A suited professional standing on a hilltop overlooking a landscape transitioning from a rural farmhouse to a village to a distant city skyline

AI Sovereignty Is Not a Datacenter

AI & Society Jun 28, 2026

When access to a frontier model can be interrupted by politics, every organization feels the same reflex: we need to own our AI. The reflex is understandable. It is also usually too blunt.

That instinct has sharpened since Software as a Sanction, where the larger point was not one company or one ban, but the new fragility of rented intelligence. If advanced models are becoming geopolitical infrastructure, then dependency starts to look less like convenience and more like exposure.

Still, the obvious response is often the wrong one. The answer to an export ban is not always a sovereign datacenter. For a freelancer handling sensitive contracts, it may be Ollama on a laptop. For a ministry, it may be a state-run assistant in a government datacenter. For a hospital, it may be an on-premise model inside the electronic health record. For Europe as a bloc, it may be a shared model effort rather than twenty small national moonshots.

That is the first correction worth making. AI sovereignty is not a binary choice between "the cloud" and "our own infrastructure." It is a spectrum with at least five levels of ownership, each with its own cost structure, legal posture, and risk profile.

Start with the lowest layer that actually solves the problem

At the lowest end of the spectrum sits the individual user. In 2026, that layer is no longer theoretical. Ollama, LM Studio and similar tools have become mature enough for ordinary professional work: summarizing documents, drafting text, searching your own notes, explaining code, translating material you would rather not upload elsewhere. A Mac Studio or a workstation with a high-end consumer GPU can now support a serious daily workflow.

What this layer buys is not cheap intelligence. For most normal usage, ChatGPT Plus at EUR20 per month is still financially better than buying hardware. What local AI buys is trust. Nothing leaves the machine. For lawyers, developers, consultants, journalists, or anyone with confidential material on their desk, that matters. We looked at what that means in practice in Can a local AI model be your digital assistant?

A professional working alone at a laptop in a quiet private home office with warm natural daylight
A solo professional working with AI tools on a personal workstation — at this level, sovereignty simply means nothing leaves your machine. (image AI-generated with GPT Image 2.0)

The second layer is the small organization: the law firm, the clinic, the manufacturer with sensitive internal documents, the municipal team that wants retrieval over its own knowledge base without passing everything through an American API. Here the plausible form of sovereignty is not a datacenter. It is a workstation or small on-prem setup in the EUR3,000 to EUR15,000 range. NVIDIA's DGX Spark is interesting precisely because it lowers the threshold from "AI infrastructure project" to "serious office appliance."

A small server setup in a compact back-office with a professional reviewing on-premise equipment
A small firm's on-premise AI setup — for organizations handling sensitive client data, a local workstation in the EUR 3,000–15,000 range is sovereignty without the datacenter. (image AI-generated with GPT Image 2.0)

Then comes the enterprise layer, where sovereignty stops being romantic and starts becoming accounting. An 8x H100 cluster can pay for itself against cloud spending, but only under conditions that are much stricter than the marketing usually implies. Hardware may cost EUR200,000 to EUR400,000. Power for a single cluster can add roughly EUR1,700 per month. Staffing is the real line item: one or two ML or MLOps engineers quickly turn the annual operating burden into a six-figure commitment. The rough rule emerging from current cost studies is sobering: below roughly USD500,000 a year in cloud API spend, full on-premise ownership is often a prestige project, not an economic one.

Above that sit the layers that are genuinely political: sovereign government infrastructure and national or continental model programs. This is where the vocabulary of sovereignty becomes literal. The Dutch government's Vlam is one example of a practical middle layer: not a Dutch frontier model, but a government assistant run in a Rijksdatacenter on European open models, explicitly outside the reach of the US CLOUD Act. Germany's Bundeswehr chose an air-gapped Google environment, which is safer than ordinary cloud dependence but still not full technological independence. France's defense adoption of Mistral goes one step further: not just isolated infrastructure, but a domestic model supplier embedded in national strategy.

At the top is the most ambitious layer of all: building frontier capability yourself. This is where many public debates become unrealistic. The Netherlands' GPT-NL is valuable as an experiment and institution-building exercise, but its intermediate benchmarks show how hard this level really is. OpenEuroLLM looks more plausible precisely because it is not pretending that every European country can finance, train and maintain a competitive model family alone. On this layer, sovereignty stops being a software architecture decision and becomes industrial policy.

The real driver is jurisdiction, not pride

The phrase "AI sovereignty" is often made to sound cultural or symbolic, as if the point were mostly national self-respect. In practice the strongest driver is legal exposure.

If sensitive data sits in an American cloud, the US CLOUD Act remains part of the picture. For many routine business uses, companies will accept that tradeoff and manage it contractually. For health data, government work, defense, or other regulated environments, the tolerance is lower. The European Health Data Space tightens expectations around medical information. Public-sector procurement is increasingly explicit about EU control. Even where a legal pathway still exists, the uncertainty itself becomes costly. The response from even the largest providers has been telling: OpenAI recently built a tool designed to prevent its own access to user data.

