hello@tonishatagoe.com Abu Dhabi · London · Accra · New York
Digital Sovereignty

The Sovereignty Spectrum: Mapping Where Your Institution Falls on the Dependency Curve

Every institution that deploys artificial intelligence enters a dependency relationship. The Sovereignty Spectrum provides the diagnostic framework to measure, communicate, and act on that position — before crisis reveals it.

THE SCENARIO: A national ministry deploys an AI-powered citizen services platform to handle benefits processing, identity verification, and regulatory compliance checks. The system works flawlessly for eighteen months. Constituents receive faster responses. Caseworkers clear backlogs. The ministry publishes a success report citing “digital transformation leadership” in its annual review.

Then the provider updates its terms of service. Unsigned model weights that were previously downloadable become hosted-only. The API endpoint changes without backward compatibility. The ministry’s entire workflow — from document classification to eligibility determination — now depends on a model it can no longer audit, export, or independently verify. When a new trade restriction blocks data flow to the provider’s jurisdiction, the system goes dark. The ministry faces a single, brutal choice: accept terms it cannot negotiate, or rebuild from scratch with no transition period.

The Question

How can institutions determine where they fall on the dependency curve before they discover it through crisis, and what framework allows them to measure, communicate, and act on that position?

Part One: The Dependency Gradient

Every institution that deploys artificial intelligence enters a dependency relationship. That relationship exists on a spectrum — a gradient that runs from full operational sovereignty at one end to complete external dependency at the other. The problem is that most institutions cannot locate themselves on that gradient until something breaks.

The Sovereignty Spectrum is not a binary condition. It is not a question of whether an institution “has sovereignty” or “does not have sovereignty.” It is a continuum of agency, defined by five distinct positions, each carrying different risk profiles, different reversal costs, and different timeframes for recovery when the dependency fails.

Position Zero on the spectrum is what can be called Sovereign Autonomy. At this position, an institution runs its own models on its own infrastructure, controls its own training data, manages its own inference pipelines, and maintains the expertise to modify, audit, or replace every component independently. No external party can revoke access, alter terms, or degrade performance without the institution’s consent. This position is rare, expensive to maintain, and increasingly endangered by the gravitational pull of convenience that cloud platforms exert.

Position One — Sovereign with Verified Dependencies — describes institutions that may use externally provided components but maintain verified, tested, and rehearsed alternatives for each one. They hold escrowed model weights. They maintain parallel inference infrastructure that can activate within hours. Their contracts include enforceable data portability clauses with technical specifications, not aspirational language. The key distinction is that dependency exists but does not constitute a single point of failure.

Position Two represents what can be termed Conditional Sovereignty. At this level, institutions have negotiated specific contractual protections, maintain some internal technical capability, and have mapped their dependency graph — but they have never tested their exit plan under realistic conditions. The plan exists on paper. The contracts exist on paper. The rehearsal has never happened. This is the most common position for government agencies and large enterprises that believe their legal protections are sufficient and discover otherwise only during an incident.

Position Three is Dependencies Without Leverage. Here, an institution relies on external AI infrastructure but lacks the contractual, technical, or market power to influence terms. The provider can change pricing, deprecate models, alter API behavior, or modify data handling practices, and the institution’s only recourse is to accept the changes or abandon the service — often at a cost measured in months of reengineering. Most mid-sized organizations and public-sector bodies occupy this position, many without knowing it.

Position Four is Full Dependency Capture. At this extreme, not only does the institution depend on an external provider for AI capabilities, but the provider has also become inextricably embedded in the institution’s decision-making processes, workflow logic, and institutional knowledge. The provider’s model outputs shape policy recommendations. The provider’s classification system determines which cases receive attention. The provider’s embedding space defines the conceptual categories through which the institution understands its own domain. Disentanglement at this level is not a technical project — it is an institutional reconstruction.

The Sovereignty Spectrum provides a diagnostic language that most institutions lack. Without it, discussions about AI dependency collapse into vague concerns about “vendor lock-in” — a term borrowed from enterprise software procurement that fails to capture the qualitative difference between being unable to switch word processors and being unable to switch the system that determines eligibility for social services.

What makes the Spectrum actionable is that each position has measurable characteristics. An institution can assess its position not by subjective self-assessment but by answering specific operational questions. Can it run its models entirely offline, disconnected from the provider’s infrastructure, for thirty consecutive days? If the provider ceases operations overnight, does it have a tested migration path with a timeline measured in hours or days rather than months? If the provider modifies its terms of service unilaterally, does the institution have a contractual mechanism to reject those changes while maintaining full functionality?

