Territory without Control: AI Sovereignty and the Governance of Circulation
Housed with The Sentinel in the living world — Blue steel under a living canopy. An angular guardian whose precision makes room for the forest’s unruly growth.
AI sovereigntyinfrastructurecirculationglobal value chainspublic procurementdemocratic accountability
Working draft v86 · 19 September 2026
Alexander Chiocchi1
Abstract
This paper asks whether states can become meaningfully sovereign in relation to AI. I take sovereignty to be a state’s capacity to act on its own in AI: to build and govern the technologies, data and infrastructure it depends on and to lower its reliance on foreign vendors, a definition adapted from the European Commission’s account of tech sovereignty (European Commission 2026c). I then press the word the Commission leaves undefined: control. Two traditions answer it differently. The territorial view rests on Weber’s (1946) definition of the state by its monopoly of legitimate force within a territory, and it reads a state’s AI sovereignty from what stands on its soil. Building on Foucault’s (2007) distinction between sovereignty over a territory and the government of circulation, I argue that AI sovereignty cannot be read from territorial form. It belongs to whoever governs the circulations that keep AI usable. I coin two terms to operationalise the distinction. Sovereignty over territory names the national placement of infrastructure across four layers: substrate, location, operator and accelerator (Lehdonvirta, Wu, and Hawkins 2024; Hawkins, Lehdonvirta, and Wu 2025; Crawford 2021). Sovereignty over circulation names public authority over capability-producing circulations (Cobbe, Veale, and Singh 2023; Farrell and Newman 2019). Value-chain and production-network theory (Gereffi, Humphrey, and Sturgeon 2005; Coe and Yeung 2015) supply seven lenses for that authority, allocation, operation, visibility, updates, continuity, refresh, and step-in and exit, and a classification rule. Dependency theory and structural power explain how a state that holds territory becomes captive to the vendor whose circulation it depends on (dos Santos 1970; Strange 1988). Ukraine’s wartime cloud migration shows where the state’s force stops. Ukraine kept its state registers running under shelling by moving them out of its territory and into a foreign vendor’s cloud. Han’s (2017) psychopolitics shows that the vendor’s power works by attraction, which force cannot counter. The state’s force reaches territory and leaves circulation untouched. The territorial and circulation readings agree on where compute is located. They disagree on what survives when a vendor acts. Four shocks since 2024 decide that question. The classification rule then places eight states on a categorical grid. The United States is included as the ceiling below which the rest are capped. I argue that sovereign-AI procurement raises a state’s sovereignty only when it increases control over circulation; where it does not, it repackages dependence as sovereignty. Mügge’s (2024) question of whom sovereignty is for shows that the lenses also measure citizens’ authority over the systems that govern them, and so give a publicly financed AI sovereignty project a standard to meet.
Keywords: AI sovereignty; infrastructure; circulation; global value chains; public procurement; democratic accountability
1. Introduction: The AI Sovereignty Controversy
The most visible definition of AI sovereignty comes from the firms that sell the hardware. Hardware vendors equate it with domestic hosting, treating control of AI accelerators on a nation’s soil as sovereign control itself (Nvidia 2024). The reading is intuitive: AI compute is observable, physically located and steeply concentrated, so its location is easily read as control (Lehdonvirta, Wu, and Hawkins 2024, 831). Many states have adopted it. Sovereign AI is now a headline national goal, and it has become something a state can buy. A data centre, a cloud region or a dedicated model deployment can carry the label.
