Skip to content
TiMiNa
All essays
The Agentic Firm · Essay 07

AI Sovereignty: the illusion nations are buying and the asset firms are ignoring

By Misagh Akhondzad/34 min read
AI sovereigntyGeopoliticsVendor riskOpen weights

Every argument about national dependency on foreign AI applies, clause for clause, to your company’s dependency on its AI vendors. Nations at least have armies, treaties and trade negotiators. Your company has a subscription agreement and a hope.

Prologue

The letter

On the evening of June 12, 2026, the US Commerce Department sent a letter that did more to educate the world about AI sovereignty than a decade of policy papers.

The letter directed Anthropic to deny foreign nationals access to its two most capable models, citing national security concerns after a suspected compromise of the models’ cyber safeguards. Within days, according to reporting at the time, access was suspended even more broadly while the company and the government worked out what the order actually required. Allied governments, who had spent two years being told that the American AI stack was the safe choice, discovered that their access to frontier intelligence was contingent on the signature of a US commerce secretary. Austria’s government wrote to Brussels urging the EU to explore hosting the company inside Europe. US officials floated a “trusted partners” carve-out to let friendly nations back in — which is another way of saying that access to the most capable cognition on earth had just become an explicit instrument of foreign policy, with a list.

Sit with what happened, because it is the whole subject of this essay compressed into one week. Banks, manufacturers, hospitals and government agencies across dozens of countries had built workflows, products and in some cases critical operations on top of a specific machine intelligence. Then a letter arrived, and the intelligence went away. No invasion, no embargo, no sanctions regime, no notice period. A capability that organizations had begun to treat as infrastructure revealed itself to be something closer to a diplomatic privilege.

Intelligence, once purchased, does not behave like a possession. It behaves like a relationship — and relationships have politics.

The deeper lesson is not that the United States did this. It is that it could, and that everyone who was surprised had been running their company, or their country, on an assumption they had never examined.

This essay is about those politics, at both of the levels where they now operate. The first level is the one everyone discusses: nations racing to build sovereign compute, sovereign models and sovereign clouds, at a pace that will push global sovereign AI spending past 100 billion dollars this year by most estimates. The second level is the one almost nobody discusses with any rigor: the firm. Because here is the uncomfortable symmetry the June letter exposed — every argument about national dependency on foreign AI applies, clause for clause, to a company’s dependency on its AI vendors.

Along the way I will be unfair, in the specific sense that I will judge sovereignty programs by what they produce rather than what they announce. That standard will be hard on Brussels, hard on the Gulf, hard on the sovereign cloud industry, and hardest of all on corporate AI strategies — including some that TiMiNa’s own clients were running eighteen months ago. It is meant to be. A concept this important deserves better than the theater currently performed in its name.

Part I

What sovereignty is, and the three things it is not

Words that appear in every keynote eventually stop meaning anything, so let us rebuild this one from the ground. Sovereignty, in its classical political sense, is the capacity to decide: to set your own rules within your own domain and to have those decisions stick.

The terms might change because of an export order, a price increase, a licensing dispute, a war, an acquisition, a model deprecation or a values conflict. Sovereignty is not tested on the days everything works. It is tested on the day the letter arrives, and it is measured by a single question: what can you still do, at what cost, the morning after?

That definition immediately disqualifies three impostors that dominate the current conversation.

THREE IMPOSTORSAutarkybuild everything yourselfanswers:can we make it all?Residencyput the servers on our soilanswers:where is the data?Regulationwrite the rules for itanswers:what may others do?SOVEREIGNTYwhat can you still do, at what cost, the morning after?it is not tested on the days everything works
Three impostors, and the question none of them answers

The first impostor is autarky, the fantasy of producing everything yourself. No nation on earth has AI autarky, including the United States, whose entire frontier rests on lithography machines from a single company in Veldhoven and advanced fabrication concentrated on an island ninety miles from the Chinese coast. Autarky is not just unachievable; pursuing it is actively harmful, because it burns finite resources replicating commodity layers instead of securing strategic ones. The 1970s oil shocks taught this lesson perfectly and everyone has forgotten it: the industrialized world did not respond to the 1973 embargo by all becoming oil producers. It responded with strategic reserves, diversified suppliers, the International Energy Agency, efficiency and alternatives. Energy security was achieved not by eliminating dependency but by designing it. Nobody drilled their way to sovereignty; they architected their way there.

The second impostor is residency, the belief that sovereignty is a question of where the servers are. This is the founding myth of the sovereign cloud industry, and it deserves more skepticism than it gets. A data center on your soil, running American silicon, serving an American model, operated under licenses that American law can reach, is not sovereignty. It is dependency with better latency and a flag on the building. The legal lineage is well established: the Schrems rulings and the CLOUD Act debates demonstrated years ago that jurisdiction follows corporate control and legal reach, not geography. Residency matters for specific compliance regimes, and it is genuinely decisive in defense, health and public sector procurement. But residency answers “where is the data,” while sovereignty asks who can change what I am able to do. Confusing the two is how governments end up celebrating facilities that a foreign export order can still switch off.

The third impostor is regulation, the belief that writing rules about a technology is a form of controlling it. Rules matter enormously, and I will defend Europe’s right to set them later in this essay. But regulating what others build is governance of consumption, not capability. A continent can write the world’s most sophisticated AI act and still discover, on a June evening, that its access to frontier intelligence depends on decisions made in Washington and San Francisco. The power to constrain is not the power to create, and only the power to create — or to credibly switch — gives the power to constrain any real leverage.