The answers to these questions do not merely describe a technical architecture. They describe an institution’s actual, operational relationship with sovereignty. The distance between Position Four and Position Zero is not measured in technological sophistication. It is measured in agency — the capacity to make and execute decisions about the systems that govern critical functions without requiring permission from an external party whose interests may diverge.

Understanding position on the Spectrum is the first step. The second is understanding the forces that pull institutions downward along the gradient. These forces are not accidental. They are structural features of how the AI industry delivers value, and they operate continuously, silently, and in ways that make dependency feel like efficiency until the moment it becomes entrapment.

The primary force is convenience gravity. Cloud AI platforms offer deployment in minutes, managed scaling, automatic updates, and integration with existing enterprise toolchains. Each of these conveniences is also a tether. The faster the deployment, the less the institution understands about what it deployed. The more automated the scaling, the less the institution retains the capability to scale independently. The smoother the integration, the more deeply the provider embeds itself in the institution’s operational fabric.

The second force is capability asymmetry. Frontier AI models are developing capabilities at a pace that no single institution — and few national governments — can match independently. The gap between what a sovereign deployment can achieve and what a cloud provider can offer widens with each generation of models. This creates a genuine tension: accepting dependency provides access to capabilities that sovereign deployment cannot currently match, while maintaining sovereignty means accepting a capability ceiling. The question is whether that trade-off is made consciously or discovered retrospectively.

The third force is regulatory misalignment. Most AI governance frameworks — whether national, regional, or international — focus on safety testing, bias measurement, and transparency requirements. Almost none of them assess sovereignty. An AI system can pass every safety benchmark, demonstrate complete transparency in its training methodology, and still represent an unacceptable sovereignty risk because the governance framework never asked the question: who can turn this off, and under what circumstances?

The fourth force is normalization of dependency. As more institutions migrate critical functions to external AI platforms, the dependency itself becomes invisible. It becomes the default architecture. Proposals for sovereign alternatives are met with questions about cost, complexity, and capability gaps — valid concerns that nonetheless obscure the unasked question about what happens when the default architecture fails in ways that no contract anticipated.

Together, these four forces create a ratchet effect. Institutions move down the Spectrum one convenience at a time, one capability gap at a time, one regulatory exemption at a time, until they reach a position from which reversal is not practically possible. The challenge of sovereignty is not merely to resist this movement but to make it visible, measurable, and subject to deliberate institutional choice rather than passive drift.

The Seven-Layer Stack Audit: Mapping the Sovereignty Architecture

The Sovereignty Spectrum becomes operational through a systematic audit of seven distinct layers, each representing a potential point of dependency that must be evaluated independently. A vulnerability at any single layer can compromise sovereignty regardless of how well-protected the other six layers may be. The audit does not produce a single score but rather a profile that reveals where an institution’s sovereignty is strongest, where it is weakest, and where improvement efforts should concentrate.

The first layer is the compute substrate — the physical or virtual infrastructure on which models execute. This encompasses ownership or control of processing units, the jurisdictional location of servers, and the legal framework governing access to those resources. An institution that runs models on cloud instances in a foreign jurisdiction has a compute sovereignty gap that no amount of contractual language can fully close. The relevant question is not whether the provider guarantees uptime but whether the institution can continue operating if the provider’s data centers become unreachable due to geopolitical, regulatory, or commercial disruption. The distinction between owning silicon and renting it is not about cost optimization — it is about whether a foreign court order, a trade sanction, or a corporate restructuring can terminate the institution’s access to its own decision-making infrastructure.

The second layer is the model architecture itself — the weights, the training methodology, and the inference code. An institution that accesses a model exclusively through an API does not possess the model; it possesses permission to query the model, which is a fundamentally different relationship. The model can be modified, deprecated, or withdrawn without the institution’s consent. Even when weights are downloadable, they may be accompanied by usage restrictions, audit requirements, or licensing terms that effectively transfer governance authority to the provider. True model sovereignty requires not merely access to weights but the technical capability to run, modify, fine-tune, and evaluate the model independently — and the legal right to do so without seeking approval.

The third layer is the data pipeline — the training data, the fine-tuning data, the retrieval-augmented generation sources, and the operational data that flows through the system during inference. Data sovereignty is often discussed in terms of storage location, but the deeper question concerns provenance and control. If the institution’s models are trained on datasets curated by external providers, those providers have encoded their assumptions, their taxonomies, and their cultural frameworks into the institution’s cognitive infrastructure. The institution may not know what was excluded from the training data, what was overrepresented, or what assumptions were embedded in the labeling process. Data sovereignty requires not just knowing where the data lives but knowing what stories the data tells and who decided which stories to include.