AI sovereignty has no settled meaning. The term is used for incompatible ends and stays underspecified: the same word serves industrial protection, vendor marketing and citizen welfare (Pava et al. 2026; Mügge 2024, 2200, 2207–8; Nvidia 2024). Three recent interventions sharpen the dispute. Grohmann and Barbosa (2026, 416) show the hyperscalers answering the question of whom sovereignty is for on their own behalf: sovereignty is now provisioned by the platforms, on their terms, as a branded cloud product. Ashraf and Veneziano (2026) fault the Tony Blair Institute’s ‘strategic agency’ framing for missing the coercion that only a disruption makes visible. Shrivastava (2026) asks which layers of the stack a state must own, control or govern and which it can safely rent. This paper answers Shrivastava’s question with Ashraf and Veneziano’s test: the layers a state must govern are the ones a disruption would reach. Some scholars reject the term altogether, holding that sovereignty is the wrong frame for a domain of flows (Mueller 2020, 779). I isolate one confusion inside the dispute: the territorial reading mistakes visible control for decisive control. AI sovereignty belongs to whoever governs what runs through the infrastructure a state hosts.
The territorial reading has the older warrant. Weber defines the state by its monopoly of the legitimate use of physical force within a given territory (Weber 1946, 78), and a data centre on national soil looks like the clearest object of that force. Foucault offers the distinction that undoes the inference. He separates power over a bounded territory from the government of circulation (Foucault 2007, 20–21, 65). Circulation is movement, exchange and contact, the dispersion and distribution of people and things through a governed space (Foucault 2007, 64). AI sovereignty turns on the second. Sovereignty over circulation is public authority over what moves: compute allocation, model access, updates and supply. Sovereignty over territory is the national placement of infrastructure: the chips, data centres and compute on a state’s soil. Holding territory and governing its circulation are distinct. I argue that sovereignty is the degree of control over circulation a state’s policy secures.
The European Commission shows the gap in live policy. It defines tech sovereignty as Europe’s ability “to act independently in the digital world by developing and controlling key technologies, data, and infrastructure, while reducing reliance on non-EU providers” (European Commission 2026c, para. 1). The decisive word is ‘control’, and the Commission uses it without defining it. Digital-sovereignty scholarship treats sovereignty as a contested claim to independence, autonomy and control (Couture and Toupin 2019, 2305, 2317; Donnelly, Ríos Camacho, and Heidebrecht 2024, 2228). The Commission’s 2026 proposals do not specify which controls make a capacity sovereign. Three non-EU hyperscalers hold over 70 per cent of the European cloud market (European Commission 2026b, explanatory memorandum). A product hosted on home soil and labelled sovereign can still leave control abroad.
Because territory and circulation are distinct, a policy that expands territory does not by itself raise control over circulation. Full-stack control, reaching every layer down to fabrication, is structured around US and Chinese hubs, the largest compute powers (Lehdonvirta, Wu, and Hawkins 2025, 1442–44, 1461–62). For every other state the realistic ceiling, which I call practical sovereignty, is governing the circulation that keeps its AI capable, backed by enough territory to make that control durable.
A definition of this kind invites an objection I take seriously. If sovereignty is control over circulation, then a case in which the vendor holds the circulation is not sovereign by definition, and the cases only illustrate what the definition already says. A territorialist can accept every description of who holds what and still reject the definition. Section 4 answers that objection with a test. The territorial and circulation readings agree on the map. They disagree on a prediction: what happens to hosted capability when the vendor acts. That prediction has been tested four times since 2024.
Two bodies of theory and one wartime case stand between the two readings and the test. Dependency theory and structural power explain how a state that holds territory becomes captive to the vendor whose circulation it depends on (dos Santos 1970; Strange 1988). Ukraine’s wartime cloud migration and Han’s account of power that works by attraction show where the state’s force stops: it reaches territory and leaves circulation untouched. A framework that measures how much a state controls still says nothing about whom that control serves. Section 8 returns to Mügge’s question and shows that the seven lenses that measure state control also measure citizens’ authority over the systems that govern them. A state that wins the lenses from a vendor can then be asked which of them it has passed on to its citizens.
Section 2 states the territorial view in its strongest form and gives it its warrant in Weber. Section 3 states the circulation view, the mechanism by which a state becomes captive, and the limit of force that Ukraine and Han make visible. Section 4 sets the test that decides between the two readings. Section 5 derives the seven lenses, the classification rule and the grid. Section 6 places eight states on it, the United States included as the ceiling below which the rest are capped. Section 7 states the argument. Section 8 asks whom sovereignty is for. Section 9 answers objections and states what would falsify the thesis. Section 10 concludes.