ComponentWhat it meansHow you know you have it
Exit capacityThe demonstrated, tested, priced ability to move to an alternative when the terms changeYou have rehearsed it and can state the days and the euros
Generative capacityOwnership of the assets that let you keep building capability regardless of which supplier sits underneathYour capability survives a change of supplier without a rebuild
Strip away the impostors and two components remain

Everything else is procurement with patriotic branding.

Part II

The sovereignty stack: seven layers, and the money is flowing to the wrong end

Intelligence is not one thing you can be sovereign over. It is a stack of dependencies, and each layer has its own geography, its own chokepoints and its own economics.

CAPITALLAYERCOMMOD.DEPREC.COMPOUNDS7 · Learning looptraces, evals, judgment6 · Applications & agentswhere cognition does work5 · Data & contextyour operational reality4 · Modelsfrontier and open weights3 · Computedata centers, cloud regions2 · Siliconlithography, fabs, accelerators1 · Energythe raw industrial inputTHE COERCION LINEthe uncoercible layers are the compounding layers — and the unfunded ones
The sovereignty stack — capital flows to the layers losing value fastest
LayerWhat it isWhere the power sits
1 · EnergyThe raw industrial input; AI turned electricity back into strategyFrance leverages nuclear, the Gulf leverages sun and gas; France plans over a million GPUs by 2030 under a €109bn program, which is at bottom an energy play
2 · SiliconLithography, fabrication, accelerators and the software ecosystem written against themOne Dutch company, one Taiwanese fabricator, one American designer — three firms, three points of failure, three instruments of statecraft
3 · ComputeData centers, cloud regions, the capacity to train and serve at scaleThe US holds roughly 60–75% of frontier-relevant capacity; all of Europe perhaps 5–10%
4 · ModelsThe frontier, and the open-weight ecosystem beneath itA two-country club at the frontier — but the layer whose sovereignty economics just inverted
5 · Data & contextWhere generic intelligence becomes specific capabilityNaturally distributed and impossible to export-control; chronically underfunded because data programs produce no ribbon-cuttings
6 · Applications & agentsWhere cognition actually does work in the economyWhere nearly all the economic value will settle; dominated by no one, and absent from national programs almost everywhere
7 · The learning loopTraces, evaluations, codified judgment — the machinery by which use becomes capabilityNations do not measure it; most firms do not know it exists; it is where sovereignty will actually be decided
The seven layers, walked from the bottom

Layer three is where sovereign money is currently pouring. The EU’s InvestAI initiative aims to mobilize 200 billion euros; its gigafactory program envisions facilities of roughly 100,000 advanced chips each, and 76 expressions of interest arrived for the first five sites. India’s national AI mission has assembled tens of thousands of GPUs. The UK launched a 500 million pound sovereign fund with the declared ambition of being an “AI maker, not an AI taker.”

Layer four contains the decade’s most important structural surprise, which is that its sovereignty economics have inverted. Open-weight models, released mostly by Chinese labs and a handful of Western ones, now sit close enough to the frontier that by mid-2026, Chinese open-weight models accounted for a majority of token traffic among top models on the largest independent routing platform — up from under 2 percent in late 2024. Model capability, the layer everyone assumed would be the ultimate chokepoint, is becoming the most portable layer in the entire stack. Hold that thought; the whole strategic argument turns on it.

The layers are commoditizing from the middle outward, and public money is flowing to precisely the layers losing strategic value fastest.

Compute, layer three, is a depreciating asset with a three-to-five-year hardware half-life, purchasable by anyone with capital, and stranded without the talent and workloads to use it. Models, layer four, are commoditizing in real time through open weights. Meanwhile layers five through seven — the layers that are firm-specific, nation-specific, compounding and impossible to export-control — receive rounding-error attention. The sovereignty race, as currently run, is a contest to own the layers that will matter least, funded by the political appeal of announcing the layers that photograph best.

Part III

Four sovereignties: how the powers are actually playing

Strategy documents describe intentions. Behavior reveals doctrine. Here is what each major player is actually doing, judged by the standard set above.

DIFFUSION — influence by giving capability awayCONTROL — influence by withholding capabilitySTACK OWNED →CHINAinfluence via unrestrictable artifactsUNITED STATESleverage via indispensable servicesEUROPErules for capability it does not holdMIDDLE POWERSself-host, diversify, stay unalignedfull-stack sovereignty is a two-member club — everyone else is designing dependency
Four doctrines, judged by behavior rather than strategy documents

The American doctrine: the stack as empire, and the contradiction inside it

American strategy is the most coherent and the most internally conflicted. The coherent part: export the full American stack — chips, cloud, models, applications — to as much of the world as possible, so that global AI runs on American rails, generates American revenue and embeds American leverage. It is the playbook that worked for the dollar, for the internet and for the cloud, executed with the confidence of a nation that holds most of layers two through four.

The conflicted part detonated in June. A stack strategy requires the world to trust the stack, while a security strategy requires the ability to deny the stack to adversaries — and the machinery of denial cannot be built without teaching allies that it could one day point at them.

WhenWhat was controlledWhich layer
2022Advanced chips2 · Silicon
2023Manufacturing equipment2 · Silicon
2025Cloud access and diffusion frameworks3 · Compute
June 2026A specific named model version, restricted by the nationality of its user4 · Models
Four years of controls, climbing the stack rung by rung

Each rung was individually defensible. Cumulatively they converted the American AI stack from infrastructure into leverage, in full view of every foreign government and CFO deciding what to build on next. Henry Farrell and Abraham Newman gave this dynamic its name years ago — weaponized interdependence: the same network centrality that makes a power indispensable makes it capable of coercion, and every act of coercion motivates the network to route around the chokepoint. The June order was weaponized interdependence applied to cognition itself, and the routing-around began within the week.

