THE SCENARIO
A nation announces a twenty-billion-dollar sovereign AI compute initiative. The strategy focuses on acquiring GPUs, building data centres, and subsidising local cloud providers. The hardware arrives. The data centres open. The cloud services launch. One year later, the sovereignty audit reveals: the GPU firmware is controlled by the manufacturer. The data centre management software is licensed from a foreign vendor. The cloud orchestration platform is a component of a global infrastructure owned by another government. The hardware is local. The sovereignty is not.
Why does the dominant narrative of AI sovereignty stop at hardware ownership?
The dominant narrative of AI sovereignty is compute ownership. A nation that acquires hardware, operates domestic data centres, and deploys public cloud infrastructure has, by this accounting, sovereign AI. This accounting is incomplete in a way that is not accidental. It produces governance fiction: the appearance of sovereignty over a stack whose governing authority operates elsewhere. The nation that builds sovereign AI on foreign compute infrastructure, foreign model governance, and foreign API governance has built a locally administered foreign AI capability. The sovereignty fiction is operationally convenient. It is cheaper to fund a compute initiative than to build governance capacity across seven layers. The compute initiative produces visible deliverables. Governance capacity produces governance outcomes that are invisible in the metrics that drive political investment.
The TEE Method — Test, Evaluate, Exit — is not a checklist. It is an architecture for sovereignty. It does not tell you what to do. It gives you a structure for deciding for yourself.
Part One: Understanding the Landscape
The progression from data architecture challenge to a structural governance condition occurs through a subtle systematic mechanism. It begins with framing: the issue is presented to decision makers as an infrastructure design challenge or a cloud cost optimisation exercise rather than a sovereignty decision. The TEE Method rejects this framing categorically. This is a sovereignty issue that has data architecture implications, not a data architecture issue that has sovereignty implications. The distinction is structural and determinative. It determines whether the entity approaches the challenge from its governance red lines or from its infrastructure procurement checklist. It determines whether the chief architect is an infrastructure specialist optimising for cost and performance or a governance official optimising for governance authority. It determines whether the procurement specifications are written by infrastructure engineers who understand cost curves or by sovereignty architects who understand the architecture of technological dependency. The choice of framing is the choice of outcome. The entity that frames sovereignty as an infrastructure problem will receive infrastructure solutions that govern from afar. The entity that frames sovereignty as a governance architecture will build the institutional capacity to govern whatever infrastructure arrives next.
The specific provisions that drive sovereignty erosion in data architecture follow a consistent pattern. They are presented as enablers: rapid deployment, world-class infrastructure, global best practice, established standards, vendor support, interoperability, cost efficiency, time to value. Each provision is legitimate in its own domain. Together, they transfer governing authority from the entity that should govern to the entities that wrote the contracts and built the platforms. The infrastructure vendor accepts a data residency clause in the contract. The clause creates the appearance of data sovereignty. The same contract contains an API governance clause that gives the vendor governing access to the data for product improvement. The residency clause governs data location. The API clause governs data access. The contract creates sovereignty in language while transferring governance in architecture. The sovereignty fiction is structurally necessary: if the contract’s governance architecture were visible in the contract language, the contract would not be signed.
A regional AI computing and cloud initiative received significant sovereign investment for domestic data processing capacity. The contract language committed the vendor to domestic data residency. The contract also provided the vendor with governing API access for platform improvement. When the sovereign sponsor requested data access controls consistent with its own data governance requirements, it discovered the API access clause — which it had reviewed and approved — gave the vendor governance priority over its own data governance provisions. The sovereignty fiction was located in the contract. The governance reality was located in the architecture. The investment was real. The sovereignty transfer was structurally embedded at the moment of contract signature. The TEE Method would have identified the governance allocation at the API governance layer before the contract was signed. Procurement after governance audit is governance construction. Procurement before governance audit is governance acceptance.
The Cloudflare and Akamai CDN case illustrates a governance transfer that operates through the commercial logic of infrastructure rather than through contractual ambiguity. Between twenty and thirty percent of the world’s sovereign traffic is routed through a small number of multinational CDN providers. Content routing is governance. Routing that prioritises content delivery by geographic region is governance applied to sovereign population behaviour. The sovereign entity has not transferred content governance explicitly. It has accepted governance transfer by choosing infrastructure that makes governance transfer architecturally simple. Governance transfer operates subliminally wherever infrastructure decisions are made in financial rather than governance language. The Critical layer for this sovereignty failure is governance routing infrastructure.