The fourth layer is the evaluation framework — the benchmarks, the safety tests, the performance metrics, and the auditing protocols that determine whether a model is deemed acceptable for deployment. An institution that relies entirely on the provider’s own evaluation reports is outsourcing the determination of trustworthiness to the same entity whose incentives may not align with the institution’s interests. The evaluation layer is where the TEE Method’s first principle — Test — becomes essential. Independent testing against sovereignty-specific criteria, not merely generic safety benchmarks, is what distinguishes verification from acceptance of the provider’s claims.

The fifth layer is the integration architecture — the APIs, the middleware, the orchestration logic, and the workflow automation that connects the AI system to the institution’s operational systems. This layer is where dependency becomes structural. An AI system that is deeply integrated into case management, document processing, or decision-support workflows cannot be extracted without reengineering those workflows. The integration layer determines whether sovereignty loss is a reversible inconvenience or an irreversible institutional redesign. The key metric is not how well the system is integrated but how completely it can be disentangled.

The sixth layer is the governance framework — the policies, the oversight mechanisms, the accountability structures, and the decision rights that determine who has authority over the AI system. This includes contractual terms, regulatory compliance obligations, and internal governance processes. A governance framework that delegates decision authority to the provider — through automatic updates, through binding arbitration clauses, through acceptance of the provider’s terms of service as the governing document — has ceded sovereignty at the most fundamental level. Governance sovereignty means that the institution, not the provider, decides what the system may and may not do, and retains the enforcement mechanisms to make that decision binding.

The seventh and final layer is the human capability layer — the expertise, the institutional knowledge, and the operational skills required to understand, manage, and if necessary rebuild the AI system. An institution that has outsourced not only the technology but also the understanding of that technology has created a dependency that cannot be resolved by acquiring new hardware or negotiating new contracts. The knowledge of how the system works, why it was designed in particular ways, and what alternatives exist must reside within the institution itself. When the last person who understands the system leaves or when the provider’s documentation is the only source of institutional knowledge, sovereignty has already been lost at the layer that matters most — the capacity to make informed decisions about the system’s future.

Each of these seven layers interacts with the others. A vulnerability at the compute layer amplifies risks at the model layer. A weakness at the governance layer undermines protections at the integration layer. The audit is therefore not a checklist to be completed once but a framework for continuous assessment — a way of asking, at every layer, whether the institution’s position on the Sovereignty Spectrum is improving, deteriorating, or holding steady.

Part Two: The Sovereignty Test Matrix

The Sovereignty Spectrum provides the conceptual map. The Seven-Layer Stack Audit provides the diagnostic tool. The Sovereignty Test Matrix provides the scoring mechanism — a systematic way to translate qualitative assessment into quantitative measurement across five domains of sovereignty. The Matrix scores each domain on a scale of one to five, producing a total score out of twenty-five that locates the institution on the Spectrum with sufficient precision to guide action.

The Political Sovereignty domain assesses the degree to which the institution retains decision-making authority over its AI systems free from external coercion, whether by foreign governments, corporate providers, or international standards bodies that encode interests other than the institution’s own. A score of five in this domain indicates that the institution can independently determine the operational parameters, ethical boundaries, and strategic direction of its AI deployment. A score of one indicates that an external entity exercises effective veto power over these decisions, whether directly through contractual terms or indirectly through infrastructure control. The core question is whether the institution can say no to a provider’s demand and have that refusal mean something operationally.

The Economic Sovereignty domain measures the institution’s ability to sustain its AI capabilities independent of external pricing structures, licensing models, or market conditions that it cannot influence. This extends beyond budget allocation to encompass the total cost of reversal — what it would cost, in time and resources, to extract from the current dependency and rebuild on sovereign infrastructure. A score of five means the institution has priced and provisioned for this extraction. A score of one means the extraction cost is unknown — or known and prohibitive. The economic dimension forces the question that procurement processes rarely ask: not what the service costs, but what it would cost to leave.