The early evidence on whether the denial arm even works should trouble Washington more than it seems to. Three years of chip controls did not produce a durable Chinese capability gap; by most serious assessments the gap narrowed, as Chinese labs, denied brute-force compute, were forced into efficiency innovations and then released the results openly. Model-level controls face a worse asymmetry: chips are physical, countable and hard to copy, while model capabilities leak through distillation, through open publication, and through the simple fact that intelligence, unlike uranium, teaches its recipients how to make more of it. America’s controls are strongest at the layer where its advantage is eroding and weakest at the layers where the future is being decided.

The Chinese counter-doctrine: openness as a weapon

China’s position was forced upon it and then, in one of the decade’s great strategic judo moves, turned into an offensive. Denied the top of the silicon stack, Chinese labs optimized ferociously for efficiency, closed most of the capability gap at a fraction of the training cost, and then did the thing no Western frontier lab dared: gave the models away. DeepSeek, Qwen, GLM, Kimi, MiniMax — an entire ecosystem of near-frontier intelligence, downloadable, modifiable, self-hostable, free.

0%25%50%75%100%majority thresholdunder 2%late 2024a majoritymid 2026endpoints measured · path indicativethe presumed ultimate chokepoint became the most portable layer in the stack
Chinese open-weight share of token traffic among top models, one independent routing platform

Understand what this achieves, because it is far more sophisticated than charity. Every developer who builds on Chinese open weights, every enterprise that self-hosts them for data control, every nation that fine-tunes them into a national model, is being handed exactly the sovereignty the American stack now visibly withholds: no API dependency, no export-order exposure, no foreign kill switch at the model layer. The June order was the greatest marketing event Chinese open weights ever received, and the traffic statistics show the world responding rationally.

Open weights are becoming China’s Belt and Road of cognition. The model costs nothing; the gravitational field it creates is the product.

Where America seeks leverage through indispensable services, China seeks influence through unrestrictable artifacts. The honest caveat: an open model you downloaded is genuinely yours at the model layer, but the ecosystem around it — the tooling, the successor models, the pace of releases — remains on Beijing’s timetable, and Chinese releases could stop, or fork toward Chinese standards, whenever strategy dictates. Free intelligence is not free of politics. It is politics conducted at a different layer.

Europe: the continent that owns a chokepoint and negotiates like it owns nothing

Now the hard audit, delivered with the affection of someone who lives here. Europe talks about sovereignty more than any other polity on earth and possesses less of it than its economy justifies. The numbers are brutal: mid-single-digit percentages of relevant training compute, no frontier lab at the true edge, its enterprises running overwhelmingly on American clouds and American models, its flagship gigafactory program mobilizing impressive sums that nonetheless purchase, as one analyst put it, not nearly enough compute at current frontier prices — into a supply chain where the relevant capacity through late 2026 was already sold before the programs were announced. Meanwhile the reflexive European instinct, to regulate first and build second, produced the AI Act years before it produced a single gigafactory, and the Act’s own timelines are already being reshuffled by omnibus amendments as the continent discovers the cost of governing a capability it does not possess.

And yet the standard bearishness on Europe misses two things, and the argument requires naming both.

First, Europe owns the single hardest chokepoint in the entire global stack and behaves as though it does not.ASML is not a European participation trophy; it is the physical precondition for every advanced chip on earth, a monopoly more absolute than anything America or China controls — and Europe has never once wielded it as leverage in AI negotiations, preferring to treat its crown jewel as a Dutch export success rather than a continental instrument. A polity that held that card and played it would negotiate frontier model access, compute allocations and technology transfer from a position no trade partner could dismiss. Europe’s problem is not that it lacks power. It is that it lacks the doctrine to use the power it has.

Second, Europe’s genuine assets sit precisely in the layers this essay argues will decide the game:the world’s second-largest advanced economy as a demand base, deep industrial data that no frontier lab can replicate, a credible open-weight champion in Mistral now building its own training and inference infrastructure from France to Sweden, and the regulatory gravity that, for all its costs, does set global defaults. A European strategy built on those assets — industrial data programs, aggressive procurement that steers demand to portable architectures, ASML-backed negotiating leverage, and open-weight ecosystems it can inspect and host — would be formidable. The strategy Europe is actually running, subsidizing depreciating compute while its firms donate their learning loops to foreign platforms, is the impostor version: residency and regulation wearing sovereignty’s clothes.

The middle powers: buying seats, renting stacks, and the nonaligned option

Everyone else faces the question the great powers are spared: what does sovereignty mean when you cannot plausibly own the stack?

The Gulf answer is capital and kilowatts. The UAE and Saudi Arabia are converting energy abundance and sovereign wealth into physical AI infrastructure and national Arabic-language models at extraordinary speed, buying a seat at the table that geography and demography would never have granted. It is a coherent play with two exposed flanks: the silicon and much of the operating expertise remain imported, meaning the dependency has been relocated rather than removed; and concentrated national compute is a concentrated target — a vulnerability that stopped being theoretical when regional drone activity near Gulf cloud infrastructure in early 2026 reminded everyone that data centers are buildings.

India’s answer is the most instructive in the world right now, because it is the most honest about trade-offs. India runs a dual strategy: national models like Sarvam and BharatGen aimed at hundreds of millions of citizens underserved by English-first frontier labs, layered on compute that is, as of early 2026, essentially all American-supplied, alongside deepening infrastructure partnerships abroad including the consequential UAE–India agreements signed this year. India is not pretending to full-stack sovereignty. It is securing the layers where it has natural advantage — language, talent, scale, application demand — while consciously renting the layers where it does not. Whether by design or necessity, that is the portfolio approach this essay will end up recommending to nearly everyone.