2. The Territorial View of Sovereign AI
The territorial view has the oldest warrant in political theory. Weber defines the modern state by its successful claim to the monopoly of the legitimate use of physical force within a given territory, and he notes that territory is one of the characteristics of the state so defined (Weber 1946, 78). The inference the territorial view draws is short: the state may use force within its territory, a data centre is within its territory, so the state can take it. The state can inspect it, tax it, staff it, seize it and cut its power. In the state-sovereignty tradition running from Bodin to Westphalia, sovereignty names the highest authority within a bounded territory (Couture and Toupin 2019, 2308; Pohle and Thiel 2020, 3). Where physical assets are located therefore looks like the clearest evidence of sovereign control. Current policy follows this intuition. Jurisdiction, public-sector priority, security review and resilience all attach to where compute is physically located (DSIT 2025, sec. 1.1; European Commission 2025a, 9). The concept of ‘sovereign control’ beneath that intuition is nonetheless contested. The term shifts across five cohorts and stretches across the digital domain (Couture and Toupin 2019, 2308; Floridi 2020, 370–71). Across these accounts, territorial location is one prerequisite among several. Locating sovereignty in territory alone is a choice to be argued.
The strongest territorial accounts read territory as a stack of four distinct layers: a material substrate, the location of compute, the operator that runs it, and the vendor whose accelerators fill it. By accelerator I mean any processing chip used to train or run AI models. At the base lies the material substrate: Crawford traces the supply chain of AI down into capital, labour and the earth’s resources, without which computation does not work (Crawford 2021, 31, 33). Above it lies the location of compute, and its distribution is starkly uneven. Together the US and China host nearly as many GPU-enabled cloud regions (49) as every other country combined (52), and that remainder takes in every lower- and lower-middle-income country (Lehdonvirta, Wu, and Hawkins 2024, 831, 834). Above location lie two further layers that Hawkins, Lehdonvirta, and Wu hold apart: the nationality of the firm that owns and operates a data centre, and the nationality of the vendor whose accelerators fill it (Hawkins, Lehdonvirta, and Wu 2025, 3). Even where location and operator are diversified, US-owned accelerators power roughly 95.5 per cent of accelerator-enabled regions (Hawkins, Lehdonvirta, and Wu 2025, 11). Ownership concentrates in a handful of hyperscalers, most of them American (Lehdonvirta, Wu, and Hawkins 2025, 1444–46).
The strongest territorial argument is possession under disruption. A state that holds functioning hardware and resident model weights can keep operating when a foreign vendor withdraws. It can direct domestic staff and allocate the equipment to priority work. A contract enforced abroad is slower and weaker than those powers. The territory authors register the limit themselves: “location without control is not sovereignty” (Hawkins, Lehdonvirta, and Wu 2025, 14). A complete map of territory does not say who governs allocation under scarcity, who pushes updates, who can suspend service, or who controls exit. Those are questions about circulation.
The International Criminal Court shows what the map leaves out. In February 2025 the United States sanctioned the Court’s chief prosecutor. Within months he had lost access to his Microsoft email and moved to a Swiss provider (Lingsma 2026). Who cut him off was disputed for a year. Microsoft’s president denied that the company had ceased or suspended any service to the Court (Lingsma 2026). A Microsoft executive told a House of Commons committee in February 2026 that the Court had made the decision itself, and the company corrected that testimony within a week (House of Commons Business and Trade Committee 2026, qq. 332–33; Clark 2026). Dutch reporting supplied the mechanism. Microsoft told the Court that the sanction obliged it to deny the prosecutor access, and that unless the Court ended his access itself, the company would end email for the whole organisation (Clark 2026). The Court suspended its own prosecutor. That is captive lock-in performed in a single exchange: the vendor’s compliance duty came down the dependency as a choice between losing one user and losing everything, and the customer carried it out. Relocation would not have helped. Under the CLOUD Act a US provider must produce data in its “possession, custody, or control” wherever it is stored (Cochrane 2022, 161), so the same service on European soil would have answered to the same sanction. The Court’s remedy was to change who governed the service: in October 2025 it announced a move from Microsoft Office to openDesk, a European open-source suite (Lingsma 2026; Robinson 2025). The territorial map cannot say who holds that control. Circulation can.