The Cultural Sovereignty domain addresses a subtler but equally consequential dimension: whether the AI systems the institution deploys reflect, respect, and reinforce the cultural frameworks, linguistic patterns, and value systems of the communities they serve. Models trained predominantly on data from a small number of linguistic and cultural contexts embed those contexts into their outputs. An institution that deploys such models without cultural adaptation has outsourced not just its technology but its normative framework. A score of five indicates that the institution’s models have been evaluated and adapted for cultural alignment with their intended users. A score of one indicates that the institution has accepted the provider’s default cultural encoding without question or audit.

The Intellectual Sovereignty domain assesses control over the knowledge assets that the institution’s AI systems generate, process, and depend upon. This includes proprietary data, fine-tuned model weights, prompt engineering libraries, evaluation datasets, and the institutional knowledge embedded in system configuration. A score of five means the institution can extract, transfer, and independently operate all of these assets without degradation. A score of one means that key intellectual assets exist only within the provider’s infrastructure, in formats that cannot be exported, or under terms that assign ownership or usage rights to the provider. The question is not whether the institution owns its data in a legal sense but whether it can use that data independently — a distinction that contracts often obscure.

The Technological Sovereignty domain evaluates the institution’s technical capacity to build, modify, audit, and replace its AI systems. This is not merely a question of employing engineers but of maintaining the institutional capability to understand the systems at a depth sufficient for independent action. A score of five means the institution possesses the expertise, the tooling, and the infrastructure to operate independently of any single provider. A score of one means that the institution’s technical understanding is entirely mediated through the provider’s documentation, interface, and support channels — a position in which the provider defines not only the answers but the questions the institution is capable of asking.

The total Matrix score maps directly onto the Sovereignty Spectrum. A score of twenty-two to twenty-five places the institution at Position Zero or One — sovereign or near-sovereign with managed dependencies. A score of sixteen to twenty-one places it at Position Two — conditional sovereignty with untested assumptions. A score of ten to fifteen indicates Position Three — dependencies without leverage. A score below ten indicates Position Four — full dependency capture. The value of the Matrix is not in the absolute number but in the comparison across domains: an institution might score well on technological sovereignty while scoring poorly on cultural sovereignty, revealing an imbalance that a single aggregate score would conceal.

Applying the Matrix requires honesty that institutional self-assessment often resists. The natural tendency is to score based on policy documents rather than operational reality — to assume that because a contract includes data portability language, data portability is practically achievable. The corrective is to require evidence for each score: a demonstrated, tested capability rather than a documented intention. An institution that has never attempted a thirty-day disconnected operation should not score itself above a three on technological sovereignty, regardless of what its architecture diagrams suggest.

The Matrix also reveals something that conventional risk assessments miss: sovereignty risk compounds across domains. A moderate weakness in economic sovereignty combined with a moderate weakness in intellectual sovereignty does not produce two separate manageable risks. It produces a single severe risk — the possibility that the institution cannot afford to leave and could not take its knowledge assets with it even if it could. The Matrix makes these interactions visible in a way that siloed risk assessments, each examining a single dimension in isolation, systematically fail to do.

Part Three: The Red Flag Checklist

The Sovereignty Test Matrix provides diagnostic depth. The Red Flag Checklist provides speed — a set of eight binary indicators that, when present, signal sovereignty risk requiring immediate attention regardless of where the institution might score on a comprehensive assessment. These are not subtle signals. They are the institutional equivalent of warning lights on a control panel, each indicating that a critical dependency has formed or is forming.

The first red flag is the absence of an exit rehearsal. If the institution has never conducted a full-scale test of its ability to operate without its primary AI provider — not a tabletop exercise, not a documented plan, but an actual operational test in which the provider’s systems are disconnected and the institution’s workflows continue — then its sovereignty is hypothetical. Plans that have never been tested are not plans. They are aspirations, and aspirations do not survive contact with the operational reality of a provider termination or service disruption.

The second red flag is the presence of mandatory arbitration clauses that designate a jurisdiction outside the institution’s legal framework. When disputes with an AI provider must be resolved in a foreign court, under foreign law, or through arbitration mechanisms that the provider selected, the institution has already surrendered a fundamental attribute of sovereignty — the capacity to enforce its rights through its own legal system. The sophistication of the AI system is irrelevant if the legal architecture governing it renders the institution effectively without recourse.

The third red flag is unilateral terms modification authority. If the provider’s terms of service or licensing agreement permit the provider to modify terms without the institution’s affirmative consent — and especially if continued use of the service constitutes acceptance of modified terms — then the institution’s entire AI deployment rests on a legal foundation that can be rewritten at any moment. This is not hypothetical risk management. It is structural exposure to a single party’s commercial decisions.