Which points to the genuinely new option on the board: nonalignment, rebuilt for cognition. For the hundred-plus nations that will never own fabs or frontier labs, the emergent playbook is visible in outline:

  • Self-hosted open weights as the base layer, immune to the June-letter scenario
  • National data and language programs — the layer no one can withhold
  • Compute secured through diversified partnerships rather than single-bloc dependence
  • Deliberate ambiguity between the American and Chinese stacks, extracting concessions from both

It is the Cold War playbook of the nonaligned movement, except this time the contested resource is intelligence and the equalizing technology, open weights, is handed out free by one of the superpowers as a matter of strategy. Small nations have never had a cheaper path to a defensible floor of capability. Almost none of them have noticed, because their advisors are busy selling them data centers.

Part IV

Four schools of thought, and what each one gets wrong

Every position in the sovereignty debate descends from one of four intellectual traditions, and it clarifies everything to name them, credit them and locate their blind spots before formulating a view.

REALISTSright: the stakes — markets will not protectmiss: a toolkit built for rivalrous goodsMARKET LIBERALSright: much sovereignty spending is wastemiss: the argument assumes market continuityTECHNO-NATIONALISTSright: capability requires building, not buyingmiss: they build the layers that photograph bestDEPENDENCY THEORISTSright: consuming without owning subordinatesmiss: open weights made the ladder climbableSHARED BLIND SPOTall four ask who should own the stack — none ask which layers are worth owning
Four schools, one shared blind spot

The realists see intelligence as the successor to oil and the precursor to military advantage: a strategic commodity whose control determines national power, justifying export controls, industrial policy and the treatment of compute as critical infrastructure. They are right about the stakes and right that markets alone will not protect them; the June letter is realism operating exactly as described. What they miss is that their toolkit was built for rivalrous physical goods, and intelligence is neither. Denying a chip denies a chip; denying a model teaches the denied party to build one, spreads the incentive to defect through every ally you frighten, and, as three years of chip-control evidence suggests, can accelerate precisely the rival capability it meant to prevent. Realism diagnoses the game correctly and then reaches for instruments from the wrong century.

The market liberalssee the entire sovereignty discourse as protectionism in a new costume: inefficient national champions, duplicated infrastructure, fragmenting standards, and politicians spending taxpayers’ billions to produce worse versions of things the market already provides cheaply. They are right depressingly often; the sovereign cloud sector alone vindicates them annually, and the history of state-picked digital champions — France’s Minitel most famously — is a graveyard of subsidized dead ends. What they miss is that their argument assumes the market’s continuity, and the market’s continuity is exactly what June disproved. Efficiency arguments are unanswerable right up until the letter arrives, at which point the inefficient redundancy you refused to build reprices from waste to survival. The liberals also forget their own counterexamples: Airbus was an inefficient political vanity project for two decades, and Galileo a redundant one, until they were, respectively, half of a global duopoly and the reason Europe’s navigation cannot be switched off from Colorado. Some inefficiencies are insurance premiums.

The techno-nationalistsbelieve every serious nation needs its own models, its own stack, its own champions, funded and protected until they stand. Their instinct that capability requires building, not just buying, is correct, and is the necessary corrective to a decade of European consumption-without-creation. What they miss is layer selection: national pride gravitates to the visible layers — models with the flag on them, data centers ministers can tour — precisely the layers commoditizing fastest, while the unglamorous compounding layers (data programs, evaluation infrastructure, application ecosystems, talent retention) go unfunded because no one cuts ribbons at an evaluation harness. Techno-nationalism, as practiced, is an aesthetic preference for the wrong layers.

The dependency theoristsframe the entire structure as extraction: the Global South supplies data, minerals, cheap annotation labor and eventually market demand, while the value, the models and the rents accumulate in two countries; local elites buy prestige projects while structural dependency deepens — cognition’s version of the colonial resource economy. This school is dismissed in Western policy rooms and should not be, because its core prediction — that consuming intelligence without owning learning loops entrenches subordination — is not only correct but is precisely this essay’s warning to European corporations, who would be startled to learn they occupy the Global South’s position in the analysis. What the dependency school misses is the exit the older colonial economies never had: open weights and portable architectures mean the ladder, for the first time, can be climbed without the incumbent’s permission. Dependency is now a choice with alternatives, which makes remaining in it a decision rather than a destiny.

Four schools, one shared blind spot. All of them argue about who should own the stack. None of them interrogate which layers are worth owning. That question has an answer, and it is where this essay has been heading from the first page.

Part V

The layer thesis: sovereignty compounds at the top of the stack

The layers of the AI stack differ in three properties that matter for sovereignty: how fast they commoditize, how fast they depreciate, and whether they compound. Judge every layer by those three tests and the strategic map redraws itself.

LayerCommoditizesDepreciatesCompounds
ComputeYes — anyone with capital can buy itViciously — a few years of hardware half-lifeNo — a GPU does not make the next GPU more valuable
ModelsYes — in real time, through open weightsWith every frontier releaseOnly for the labs that train them, not the nations that host inference
Data & contextNever — your operational reality is definitionally yoursNoYes
Learning loopNeverAppreciates with use rather than depreciatingBy construction — every cycle lowers the cost and raises the trust of the next
Three tests, applied honestly

The first two rows are the layers absorbing the overwhelming majority of the world’s sovereign AI capital, and they share the economic profile of, respectively, industrial equipment and perishable inventory. The last two receive rounding-error attention. And there is a fourth property, decisive for this essay’s subject, that the three tests do not capture.

