Explore our practitioner's guide to sovereign AI. Discover our 5-layer framework, hardware-to-application strategies, and the UK's path to AI sovereignty.
Sovereign AI has recently become a mainstream fixture in public discourse (Alduhishy 2024; Pava et al. 2026; Stanford Institute for Human-Centered Artificial Intelligence 2026; Tony Blair Institute for Global Change 2026) as countries and organisations race to reduce external dependence across their AI stack. This interest has been matched by substantial public investment, including Canada’s C$2 billion Sovereign AI Compute Strategy, the United Kingdom’s £500 million Sovereign AI Unit and the EU’s plan to mobilise more than €30 billion for AI Gigafactories (Innovation, Science and Economic Development Canada 2024; Department for Science, Innovation and Technology 2026; European Commission 2026).
Yet, much of the current discourse on sovereign AI focuses on policy, geopolitics, and strategy, with less attention to the engineering decisions and choices involved in actually building these systems (Tanner et al. 2026; World Economic Forum 2026; Joshi 2026),
This blog seeks to help fill that gap. It examines sovereign AI through a technical lens - from the perspective of the engineering teams actually building and implementing these systems. Our goal is a generalisable framework that institutions, both public and private, can adapt and use to decide what level and form of AI sovereignty is right for them based on their priorities and constraints. The framework does not assume that building or owning a sovereign AI stack is always the right objective. In some cases it may be; in others, the same goals may be reached more effectively by other means.
Additionally, not every AI use case, industry, or institution will require sovereign AI. This blog is therefore intended specifically for contexts where sovereignty is a meaningful requirement. This includes countries and critical public or private institutions where control, resilience, and security are important.
What is “Sovereign AI” in practice?
Despite the proliferation of the term, there is no universal consensus on what ‘sovereign AI’ actually means (Pava et al. 2026; World Bank 2026; Chavez, Chilukuri, and Scanlon 2026). This definitional ambiguity is compounded by a practical constraint: the AI stack is extensive, and no nation can realistically achieve end-to-end domestic ownership across every layer.
Neither of these constraints, however, undermine the rationale for pursuing AI sovereignty. They simply suggest that AI sovereignty is not a black-and-white concept, where a country either “has” sovereignty or “does not” depending on whether it owns a particular layer of the AI stack. Instead, AI sovereignty can take different forms, and the inability to own every layer domestically does not prevent institutions from retaining control across their entire stack.
Given this view, we will treat sovereign AI as control over the critical capabilities, dependencies, and chokepoints across the AI stack. That control might come from owning them outright or securing them by other means. The aim is to ensure that critical AI deployments keep running and sensitive data remains under control, even when corporate, technical, or geopolitical external conditions change.
This flexibility in how the control is achieved, as we demonstrate in our framework below, can give institutions greater scope to deliberately decide what AI sovereignty should look like in their own unique context, rather than adopting a one-size-fits-all approach to achieving it.
Personalising the sovereignty architecture, layer by layer
As with the definition of sovereign AI, there is no single agreed-upon framework for how sovereignty should be implemented across the AI ecosystem. We therefore begin by mapping the underlying AI stack. We use the five-layer structure developed by the World Bank and OECD as the backbone of this framework, and then examine what sovereignty can mean at each layer (OECD 2025; World Bank 2026).
At each layer, we ask the same three questions: what is this layer, what are the options available in this layer, and how can this layer be customised for sovereignty in a given context or use case. Working through the framework layer by layer can help governments and organisations identify the approaches to AI sovereignty that best fit their needs and constraints.

Two considerations apply across every layer:
- Accountability: who makes decisions, approves changes, and is responsible for the outcome.
- Audit and traceability: keeping records of access, changes, data, models, and system actions so that what happened can be traced later.
Additionally, we highlight a few caveats worth keeping in mind when using this framework.
First, the table is meant to be practical rather than exhaustive. It focuses on the most consequential decisions and groups related implementation choices into useful categories. In practice, additional sub-decisions may be needed depending on the use case, sector, regulatory environment, and an institution’s technical maturity. The framework should therefore be treated as a starting point and should be extended or adapted as required.
Second, the framework is model-agnostic. While it was developed primarily with language models in mind, its core principles also apply to other AI modalities, including vision and multimodal systems.