The Seven Layer Stack Audit
The sovereignty erosion mechanism unfolds across seven layers. Each layer represents a governance allocation point. Each layer is independently addressable. Together, they determine the entity’s genuine sovereignty position. The Entity is counting compute CPUs as sovereignty while the governance sits in the firmware. The sovereign initiative that can name the layers where governance has been genuinely exercised and the layers where governance has been accepted without examination has completed the first governance step. The next step is governance construction at each ungoverned layer.
| Layer | Governance Authority | Sovereignty Score (1–5) | Critical Dependency |
|---|---|---|---|
| Layer 1: Hardware & Compute | GPU and hardware manufactured by NVIDIA and AMD; GPU firmware controlled by manufacturer; data centre operations through domestic operator with foreign software stack | 2 | NVIDIA firmware: zero domestic governance; foreign manufacturer sets operational parameters |
| Layer 2: Foundational Models & Training Data | Core AI models developed by G42 with training data sourced from global pool with limited indigenous curation; API access to supplementary models (Azure OpenAI, Google) governed by foreign terms | 2 | Training data jurisdiction: domestic data contributing to model trained under foreign legal framework |
| Layer 3: API & Middleware | NVIDIA GPU orchestration layer controls compute allocation; Azure middleware layer governs API access; Google Vertex AI middleware for model serving | 1.5 | NVIDIA compute allocation governance + Azure API governance: dual-foreign control |
| Layer 4: Platform & Application | Khazna sovereign cloud infrastructure operational; stc Ground computing platform; domestic application layer with some indigenous capability; platform governance through foreign orchestration middleware | 3 | Khazna and stc Ground: genuine domestic infrastructure; governance vesting in domestic entities |
| Layer 5: Data Architecture & Sovereignty | Physical data residency at domestic facilities; data export governed by contractual clauses and PDPL adequacy mechanism; PDPL adequacy determined by regulator without parliamentary oversight | 2.5 | PDPL adequacy: foreign legal jurisdiction disguised as domestic governance mechanism |
| Layer 6: Governance & Regulatory Framework | UAE AI Governance Principles (domestic); NCA ECC cybersecurity standards (domestic); NESA IAS incorporating international standards; ZATCA e-invoicing federal mandate | 3 | NESA IAS adoption: international governance framework integrated into domestic regulatory infrastructure |
| Aggregate Sovereignty Score | Compute and model governance structurally foreign; platform layer showing genuine domestic sovereignty; data governance obscured by adequacy fiction | 2.7/5 | CRITICAL FAILURE: Layer 3 (API & Middleware) dual-foreign governance creating CRITICAL LAYER; Platform layer (L4) is the sovereign opportunity |
The GPU firmware layer is the most direct governance sovereignty failure. An NVIDIA firmware update to a domestically deployed data centre happens without domestic governance consent. The firmware controls power distribution, thermal management, compute allocation, error handling, and security configuration. A foreign manufacturer’s firmware update — delivered without notification to the domestic operator beyond standard vendor communication — altered compute allocation policy on production systems. The domestic operator’s governance authority over its own compute environments terminated at the firmware boundary. Domestic data centre sovereignty is a sovereignty pretense when firmware governance resides outside domestic authority. The Khazna initiative at MBZUAI addresses infrastructure sovereignty while the firmware layer remains entirely ungoverned. Building domestic governance capacity at the infrastructure layer requires addressing the firmware layer simultaneously. Treating the infrastructure as sovereign because it is physically domestic while the firmware is foreign is the most common sovereignty fiction in AI sovereignty initiatives.
The foundational model layer operates under API governance governance that makes the governance fiction structurally transparent. A domestic institution that trains its own AI model on domestic data but deploys through an Azure OpenAI or Google Vertex API is exercising API governance, not model governance. The API substantive governance — the API versioning policy, access conditions, rate limits, modelling update cycles, data handling obligations, audit permissions — is governed by the foreign provider. KSA’s NCC and Draft AI Regulation contain provisions requiring AI system documentation and transparency. These provisions govern the domestic deployer’s documentation obligations. They do not govern the API governance that the deployer operates through. The domestic institution must document what the foreign API does. It cannot govern what the foreign API does. This is the structural condition of foreign model dependency: the sovereign entity governs documentation, not capability.