INSTRUMENT OF ANOTHER SOVEREIGN7 · Learning loopuncoercible6 · Applications & agentsuncoercible5 · Data & contextuncoercible4 · Modelsmodel-access order · nationality gating3 · Computecloud jurisdiction · corporate control2 · Siliconexport controls · equipment licensing1 · Energydomestic policy · grid allocationNO LETTER REACHES ABOVE THIS LINEa fortress with the vault outside the walls is the standard corporate design
The reach of a letter

No letter from any commerce department can confiscate your evaluation harness, your trace corpus, or your institution’s codified judgment.

An export order can block a chip shipment and gate a model API. It cannot reach layers five through seven. The upper layers are not just the compounding layers — they are the uncoercible layers, and a sovereignty strategy that ignores them is a fortress with the vault outside the walls.

This inverts the standard picture completely. The standard picture says sovereignty flows bottom-up: secure the chips and compute, and the rest follows. The layer thesis says that for everyone except the two full-stack powers, sovereignty flows top-down.

  1. 01Own the uncoercible compounding layers absolutely.
  2. 02Secure the middle layers through portability and portfolio.
  3. 03Accept the bottom layers as designed dependencies — the way every nation accepts that it does not fabricate its own aircraft engines.

The oil-shock generation would recognize this instantly: reserves, diversification, efficiency, alliances — not universal drilling.

And the layer thesis carries one more implication, the one that pivots this essay from nations to firms. The top layers of the stack — context, applications, learning loops — do not primarily live in governments. They live inside companies. Which means the entities with the most natural access to the only truly sovereign layers of the AI stack are not nations at all. They are firms, and almost none of them have realized they are holding the position everyone else is spending billions trying to reach.

Part VI

The firm as a small nation

Every argument in the first half of this essay now replays at corporate scale, and the mapping is not a metaphor. It is an isomorphism.

NATIONFIRMA superpower it depends onThe model providerTerritory occupied under licenseThe cloud regionTreatiesVendor contractsTrade policyData flowsSuez, 1956The letter, June 2026most CEOs experienced their Suez moment as an IT incident
The firm as a small nation — an isomorphism, not a metaphor

A firm running its operations on rented intelligence has a foreign policy whether it acknowledges one or not. Its model provider is a superpower it depends on: the relationship is productive, asymmetric and revocable. Its cloud is territory it occupies under license. Its vendor contracts are its treaties — negotiated, in most companies, by a procurement function that prices subscriptions as commodities rather than dependencies as alliances. Its data flows are its trade policy. And the June letter was its Suez moment: the week every dependent power discovered that the guarantor’s interests and its own are aligned only until they are not.

Companies in dozens of countries lost access to frontier capability that month not because of anything they did, but because of a dispute between sovereigns conducted over their heads, settled at a layer they could not see, on a timeline they could not influence. That is what it feels like to be a small nation. Most CEOs experienced it as an IT incident.

The corporate sovereignty stack mirrors the national one layer for layer. Energy and silicon: irrelevant to own, essential to understand, because your provider’s exposure is your exposure, one supply chain up. Compute: rented from an oligopoly of three hyperscalers whose terms, prices and jurisdictional obligations you do not control, and whose home government’s legal reach — as a decade of transatlantic data jurisprudence established — follows corporate control across borders regardless of where your data physically sleeps. Models: the June lesson, now priced into every rational architecture. Then the top three layers — context, applications, learning loops — where the firm is not a dependent at all but the natural sovereign, holding assets no vendor and no government can replicate or revoke.

Which produces the corporate mirror-image of the national pathology, and it would be funny if it were not so expensive. Nations overinvest in the bottom of the stack; firms underinvest in the top of theirs. The typical enterprise AI strategy in 2026 consists of choosing which superpower’s stack to depend on, negotiating the rent, and then, through architectural carelessness, donating its traces, its corrections and its codified judgment — the only layers where it holds sovereign advantage — into that same vendor’s improvement pipeline. It is as if a small nation, having prudently decided it cannot build aircraft carriers, concluded it should also give away its ports.

The Token Capital essay named this negative capital formation. This essay names its strategic meaning.

A firm that owns no learning loop has no sovereignty to lose, because it never established any. It is not a small nation. It is a market.

Part VII

The firm’s sovereignty doctrine: five principles

Nations write security doctrines: documents that name their dependencies, define their red lines and specify what they will do when the environment turns hostile. Firms have disaster recovery plans for earthquakes and ransomware, and nothing at all for the scenario that actually materialized this June. So here is the doctrine — five principles, each with a test attached, because a principle without a test is a poster.

PrincipleThe test
1 · Sovereignty is exit capacity, and exit capacity is a numberOnce a year, move one production workflow to an alternate model. Measure the days and the euros. Report both to the board next to the insurance premiums.
2 · Own the learning loop absolutely, rent everything below it comfortablyWhere do the traces physically and contractually live, and what fraction of this quarter's agentic work produced learning that accrued to us rather than to the landlord?
3 · Run a dependency portfolio, not a dependencyFor each critical workflow, name its second source — and confirm the second source has actually served production traffic within the last two quarters.
4 · Map jurisdictional exposure one layer past your contractsFor your most valuable agentic workflow, list the sovereigns who could degrade it this quarter. If the list surprises the executive committee, the map was overdue.
5 · Match sovereignty investment to workflow criticalityA two-axis review, criticality against sovereignty investment, run annually. Every cell of over-protection is waste; every cell of under-protection is the June letter with your logo on it.
Five principles, five tests

Principle one: exit capacity is a number

Not a clause in the contract; a rehearsed, measured operational fact. For every AI-dependent workflow, the firm should know its switching time and switching cost to the next-best alternative, the way a treasury knows its liquidity. In the Token Capital essay I described a distributor that migrated its primary model provider in nine days because every capability re-certified automatically against its own evaluation harness. That number — nine days — is what corporate sovereignty looks like when it is real.