3. The Circulation View and the Limit of Force
Foucault distinguishes three modalities of power by what they act on. Sovereignty is exercised within the borders of a territory, discipline on the bodies of individuals, and security over a whole population (Foucault 2007, 11). Security governs circulation. His own case is the eighteenth-century town, which secured itself by governing the goods and people moving through it (Foucault 2007, 17–19). The milieu that security governs, the space in which circulation is carried out, is in his words completely different from the juridical notion of sovereignty and the territory (Foucault 2007, 21–22). The distinction belongs to the shift he later names governmentality, where territory becomes one component of what a state manages (Foucault 2007, 108–10). Aradau and Blanke (2010, 1–3) read the same lectures as an account of how circulation becomes the object of government, and they fault that reading for leaving out production: who makes what circulates, and on what terms. Their correction is the one this paper needs. AI capability is a maintained and governed set of services and updates, held in no single artefact. A data centre can sit in a state’s territory and still be governed by whoever holds the levers over the circulation it depends on. The physical site of a thing is now disconnected from where it is accessed and controlled, so location no longer settles who governs it (Daskal 2015, 326).
Foucault does not deny Weber’s premise. He relocates it. Force acts on the territory. Circulation is governed by other means: by allowing circulations to take place and controlling them, through mechanisms that in Foucault’s words do “not function on the axis of the sovereign-subjects relationship” (Foucault 2007, 65). The two do not convert. A state can seize every accelerator on its soil and have thereby seized nothing that allocates the next generation, pushes the next update or ships the replacement. The monopoly on violence is a monopoly over the territory. Violence cannot take sovereignty over circulation, because the circulation is not in the territory to be taken.
Two bodies of theory explain how a state that holds territory becomes captive to the vendor whose circulation it depends on. Dependency theory supplies the mechanism. For Theotonio dos Santos, ‘the new dependence’ works through multinational corporations and their technology monopoly, so a dependent economy expands only as a reflection of the dominant one (1970, 231–32, 234). Scholarship on data colonialism reads the same structure in computing (Couldry and Mejias 2021, 789). The structure recurs at the compute layer: one vendor, Nvidia, holds 92 per cent of the market in GPUs, the most widely used accelerator (Srnicek 2025, “The Generative AI Stack,” para. 2). That structural power rests on two US chokepoints: the chip-design tools and architectures, and the export-control law that reaches any foreign chip built with them (Beaumier and Cartwright 2024, 8, 14; Malkin and He 2024, 679, 682). Susan Strange names the power this creates as ‘structural power’, which “confers the power to decide how things shall be done” (Strange 1988, 25). Owning a data centre is territorial power. Setting the allocation, model access and update cadence it must run within is structural power, and structural power belongs to whoever governs the circulation, because power balances are set by the interdependence among actors (Cobbe, Veale, and Singh 2023, 1190). An AI model is itself such a circulation: the provider decides who gets access, on what terms, and can change or withdraw it at any time (Cobbe and Singh 2021, 20; Cobbe, Veale, and Singh 2023, 1195).
