hello@tonishatagoe.com Abu Dhabi · London · Accra · New York
AI Governance

Why AI Governance Frameworks Keep Treating Sovereignty as a Technical Parameter

<p>A regulatory sandbox for AI is launched with great fanfare. The sandbox tests technical safety, bias metrics, and robustness benchmarks. The participants are technology companies. The regulators are technology regulators. The civil society observers are invited to comment on the technical reports. The governance question — who decides what safety means for this society — is never asked. The sandbox is technical. Sovereignty is absent. The dominant paradigm in AI governance is technical risk management. Identify the hazard, measure the probability, mitigate the impact, monitor the residual. This paradigm works for engineering. It fails for sovereignty.</p>

THE SCENARIO

A regulatory sandbox for AI is launched with great fanfare. The sandbox tests technical safety, bias metrics, and robustness benchmarks. The participants are technology companies. The regulators are technology regulators. The civil society observers are invited to comment on the technical reports. The governance question — who decides what safety means for this society — is never asked. The sandbox is technical. The sovereignty is absent.

Why do AI governance frameworks keep treating sovereignty as a technical parameter?

The dominant paradigm in AI governance is technical risk management. Identify the hazard, measure the probability, mitigate the impact, monitor the residual. This paradigm works for engineering. It fails for sovereignty. Sovereignty is not a risk to be managed. It is a capacity to be built. The entity that treats sovereignty as a technical compliance exercise will build technical compliance mechanisms that satisfy auditors while the governance authority drains away. The question is not whether the system is safe. The question is who defines safety.

The TEE Method — Test, Evaluate, Exit — is not a checklist. It is an architecture for sovereignty. It does not tell you what to do. It gives you a structure for deciding for yourself.


Part One: Understanding the Landscape

The progression from AI governance challenge to a structural governance condition occurs through a subtle systematic mechanism. It begins with framing: the issue is presented to decision makers as a technical implementation challenge or a commercial efficiency opportunity rather than a sovereignty decision. The TEE Method rejects this framing categorically. This is a sovereignty issue that has AI governance implications, not an AI governance issue that has sovereignty implications. The distinction is structural and determinative. It determines whether the entity approaches the challenge from its governance red lines or from its operational wish list. It determines whether the chief negotiator is a technical specialist optimising for feature sets or a governance official optimising for autonomy. It determines whether the governance provisions are drafted by technical specialists who understand feature sets or by sovereignty experts who understand the architecture of technological dependency. The choice of framing is the choice of outcome. The entity that frames sovereignty as a technical problem will receive a technical solution that solves the wrong problem. The entity that frames sovereignty as a governance architecture will build the institutional capacity to govern whatever technology arrives next.

The specific provisions that drive sovereignty erosion in AI governance follow a consistent pattern observed across multiple jurisdictions. They are presented as facilitators: efficiency, modernisation, compliance, standardisation, investor protection, consumer protection, innovation promotion, market access. Each of these provisions is legitimate in isolation. Together, they form an architecture that transfers governing authority from the entity that should govern to the entities that drafted the standards. An international advisory body recommends that nations adopt a particular AI safety framework. A foreign technology consortium implements the framework as a product standard. A national regulator adopts the recommendation as a domestic regulatory requirement. The foreign consortium that wrote the standard now governs what compliance looks like inside the adopting nation. The nation has legislated its own governance out of the picture. Every mechanism of the transfer operates through legitimate procedural pretences, which is precisely why the transfer goes undetected.

A Gulf Cooperation Council state adopted a foreign AI governance framework to signal regulatory maturity to international investors. Five years later, the government attempted to impose data residency requirements on AI deployments operating under that framework. The compliance architecture, built around the international standard, made the requirement architecturally incompatible. The governance framework had been designed for open global deployment. It had never been designed to accommodate a sovereign data residency constraint. The investment was domestic. The governance architecture was not. A legislative reversal now requires rebuilding the entire domestic AI compliance ecosystem from scratch. Sovereignty is not something that can be incrementally improved after a system is deployed. And neither is the decision to accept a governance framework drafted by a foreign entity.

