THE SCENARIO
A small nation in the Global South receives an offer it cannot easily refuse. A major technology company will build the country’s national AI infrastructure — its compute clusters, its large language models, its government AI applications — at no upfront cost. The offer promises accelerated digital transformation, leapfrogging decades of infrastructure development. The fine print, written not in legal terms but in architectural ones, is that the infrastructure will run on the company’s proprietary platform, integrate with the company’s ecosystem, and generate data that flows to the company’s servers. The nation will own the applications. It will not own the stack. It will be sovereign in name but dependent in practice.
This is not a hypothetical. It is the model being deployed across multiple continents, and it is the most important governance question that almost no one is asking: who really controls the AI systems that increasingly govern our institutions, economies, and lives?
Artificial intelligence governance discussions tend to focus on the visible layer — the ethics guidelines, the regulatory frameworks, the transparency requirements, the safety protocols that governments and corporations publish with great ceremony. These are important. They are also incomplete. They address the question of how AI should behave. They do not address the question of who controls the systems that control behaviour.
This article examines the uncomfortable question of power in AI governance. It argues that the concentration of control over AI infrastructure, standards, and governance mechanisms constitutes a structural power asymmetry that existing governance frameworks do not address. It introduces the TEE Method™ framework — Territory, Exchange, Enforcement — as a tool for analysing who actually controls AI systems, how control is exercised, and what sovereignty means in an AI-mediated world.
This article examines the uncomfortable question of who really controls AI systems, the concentration of power in AI development and deployment, governance capture through standardisation, and the fundamental sovereignty question of who decides how AI is governed.
Part One: The Architecture of AI Power
To understand who controls AI, one must look past the applications visible to end users and examine the layered architecture of the AI stack. Power in AI is not concentrated in any single layer. It is distributed across the stack in ways that create dependencies at every level — and the entity that controls the most layers controls the most outcomes.
Layer 1: Compute Infrastructure
The foundation of AI power is computational. Training frontier models requires GPU clusters that cost hundreds of millions of dollars and consume megawatts of energy. Fewer than a handful of companies globally possess this capability — primarily NVIDIA at the chip level, and the major cloud providers (AWS, Google Cloud, Microsoft Azure) at the infrastructure level. A nation that cannot access cutting-edge compute cannot train frontier models. A startup that cannot afford GPU time cannot compete. An institution that depends on cloud-provider AI services operates on infrastructure it does not control, under terms it cannot negotiate, at prices it cannot predict.
This concentration means that decisions about compute access — who gets it, at what price, under what conditions — are effectively governance decisions made by private actors. When a cloud provider changes its terms of service, it is exercising governance authority over every AI system running on its infrastructure. When a chip supplier prioritises one customer over another, it is shaping the trajectory of AI development globally. This is not a technical question. It is a power question thinly veiled as a market transaction.
“Control of compute is control of AI. The entity that decides who can train models, what models can be trained, and how much they cost is exercising governance power that no ethics framework captures and no regulation addresses.”
— TEE Method™, SOVEREIGN (2026)
Layer 2: Foundational Models
The second layer of power is the model itself. The large language models, vision models, and multimodal systems that power the AI ecosystem are overwhelmingly produced by a small number of organisations concentrated in two jurisdictions: the United States (OpenAI, Google, Anthropic, Meta) and China (DeepSeek, Baidu, Alibaba). These organisations make foundational decisions about what their models can do, cannot do, and will not do — decisions encoded in training data, reinforcement learning from human feedback, safety guardrails, and usage policies.
When a foundational model provider decides that certain types of queries will be refused, certain topics will be handled in prescribed ways, or certain outputs will be filtered, it is exercising governance authority over every application built on that model. The decision is presented as a safety measure, and often it genuinely is. But safety decisions are also power decisions. The entity that defines acceptable outputs defines the boundaries of permissible discourse within the systems it powers. When those systems are adopted by governments, enterprises, and educational institutions globally, the model provider’s values become operational norms for entire societies.