That structure meets force in war. War pulls the two modalities furthest apart, and Ukraine demonstrates it. A week before the full-scale invasion, on 17 February 2022, the Verkhovna Rada adopted a law on cloud services that let public bodies procure cloud services from listed providers and barred state secrets, restricted official information and the state registers from cloud resources located abroad (Verkhovna Rada of Ukraine 2022, art. 11). A wartime resolution of 12 March lifted that bar for the duration of martial law: it authorised locating state information resources and public registers on cloud resources and in data centres outside the country, and making additional backup copies of them (Cabinet of Ministers of Ukraine 2022a, paras. 1, 3). By December AWS had migrated about a hundred state registers and critical databases, and the ministry linked that migration to services continuing through shelling and power outages; its summary was that Russian missiles cannot destroy the cloud (Cabinet of Ministers of Ukraine 2022b). Under force, territory was the liability: a register that can be seized can be shelled. Ukraine preserved its public functions by moving them out of its territory and into a circulation it does not govern. It gave up territory to hold continuity, and it accepted a vendor’s terms to do so. Whether it holds allocation, updates or exit against AWS is not established, and in March 2022 it was not the question. The case is digital public infrastructure, and that is what makes it the clean test: the shock was force itself, and the territorial reading failed against the very instrument it trusts. A state that loses control over its circulations in wartime loses it because force is the wrong modality, whatever force it holds. The dependence was chosen by policy: the resolution names the purpose in its title, keeping public registers working under martial law, names the means, hosting outside the country, and sets an end, six months after martial law ceases (Cabinet of Ministers of Ukraine 2022a, paras. 1, 4). That is dependence a state governs on purpose, and under fire: a named dependency, a stated purpose and a fallback.
The territorialist’s second error is to read the vendor’s power as force in another form. Han’s psychopolitics names the form it takes: a smart power that seduces where older power forbade, works through the subject’s freedom and is experienced as convenience (Han 2017, 14). Sovereignty-as-a-service is smart power at the scale of the state. No vendor coerced the UAE into the Stargate campus it hosts. The campus is wanted; the terms are accepted because the service is superior and immediate; the dependence is chosen, and because it is chosen it does not register as dependence. Dos Santos’s ‘new dependence’ already worked through investment, with no occupation required (1970, 231–32). Han supplies the mechanism by which it stops feeling like dependence at all. This is why a label suffices. The state that buys sovereignty-as-a-service gets what it wanted, and is pleased. Farrell and Newman describe the moment smart power turns hard: the network that attracted becomes the chokepoint the hub turns against those inside it (2019, 45). The shocks of the next section are that turn observed in real time, and one of them reached every customer who had, freely and sensibly, chosen the better model.
4. The Test: What Survives When the Vendor Acts
The territorialist and I agree on the map. We disagree on a prediction. The territorialist predicts that capability hosted on national soil survives the vendor’s decisions, because the hardware and the resident weights sit within reach of the state’s force. I predict that hosted capability survives only as far as the state governs the circulations that keep it capable: allocation under scarcity, updates, and the refresh of hardware. The disagreement is about what happens when the vendor acts. It is empirical, and it has been tested.
Start with the territorialist’s best asset, the resident model. Weights do not rot. A downloaded model serves a stable task indefinitely without further contact with its vendor. What decays is the relation between a frozen model and a moving world. Security fixes stop. The surrounding software moves on. Accelerators fail and no vendor refreshes them. For a narrow, stable public function a frozen model can be adequate for years, and Section 9 concedes exactly that case. For the functions sovereign-AI programmes actually promise, frontier access and public services exposed to adversaries, possession buys a capability that stops being frontier on the day the vendor leaves and stops being safe soon after. The territorialist’s asset ages at the vendor’s pace.
Four shocks since 2024 discriminate between the two predictions.
Allocation. In March 2026 Google capped Meta’s purchase of Gemini capacity as demand strained supply, delaying Meta’s internal AI projects (Murphy and Morris 2026). Meta owns one of the largest compute estates on earth. Its territory was not the constraint; its access to a circulation it does not govern was. Alphabet ($4.5 trillion) is the lead firm over Meta ($1.5 trillion) in the sense Section 5 defines (CompaniesMarketCap 2026a, 2026b). If one of the largest buyers on earth can be rationed, a state buying capacity from the same vendors holds no stronger hand. The territorialist predicts that Meta’s estate insulates it. It did not.