The structural mechanism operates through the semantic framing of AI governance itself. When regulators speak of risk management frameworks, they implicitly accept the premise that AI is a product to be deployed safely rather than a governing infrastructure to be controlled. When industry bodies speak of responsible AI, they define responsibility in operational terms rather than authority terms. Safe for whom. Compliant with whose standard. Audited by which body. These questions go unaddressed because the framing precludes the sovereignty question before it encounters governance. The EU AI Act’s self-assessment obligations assign conformity assessment to the manufacturer. The assessment asks whether the system meets the regulatory requirements. It does not ask who wrote those requirements. It does not ask whether the adopting state had governance authority over the standard’s drafting. It treats governance authorship as irrelevant to governance compliance. The result is compliance with governance by another entity dressed in the language of sovereignty.


The Seven Layer Stack Audit

The sovereignty erosion mechanism unfolds across seven layers. Each layer represents a governance allocation point. Each layer is independently addressable. Together, they determine the entity’s genuine sovereignty position.

Layer Governance Authority Sovereignty Score (1–5) Critical Dependency
Layer 1: Hardware & Compute GPU firmware governed by NVIDIA; domestic data centre management through foreign-licensed software; cloud orchestration through global compute grid 2 NVIDIA firmware: no domestic override; cloud access policy determined by foreign vendor
Layer 2: Foundational Models & Training Data Most capable models developed abroad; API access governed by foreign terms of service; model weights and training data subject to foreign jurisdiction 1 Foreign model API: governing access can be revoked or modified unilaterally
Layer 3: API & Middleware Azure OpenAI and Google Vertex AI impose foreign governance on local deployment; NVIDIA GPU orchestration layer controlled by foreign firm 1 NVIDIA GPU orchestrator + Azure OpenAI governance layer
Layer 4: Platform & Application Active domestic cloud projects (Khazna, stc Ground); limited indigenous model capability; governance embedded through foreign orchestration layers 2 Domestic infrastructure with governance vesting in foreign orchestration layer
Layer 5: Data Architecture & Sovereignty Physical residency in domestic infrastructure; contractual data governance clauses; US CLOUD Act creates foreign legal jurisdiction; PDPL adequacy delegated to regulator 2.5 CLOUD Act override: foreign legal system with greater jurisdiction than domestic data governance
Layer 6: Governance & Regulatory Framework PDPL and NCA ECC provide domestic governance foundations; NESA IAS and CBUAE AI Guidelines incorporate international standards; NIST adoption as governance reference 3 NESA IAS adoption: foreign technical standards ratified as domestic regulatory requirements
Aggregate Sovereignty Score Multi-layer structural dependency: compute, models, and middleware governed abroad; regulatory layer with domestic foundations incorporating foreign governance 2.4/5 CRITICAL FAILURE: Layer 2 (Foundational Models) structurally complete governance transfer; Layer 3 (API & Middleware) simultaneously complete. No domestic reversal mechanism

An NVIDIA firmware update to a domestically deployed compute environment operates without domestic governance consent. The cloud compute allocation policy determining which workloads receive priority is governed by a foreign provider’s business logic. A foundation model API revocation clause can terminate access to the primary AI capability of a domestic institution within thirty days. The domestic compute investment creates the appearance of sovereignty while the governance architecture above it operates entirely outside domestic authority. The entity’s national AI strategy has addressed compute hardware investment without addressing governance of the firmware layers that make compute operational. Addressing hardware investment while leaving firmware governance intact is like building a national administrative building while leasing the locks from a foreign firm.

The sovereignty risk at the foundational model layer operates through API governance. A foreign provider’s model API terms of service constitute a governance document that determines access conditions, use restrictions, data handling obligations, audit permissions, and termination rights. When a domestic institution deploys through that API, it is governing its AI capability through a governance document written by a foreign entity. The ISO/IEC 42001 self-assessment provision that the domestic regulator has mandated does the vendor’s governance assessment or the vendor’s governance assessment review the vendor’s governance assessment. The governance of the assessment is conducted by the vendor. The governance audit is a governance fiction.

The PDPL adequacy mechanism provides a domestic governance mechanism that produces a foreign governance outcome. Article 14 of the UAE’s PDPL permits international data transfers to jurisdictions the regulator designates as providing an adequate level of data protection. The designation is made by the regulator without parliamentary scrutiny. The entity designated as adequate is not subject to domestic governance. The domestic governance process provides governance fiction, not governance fact. A data transfer to an adequate jurisdiction is governed by the adequate jurisdiction’s governance. The domestic entity that made the transfer has transferred governance over its data to a foreign governance system without a legislative decision to do so. This is not a legal technicality. It is the mechanism through which data sovereignty is routinely transferred.


