Table of Contents
AbstractThe concept of ‘AI sovereignty’ has achieved remarkable currency in national security and technology policy circles. Yet the term conceals a fundamental ambiguity. Sovereignty can be proclaimed through legislation and strategy documents while remaining structurally hollow in the absence of indigenous computational infrastructure, training data autonomy, and domestic model development capacity. This article argues that declaratory AI sovereignty — asserting national control over AI through governance frameworks alone — constitutes a category error with direct consequences for national security and technological leadership. Drawing on comparative evidence across five dimensions — compute, data, model, regulation, and partnership — it shows that middle powers and emerging economies occupy a structurally distinct position: high in regulatory ambition, shallow in infrastructure depth. Closing this gap ultimately requires infrastructure investment, political will, and international redistribution of AI capacity that no existing framework has yet achieved.
1. Introduction
Artificial intelligence has become a strategic asset of the first order. Governments worldwide have published national AI strategies, established dedicated authorities, enacted regulatory frameworks, and made significant public investments, many under the banner of ‘AI sovereignty’: the idea that a nation should control its own AI capabilities rather than depending on foreign systems, firms, or governments for technologies that increasingly shape economic productivity, military capability, and national security.
The stakes are concrete. A government that depends on foreign AI companies for its own national-language processing capabilities is structurally exposed at a point of maximum sensitivity. A defence establishment that relies on AI systems whose training data and model architecture are controlled abroad faces adversarial risks that no domestic policy framework alone can mitigate. A cyber security apparatus that cannot audit the AI tools it deploys cannot be confident those tools are free of vulnerabilities, biases, or backdoors embedded at the design stage. And a state that integrates foreign AI systems into its critical infrastructure without understanding those systems’ failure modes is making a security bet whose terms it does not control.
Yet sovereignty can be declared without being achieved. A state may enact comprehensive AI legislation while running on foreign cloud infrastructure. It may establish a national AI authority while depending entirely on foundation models it did not train. It may assert data sovereignty while its most critical datasets sit on servers it does not own and cannot inspect. This gap between declaratory sovereignty and operational sovereignty is the central concern of this article. Its implications for national security, defence planning, and technological leadership are both underanalysed in the academic literature and urgently consequential for policy.
2. Two Kinds of Sovereignty: An Analytical Framework
‘AI sovereignty’ is used in at least four distinct ways in contemporary policy discourse: regulatory sovereignty (the capacity to govern AI systems deployed within a territory through law and regulation); computational sovereignty (control over the hardware and energy infrastructure on which AI runs); data sovereignty (control over the training datasets from which AI capabilities are derived); and model sovereignty (the capacity to develop and maintain foundation models domestically). These are not interchangeable, and conflating them produces governance frameworks that feel sovereign while remaining structurally dependent.
The Goswami (2024) maturity model disaggregates sovereignty into five operational levels: basic regulatory capacity; dedicated institutional infrastructure with real budgetary authority; data governance architecture including localisation regimes and federated access mechanisms; domestic model development capacity; and compute sovereignty through indigenous or reliably allied semiconductor and cloud infrastructure. States operating at levels one and two — which describes most of the world, including many states with sophisticated-sounding AI strategies — frequently describe themselves as AI-sovereign. But their exposure to unilateral decisions by foreign firms and governments remains structurally unreduced.
For national security analysts, this distinction maps directly onto risk exposure. Al Mansoori (2025) identifies three specific security risks that follow from this misperception: supply chain exposure, audit incapacity, and dependency as leverage — where foreign control of critical AI infrastructure creates implicit coercive potential that constrains policy choices even when never exercised. This yields four ideal types: governance leaders (high ambition, deep infrastructure: the US, China); governance aspirants (high ambition, shallow infrastructure: most middle powers and emerging economies); infrastructure holders without governance; and governance outsiders. The governance aspirant position is structurally unstable from a national security perspective, and its consequences are the focus of the regional evidence that follows.
3. Regional Evidence: The Gap in Practice
Africa — Governance Architecture in a Compute Desert
African governments are developing AI governance frameworks at speed, but those frameworks govern systems they do not control, on infrastructure they do not own, producing value that largely accrues elsewhere. Kenya is instructive: M-PESA’s dominance of domestic payments, processing over 40% of GDP by 2024, demonstrates that public digital infrastructure investment can generate transformative, security-relevant outcomes. But the AI models used by Kenyan firms and government agencies are trained in California and Shanghai. African defence and security establishments that deploy AI tools built on foreign infrastructure operate those tools under conditions they cannot fully audit, and the governance frameworks they enact do not change that structural reality.
South Asia — The Limits of Infrastructure Aspiration
India presents the strongest counterargument to the dependency framing, and thereby illustrates its limits most sharply. India Stack, Aadhaar, UPI, and the Data Empowerment and Protection Architecture form the most sophisticated domestically developed digital public infrastructure outside the US and China. The BharatGen initiative for indigenous Indian-language foundation models represents a direct attempt at operational sovereignty, motivated by a genuine security concern: India’s twenty-two constitutionally recognised languages are systematically underrepresented in global foundation models. Yet even India remains dependent on NVIDIA-manufactured accelerator hardware, a dependency that US chip export controls can constrain unilaterally. No domestic governance framework changes this.