The Platform layer (Layer 4) is where sovereignty can genuinely be exercised. Khazna, stc Ground, and the MBZUAI research infrastructure represent genuine domestic governance infrastructure. The challenge at this layer is governance integration: connecting the sovereign compute and platform governance to sovereign model governance and sovereign data governance. A sovereign platform that connects to foreign API governance at Layers 2 and 3 has not solved the governance problem. It has solved the hosting problem. The governance problem requires governance solutions at every layer. The TEE Method provides the format for governance construction across all seven layers simultaneously.
Part Two: The Sovereignty Test Matrix
The sovereignty erosion mechanism is not a single event. It is a structural condition that the specific provisions create across the entity’s operation. The Test Matrix maps this condition across the platform governance landscape, identifying for each layer where sovereignty is genuinely held, where it is claimed but not exercised, and where it has been transferred without the entity’s explicit recognition. The Critical layer in the platform sovereignty audit is always the API governance layer: the layer through which foreign capability is accessed and foreign governance is applied to domestic operation. The entity that cannot demonstrate sovereign API governance has not integrated API governance into its sovereignty architecture. The entity that treats API governance as a procurement issue rather than a sovereignty issue is building sovereignty fiction, not sovereignty fact. The sovereign platform that connects to sovereign application governance but upstream governance at API or model layers is governed at the upstream layers.
Does the entity’s domestic compute infrastructure include governance governance of the firmware governing its operation, or is domestic sovereignty a governance fiction at the firmware boundary? Does the indigenous model training programme include governing authority over how the model is deployed and accessed, or is deployment governance exercised by a foreign platform operating the API? Can the entity terminate its dependency on any critical API within ninety days without governance failure — or is governance transfer structurally irrecoverable without rebuilding the capability the API provides? Does the entity maintain a real-time map of all data flows that exit domestic jurisdiction, or are data exports governed by contractual adequacy fiction rather than operational visibility? Does the domestic regulatory framework require legislative scrutiny of all international standard adoptions that allocate governance authority to external bodies, or is standard adoption an administrative exercise that transfers governance without legislative accountability? Is API access to foreign models governed by domestic contract terms that include governance audit rights, or is the entity governed by foreign terms of service it cannot modify? Does the entity have a governance exit path that does not include governance concession to the vendor from whom governance is being recovered — or is the exit path negotiated with the governing entity, which is not an exit path but a governance concession? Answers to these questions locate governance authority precisely. They reveal governance fiction where governance capability was assumed. They reveal governance capability where governance fiction was assumed. The TEE Method provides the format for governing governance construction.
Part Three: Red Flag Checklist
If three or more of the following apply, data sovereignty is not a future risk — it is an existing condition.
- National AI compute investment has addressed hardware acquisition without addressing GPU firmware governance — domestic compute sovereignty ending at firmware boundary.
- Domestic model training operates through foreign API access (Azure OpenAI, Google Vertex AI) where API governance governs domestic capability rather than domestic governance governing API access.
- Data residency requirements in cloud contracts are accompanied by API access and data export clauses that govern data access by the foreign provider — sovereignty fiction in the residency clause, governance transfer in the API clause.
- Cloud CDN infrastructure routes a significant portion of domestic population traffic through foreign servers governed by foreign entities — content governance by foreign corporate policy.
- Training data for a domestic AI model is collected under the legal jurisdiction of a foreign data governance framework — model governed by foreign legal system despite domestic training origin.
- The domestic PDPL adequacy mechanism permits data transfer to foreign jurisdictions without parliamentary oversight — data governance transferred through regulatory designation, not legislative decision.
- An independent audit would find that foreign API governance extends to core domestic AI capabilities (credit scoring, healthcare AI, legal AI) without domestic governance modification or audit rights.
- Domestic AI infrastructure includes a blockchain settlement layer governed by a foreign protocol whose governance cannot be modified by domestic legal process — foreign governance architecture embedded in financial infrastructure.
- Domestic regulatory frameworks adopt international standards (ISO/IEC, IEEE, NIST) as domestic requirements without a parliamentary scrutiny process for governance allocation — governance transfer through administrative adoption rather than legislative decision.
- The domestic AI institution cannot demonstrate an exit path from its primary API dependency that does not require licensing concession from the foreign governing entity — governance concession, not governance independence.