Part Two: The Sovereignty Test Matrix

The sovereignty erosion mechanism is not a single event. It is a structural condition that the specific provisions create across the entity’s operation. The Test Matrix maps this condition across the regulatory and technological landscape, identifying for each domain where sovereignty is genuinely held, where it is claimed but not exercised, and where it has been transferred without the entity’s explicit recognition. The Critical layer in any sovereignty audit varies, but it is the layer the vendor guards most carefully: proprietary model architecture, cloud provider API access policy, CDN routing governance infrastructure. The governance architecture at the Critical layer determines the governance architecture of the entire stack. A single layer operating at sovereignty score one or two is a sovereignty failure that propagates governance transfer across every layer above it. Governance at layer five cannot securely govern governance assessed at layer two.

Does domestic AI regulation exercise indigenous governance authority, or does it delegate governance to compliance with international frameworks written by foreign technology vendors? Does the entity retain the structural authority to reject a technical standard without destroying indigenous AI capability, or has the adoption of the standard made rejection structurally impossible? Does the regulatory framework contain a domestic override mechanism for any international obligation it adopts, or is compliance to foreign standards the ceiling of domestic governance authority? Can the entity demonstrate legislative scrutiny of every foreign governance provision it has adopted, or has that process been reduced to administrative adoption? Can a senior government official in the relevant ministry explain the governance architecture of the AI compliance framework currently in force, or is governance knowledge concentrated in a small group of consultants trained in the foreign standard? Does the entity’s own AI deployment operate through API terms the entity did not negotiate, on infrastructure whose governance the entity does not control, with data whose legal protection is governed by a foreign jurisdiction? Answers to these questions are binary. The entity either holds governance authority or it does not. The TEE Method makes this determination administratively tractable.


Part Three: Red Flag Checklist

If three or more of the following apply, AI governance sovereignty is not a future risk — it is an existing condition.

  1. National AI strategy mandates compliance with international standards (ISO/IEC 42001, IEEE 7000 series) not developed or ratified by domestic institutions.
  2. AI regulation delegates conformity assessment to the vendors whose AI systems are being assessed — self-assessment as the primary governance mechanism.
  3. Domestic AI governance institutional capacity is trained by the vendors who profit from the compliance framework being implemented.
  4. Cloud contract termination clauses are treated as sovereignty protections rather than recognition that the contractual relationship does not constitute governance ownership.
  5. Data residency requirements exist without a legal framework that overrides foreign jurisdiction clauses in vendor data processing agreements (US CLOUD Act extraterritorial reach).
  6. National procurement rules mandate technical specifications that mirror a foreign AI vendor’s product architecture rather than independently developed domestic standards.
  7. AI model access for the domestic institution depends on API terms of service written by a foreign provider and unilaterally modifiable without domestic recourse.
  8. The NESA IAS cybersecurity framework for AI systems in the UAE is adopted from international standards without domestic governance override provisions — governance transfer through regulatory adoption.
  9. PDPL Article 14 adequacy determination for data transfers is delegated to the regulator without parliamentary oversight or appeal process — governance over data sovereignty held by the regulator’s designation, not by legislative decision.

Part Four: Phased Implementation Framework

Phase Timeframe Key Actions
Assessment Weeks 1-4 Complete Seven Layer Stack Audit of the full AI governance ecosystem; produce Sovereignty Test Matrix scores per layer; identify sovereignty traps via the Red Flag Checklist; publish initial Sovereignty Score with governing authority mapping
Strategic Planning Months 2-3 Develop withdrawal protocols for the three highest-risk governance dependencies; identify and pilot domestic alternatives (Khazna, stc Ground, Jais, AceGPT where appropriate); begin knowledge transfer programmes to reduce governance knowledge concentration; negotiate contractual protections including data portability, transparent pricing, genuine exit provisions, and governance audit rights; form the Sovereign Governance Caucus
Sovereign Transition Months 4-6 Execute Phase 1 exit protocols; deploy domestic alternatives; establish domestic AI governance standards where none exist; conduct parliamentary review of all international standard adoption processes; develop domestic certification regime as complement to — not replacement for — international standards
Institutionalisation Ongoing Quarterly sovereign governance exercises; staff training in TEE Method methodology; national AI sovereignty register tracking dependency changes; annual sovereignty scorecard with measurable improvement targets; bi-annual strategic adjustment cycles; legislative sovereignty review requirement for all future international standard adoptions