Layer 3: Platform Ecosystem
The third layer is the platform ecosystem — the APIs, marketplaces, deployment tools, and integration frameworks through which AI capabilities are delivered to end users. Companies like OpenAI, Microsoft, Google, and Anthropic do not merely sell models. They sell platforms that determine how models can be used, extended, monitored, and governed. Platform terms of service govern what applications can be built, what data can be processed, and what constitutes acceptable use.
These platform terms are not negotiated. They are imposed. A government that builds an AI application on OpenAI’s API does not negotiate acceptable use policies — it accepts them. A university that adopts Google’s AI tools does not define data governance boundaries — it operates within Google’s. The platform provider sets the rules, and the adopting organisation operates within them. This is governance by architecture, not by consent.
Layer 4: Standards and Benchmarks
The fourth layer of AI power is the least visible and arguably the most consequential. Standards — for model evaluation, safety testing, bias measurement, and performance benchmarking — determine what counts as a good AI system. The organisations that control the standards control what is measured, how it is measured, and what thresholds define acceptable performance.
Standards development in AI is dominated by the same concentration of power found in other layers. Major technology companies contribute the most researchers to standards bodies, fund the most benchmark development, and publish the most evaluation frameworks. Academic institutions and smaller players participate, but the agenda is set by the organisations with the resources to shape it. The result is that standards tend to reflect the priorities, values, and assumptions of the organisations that dominate their development — a form of governance capture that is difficult to detect and harder to challenge.
Part Two: Governance Capture Through Standardisation
The power dynamics of AI standardisation merit closer examination because they represent a particularly subtle form of governance capture. Unlike compute access or model ownership, which are overtly concentrated, standardisation operates through processes that appear open, technical, and meritocratic. The appearance masks the reality of structural advantage.
How Standards Become Governance
Standards serve multiple functions in the AI ecosystem. They provide a basis for comparing model performance. They establish safety benchmarks that developers aim to meet. They create a common vocabulary for discussing capabilities and risks. Increasingly, they form the basis for regulation — governments reference standards in AI legislation, procurement requirements, and liability frameworks.
When a standard is referenced in regulation, it stops being a technical tool and becomes a governance instrument. The organisation that influenced the standard’s content has effectively influenced regulation without engaging in the legislative process. This is governance capture through standardisation: private control over the technical specifications that regulation depends on, exercised through processes that are formally open but practically exclusive.
The Exclusion Problem
Standardisation processes require resources that most potential participants do not possess. Developing a benchmark requires significant compute, expertise, and time. Participating in standards bodies requires travel, legal support, and institutional capacity. Small nations, small enterprises, and civil society organisations cannot meaningfully participate in processes that will shape the AI systems they are expected to adopt and be governed by.
The result is a standardisation ecosystem in which the governed do not participate in writing the rules that govern them. A nation in the Global South will adopt AI safety standards developed by American technology companies and European research institutions. A small enterprise will implement bias measurement frameworks designed by the platforms whose biases they are supposed to measure. The standards are presented as neutral technical instruments. They are, in fact, expressions of the power structures that produced them.
GOVERNANCE CAPTURE — The Standardisation Pipeline
1. Resource asymmetry: Standards development requires compute, expertise, and institutional capacity that most potential participants lack.
2. Agenda setting: The organisations with the most resources shape what gets measured, how it is measured, and what thresholds define acceptable performance.
3. Regulatory incorporation: Governments reference industry-developed standards in legislation, procurement, and liability frameworks, transforming technical specifications into governance instruments.
4. Lock-in: Once standards are embedded in regulation and procurement, switching costs make them effectively permanent, entrenching the power structures that produced them.
The governed rarely participate in writing the rules that govern them. This is not malice. It is architecture.
The Sovereignty Gap in AI Standards
The exclusion of nations, institutions, and communities from standardisation processes creates what can be called the sovereignty gap in AI governance: those who are expected to adopt and comply with AI standards have no meaningful role in shaping them. This gap is not a temporary oversight that will be resolved as standardisation matures. It is a structural feature of a system in which power and resources are distributed asymmetrically.
Closing the sovereignty gap requires more than inviting more participants to existing processes. It requires asking whether the processes themselves adequately represent the interests of the governed, whether the standards they produce reflect values beyond those of their dominant contributors, and whether alternative standardisation pathways exist that might produce more inclusive outcomes. These are not questions that the current standardisation ecosystem is designed to answer.