DAYS TO MOVE THE DEDUCTION WORKFLOW TO AN ALTERNATE MODELthe nine-day standardBefore the auditnever evaluated against a second model4–6 monthsDrill 1 · month 8painful and instructive16 daysDrill 2 · two quarters laterthe same workflow, again6 daysa firm that has never rehearsed exit does not have an exit — it has an intention
Switching time for one production workflow, measured rather than estimated

A firm that has never rehearsed exit does not have an exit; it has an intention. And the market should, and will, start pricing the difference: two firms with identical revenues and identical AI capabilities are not identically valuable if one can switch providers in nine days and the other is, in every sense that matters, a protectorate.

Principle two: own the loop absolutely, rent everything below it

This is the layer thesis as capital allocation. The firm’s uncoercible layers — context, evaluations, traces, codified judgment — must be held in assets the firm controls technically and contractually, with no exceptions and no convenience-based leakage. Below that line, dependency is not merely acceptable; it is optimal. Renting frontier intelligence is the greatest input bargain in industrial history, and refusing it out of sovereignty anxiety is the corporate version of autarky, the impostor strategy.

Principle three: a portfolio, not a dependency

No treasury holds one currency; no supply chain worth the name holds one supplier for a critical input; and after June, no serious firm should hold one model provider for critical cognition. The practical shape, visible already in sophisticated European enterprises, is a three-tier portfolio.

SHARE OF COGNITIVE VOLUME60%25%15%Small fine-tunedhigh-volume routine cognitionowned outrightOpen weightregulated and sovereignty-criticalself- or EU-hostedFrontier APIthe genuinely hard residualrented, gladlyrouting is policy, adjustable in days — because the geopolitics now moves
A three-tier dependency portfolio — the tiers back each other up

The tiers back each other up. The routing between them is policy, adjustable in days when the geopolitics moves — because the geopolitics now moves. An untested backup is a hope with a line item.

Principle four: map exposure one layer past your contracts

Your legal team knows which law governs your vendor agreements. Almost no one knows which sovereigns govern the vendor’s dependencies: whose export regime gates the models, whose courts can reach the cloud’s parent company, whose airspace the data centers sit under, whose fabs the whole edifice ultimately rests on.

WHO CAN CHANGE THE TERMSAgentic workflowyour jurisdictionApplication layeryour jurisdictionModelgated by one export regimeCloudcorporate control reaches across bordersData centerhost state · physical securityAcceleratorsone designer, one control regimeFabricationconcentrated on one islandLithographyone company, one countrywhatlegalknows▪ single-sovereign chokepoint — five of the eight layersthe June order came from a jurisdiction with no contract at all
Sovereignty mapping — one layer past your contracts

The June order taught the lesson: the binding constraint arrived from a jurisdiction most affected firms had no contractual relationship with at all. Sovereignty mapping means tracing each critical workflow down the stack and asking, at every layer, which governments could change the terms — then treating any single-sovereign chokepoint the way a supply chain officer treats a single-factory component.

Principle five: refuse both paranoia and complacency

Sovereignty is expensive, and buying it uniformly is how firms convert a strategy into a tax. The instrument here is the same Graduated Autonomy Ladder that governs trust: workflows that run high on the ladder, executing consequential decisions autonomously, warrant the full doctrine — portable architecture, second-sourced models, owned loops, rehearsed exits. Experimental and low-stakes work warrants none of it, and burdening it with sovereignty requirements is how innovation teams learn to route around governance entirely.

A TAX ON EXPERIMENTSteams learn to route around governanceTHE FULL DOCTRINEportable, second-sourced, owned, rehearsedCORRECT — LEAVE IT ALONElow stakes deserve no ceremonyTHE JUNE LETTER, WITH YOUR LOGOconsequential work, unrehearsed dependencyLOW CRITICALITYHIGH CRITICALITYHIGHLOWINVESTMENTrun it annually — every mismatched cell is either waste or exposurebuying sovereignty uniformly is how a strategy becomes a tax
Match sovereignty investment to workflow criticality — refuse both paranoia and complacency

Five principles, five tests, and a one-sentence summary a CEO can carry into any vendor negotiation.

We will rent your intelligence gladly, on the understanding that the learning belongs to us and the exit stays warm.

A vendor who resists either clause has just told you what business they are actually in.

Part VIII

A sovereignty audit, worked: one European firm, before and after

Doctrines convince nobody in the abstract, so here is the audit as we run it, on a composite drawn from the European mid-market where TiMiNa works: a consumer goods firm, 1.2 billion euros of revenue, eleven markets, eighteen months into an enthusiastic agentic program. Deduction resolution, demand sensing and content generation all run agentically; the board deck calls AI a core capability. Then the audit asks the June question, workflow by workflow: what still works, at what cost, the morning after?

TestFinding
Jurisdiction map (P4)Every consequential workflow routes through a single frontier API, contracted through a single hyperscaler, both governed from one foreign jurisdiction. Three sovereigns the firm has no relationship with could each degrade its operations this quarter; its most critical dependency chain passes through an export regime it had never heard of.
Exit test (P1)Switching the deduction workflow to an alternate model is estimated, honestly, at four to six months — because nothing was ever evaluated against a second model and half the prompts encode one vendor's quirks.
Loop audit (P2)Trace capture sits at 11 percent. For eighteen months, nine tenths of the corrections, judgment and learning generated by the firm's own experts flowed into retention policies it does not control.
The findings — typical, which is what makes them worth publishing

On paper the firm has an AI capability. Under audit it has a well-decorated dependency, and its 2.3 million euros of annual AI spend has been building, in roughly equal parts, its own productivity and someone else’s asset.