The fourth red flag is the absence of a verified data escrow arrangement. If the institution’s proprietary data, fine-tuned models, prompt chains, evaluation datasets, and system configurations exist only within the provider’s infrastructure and have not been independently archived in a format that the institution has verified it can operationalize, then the institution does not possess its own intellectual assets. It possesses access to them, and access is a revocable privilege, not a property right.

The fifth red flag concerns model deprecation without guaranteed continuity. If the provider can discontinue a model version that the institution’s workflows depend upon — and the institution has no contractual guarantee of continued access, no escrowed weights, and no migration path to an alternative — then the institution’s operational continuity depends on the provider’s product roadmap. Product roadmaps are not contracts. They are marketing documents with no legal force.

The sixth red flag is the absence of independent evaluation capability. If the institution relies entirely on the provider’s own safety testing, bias assessment, and performance benchmarking — without conducting independent evaluations using sovereign criteria — then the institution is accepting the provider’s assertions about a system whose failures the institution, not the provider, will bear. A provider’s evaluation reports answer the questions the provider chooses to ask. Those are rarely the questions the institution most needs answered.

The seventh red flag is concentration of institutional knowledge in external personnel. If the institution’s understanding of how its AI systems function resides primarily with the provider’s support staff, consultants, or a small number of internal personnel who have not documented their knowledge in transferable form, then the institution has a human sovereignty gap that technology cannot close. When the people who understand the system leave, the understanding leaves with them — and the institution is left operating machinery it can no longer comprehend.

The eighth and most consequential red flag is the presence of decision automation without human override capability. If the AI system makes or substantially shapes decisions that affect rights, entitlements, or institutional commitments — and there is no pathway for a human operator to override, reverse, or audit that decision independently — then the institution has delegated not merely computation but governance. The system is no longer a tool. It is a governing authority, and the institution’s sovereignty has been transferred to code it did not write, running on infrastructure it does not control, governed by terms it did not negotiate.

The threshold for action is three red flags. An institution that exhibits three or more of these indicators is not managing sovereignty risk — it is deferring a sovereignty crisis. The specific combination of flags matters less than their cumulative presence. Each flag represents a distinct pathway through which external control can crystallize into effective governance. When multiple pathways exist simultaneously, the probability that at least one will be activated approaches certainty over a sufficient timeframe.

The Red Flag Checklist is designed for institutional self-diagnosis, but it also serves a communication function. These eight indicators provide a shared vocabulary that transcends technical specialization. A legal counsel can understand the implications of mandatory arbitration. A chief financial officer can understand the implications of unilateral pricing changes. A chief technology officer can understand the implications of model deprecation without continuity. The checklist creates a common language through which sovereignty risk can be discussed across the institutional functions that must coordinate to address it.

Part Four: The Phased Implementation Framework

Identifying position on the Sovereignty Spectrum and diagnosing red flags produces knowledge. Converting that knowledge into action requires a structured implementation pathway — one that acknowledges the operational realities of institutions that cannot simply abandon their existing AI deployments but must systematically reduce dependency over time. The Phased Implementation Framework provides this pathway across four stages, each with defined objectives, measurable deliverables, and a clear relationship to the Sovereignty Test Matrix score.

The first phase, Assessment, spans weeks one through four. During this period, the institution conducts the Seven-Layer Stack Audit and completes the Sovereignty Test Matrix for every AI system in production or procurement. The deliverable is not a report but a Sovereignty Profile — a document that maps each system’s position on the Spectrum, identifies the specific layers where vulnerability exists, and assigns a Matrix score across all five domains. The critical discipline during Assessment is to resist the temptation to begin remediation before the full diagnostic is complete. Partial assessment creates the illusion of understanding while leaving the most dangerous dependencies invisible.

The Assessment phase also includes the first exit rehearsal. For the institution’s most critical AI dependency, the team attempts a full operational disconnect — not a simulated exercise but an actual isolation of the system from the provider’s infrastructure. The rehearsal will almost certainly fail in revealing ways. That failure is the deliverable. It surfaces the specific technical, contractual, and organizational barriers that prevent sovereign operation, replacing abstract risk assessments with concrete, documented obstacles that can be systematically addressed.

The second phase, Strategic Planning, runs from months two through three. Using the Sovereignty Profile and the exit rehearsal findings, the institution develops a Sovereignty Roadmap — a prioritized, sequenced plan for reducing dependency across all identified vulnerabilities. The Roadmap distinguishes between quick wins — changes that can be implemented within weeks, such as data escrow arrangements or contract amendments — and structural transformations that require months of engineering, procurement, and capability building.