Part Three: The Sovereignty Question
The concentration of AI power across compute, models, platforms, and standards raises a fundamental question that most governance frameworks avoid: who decides how AI is governed?
This is not a question about what regulations should say. It is a question about who has the authority to determine what regulations say, who has the capacity to implement them, and who has the power to ensure they are enforced. In the current AI ecosystem, the answers to all three questions point in the same direction: the small number of organisations that control the stack also control the governance conversation.
Territory: Who Controls the AI Space?
The TEE Method™ begins with Territory — the domain over which governance authority is exercised. In AI, the relevant territory is not geographic. It is operational: the systems, data, decisions, and outcomes that AI governs. The question of who controls this territory is the foundational power question.
Currently, the territory of AI is controlled by the organisations that own the infrastructure, develop the models, operate the platforms, and set the standards. Governments regulate at the margins — imposing requirements on how AI can be used within their jurisdictions, but exercising no control over the systems themselves. This is the fundamental asymmetry of AI governance: states have territorial sovereignty, but AI has operational sovereignty that transcends territorial boundaries.
| Layer | Who Controls It | Nature of Control | Governance Implication |
|---|---|---|---|
| Compute | 3 cloud providers + 1 chip manufacturer | Access, pricing, terms of service | Private governance of who can participate in AI development |
| Models | 5-10 organisations in 2 jurisdictions | Training data, alignment, safety guardrails | Private values become operational norms for adopting societies |
| Platforms | Same 5-10 organisations | APIs, marketplaces, acceptable use policies | Unilateral rule-setting for ecosystem participants |
| Standards | Industry-led bodies, resource-heavy contributors | Benchmarks, evaluation protocols, certification | Governance capture through technical specification |
Exchange: What Is Being Traded for AI Capability?
The Exchange dimension of the TEE Method™ asks what is being given up in return for AI capability. The answer is revealing. Nations and institutions that adopt AI systems from dominant providers trade autonomy for capability. They gain access to state-of-the-art AI in exchange for operational dependence, data flows, standardisation lock-in, and — most critically — governance authority.
The trade is rarely explicit. No contract states that adopting a cloud provider’s AI tools means ceding operational governance to the provider. But the architecture of the exchange makes the trade unavoidable: the provider’s infrastructure hosts the systems, the provider’s platform governs the interactions, the provider’s standards define acceptable outputs, and the provider’s ecosystem creates switching costs that deepen over time. The trade is structural, not contractual. It is no less binding for being unstated.
The uncomfortable question is whether the exchange is worth it. For nations with no domestic AI capability, the answer may be yes — access to AI that would otherwise be unavailable may justify dependence. But the question is rarely asked explicitly. The exchange is treated as a technology procurement decision rather than a sovereignty decision. The TEE Method™ insists that every AI adoption is a sovereignty decision, whether or not the adopting organisation acknowledges it.
Enforcement: Who Ensures AI Governance Is Followed?
The Enforcement dimension addresses who has the capacity to ensure that AI governance commitments are actually implemented. This is the most neglected dimension of AI governance because it exposes the gap between aspiration and capability.
Most nations lack the technical capacity to audit AI systems running on third-party infrastructure. They lack the expertise to evaluate whether deployed models comply with their regulations. They lack the resources to develop independent evaluation capabilities. The result is a governance system in which the entities being governed — AI developers and deployers — are also the only entities with the capacity to verify compliance.
This is not governance. It is self-regulation presented as governance. And self-regulation, as the history of technology governance demonstrates, reliably fails when the incentives of the regulated diverge from the interests of the governed. The enforcement gap is not a technical problem to be solved by better auditing tools. It is a power problem that requires structural intervention.
Part Four: Pathways to AI Sovereignty
If the analysis above seems bleak, it is because the power asymmetries in AI are real, structural, and not addressable by the governance approaches currently on the table. But the TEE Method™ is not designed to diagnose without prescribing. It provides a framework for identifying intervention points where sovereignty can be reclaimed.
