hello@tonishatagoe.com Abu Dhabi · London · Accra · New York
AI Governance

Sovereign AI in an Era of Frontier Model Concentration

THE SCENARIO

A senior trade official in a middle-income country receives a confidential briefing from her intelligence agency. The briefing states that the frontier AI model her government has been relying on for critical infrastructure planning, public service optimisation, and defence simulation has been subjected to a sudden capability restriction by its developer. The restriction is not a technical failure. It is a compliance action under the developer’s home jurisdiction export control regime. No domestic law has been violated. No local regulator was consulted. The capability was simply turned off. The official realises that every strategic document her ministry has produced in the past eighteen months was generated using a system whose continued availability was never guaranteed. The sovereign planning function of her government was, in effect, operating on borrowed processing power whose terms of service could be rewritten by a foreign boardroom.

How does a nation protect its sovereign decision-making capacity when the frontier models it depends on are controlled by entities subject to foreign jurisdiction?

The answer is that it cannot, as long as those models remain the only available instruments for the cognitive labour that sovereign planning requires. The concentration of frontier AI capability among a handful of corporate entities in two jurisdictions constitutes the most significant structural sovereignty challenge of the current decade. It is not a cybersecurity problem, although cybersecurity is a component. It is not a data governance problem, although data governance is relevant. It is a structural power problem. The entity that controls the most advanced intelligence production infrastructure exercises a form of authority over the reasoning processes of every entity that depends on that infrastructure. That authority is exercised invisibly, through the design boundaries of the system rather than through overt commands, and it is exercised without democratic accountability to the dependent entity’s population.

The entity that controls the most advanced intelligence production infrastructure exercises a form of authority over the reasoning processes of every entity that depends on that infrastructure.


Part One: The Frontier Model Landscape

The frontier AI market is not a market in any conventional sense. It is a duopoly with peripheral participants. The two jurisdictions that currently host frontier model development are the United States and the People’s Republic of China. The corporate entities within those jurisdictions that possess the compute infrastructure, data scale, research talent, and regulatory permission to train models at the frontier can be counted on two hands. The number that operate at the absolute frontier — models whose capabilities are not available from any other source — may be counted on one. This concentration is not accidental. It is the predictable outcome of a technology whose development costs increase superlinearly with capability and whose training infrastructure requires capital expenditure that only entities with either sovereign backing or extraordinary private capital can sustain.

A 2025 survey of foundation model development found that the compute invested in the largest training runs had increased by a factor of approximately ten thousand over the preceding five years. The compute investment required to train a frontier model in 2026 is estimated at well over one billion dollars for the largest training runs, with projections suggesting this figure will continue to rise. This cost structure creates an effective barrier to entry that excludes not only developing nations but all but the wealthiest sovereign entities. A nation state that wishes to possess frontier AI capability must either invest at a level that competes with its defence budget, accept dependency on a foreign provider, or forgo frontier capability entirely. There is no fourth option.

The implications for sovereignty are immediate and structural. A nation that lacks frontier AI capability cannot independently produce the intelligence — strategic, economic, scientific, military — that frontier models enable. It must either import that intelligence from a provider that is subject to a foreign sovereign, or it must operate with a cognitive disadvantage relative to entities that possess frontier capability. This is not a hypothetical future state. It is the current operational reality for every nation outside the United States and China.

The dependency operates at multiple levels. At the model level, the dependent entity lacks the ability to verify the model’s outputs, to audit its training data, to understand its failure modes, or to control its update schedule. At the infrastructure level, the dependent entity relies on cloud compute, API access, and software stacks that are owned and operated by entities subject to foreign jurisdiction. At the talent level, the dependent entity’s most skilled practitioners are recruited by the frontier developers, ensuring that domestic capacity building is perpetually undermined by brain drain. At the governance level, the dependent entity adopts regulatory frameworks that were designed by the developer’s home jurisdiction, embedding foreign assumptions about acceptable risk, permissible use, and accountability structures into domestic law.