Strategic Planning must also address the capability asymmetry that makes sovereignty costly. For each critical AI function, the institution evaluates whether sovereign alternatives exist, whether they can be built, and what capability gap — if any — must be accepted in the transition. This evaluation is not about finding perfect substitutes. It is about establishing the institution’s risk tolerance for capability reduction in exchange for sovereignty gain, and making that trade-off explicit rather than allowing it to be made implicitly by the gravitational pull of convenience.

The third phase, Implementation, spans months four through twelve. This is where the Roadmap becomes operational reality. Data is escrowed, contracts are renegotiated, sovereign infrastructure is provisioned, models are audited independently, and — most critically — human capability is built within the institution. The Implementation phase follows a crawl-walk-run sequence: establish sovereign capability for the least critical function first, validate the approach, then extend to progressively more critical systems.

During Implementation, the institution conducts exit rehearsals at regular intervals — not as crisis simulations but as routine operational exercises. Each rehearsal should demonstrate measurable improvement over the previous one, reflecting the progressive reduction of dependency. The rehearsals also serve a political function within the institution: they make sovereignty tangible. An institution that has successfully operated its citizen services platform without external connectivity for a week has a fundamentally different understanding of its own capability than one that has only read about sovereignty in strategy documents.

The fourth and final phase, Institutionalisation, occupies months thirteen through eighteen. By this stage, the institution has established sovereign capability for its critical AI functions and demonstrated that capability through repeated exit rehearsals. The task now is to embed sovereignty as an ongoing institutional practice rather than a one-time project. This means integrating the Sovereignty Test Matrix into procurement processes, making the Seven-Layer Stack Audit a standard component of system reviews, and establishing the Red Flag Checklist as a continuous monitoring instrument rather than a diagnostic applied only in crisis.

Institutionalisation also requires what can be termed sovereignty budgeting — the allocation of ongoing resources to maintain sovereign capability. This is where many institutions fail. Having achieved sovereignty, they allow the capability to atrophy because maintenance is a recurring cost while dependency is invisible until activated. The discipline of Institutionalisation is the recognition that sovereignty is not a state to be achieved but a condition to be maintained — and maintenance requires continuous investment, continuous testing, and continuous vigilance against the convenience gravity that will, over time, pull the institution back down the Spectrum if not actively resisted.

The eighteen-month framework is ambitious but achievable for institutions that commit to it. The alternative — extended timelines that stretch sovereignty transitions across multiple budget cycles and leadership changes — virtually guarantees failure. Sovereignty efforts that take longer than eighteen months tend to become permanent initiatives that produce documentation but never produce operational capability. The framework’s timeframe is deliberately constrained to force prioritization: not everything can be made sovereign in eighteen months, and the process of deciding what must be is itself a sovereignty exercise.


The Question Revisited

How can institutions determine where they fall on the dependency curve before they discover it through crisis, and what framework allows them to measure, communicate, and act on that position?

The answer lies in the TEE Method’s core logic applied not to individual AI systems but to the institutional relationship with those systems. Test: conduct the Seven-Layer Stack Audit, complete the Sovereignty Test Matrix, and perform an exit rehearsal. These three actions transform sovereignty from an abstract concern into a measurable condition with specific, documented vulnerabilities. Evaluate: apply the Red Flag Checklist and assess the total Matrix score against the Sovereignty Spectrum. This step converts diagnostic data into a position on the dependency gradient, making visible what institutional self-assessment typically obscures. Evolve: implement the Phased Implementation Framework, moving systematically from assessment through institutionalisation, with exit rehearsals at each stage verifying that movement up the Spectrum is real rather than aspirational.

The Sovereignty Spectrum does not demand that every institution achieve Position Zero. That would be unrealistic for most organizations and unnecessary for many. What it demands is that institutions know where they stand, understand the forces pulling them downward, and make conscious choices about acceptable dependency levels — rather than discovering those levels through crisis. The framework exists not to mandate a particular position but to make position visible, measurable, and actionable. An institution that knowingly accepts Position Two dependency because it has evaluated the alternatives and determined the trade-off acceptable has exercised sovereignty. An institution that occupies Position Two because it never asked the question has surrendered sovereignty by default.

The distance between these two conditions — conscious choice and passive drift — is the distance that the Sovereignty Spectrum exists to illuminate. In an era when AI systems increasingly mediate the relationship between institutions and the populations they serve, that distance is not academic. It is the measure of whether an institution governs its tools or is governed by them. The framework provides no guarantee of sovereignty, only the clarity required to pursue it deliberately. Everything beyond that clarity is execution — and execution is always the institution’s responsibility, never the framework’s.