Pathway 1: Compute Sovereignty
The most direct pathway to AI sovereignty is control over compute infrastructure. Nations and institutions that invest in domestic compute capacity — whether through state-funded GPU clusters, regional compute cooperatives, or sovereign cloud infrastructure — reduce their dependence on external providers and gain the ability to train and run models on their own terms. This is expensive, but the cost of dependence is higher.
Key actions: Invest in national and regional compute infrastructure. Establish compute access as a strategic resource, not a market commodity. Develop sovereign cloud capabilities for sensitive government and institutional AI workloads.
Pathway 2: Model Sovereignty
Control of foundational models does not require training frontier models from scratch — a prohibitively expensive undertaking for most nations. Model sovereignty can be achieved through fine-tuning open-weight models on locally relevant data, developing domain-specific models for critical sectors (healthcare, agriculture, public administration), and building evaluation frameworks that reflect local values and priorities.
Key actions: Invest in open-weight model ecosystems. Develop local fine-tuning and alignment capacity. Create national evaluation frameworks that measure what matters for domestic contexts, not just what global benchmarks measure.
Pathway 3: Governance Sovereignty
Governance sovereignty means developing the capacity to set rules for AI within one’s jurisdiction that reflect local values, priorities, and risk appetites. It does not mean rejecting international standards — it means participating in their development, adapting them to local context, and maintaining the capacity to diverge when standards conflict with local interests.
Key actions: Build domestic AI governance expertise. Invest in regulatory capacity, including technical auditing capabilities. Develop procurement frameworks that require sovereignty protections. Participate actively in international standards development with adequate resources and representation.
Pathway 4: Strategic Sovereignty
Strategic sovereignty is the capacity to decide which AI dependencies are acceptable and which are not. It recognises that complete independence in AI is impossible for most nations — the question is not whether to depend, but how to manage dependence strategically. Strategic sovereignty requires the ability to assess the sovereignty implications of AI adoption decisions, negotiate terms that protect core interests, and maintain the capacity to switch when dependence becomes unacceptable.
Key actions: Conduct sovereignty impact assessments for all major AI procurement decisions. Develop diversification strategies that reduce reliance on single providers. Establish contractual protections — data sovereignty guarantees, portability requirements, audit rights — in AI procurement agreements.
“AI sovereignty is not about building everything yourself. It is about maintaining the capacity to decide — which dependencies to accept, which capabilities to develop, and which standards to follow. Sovereignty is the ability to say no. Everything else is administration.”
— TEE Method™, SOVEREIGN (2026)
The Question That Will Not Be Answered by Silence
The uncomfortable question at the heart of AI governance is not a technical question. It is not a regulatory question. It is a power question: who decides, and by what authority do they decide?
The current answer, inconvenient as it may be, is that a small number of private organisations — concentrated in a small number of jurisdictions — exercise operational governance over the AI systems that increasingly govern the rest of the world. Ethics frameworks, transparency requirements, and safety protocols address the symptoms of this power concentration. They do not address the concentration itself.
The organisations that control AI infrastructure, models, platforms, and standards are not necessarily malevolent. Many are genuinely committed to responsible AI development. But good intentions do not alter power structures. The question is not whether the controllers of AI power are benevolent. It is whether the governed have any meaningful say in how that power is exercised.
The TEE Method™ does not offer a comfortable answer to this question. It offers a framework for asking the question clearly, analysing the structures that produce the answer, and identifying the points at which sovereignty can be reclaimed. The answer will not be found in another ethics guideline or a new regulatory proposal. It will be found in deliberate, structural interventions that redistribute the capacity to decide — from the few to the many, from the private to the public, from the concentrated to the distributed.
The uncomfortable question will not be answered by silence. It will be answered by sovereignty — or by its absence.
◆ The One Question ◆
If the AI systems that govern your institutions are controlled by organisations you did not choose, running on infrastructure you do not own, using standards you did not shape — are you sovereign, or are you a tenant in someone else’s architecture?
This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? — a 101,000-word investigation into AI governance, digital sovereignty, and the TEE Method™.
Tonisha Tagoe advises on AI governance, sovereignty strategy, and technology procurement.