Part Four: Phased Implementation Framework
| Phase | Timeframe | Key Actions |
|---|---|---|
| Assessment | Weeks 1-4 | Complete Seven Layer Stack Audit of the full data sovereignty ecosystem; produce Sovereignty Test Matrix scores per layer; identify sovereignty traps using the Red Flag Checklist; map all data flows exiting domestic jurisdiction; produce initial Sovereignty Score with governance allocation documentation |
| Strategic Planning | Months 2-3 | Develop withdrawal protocols for the three highest-risk governanc dependencies (prioritising API and middleware layers); identify domestic alternatives (Khazna, stc Ground, Jais, AceGPT); begin knowledge transfer programmes to reduce governance knowledge concentration at foreign API layers; negotiate contractual protections including data portability, transparent pricing, genuine exit provisions, and API governance audit rights; form the Sovereign Governance Caucus for domestic platform operators |
| Sovereign Transition | Months 4-6 | Execute Phase 1 exit protocols at highest-risk layers; deploy indigenous model serving through domestic API infrastructure (Khazna); establish domestic safety and compliance standards for data processing; conduct legislative review of all international standard adoption processes; develop PDPL adequacy review mechanism with parliamentary oversight |
| Institutionalisation | Ongoing | Quarterly sovereignty governance exercises; staff training in TEE Method for platform governance; national data sovereignty register tracking all cross-border data flows; annual sovereignty scorecard with measurable improvement targets; bi-annual strategic adjustment cycles; API governance as a legislative oversight category in national digital infrastructure law |
The political economy of platform sovereignty transfer operates through a mechanism that is structurally similar to the AI governance case but operates one layer closer to operational reality. The foreign vendor does not need to govern the political process. It needs to govern the API. The API governance is cheaper to maintain than the political governance the sovereign entity exercises. The sovereign entity’s governance is exercised through contracts the vendor has already structured. The vendor’s governance is exercised through API terms the sovereign entity cannot alter. The asymmetry is structural, not contractual. Contractual asymmetry reflects architectural asymmetry. The sovereign entity renegotiates contracts while the vendor renegotiates architecture. The vendor wins.
The governance fiction at the adequacy layer is a particularly pernicious form of governance transfer because it is legally sanctioned by the sovereign state’s own regulatory framework. The PDPL adequacy mechanism is not an imposition from outside. It is a domestic governance choice expressed through domestic regulation. The regulator’s adequacy designation constitutes a governance act. The decision that jurisdiction X provides adequate data protection is exercised by a domestic regulator without legislative oversight. The act of designation transfers governance over data flowing to X without a legislative decision to transfer governance. The entity whose data is being transferred has no mechanism to challenge the adequacy determination that transfers its governance. This is governance by regulatory fiction maintained through a procedure that appears to protect sovereignty while discharging it.
The exit cost for platform governance transfer compounds across layers. Exiting NVIDIA GPU firmware governance requires a domestic alternative to NVIDIA’s firmware update management system. No domestic alternative currently exists at scale in the region. A domestic firmware alternative would require not just engineering capability but governance capability: a domestic entity capable of making firmware update decisions that serve domestic governance priorities. Exiting Azure OpenAI governance requires a domestic model serving infrastructure that can deliver comparable capability. Khazna and stc Ground address the hosting layer. They do not individually address the model governance layer. Exiting CDN governance requires domestic or regional CDN alternative or domestic routing governance that bypasses foreign CDN governance for domestic traffic. Neither exists at national scale. The governance exit cost at each layer is real, significant, and requires pre-existing governance investment. Building the governance capacity after the governance transfer has occurred is exponentially more expensive than building it before. The TEE Method operates on the premise that governance capacity is built before governance events require it.
Russia provides a partial sovereignty case study. The Sovereign Internet Law of 2019 established a technical and legal architecture for domestic internet governance. The infrastructure includes domestic DNS root servers, domestic routing controls, and domestic content filtering mechanisms. The sovereignty position at the routing governance layer is genuine. At the CDN and CDN sourcing layer, Russian infrastructure depends heavily on foreign hardware imports and foreign interconnection agreements. The CDN governance that routes Russian internet traffic is partly foreign-governed. The sovereignty architecture meets sovereignty criteria while the practical sovereignty position includes foreign governance exposure at the CDN layer. Russia’s case demonstrates that sovereignty architecture does not require complete layer governance. It requires governance architecture at every layer that governs the sovereign entity’s operation. A layer with partial governance is a sovereignty vulnerability. A layer with no governance is a sovereignty failure. The assessment distinguishes architecture from implementation.