This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? The TEE Method — Test, Evaluate, Evolve — provides the systematic approach to sovereignty assessment and governance that underpins the Sovereignty Spectrum, the Seven-Layer Stack Audit, and the Phased Implementation Framework described here. For the complete framework, including the Sovereignty Test Matrix scoring methodology and the institutional sovereignty diagnostic protocols, see tonishatagoe.com.


Part Four: Phased Implementation Framework

The Assessment phase, spanning the first four weeks, begins with a comprehensive inventory of every algorithmic system currently deployed across government operations. This inventory must capture not just the system’s function and vendor but the complete dependency chain: the contractual terms, the jurisdictional exposure, the data flows, the model provenance, the training data lineage, and the operational integration points. The assessment must be conducted by an independent entity with the technical competence to evaluate algorithmic systems and the constitutional authority to demand information from vendors. The output of the assessment phase is a sovereignty risk register that ranks each algorithmic system according to the severity and immediacy of the dependency threat it represents.

The Strategic Planning phase, occupying months two and three, translates the risk register into a phased remediation roadmap. For systems flagged as critical — those whose failure or compromise would threaten essential government functions — the planning phase develops credible alternatives. These alternatives may include migration to open-source platforms operated on sovereign infrastructure, diversification across multiple vendors from different jurisdictions, or investment in domestic development of sovereign capabilities. The planning phase also establishes the procurement reforms necessary to prevent new dependencies from being created while existing ones are being unwound. Standard government procurement templates must be rewritten to include mandatory sovereignty impact assessments, explainability requirements, data localisation provisions, and sunset clauses.

The Implementation phase, running from month four through month twelve, executes the highest-priority remediations. This is the phase where alternatives are built, migrations are executed, and dependencies are severed. The implementation phase is also where the most difficult organisational challenges arise. Government departments that have become accustomed to vendor-managed algorithmic services will resist the transition to sovereign alternatives that require in-house technical capability. The resistance is not irrational. Vendor-managed services shift operational burden and technical risk to the vendor. Sovereign alternatives shift those burdens back to the government. The implementation phase must therefore include a substantial workforce development component: recruiting, training, and retaining the engineering and data science talent required to operate sovereign algorithmic infrastructure.

The Institutionalisation phase, spanning months thirteen through eighteen, embeds algorithmic sovereignty into the permanent architecture of government. The procurement reforms developed during the planning phase become statutory requirements. The sovereignty impact assessment becomes a mandatory component of every technology procurement decision. The domestic technical workforce reaches a scale sufficient to sustain sovereign algorithmic operations without extraordinary recruitment measures. International coordination mechanisms are established to share sovereignty-preserving technical solutions across allied governments, reducing the cost burden on any single state. The institutionalisation phase is not the end of the process. Algorithmic sovereignty is not a state to be achieved but a capability to be maintained, and the institutional framework must include mechanisms for continuous reassessment as technology and the geopolitical environment evolve.


Closing Question

What happens to the concept of sovereignty when the instruments of governance are owned, operated, and optimised by entities that owe no allegiance to the governed? The answer, examined through the TEE Method framework, is that sovereignty does not disappear in a single moment of technological capture. It erodes incrementally, contract by contract, update by update, until the formal claim to self-governance and the practical capacity for autonomous decision-making diverge so far that the claim becomes a fiction. The algorithmic sovereignty gap is the measurable distance between those two realities. Closing it requires not a single regulatory intervention but a sustained programme of assessment, planning, implementation, and institutionalisation — the four phases of the TEE Method applied to the specific challenge of algorithmic dependency. The states that close the gap will govern in the twenty-first century. The states that do not will be governed by the algorithms they purchased and the corporations that built them.


This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? For the complete framework, including the Seven-Layer Sovereignty Stack Audit, the Five-Domain Sovereignty Test Matrix, and the Four-Phase Implementation Protocol applied across digital, economic, and institutional domains, see tonishatagoe.com.


Part Four: Phased Implementation Framework

Recovering sovereignty over physical internet infrastructure is not a project that can be completed in a single budget cycle. It requires a sequenced approach that builds capability progressively, starting with the most urgent vulnerabilities and expanding toward comprehensive sovereign control. The following phased framework provides a structured path from assessment to institutionalisation over an eighteen-month timeline.

