their proposed alternative is “credible sovereignty”: the demonstrable capacity of a state, organization or community to inspect AI systems, intervene in how they operate and hold responsible actors accountable. It is a deceptively simple shift, but one with major implications for governments now investing in sovereign clouds, national language models, domestic computing capacity and data-localization regimes.
The Real Test of Sovereignty Starts After the AI System Is Deployed
According to the review, sovereignty should be treated as an operational capability rather than a political label. A government can have legal jurisdiction over an AI service while lacking meaningful control over the cloud infrastructure, model weights, evaluation systems or supply chains on which that service depends.
The authors describe sovereignty as layered because control at one part of the AI stack does not guarantee control elsewhere. A country may keep sensitive datasets domestically while depending on foreign hyperscale computing, or operate a national AI model whose underlying tools cannot be independently audited. In those cases, sovereignty exists formally but remains incomplete operationally.
The review proposes three practical tests: inspection, intervention and accountability.
- Inspection asks whether authorized institutions can understand and audit what the system is doing.
- Intervention asks whether they can suspend, modify, migrate or withdraw it.
- Accountability asks whether responsibility for failures and harms is clearly assigned and enforceable.
This framing moves AI sovereignty away from symbolic technology nationalism. The critical question becomes not whether every component is domestically owned, but whether external dependencies remain visible, governable and replaceable when necessary.
Cloud Contracts and Procurement May Matter More Than National AI Models
Sovereignty is often created through mechanisms that receive far less political attention than national model launches. Procurement conditions, cloud contracts, certification requirements, audit access, deployment architecture and data-governance arrangements can determine whether governments possess meaningful control over AI systems.
For public agencies, that means sovereignty can be embedded in seemingly technical contractual provisions. Requirements covering data residency, incident reporting, access to model documentation, workload portability and rights to suspend or migrate services may ultimately determine whether an institution can respond effectively when something goes wrong.
The study also challenges the assumption that regulation alone creates sovereignty. Europe provides an important example in the literature: strong regulatory authority can establish obligations, certification systems and oversight, but domestic capability may still lag in computing infrastructure, models, suppliers and evaluation expertise. Regulation without corresponding capacity can leave governments powerful on paper but dependent in practice.
Investment in AI infrastructure needs to be matched by evaluation expertise, skilled regulators, cybersecurity capability, procurement competence and independent technical assurance. Building compute without governance creates one kind of weakness; writing rules without the ability to enforce them creates another.
Sovereign AI Can Reduce Foreign Dependence and Still Deepen Inequality at Home
Strategies designed to reduce dependence on foreign technology providers can produce new concentrations of power inside national borders. If only a handful of large companies or state-linked institutions can afford sovereign clouds, compliance systems and specialist AI teams, smaller agencies, firms and research organizations may become more dependent rather than less. The literature reviewed by the authors warns that sovereign AI can widen internal digital divides and create new domestic gatekeepers controlling compute, data access and deployment approvals.
This concern becomes even more significant in developing countries. The study’s Global South theme shows that national AI strategies do not automatically produce meaningful local ownership, particularly where countries remain dependent on imported infrastructure, external expertise or proprietary platforms. Comparative work cited in the review suggests that apparently similar AI policies can differ sharply in feasibility, political intent and the degree of control they actually provide.
The authors also broaden sovereignty beyond states. Communities and Indigenous groups may have legitimate claims over how their data, languages and knowledge are used in AI systems. In this context, sovereignty becomes a question of participation, consent and the ability to challenge decisions, not merely state control over infrastructure.
For the Global South, this means replacing dependence on foreign platforms with dependence on domestic monopolies would change who holds power without necessarily improving inclusion, accountability or public benefit.
The Hardest Policy Challenge Is Building Control Without Building Isolation
AI sovereignty is unfolding against growing geopolitical competition over chips, cloud infrastructure, export controls and advanced models. The review finds that governments are responding less through complete technological self-sufficiency than through selective interoperability and trusted blocs.
Countries want greater control over strategic AI systems, yet AI safety, standards, research and cross-border services all depend on cooperation. The study suggests that shared evaluation standards and interoperable assurance systems can allow countries to retain authority without forcing every jurisdiction to duplicate infrastructure or isolate itself technologically.
Blanket localization may be a poor substitute for strategic control. The authors recommend clearer distinctions between genuinely sensitive workloads and lower-risk applications, combined with requirements for audit access, incident reporting, model documentation and enforceable oversight. Such thresholds can reduce the risk that localization merely raises costs without improving real sovereignty.
The study’s evidence base consists of Scopus-indexed English-language scholarship from 2020–2026, leaving out substantial non-English, gray-policy and technical literature. The authors also acknowledge that their concept of credible sovereignty has not yet been empirically validated against real-world deployments, audit outcomes or comparative incidents.
The limitation also points directly to the next research frontier. Credible sovereignty now needs to be tested through actual sovereign-cloud programs, public-sector AI systems, procurement regimes and cross-border deployments. Researchers will need to establish measurable thresholds for what genuine inspection, intervention and accountability look like under real operational pressure.
The strategic value of the study lies in exposing a misconception at the center of the sovereign-AI debate. Sovereignty is not proven by a national flag on a data centre, a domestically branded model or a legal requirement that information stay within national borders. It is proven when institutions can understand critical systems, challenge their operation, move away from suppliers when necessary and enforce responsibility when failures occur.
For developing economies that cannot realistically reproduce every layer of the global AI supply chain, their goal does not have to be technological autarky. A more achievable, and potentially more useful, objective is to make unavoidable dependencies transparent, contestable and strategically manageable.
In that sense, the emerging race for sovereign AI may ultimately be less about who owns the most infrastructure than about who retains credible power over it. The countries that succeed will not necessarily be those that isolate themselves from global technology networks, but those that can participate in them without surrendering their capacity to inspect, intervene and hold powerful actors accountable.













Leave a Reply