Finally, what AI sovereignty should look like in practice will vary by context and, even within the same country or organisation, by use case. A frontier AI economy, a middle-power state, and a developing country each operate under different constraints and their sovereignty architecture will look very different. Within the same country, a patient-facing health tool and an internal document assistant may require very different levels and forms of control, even if they are built on the same national stack.
UK case study
The United Kingdom’s AI strategy illustrates a way to implement this framework in practice, prioritising critical dependencies to ensure national resilience and mitigate vendor lock-in (UK Parliament 2026). The government provides the foundational support – through infrastructure, investment, and procurement – while the private sector is essential for delivering innovative, market-ready solutions.
1. Hardware
At the lowest layer of the value chain, hardware sovereignty is being pursued by disrupting the global NVIDIA/CUDA bottleneck. One such example is the investment in UK-based semiconductor startups like OLIX (Department for Business and Trade 2026). Backing novel silicon architectures allows the UK to retain sovereign leverage in the hardware supply chain.
2. Infrastructure
To ensure workloads have a secure environment to run, the UK addressed the infrastructure layer by launching the £500 million Sovereign AI Fund (Department for Science, Innovation and Technology 2026), giving startups fully funded access to Isambard-AI at the Bristol Centre for Supercomputing (BriCS). By allocating up to one million GPU hours per organisation, the state guarantees that critical national AI research is not entirely dependent on foreign hyperscalers.
3. Data
To secure data pipelines from creation to curation, the UK deployed a £160 million Strategic Assets Grant Programme. This initiative cultivates highly curated, sovereign datasets, ensuring the national training corpus accurately reflects British legal, cultural, and institutional nuance rather than relying exclusively on foreign brokers (Sovereign AI Fund 2026).
4. Models
The UK recognised that reliance on foreign, proprietary APIs for inference introduces unacceptable risk for highly regulated sectors. At the model layer, Cosine have actively partnered with the UK Sovereign AI Fund to engineer Lumen Sovereign, Britain’s first fully sovereign frontier AI model. Co-designed with a coalition of major UK institutions (including BAE Systems, Vodafone, and the London Stock Exchange Group), the model is being trained entirely on domestic soil, utilising 500,000 GPU hours on Isambard-AI Phase 2.
5. Serving & Orchestration
A sovereign model is only as secure as its deployment environment. The UK is actively mitigating orchestration risks by backing localised deployment frameworks. For instance, London-based Doubleword, also backed by the Sovereign AI Fund (Department for Science, Innovation and Technology 2026), provides a self-hosted enterprise inference stack optimised for high-volume batch workloads, reducing the high operational compute costs typically associated with localised models. Similarly, Cosine’s orchestration architecture for Lumen Sovereign bypasses public API routing, with the model designed for fully air-gapped deployment. This ensures traffic routing and inference execution for critical infrastructure occur without exposing operational context or system prompts.
6. Application
The UK is cultivating a diverse application ecosystem. Firms like Faculty have pioneered this layer by deploying their Frontier decision intelligence operating system (Faculty 2025) to manage critical public-sector workflows, such as forecasting NHS hospital demand during crises.
By strategically investing across the full stack, the UK provides a blueprint for middle-power states: establishing sovereignty through deliberate, structural engineering of the domestic value chain.
Conclusion
As this framework shows, achieving AI sovereignty does not require an institution to manufacture every semiconductor domestically, nor isolate itself from the global technology ecosystem. Instead, it requires assessing dependencies and applying rigorous systems engineering across the entire value chain.
Regardless of the approach, the goal remains the same: ensuring that critical national capabilities remain operational, secure, and aligned with national values. Ultimately, sovereign AI is achieved when a state retains the undeniable technical control over its data, its models, and its future.
Authors
Cosine Team
- Niall Devlin, ML Engineer
- Robert Gibson, Product Marketing
External Collaborators†
- Harshali Ranjan*, AI Engineer (External Author)
- Kristoffer Bjärkefur, Data Scientist (External Contributor)
- Luis Eduardo San Martin, Data Scientist (External Contributor)
† The views expressed in this article are solely those of the authors and contributors and do not represent the views of their past or present employers in any capacity.
* Harshali Ranjan was the primary external author, with review and feedback from Kristoffer Bjärkefur and Luis Eduardo San Martin.