China’s case is instructive in a different register. China exercises effective sovereignty over its domestic AI ecosystem through a combination of technical controls and legal architecture. The governance is domestically constructed. It is operationally effective. It is sovereign in the governance architecture sense. China’s global technology companies simultaneously exercise governance authority over AI operations in other jurisdictions through market penetration, API adoption, and regulatory influence. The structural condition makes China simultaneously sovereign domestically and a sovereignty threat abroad. The distinction between sovereignty and sovereignty threat is not captive to the technical condition of domestic governance. It is governed by governance design. A sovereign AI nation that deploys its technology through governance mechanisms that absorb foreign governance is creating foreign governance dependencies even as domestic governance is exercised. The TEE Method applies to both conditions: domestic sovereignty construction and governance architecture design that does not create governance dependencies in receiving jurisdictions.
The regional AI governance coalition provides the closest current example. A group of national AI governance officials has produced a joint AI governance framework, published a joint ministerial declaration, and established a working group to harmonise domestic AI governance across member states. The governance cooperation is real. The sovereignty position it produces is more complicated than the governance language suggests. Governance cooperation among jurisdictions that have not completed Seven Layer Stack Audits of their own infrastructure produces governance coordination that is harmonised across governance positions that have not been sovereignty assessed. The governance reached in the joint framework is reached on a foundation of unexamined governance. Willingness to cooperate does not substitute for governance architecture. The governance coordination that appears to be an AI governance advance is, at the governance architecture level, a structural governance failure consensus among sovereign entities that have not exercised sovereignty at the governance architecture level.
The Closing Question
The data architecture narrative of AI sovereignty focuses on hardware, location, and infrastructure — not on governance architecture across the layers where actual governance authority resides. A sovereign compute initiative that addresses hardware without addressing firmware, model governance, API governance, and data export governance is building governance fiction subsidised by public investment. The governance fiction is operationally convenient because it does not require the institutional investment that genuine governance construction demands. It produces a sovereignty narrative that is politically useful and structurally hollow.
The TEE Method requires governance assessment before governance procurement. The Seven Layer Stack Audit identifies governance allocation before governance contract signature. The phased implementation provides a governance construction pathway that addresses governance architecture at every layer simultaneously rather than treating governance at one layer as sovereignty. The entity that exercises governance authority at the firmware boundary, at the API governance layer, at the model governance layer, and at the data governance layer simultaneously is building governance sovereignty. The entity that exercises governance at any single layer while accepting governance transfer at others is building governance fiction.
Governance rehabilitation is a governance exercise and not an audit exercise. It is governed by governing and not by theory. A governance plan written on paper without governance exercised at every layer is a governance fiction — not a sovereignty plan. Governance audit evidence without demonstrated governance capacity exercises governance illusion effectively. The sovereign entity does not improve its governance position by purchasing governance services from the vendor that governed its stack. It improves its position by constructing governance at every layer where governance construction is required. The platform layer is where this construction begins. The API governance layer is where it becomes operationally real. The firmware layer is where it becomes technically sovereign.
Governance is not acquired through sovereignty theory. It is acquired through the act of governing. The TEE Method provides the format for governance exercise. The Seven Layer Stack Audit provides the format for sovereignty rehabilitation. The phased implementation provides the path. The closing question is whether the governance architecture the entity is currently deploying is genuinely sovereign or merely configured to appear sovereign while transferring governance authority at the layers that matter.
The entity that has exercised governance authority at every layer has sovereignty. The entity that has not built governance architecture at any layer is governed by another entity’s architecture. The binary is the decision the entity makes now: accept governance transfer or construct governance sovereignty. Acceptance is passive. It requires no governance effort. It produces no governance capacity. It requires no political investment. It is always the default. Agency requires governance construction at every layer. It produces governance sovereignty. It requires the governance capacity to exercise governance under pressure. It is always more difficult than acceptance. It is always the only path that produces the outcome to which the entity claims to be committed. The answer is binary. The path is structured. The TEE Method is the methodology for walking it.
This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? by Toni Shatagoe.