The remediation takes three quarters and costs less than one year of that spend. The learning loop comes home first, because leakage compounds daily: traces routed to firm-controlled storage, an evaluation harness built from 14,000 adjudicated historical cases, contractual learning clauses renegotiated with both vendors, capture rate to 85 percent by the second quarter. The portfolio comes next: an EU-hosted open-weight tier stood up for the regulated-data workflows, a small model fine-tuned on the firm’s own deduction traces absorbing 60 percent of routine volume at a fraction of frontier cost, the frontier API retained — gladly — for the hard residual. Then the drill: in month eight the firm rehearses a full switch of one production workflow. It takes sixteen days, painful and instructive; the second rehearsal, two quarters later, takes six.

BEFOREAFTERTrace capture rate11%85%Routine volume on owned or portable tiers0%60%Critical workflows with a tested second source0%100%cost: roughly what the firm spends insuring buildings that have never caught fire
One European firm, three quarters of remediation, ~€800k

Total incremental cost of the entire program: about 800,000 euros, or roughly what the firm spends annually insuring buildings that have never once caught fire.

What did it buy? Nothing visible, on a good day. Cognition costs per routine decision actually fell, courtesy of the small-model tier, but that was a side effect. What the firm bought is the morning after: the tested ability to lose any single vendor, any single model, or any single jurisdiction’s goodwill and keep resolving claims by the end of the week.

Part IX

The subsidiarity of sovereignty: where nation and firm meet

The two halves of this essay now connect, because the national and corporate games are not parallel. They are nested, and the nesting suggests a principle that neither governments nor companies have articulated: sovereignty subsidiarity. Each layer of the stack should be secured at the lowest level capable of actually holding it, and interventions from the wrong level fail predictably.

7 · Learning loop6 · Applications & agents5 · Data & contextFIRMS ONLY4 · ModelsECOSYSTEMS3 · ComputeMARKETS, THEN NATIONS2 · Silicon1 · EnergyNATIONS & ALLIANCESa million firms with owned loops and nine-day exits is more national sovereigntythan five gigafactories — and no foreign order can reach any of it
Sovereignty subsidiarity — secure each layer at the lowest level that can hold it

Energy and silicon can only be secured by nations and alliances; no firm hedges lithography. Compute is secured by markets when they work and by national programs when concentration or coercion breaks them. Models, after the open-weight inversion, are best secured by ecosystems — plural providers, portable standards, inspectable weights — which governments can cultivate but should not try to own; two decades of national champion projects show what happens when they try. And the top layers can onlybe secured by firms, because that is where the assets live. No gigafactory program reaches them, and no ministry can codify a distributor’s promotion judgment on its behalf.

Which reframes what good national strategy looks like for everyone outside the top two powers. If the compounding layers live inside firms, then the highest-leverage sovereignty instrument a government owns is not the subsidy program at the bottom of the stack. It is procurement and policy that shape how thousands of domestic firms build at the top of theirs:

  • Public purchasing that mandates portable, exit-tested architectures, so national demand steers the market toward sovereignty-compatible design
  • Data institutions that pool sectoral context no single firm could assemble
  • Incentives that treat trace repatriation and evaluation infrastructure the way earlier industrial policy treated R&D

A million firms with owned learning loops and nine-day exits constitute more national sovereignty than five gigafactories, at a fraction of the cost, and no foreign order can reach any of it.

Europe, of all polities, with its enterprise density and its regulatory reflexes, is best positioned on earth to run this strategy — which is precisely why its current fixation on the bottom of the stack qualifies as tragedy rather than mere error.

The nesting cuts the other way too, and firms should read it as warning. Corporate sovereignty exists inside a national envelope: a firm’s exit options are only as good as the alternatives its jurisdiction permits, and the era of governments regulating which models their companies may use has visibly begun — from Washington’s nationality-gated access to Brussels’ compliance regimes to Beijing’s approved-model lists. The firm that builds portable architecture is not just hedging vendors. It is hedging its own government’s future decisions, which is a sentence that would have sounded paranoid in 2024 and reads as elementary prudence after June.

Part X

The strongest objections, taken seriously

An argument this opinionated owes its critics their best case, so before the verdict: four objections, steelmanned and answered.

The objectionThe answer
“This is multi-cloud rhetoric with a flag on it, and multi-cloud mostly failed.”Correct about untested portability — which is why the doctrine is built on rehearsed drills with published numbers, not architecture diagrams. But cloud lock-in was priced in switching costs; model lock-in is priced in switching costs plus geopolitical revocation risk. Multi-cloud failed because the disaster it insured against never arrived. This one has now arrived once, with a return period nobody can estimate.
“Open weights are a security and capability trap.”Partly right on all three counts — frontier gap, opaque provenance, self-hosting burden — and the portfolio concedes all three by keeping frontier APIs for frontier problems. But most enterprise cognition is not frontier cognition, and an owned harness converts even an opaque model into a measured one, which is more than most firms can say about the APIs they trust today.
“Sovereignty economics favor the giants; this is a luxury tax the mid-market cannot pay.”It would be, if the doctrine required running your own model stack. It requires nothing of the sort: the audit, the trace repatriation, the second source and the annual drill cost the worked example well under one year of existing AI spend. Sovereignty at the bottom of the stack is a rich nation's game. Sovereignty at the top is priced like insurance.
“You underweight the case for trusting the American stack.”Notice what the objection asks you to underwrite: not a prediction about markets, which firms are competent to make, but a prediction about the internal politics of a foreign government across a decade of great-power rivalry, which no board is competent to make. The doctrine does not require believing the June scenario is likely — only noticing that its probability is unknowable, its impact total, and its insurance cheap.
Four objections

On that last one, the objection most boards actually believe, usually silently: firms hedge currencies they trust. They can hedge minds they trust too.