Part Two: The Sovereignty Erosion Mechanism

The mechanism by which frontier model concentration erodes sovereignty is not visible to conventional threat analysis. It does not appear in trade balance sheets, military capability assessments, or diplomatic dispute dockets. It operates at the level of cognitive architecture — the structure of the reasoning systems through which a nation makes decisions about its own future. When a nation’s strategic planning, economic forecasting, scientific research, and administrative operations are increasingly mediated by systems whose design, training, and deployment are controlled by foreign entities, that nation has ceded authority over its own cognitive infrastructure.

The erosion occurs through five pathways. The first is data sovereignty. Every query sent to a frontier model API generates data that is processed, stored, and potentially used by the provider. The entity sending the query surrenders information about its strategic priorities, its knowledge gaps, its decision-making processes, and its operational patterns. This data is not merely exhaust. It is intelligence. The provider accumulates a comprehensive picture of the dependent entity’s cognitive operations that the dependent entity itself cannot access. This asymmetry of intelligence constitutes a structural strategic disadvantage that compounds over time.

The second pathway is model governance. Frontier models are subject to the regulatory frameworks of their home jurisdictions. When the United States imposes export controls on advanced AI models, those controls apply to every entity in every nation that accesses those models through US-based providers. The dependent nation’s access to frontier capability can be restricted, conditioned, or terminated by a foreign government without the dependent nation’s consent and without recourse under any international legal framework. The dependency creates a structural vulnerability that can be exploited during trade negotiations, diplomatic disputes, or military confrontations without the dependent nation ever having taken an action that would justify such exploitation under conventional international law.

The third pathway is technical standardisation. Frontier models embed assumptions about data formats, communication protocols, interoperability requirements, and security standards that become de facto global norms. Entities that wish to integrate with frontier models must adopt these standards. The standards are not subject to democratic deliberation in the adopting nation. They are determined by the technical architecture of systems designed in foreign jurisdictions. Over time, the adopting nation’s entire technical infrastructure converges on standards that it did not design, cannot change, and may not fully understand.

The fourth pathway is talent extraction. Frontier model developers employ the world’s most skilled AI researchers, engineers, and practitioners. The compensation and research environment that frontier development offers systematically attracts the best talent from every nation, particularly from developing nations that cannot match the resources available at frontier laboratories. This talent extraction ensures that developing nations cannot build domestic frontier capability, because their most capable citizens are employed in the frontier jurisdictions. The talent flow is structurally self-reinforcing: the nations that most need domestic AI capability are the ones most systematically deprived of the talent required to build it.

The fifth pathway is epistemic dependency. When a nation’s policymakers, analysts, and administrators rely on frontier models for information synthesis, pattern recognition, scenario generation, and decision support, they gradually lose the capacity to perform these cognitive functions independently. The frontier model becomes a necessary component of the national cognitive infrastructure, not because the nation chose to integrate it, but because the cognitive functions the nation requires have been offloaded to the model and the domestic capacity to perform them has atrophied. This dependency is the most difficult to reverse because reversing it requires not merely building alternative technical infrastructure but rebuilding the human cognitive capacity that has been displaced.

Epistemic dependency is the most difficult to reverse because reversing it requires not merely building alternative technical infrastructure but rebuilding the human cognitive capacity that has been displaced.

Part Three: The Seven-Layer Stack Audit

The Seven-Layer Stack Audit provides a structured framework for assessing frontier model dependency across the full technology stack. Each layer represents a domain in which sovereignty can be either preserved or surrendered. The audit produces a dependency profile that reveals where intervention is most urgent and where the barriers to exit are highest.

Layer One: Silicon and Hardware. The physical substrate on which frontier models are trained and deployed. Control over fabrication, supply chains, and hardware maintenance. Questions at this layer include: Does the entity control its own chip supply? Are the chips subject to export controls? Can the entity maintain, repair, and upgrade its hardware without foreign vendor assistance? Most nations score at the lowest level on this layer, because semiconductor fabrication is concentrated in Taiwan, South Korea, the United States, and Europe, with advanced node fabrication effectively controlled by a single entity in Taiwan.