The political economy of governance transfer rewards the architects of its perpetuation. The foreign compliance framework was deployed competitively. The domestic institution that adopted it was rewarded for speed and cost. The political cost was invisible. Now the institutional knowledge required to operate the foreign framework is concentrated in a small cadre of domestic specialists trained on the foreign standard. Those specialists have professional interests aligned with the continuation of the framework that certified their expertise. The ministry that might challenge the framework is staffed by people whose career credibility depends on its credibility. Governance rehabilitation requires changing an incentive structure that has been operating for years. It requires political infrastructure that does not exist in the current governance architecture.

Every adoption of a foreign AI governance framework without a completed Seven Layer Stack Audit is a future governance reconstruction project. The political cost of that reconstruction grows geometrically with the number of institutions that have adopted the framework, the complexity of the systems that depend on it, and the concentration of governance knowledge in the foreign framework’s governance discipline. The decision to construct sovereign governance must be made before the governance dependency becomes structurally entrenched. If the decision is delayed until the governance dependency has been built into the compliance infrastructure of every major domestic institution, the cost of reversal approaches the cost of rebuilding the AI ecosystem. The TEE Method provides the format for governance construction. The phased implementation provides the political pathway. The political will must be supplied by the entity that exercises governance.

Indonesia’s data localization reversal — where a constitutional court overturned a data localization law because the government had not demonstrated necessity — illustrates the fragility of sovereignty arguments that depend solely on legislative will without governance architecture. Chile’s court challenge to Microsoft data access under the CLOUD Act and Brazil’s LGPD mechanism creating regulatory alignment facilitating global data transfers demonstrate that sovereignty governance is now being contested at multiple governance layers simultaneously. The Critical layer for the sovereignty failure is the governance layer that the vendor guards most carefully: API access governance, API terms governance, or model governance. The Critical layer governs the governance of the stack. Exiting foreign governance at the Critical layer requires replacing the Critical layer with domestic governance. Every Critical layer access maintained under a foreign contract is an ongoing governance exposure requiring either contractual remediation or a genuine exit path.


The Closing Question

The question that opens this analysis is not a rhetorical device. It is the defining structural question of the AI governance era. AI governance — who determines what AI systems do, who sets the standards, who audits compliance, who holds governing authority over the technology — cannot be decided by the entities that build AI systems and write international standards. It must be decided by elected governments and accountable institutions. The two paths diverge at the moment of first adoption. The path toward governance by another entity is always framed as a practical interim measure or a market reality. Each step becomes structurally entrenched. Each market reality becomes a governance reality. Each efficiency mechanism becomes permanent governance architecture. The path is easy. The reversal is not.

The sovereign path is also incremental. But each step expands governance capacity rather than contracting it. Each measurement becomes a governance checkpoint. Each exit mechanism becomes a genuine architectural alternative. It requires institutional investment that produces no visible product. It requires political patience for a return spanning multiple electoral cycles. But it produces the one outcome that is indispensable: governance over the entity’s own digital future.

The entity that cannot demonstrate governance decisions at every layer of its stack is not sovereign. The entity that has sovereignty in governance language but not in governance architecture is not sovereign. The entity that defines sovereignty as compliance with a governance framework audited by a foreign vendor is not sovereign. Sovereignty is the capacity to govern. Not in language. In architecture. In layers. In every governance decision that matters. The TEE Method gives the entity that capacity. The Seven Layer Stack Audit gives the entity the evidence. The phased implementation gives the entity the path. The rest is the entity’s governance choice. It is not choosing between sovereignty and compliance. It is choosing between sovereignty and a contract that governs in the language of sovereignty while exercising governance from outside the domestic governance architecture. The closing question is whether the governance architecture currently in force is genuinely sovereign.

The answer determines not only the sovereignty position of the entity but the kind of governance authority it will exert over its digital future. The binary is acceptance or agency.


This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? by Toni Shatagoe.

Keep Reading

Related Articles

Get in Touch
LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…

LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…