“States that mistake sophisticated governance declarations for achieved sovereignty will plan their national security architecture on foundations that do not exist.”
Southeast Asia and Europe — Governance Without Control
Singapore’s AI Verify governance testing toolkit has been adapted by multiple Southeast Asian states and represents genuine regional governance leadership. But an organisation that deploys a foreign-built large language model and uses AI Verify to test its outputs has achieved accountability procedures, but not sovereignty. For defence and security applications, this asymmetry represents a fundamental constraint on operational security assurance. The EU AI Act illustrates the same tension at the highest level of regulatory sophistication — the most ambitious exercise of regulatory extraterritoriality yet enacted. Yet European AI systems deployed in security contexts operate on American cloud infrastructure, whatever European governance frameworks assert. The GAIA-X initiative, designed to build a federated European cloud, produced governance standards and certification frameworks; actual cloud infrastructure usage in Europe remains predominantly American. Regulatory sovereignty and infrastructure sovereignty are not the same thing.
Latin America — The Infrastructure Lesson
Brazil’s Pix payment infrastructure, developed by the Banco Central do Brasil and adopted by over 140 million users by 2024, demonstrates that public infrastructure investment can reduce structural dependency in a critical domain. The lesson is not that the Pix model transfers readily to AI compute infrastructure — the capital requirements and technical complexity are far greater. But it demonstrates that infrastructure sovereignty, where deliberately built, creates governance options that regulation alone cannot produce.
4. Four Failure Modes of Declaratory Sovereignty
- Regulation without leverage — comprehensive AI governance frameworks provide limited purchase on foreign developers’ behaviour without market scale or infrastructure control (Roberts et al., 2024).
- The accountability gap — when frameworks govern exclusively foreign infrastructure, requirements depend on compliance the infrastructure owner can always withdraw.
- Cooperation asymmetry — international AI governance frameworks are designed primarily by governance leaders; middle powers’ participation tends to be consultative rather than constitutive (Ishkhanyan, 2025).
- Openwashing and verification failure — strategic use of open-source rhetoric while retaining control over consequential components creates verification problems no current international body is equipped to address.
5. Conclusion: Governance Realism and the Infrastructure Imperative
Governance frameworks are not useless. The capacity to set terms for AI deployment within a territory has genuine value even without infrastructure sovereignty. Kenya’s regulatory sandbox has produced real governance learning applicable across the region. Singapore’s AI Verify has shaped practice across Southeast Asia. Brazil’s data protection law has altered the behaviour of foreign firms in ways that bear directly on national data security. Governance leadership is achievable before infrastructure sovereignty, and it has meaningful security co-benefits.
But governance leadership without infrastructure sovereignty is bounded in ways that require honest acknowledgment, especially in national security contexts. It cannot compel access to model internals for security auditing. It cannot prevent unilateral service withdrawal from AI systems integrated into critical infrastructure. It cannot ensure that AI systems used in defence contexts reflect the operational requirements of the deploying state rather than those of the state where the systems were built. And it cannot generate the economic rents from AI development that would fund the infrastructure investment making subsequent governance genuinely effective.
The governance aspirant condition is not a transitional state through which all countries will inevitably pass. It is a structural position in the international political economy of AI, maintained by capital concentration, network effects, and talent geography that reinforce existing advantage. Some states will make meaningful progress: India’s trajectory toward compute and model sovereignty is credible on a decade-long horizon; Brazil has demonstrated with Pix that deliberate public infrastructure investment can reduce dependency in critical domains. But for most middle powers and emerging economies, the infrastructure path to operational sovereignty is measured in decades and requires resources that neither domestic budgets nor current international cooperation frameworks reliably provide.
The central strategic implication is this: states that mistake sophisticated governance declarations for achieved sovereignty will plan their national security architecture on foundations that do not exist. When AI systems are integrated into defence planning, intelligence analysis, critical infrastructure management, and cyber security operations under the assumption of control that is not operationally real, the consequences of that misperception can be severe and can materialise precisely when the stakes are highest.
Addressing this requires more than better governance frameworks. It requires political will to invest in public AI infrastructure, financial resources at a scale that demands international cooperation, and redistribution of AI development capacity that no existing multilateral framework has yet achieved. Acknowledging these problems honestly, rather than substituting declaratory sovereignty for the real thing, is the indispensable first step toward policies that serve the actual security needs of nations rather than their preferred self-image.
“Acknowledging these problems honestly, rather than substituting declaratory sovereignty for the real thing, is the indispensable first step.”
References
- Human Rights Watch (2023)
- UN Committee on the Rights of the Child (2022)
- UN Special Rapporteurs (2022)
- Freedom House, Freedom in the World 2024
- Congressional-Executive Commission on China, Annual Report 2023
- 116th U.S. Congress, Tibetan Policy and Support Act of 2020.
About the Author
Maya Sherman
maya.sherman.india@gmail.com
Submitted to Ignited Minds Today, Issue 2, June–July 2026. © Maya Sherman, June 2026.