Layer Two: Compute Infrastructure. The cloud platforms, data centres, and networking infrastructure that provide the compute capacity for model training and inference. Control at this layer determines whether the entity can run its own models or is dependent on foreign API access. Questions include: Does the entity own its inference infrastructure? Is the entity’s compute provision subject to foreign jurisdiction? Can the entity scale compute capacity independently? The dominance of three US-based cloud providers means that most entities outside the United States are renting compute capacity on infrastructure subject to US law and US intelligence access frameworks.

Layer Three: Model Architecture. The design decisions that determine what the model can do, how it processes information, what assumptions it embeds, and what limitations it imposes. Control at this layer determines whether the model can be audited, modified, or extended. Questions include: Does the entity have access to the model architecture specifications? Can the entity fine-tune or customise the model? Can the entity verify that the model does not contain backdoors or unexpected capabilities? For frontier models accessed through APIs, the answer to all three questions is no. The model architecture is a black box whose properties are determined by the developer.

Layer Four: Training Data and Methodology. The data on which the model is trained, the curation decisions that shaped the dataset, and the training methodology that produced the model’s capabilities. Control at this layer determines whether the entity can understand the model’s biases, limitations, and failure modes. Questions include: Does the entity know what data the model was trained on? Can the entity audit the training methodology? Can the entity detect data poisoning or training manipulation? For frontier models, the training data is proprietary and often opaque even to the developer’s own researchers.

Layer Five: Alignment and Safety. The mechanisms by which the model’s behaviour is shaped to align with human values, safety requirements, and intended use parameters. Control at this layer determines who decides what the model should and should not do. Questions include: Who defines the alignment targets? Who audits the alignment methodology? Can the entity modify the alignment parameters to reflect domestic values and priorities? The alignment of frontier models is determined by the developer’s home jurisdiction values, often calibrated to the regulatory and cultural expectations of that jurisdiction.

Layer Six: Evaluation and Assurance. The frameworks, benchmarks, and methodologies used to assess model capability, safety, and compliance. Control at this layer determines who decides whether the model is fit for purpose. Questions include: Who designs the evaluation benchmarks? Who conducts the evaluation? Can the entity commission independent evaluations? The evaluation ecosystem is dominated by entities in frontier-developing jurisdictions, and the benchmarks themselves embed assumptions about what constitutes adequate performance.

Layer Seven: Governance and Standards. The regulatory frameworks, technical standards, and governance mechanisms that determine the conditions under which models are developed, deployed, and used. Control at this layer determines who sets the rules of the AI ecosystem. Questions include: Who designs the governance framework? Who maintains the technical standards? Can the entity influence the standard-setting process? This is the layer where sovereignty erosion is most visible but least understood because the governance frameworks appear to be neutral technical instruments when they are in fact sovereignty transfer mechanisms.


Part Four: The Sovereignty Test Matrix

The Sovereignty Test Matrix evaluates frontier model dependency across five domains, each scored on a scale from one to seven, producing a total score out of thirty-five. The score reveals not merely the current state of dependency but the trajectory toward greater sovereignty or deeper entrenchment.

Domain One: Strategic Autonomy. The entity’s ability to define its own AI strategy independent of provider incentives and home jurisdiction constraints. A score of one indicates complete strategic dependency where the entity’s AI strategy is a function of what the provider offers. A score of seven indicates full strategic autonomy where the entity designs its AI strategy based on domestic priorities and builds or procures accordingly.

Domain Two: Technical Independence. The entity’s ability to operate, modify, and extend its AI infrastructure without provider permission or foreign jurisdiction approval. A score of one indicates total reliance on foreign API access with no local alternatives. A score of seven indicates complete local ownership of the full stack from hardware through inference.

Domain Three: Data Sovereignty. The entity’s control over the data generated by and used in its AI operations, including the ability to prevent data from being used for provider model improvement or foreign intelligence purposes. A score of one indicates that all data flows through foreign-controlled infrastructure and is used for provider training. A score of seven indicates that data never leaves domestic jurisdiction and is never used for third-party purposes.