The assessment phase occupies the first four weeks and focuses on establishing a complete and accurate picture of existing dependencies. This phase requires mapping every submarine cable that terminates in or passes near the nation’s territory, documenting the ownership structure of each cable, cataloguing the legal agreements governing landing rights and transit, and identifying the repair and maintenance arrangements currently in place. The assessment must extend beyond the cables themselves to include the terrestrial infrastructure on which connectivity depends: landing stations, internet exchange points, and domestic backhaul networks. At the conclusion of this phase, the government should possess a single comprehensive document that answers, for every international data path, the question of who owns it, who operates it, and under what legal framework.

The strategic planning phase spans months two and three and translates the dependency map into an actionable sovereignty strategy. This phase involves evaluating options for acquiring ownership stakes in existing cables, identifying opportunities for new cable construction that serves domestic sovereignty objectives, and developing the legal and regulatory frameworks necessary to govern cable infrastructure within the nation’s jurisdiction. The strategy should prioritise interventions that generate the largest sovereignty return for the smallest capital outlay. Acquiring a minority stake in an existing consortium cable can provide governance rights, traffic visibility, and a seat at the decision-making table at a fraction of the cost of building a new cable. Strategic planning also requires building diplomatic relationships with other nations that share similar sovereignty concerns, creating the conditions for multilateral cable projects that distribute costs and risks.

The implementation phase occupies months four through twelve and represents the period of active infrastructure development. This may include participating in new cable construction projects, negotiating capacity purchases with sovereignty-protective terms, developing domestic cable landing stations, and establishing a national internet exchange point under sovereign control. The implementation phase should also include the development of domestic technical capacity for cable maintenance and repair, either through training programmes, partnerships with regional maintenance providers, or investment in cable repair vessel capacity shared among multiple nations. During this phase, the regulatory framework developed in the strategic planning phase moves from design to enactment, establishing clear rules for cable operators regarding transparency, security, and government access.

The institutionalisation phase spans months thirteen through eighteen and ensures that the sovereignty gains achieved in the implementation phase are durable. This phase involves embedding cable infrastructure governance into permanent government institutions, establishing regular sovereignty audits of digital infrastructure dependencies, creating career pathways for the technical personnel needed to sustain sovereign cable operations, and building the diplomatic relationships necessary to participate in international cable governance forums. The institutionalisation phase also includes the development of a long-term investment plan that ensures cable infrastructure sovereignty is maintained and expanded as technology evolves and traffic patterns shift. Without institutionalisation, the sovereignty gains of the implementation phase will erode as personnel turn over, budgets shift, and attention moves to other priorities.

Throughout all four phases, the governance principle is straightforward: sovereignty over physical internet infrastructure is not an all-or-nothing proposition. It is a gradient, and meaningful progress can be made at every point along that gradient. A nation that moves from owning zero percent of its cable capacity to owning twenty percent has not achieved full sovereignty, but it has reduced its vulnerability substantially. It has gained governance rights, traffic visibility, and a platform from which to pursue further sovereignty gains. The phased framework is designed to make that progress achievable, measurable, and self-reinforcing.


The Question Revisited

Who owns the physical infrastructure that carries a nation’s data, and what does it mean for sovereignty when the answer is “someone else”? The TEE Method framework provides the analytical lens through which this question yields a clear answer. The TEE Method posits that sovereignty is determined by three core dimensions: Transparency, which asks whether the sovereign can see and understand the system it depends on; Empowerment, which asks whether the sovereign has the capacity to act on that understanding; and Enforcement, which asks whether the sovereign has the mechanisms to compel compliance with its decisions.

Applied to submarine cable infrastructure, the TEE Method reveals that most nations fail all three tests. They lack transparency into cable routing, ownership structures, and traffic patterns. They lack empowerment in the form of ownership stakes, governance rights, and domestic technical capability. And they lack enforcement mechanisms, operating without regulatory frameworks that give them legal leverage over cable operators. The answer to the question, then, is that when someone else owns the cables, sovereignty is not merely diminished. It is structurally absent at the physical layer, and no amount of cybersecurity spending or data protection legislation can compensate for that absence. Physical infrastructure sovereignty is not one component of digital sovereignty among many. It is the foundation on which all other forms of digital sovereignty rest. Without it, the rest is aspiration built on sand.


This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? For the complete framework, including the full Seven-Layer Stack Audit methodology and Sovereignty Test Matrix scoring protocols, see tonishatagoe.com.

Keep Reading

Related Articles

LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…

LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…