On the second: provenance anxiety without evaluations is vibes. Evaluations without provenance is engineering.

Part XI

The take: what I actually believe

I promised a formulated opinion rather than a survey, so here it is, in six claims, stated without diplomatic padding.

One: most sovereign AI spending is buying depreciating theater.The gigafactories, the flag-draped data centers, the national model announcements — the majority of this capital is purchasing the commoditizing middle of the stack, assets with hardware half-lives and API-era relevance, selected for announceability rather than for the three properties that matter. Much of it will be studied in a decade the way we now study the sovereign cloud initiatives of the 2010s: sincere, expensive and strategically beside the point.

Two: full-stack sovereignty is a two-member club, permanently, and the honest strategic question for everyone else is dependency design. No third polity will assemble frontier labs, leading fabs, hyperscale compute and the talent flywheel within any horizon that matters. Pretending otherwise wastes the resources that could secure what is actually securable. The mature posture, for a nation of eight million or a firm of eight hundred, is the same: absolute ownership of the uncoercible layers, engineered portability through the middle, and negotiated, diversified, eyes-open dependency at the bottom.

Sovereignty is not the absence of dependence. It is the absence of helplessness within dependence.

Three: open weights moved the sovereignty frontier, and this is the most under-priced strategic fact of 2026.The model layer, five years ago the presumed ultimate chokepoint, is now the most portable layer in the stack, available at near-frontier quality for the cost of the hardware to run it. The binding constraints on sovereignty have moved up the stack — to data, applications, learning loops and talent — and every strategy document still treating model access as the crown jewel is defending the previous war’s hill. The corollary is uncomfortable for Washington and should be said plainly: model-level export controls are not just leaky, they are counterproductive, accelerating the open ecosystem they cannot contain while spending the ally trust that the stack strategy depends on. You cannot simultaneously be the world’s infrastructure and the world’s leverage. June proved the world has noticed.

Four: the decisive sovereignty asset of the next decade is the learning loop, and it is currently being given away by almost everyone who owns one.Nations measure GPUs; firms measure licenses; nobody measures who keeps the learning. The entities that internalize this first — firms that repatriate their traces, nations that steer their economies toward loop-owning architectures — will compound while everyone else rents, and the gap will look modest for three years and unbridgeable after seven, because that is what compounding does.

Five: for firms, sovereignty is about to become a valuation line.Acquirers, insurers and eventually markets will learn to price the difference between a company with rehearsed nine-day exits and owned loops, and a company whose entire cognitive capability evaporates with one vendor’s terms change. AI due diligence today counts licenses and use cases. Within five years it will demand the exit drill results and the trace ownership audit, and the discount applied to cognitive protectorates will be measured in turns of EBITDA.

Six: the sovereignty conversation will get worse before it gets better, and the theater will escalate.Expect trusted-partner blocs that formalize the June logic into standing architecture; expect attempted model non-proliferation regimes, and expect them to fail for the reasons chip controls disappointed; expect a wave of sovereignty-washing as every vendor repaints residency as independence; and expect at least one more June, from at least one more capital, before the decade ends. None of this is a forecast of catastrophe. It is a forecast of weather — and the entire argument of this essay is that weather is not something you predict your way out of. It is something you build for.

Conclusion

The morning after, again

Return one last time to the June letter, and to the question this essay opened with: what can you still do, at what cost, the morning after?

For most of the affected world, the honest answer that week was: wait. Wait for the carve-out, wait for the clarification, wait for the sovereigns to settle a dispute conducted entirely over their heads. Waiting is the posture of the dependent, and it felt, for governments and companies alike, exactly as it has always felt in the older domains of oil and currency and grain: the discovery that what you had booked as infrastructure was, all along, someone else’s favor.

But somewhere that same week, a distributor’s deduction agents kept resolving claims, because the models underneath them were swappable and the judgment inside them was owned. A handful of enterprises re-routed critical cognition to their second source by Friday. A few nations with self-hosted open weights and national data programs noted the news with interest rather than alarm. None of them were sovereign in the impostor senses. They produced no chips, trained no frontier models, hosted no gigafactories. They had simply done the unglamorous work of owning the uncoercible layers and keeping the exits warm — and so, on the morning after, they continued.

The sovereign is whoever can say no and keep working.

Nations have spent a hundred billion dollars this year trying to buy that sentence at the bottom of the stack, where it is not for sale. Firms could build it at the top of theirs for a fraction of the cost, and mostly have not started. The next letter is already being drafted somewhere; letters always are. Sovereignty is what you did about it in the years before it arrived.

Sources

Selected sources and further reading

Sovereign AI programs.Carnegie Endowment’s 2026 analysis of sovereign AI programs, including India’s national missions.

The June 2026 controls. Lawfare and PIIE assessments of the US model-access controls and their effects.

The compute gap.EY’s 2026 estimates of the transatlantic compute gap.

European and national programs.Reporting on the EU’s InvestAI and gigafactory programs, the UK Sovereign AI Fund, France 2030 and Mistral’s infrastructure expansion.

Weaponized interdependence.Farrell and Newman’s foundational work on how network centrality becomes coercive power.

From guide to production

Want help choosing the right architecture for your process?

We map where agents create leverage in FMCG operations, then build and ship the ones that pay back. One call to pressure-test your highest-leverage use case.

All essays