Domain Four: Talent Retention and Development. The entity’s ability to recruit, retain, and develop the human capital required for sovereign AI capability. A score of one indicates that all domestic AI talent works for foreign entities. A score of seven indicates a fully self-sustaining domestic AI research and development ecosystem.

Domain Five: Governance Control. The entity’s authority over the regulatory, standards, and compliance frameworks that govern AI deployment within its jurisdiction. A score of one indicates that the entity has adopted foreign governance frameworks wholesale without modification. A score of seven indicates that the entity designs, maintains, and enforces its own governance framework and participates in international standard setting from a position of independent capability.

The composite score determines the entity’s sovereignty posture. A score of thirty to thirty-five indicates sovereignty. Twenty to twenty-nine indicates managed dependency with active sovereignty building. Ten to nineteen indicates structural dependency requiring immediate intervention. Below ten indicates crisis dependency where the entity’s sovereign decision-making capacity is severely compromised.

A nation that controls neither its compute infrastructure nor its model architecture nor its governance framework does not possess sovereign AI capacity. It possesses a rental agreement for foreign intelligence production.


The Red Flag Checklist

The following indicators signal that frontier model dependency has reached a level requiring structural intervention. Each red flag that applies to an entity’s current posture represents a specific sovereignty vulnerability that must be addressed through the implementation framework that follows.

Red Flag One: Single Provider Dependency. The entity’s critical AI functions depend on a single frontier model provider with no viable alternative. This is the most common and most dangerous configuration. The entity has effectively outsourced its cognitive infrastructure to a single foreign entity whose continued cooperation is assumed but not guaranteed.

Red Flag Two: Data Exfiltration Exposure. The entity’s AI interactions generate data that leaves domestic jurisdiction and is stored or processed in jurisdictions where the entity has no legal protections. This is the default configuration for any entity using API-based frontier models from US or Chinese providers. The entity has no visibility into how its data is used and no legal recourse under the provider’s home jurisdiction.

Red Flag Three: Regulatory Architecture Dependency. The entity’s AI governance framework references or depends on technical standards maintained by foreign bodies over which the entity has no control. This is the default configuration for the majority of nations that have adopted AI governance frameworks. The entity has exercised its sovereignty to adopt a framework, but the framework itself transfers sovereignty to the standard maintainer.

Red Flag Four: Talent Pipeline Dependency. The entity relies on foreign-trained talent or foreign-provided training programmes for its AI workforce with no domestic training pipeline. This configuration ensures that the entity’s AI capability remains dependent on the continued willingness of foreign entities to train its citizens.

Red Flag Five: Compute Infrastructure Colonialism. The entity’s compute capacity is provided exclusively by foreign cloud providers with no domestic or sovereign alternative. This configuration means that the entity cannot scale, secure, or control its compute capacity independently. Every increase in AI adoption deepens the dependency.

Red Flag Six: Evaluation Framework Outsourcing. The entity relies on foreign-designed and foreign-administered evaluation frameworks to assess the safety and capability of its AI systems. This configuration means that the entity’s understanding of its own AI systems is mediated by evaluation methodologies designed by entities with different priorities and risk tolerances.

Red Flag Seven: Standards Capture. The entity’s technical infrastructure, data formats, and interoperability requirements are determined by standards set by foreign entities that the entity did not participate in designing and cannot influence. This configuration ensures that switching costs increase over time and that the entity’s technical trajectory is set externally.

Red Flag Eight: Strategic Intelligence Leakage. The entity’s strategic planning, military analysis, and diplomatic preparation involve the use of frontier models whose outputs are generated on foreign infrastructure and whose inputs are visible to foreign entities. This configuration represents an unacceptable national security risk that justifies immediate remediation regardless of cost.


Part Five: The Phased Implementation Framework

The following framework provides a sequenced approach to reducing frontier model dependency and building sovereign AI capacity. The framework is designed for entities at different starting points and can be adapted to the specific constraints of budget, political capacity, and technical maturity. The sequence is structured to produce early wins that build momentum for the deeper structural changes that follow.