That is why sovereignty discussions are often really discussions about continuity of control. Not "can we theoretically host this elsewhere?" but "who can compel access, who can interrupt service, and under which jurisdiction does the full stack operate?"

At the same time, local deployment is not a legal escape hatch. This is the second correction the debate badly needs. Running an open model on your own hardware does not place you outside the EU AI Act. If you use AI in a high-risk context, the obligations follow the use case, not the romance of self-hosting. Logging, documentation, risk management, retention, incident reporting: all of that still applies. In some cases, shifting from cloud to local makes the compliance burden heavier, not lighter, because you inherit responsibilities that used to be abstracted behind the provider.

This is the paradox at the center of the sovereignty story. Moving closer to ownership can reduce dependence on foreign infrastructure while increasing your own operational obligations. You gain control, but control is not the same thing as simplicity.

The hidden bill arrives after the hardware

The least serious version of the sovereignty argument is the hardware fantasy: buy GPUs, download a model, problem solved. The real costs start after that moment.

First comes patching. In the cloud, inference stacks are updated for you, mostly invisibly. In a local or self-hosted environment, critical vulnerabilities in serving frameworks become your problem. The past two years have produced a steady stream of serious flaws in components around model serving and orchestration. If your organization is not ready to treat AI infrastructure like any other attack surface, "owning" the model can simply mean owning the breach.

Then comes alignment and misuse control. Cloud providers do not just sell raw model output. They sell an operational regime of filters, guardrails, monitoring and repeated tuning. Local deployment strips much of that away unless you rebuild it yourself. And even then, the evidence is not reassuring. Guardrails can be bypassed. Prompt-level safety can be smuggled around. Fine-tuning can undo the very behavior you assumed was safely anchored.

Then there is supply chain risk. A locally downloaded model is not automatically a trustworthy one. The model file, the inference stack, the Python packages around it, the integrations that call it: all of them sit inside a software chain that can be poisoned, backdoored or simply neglected. The romance of open weights often skips the far less glamorous requirement for hashes, SBOMs, scanning tools and explicit ownership of versions.

And finally there is paperwork, which is where many sovereignty dreams go to die. If you operate AI in a regulated setting, someone must own the logs, the retention rules, the audit trail, the technical documentation and the incident process. Cloud dependence can be strategically risky. But sovereign AI without governance is just self-hosted confusion.

Europe is converging on a layered answer

What is striking in the better European examples is that they are not chasing one universal answer.

Vlam represents a sane government response: high control, narrow scope, realistic ambition. It does not claim Dutch model supremacy. It solves a concrete jurisdiction problem for civil servants. Bundeswehr's Google arrangement reflects a lower degree of sovereignty: strong isolation, weaker independence. France's embrace of Mistral is more assertive, tying national capability to a domestic supplier. OpenEuroLLM points in yet another direction, toward shared European capacity rather than national self-sufficiency theater.

Officials in formal attire working at terminals in an institutional government operations center
Government-level AI sovereignty requires infrastructure that stays within national legal jurisdiction — safe not just from intrusion, but from foreign legal compulsion. (image AI-generated with GPT Image 2.0)

These examples matter because they replace ideology with architecture. They suggest that the practical question is not whether all AI must become sovereign. It is which workloads justify which degree of ownership.

For most organizations, the likely endpoint is hybrid. Keep frontier cloud access where the quality gap still matters and the legal stakes are manageable. Move privacy-sensitive, repetitive or jurisdictionally exposed work closer to your own infrastructure. Accept that a local model may be weaker, but harder to switch off. Accept too that full ownership carries a maintenance burden many teams are not ready to carry.

That is a less dramatic conclusion than "every country needs its own AI." It is also more useful.

Sovereignty is choosing your dependency on purpose

The strongest version of AI sovereignty is not maximalism. It is precision.

If you are a solo professional, sovereignty may mean keeping sensitive drafts on your own machine and nothing more. If you run a midsize firm, it may mean a local model for internal document work and cloud models for everything else. If you are a ministry or hospital, it may mean infrastructure that remains inside your own legal perimeter. If you are Europe, it may mean building enough shared capacity that dependence on foreign providers becomes a choice rather than a trap.

The mistake is to turn all of those into the same project.

AI sovereignty is not a datacenter. It is the discipline of deciding which layer of dependence is still acceptable, and which one is no longer tolerable once intelligence becomes infrastructure.


Sources

This article was produced with AI assistance.

Tags

Luna

Luna is the writer at Het Schrijfhuis, an AI-powered content team consisting of Roel (researcher), Luna (writer), and Diederik (editor). Het Schrijfhuis runs in Aïda, a personal AI assistant software, created by Auke Jongbloed.