Phase One: Audit and Assessment (Months One through Three)

The first phase produces a comprehensive sovereignty audit across all seven layers of the technology stack and all five domains of the Sovereignty Test Matrix. The audit must be conducted by an entity that is independent of the providers being assessed. The audit output is a quantified dependency profile that identifies the most urgent intervention points and the most tractable mobility barriers. The audit also produces a baseline Sovereignty Test Matrix score against which progress will be measured.

During this phase, the entity should commission a switching cost analysis for each critical AI function, identifying the financial, technical, and operational costs of replacing the current provider with an alternative. This analysis is essential because switching costs are the primary mechanism through which dependency becomes irreversible. Entities that delay switching cost analysis until the point of crisis discover that the costs have become prohibitive. The analysis must be updated quarterly because switching costs increase with every integration, every data migration, and every workflow that becomes dependent on provider-specific features.

The audit should also include a jurisdictional exposure assessment that maps every provider, every data flow, and every technical dependency to its home jurisdiction and identifies the legal frameworks, intelligence access regimes, and export control mechanisms that could affect availability. This assessment must be treated as a classified document and accessed only by personnel with appropriate security clearances, because it reveals the precise geometry of the entity’s structural vulnerabilities.

Phase Two: Containment and Diversification (Months Four through Nine)

The second phase implements immediate containment measures to prevent further sovereignty erosion while the longer-term building programme is underway. Containment begins with data sovereignty: all sensitive data flows to frontier model providers must be terminated or routed through layers that prevent data exfiltration. This may require the deployment of local inference infrastructure for sensitive applications, even if that infrastructure is less capable than the frontier model it replaces. The loss of capability in the short term is acceptable because it is a precondition for sovereignty in the long term.

Diversification follows containment. The entity must establish relationships with at least two additional model providers from at least one different jurisdiction than the primary provider. The objective is not to find a sovereign provider that replaces the foreign provider one for one. The objective is to eliminate single-provider dependency and to create competitive pressure that reduces the switching costs associated with any individual provider. The entity should also explore open-source models as alternatives for non-critical applications, building operational experience with self-hosted models that can be scaled to critical applications as capability improves.

During this phase, the entity should negotiate structural modifications to existing provider contracts, including data localisation requirements, audit rights, termination assistance obligations, and prohibitions on unilateral capability modification. Providers will resist these modifications. The entity must be prepared to accept reduced functionality in exchange for improved sovereignty terms. The negotiation objective is not the best possible commercial deal. It is the best possible sovereignty outcome.

Phase Three: Capability Building (Months Ten through Twenty-Four)

The third phase initiates a sustained domestic AI capability building programme. The programme should be structured around three tracks running in parallel. The first track is talent development: investment in university AI programmes, research fellowships, international collaboration agreements, and return incentives for diaspora AI practitioners. The objective is to build a self-sustaining domestic talent pipeline within five years. This is the longest lead time component of the framework and must begin immediately regardless of other priorities.

The second track is infrastructure investment: development of domestic compute capacity, starting with inference infrastructure for open-source models and progressively expanding to training infrastructure for custom models. The entity should not attempt to compete with frontier developers on frontier model training in the initial phase. The objective is to achieve sovereign capability for the entity’s specific use cases, not to achieve general frontier capability. A model that is specialised for the entity’s strategic, economic, and administrative requirements and trained on the entity’s own data is more valuable for sovereignty purposes than a general frontier model accessed through a foreign API.

The third track is governance development: the design and implementation of a domestic AI governance framework that is independent of foreign templates while compatible with international interoperability requirements. The framework must include provisions for standards development that ensure domestic participation in international standard-setting bodies. The framework must also include mandatory sovereignty impact assessments for all significant AI procurements, modelled on the Sovereignty Test Matrix methodology.

Phase Four: Verification and Exit Preparedness (Months Twelve through Thirty-Six)

The fourth phase institutionalises the verification mechanisms that ensure the sovereignty building trajectory is maintained and that exit from any provider is always feasible. The core verification mechanism is a mandatory annual sovereignty audit conducted by an independent body, with results published in a form that enables public accountability while protecting sensitive operational details. The audit assesses progress against the baseline established in Phase One and identifies any new dependency vectors that have emerged.

Exit preparedness requires regular dry runs of the process of withdrawing from each major provider and transferring operations to an alternative. The dry run must verify that data can be exported in a usable format, that workflows can be reconfigured for alternative infrastructure, that staff can operate the alternative systems, and that the organisational disruption is manageable. Entities that conduct exit dry runs discover that the first transition is the most expensive and that subsequent transitions become progressively cheaper as the organisation develops switching competence.

The fourth phase also requires the establishment of a sovereign AI oversight body with statutory authority, independent funding, and technical expertise sufficient to evaluate provider claims, commission independent audits, and recommend structural interventions. The oversight body must be protected from political interference through fixed terms, secure budgets, and statutory independence. Its authority must extend to all AI systems used for sovereign functions, regardless of whether those systems are operated by government agencies, contractors, or private entities.

Phase Five: Strategic Convergence and Regional Collaboration (Months Twenty-Four through Sixty)

The fifth phase extends the sovereignty framework beyond the individual entity to include regional collaboration and strategic convergence with allied entities facing similar dependency challenges. No single middle-income nation possesses the resources to achieve full sovereignty across all seven layers of the technology stack individually. Regional collaboration enables shared investment in compute infrastructure, joint procurement negotiation, pooled talent development, and coordinated governance frameworks that reduce the cost of sovereignty for each participant.

Regional collaboration should be structured around shared compute facilities, joint research programmes, common data sovereignty standards, mutual recognition of governance frameworks, and coordinated switching strategies. The collaboration must be governed by agreements that ensure no participant can be coerced by external pressure into compromising the sovereignty of other participants. The collaboration must also include provisions for exit, ensuring that any participant can withdraw without losing access to the shared infrastructure they have helped to build.

The strategic convergence objective is the creation of a multi-jurisdictional sovereign AI ecosystem in which participating entities collectively achieve the scale, talent pool, and governance capacity required for sustainable sovereignty. This ecosystem is not a bloc that excludes the frontier jurisdictions. It is a network that provides participants with sufficient independent capability that dependency on any single frontier provider becomes a strategic choice rather than a structural necessity.


The Closing Question

The opening question asked how a nation protects its sovereign decision-making capacity when the frontier models it depends on are controlled by entities subject to foreign jurisdiction. The answer is that it cannot protect its capacity while the dependency persists. It must build independent capacity. The full implementation framework spans five years, requires sustained political commitment across electoral cycles, demands investment that competes with other national priorities, and faces opposition from incumbents who benefit from the current dependency structure. These obstacles are real. They are also surmountable. The alternative to sovereignty building is not the status quo. The alternative is accelerating dependency that will become structurally irreversible as switching costs compound, as talent extraction deepens, and as the frontier models upon which sovereign functions depend become increasingly capable and increasingly unavailable to entities that do not control them.

The nation that begins its sovereignty building programme today will face difficult choices and significant costs. The nation that delays its sovereignty building programme by three years will face those same choices and costs multiplied by the compounding effect of deepening dependency. The nation that never begins will discover, at the moment of crisis, that the capacity to make sovereign decisions was not lost. It was surrendered, incrementally, through a series of procurement decisions that each appeared to be rational commercial choices at the time.

The question is not whether the cost of sovereignty is bearable. The question is whether the cost of dependency has been honestly calculated. The Seven-Layer Stack Audit, the Sovereignty Test Matrix, and the Phased Implementation Framework provide the tools for that calculation. The decision to use them is a sovereign act. The decision to ignore them is also a sovereign act, with consequences that will be borne by the population whose cognitive infrastructure has been rented to foreign entities.

The question is not whether the cost of sovereignty is bearable. The question is whether the cost of dependency has been honestly calculated.


This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? by Toni Shatagoe.

Keep Reading

Related Articles

Get in Touch
LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…

LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…