Continuity. On 12 June 2026 Anthropic announced that a US government directive required it to suspend access to Fable 5 and Mythos 5 by foreign nationals, and that it was disabling both models for all customers to comply (Anthropic 2026). The directive attached to nationality. The vendor’s chosen compliance policy attached to everyone. Where any customer’s compute sat was irrelevant to the outcome. A sovereign campus serving those models on national soil lost them on the same day as a start-up on a laptop. The territorialist predicts that location protects access. It did not.
Recovery. When OpenAI blocked API access from mainland China and Hong Kong in mid-2024 (Chen 2024), Chinese developers did not seize anything. They produced the circulation at home: DeepSeek’s R1 (DeepSeek-AI 2025), Alibaba’s Qwen3 (Qwen Team 2025) and Zhipu’s GLM-5.2 (Zhipu AI 2026), near-frontier and open-weight. Continuity was restored by governing the model layer, not by holding the data centres, which China held before the block and which did nothing for it on the day. The territorialist predicts that recovery comes from possession. It came from policy over circulation.
Refresh. China’s access to advanced accelerators has been a persistent focus of US policy. Export controls denied the leading chips from October 2023 (BIS 2023, 73474, 73493). In January 2026 the Bureau of Industry and Security moved to conditional case-by-case review for specified chips including Nvidia’s H200, following a presidential announcement that priced the concession at a quarter of the sale revenue (BIS 2026). The lever moved twice in three years, and it moved in Washington. Domestic substitutes such as Huawei’s remain lower-quality (Srnicek 2025, “An Interregnum,” conclusion, para. 9). The state that holds more data centres than any except the United States does not govern the refresh of the chips inside them. The territorialist predicts that a deep domestic base secures its own renewal. It does not.
In each case the territorial reading predicts survival and gets degradation, or predicts that policy is beside the point and gets recovery through policy. That is the test the cases in Section 6 inherit. Every verdict there is a verdict about which prediction the state’s arrangement would survive.
5. Control over Circulation: Lenses, Rule and Grid
Control over circulation is the public authority a state’s policy secures over the allocation, operation, visibility, updates, continuity, refresh and exit of its AI capability-producing circulation. It arises through ownership, regulation, contract, operational competence or a viable alternative; a contractual promise counts to the extent that institutions and technical means make it usable. Recent scholarship converges on this definition, treating digital sovereignty as legitimate, effective authority (Roberts 2024, 1–2; Donnelly, Ríos Camacho, and Heidebrecht 2024, 2228), an authority that is checkable because compute allocation and structuring are detectable (Seferis and Fist 2026, 37904). Two bodies of theory locate where that control rests: global value-chain governance (Gereffi, Humphrey, and Sturgeon 2005) and global production networks (Coe and Yeung 2015). Together they yield two groupings, coordination control and captive lock-in.
Control follows coordination. In a value chain, governance is explicit coordination, and the degree of coordination rises with power asymmetry. Firms at one end transact at arm’s length through the market; at the other extreme, lead firms exert power directly on their suppliers (Gereffi, Humphrey, and Sturgeon 2005, 87–88). Coordination plus asymmetry defines a lead firm, and an AI vendor with substantial control over a layer of territory is one in this sense: it sets the terms on which buyers receive compute, model access or updates. A buyer with no alternative source cannot walk away.
Lock-in by a lead firm is structural to the chain. It can be diagnosed from three variables: the complexity of the transaction, how far its terms can be codified, and the capability of the supplier (Gereffi, Humphrey, and Sturgeon 2005, 85). When a transaction is complex, its terms are codified by one side, and the other cannot readily switch, that side turns captive, facing switching costs that make exit unattractive (Gereffi, Humphrey, and Sturgeon 2005, 86–87). Gereffi’s captive party is a supplier firm; I extend the form to the state as buyer. The extension is exact where it matters. The state’s territorial sovereignty, like the supplier firm’s legal independence, is genuine and untouched, and it does not exempt the state from the vendor’s allocation decisions, update cadence and export conditions. The state keeps taxation, regulation and force; Section 3 showed what those buy. Four vendors, Anthropic, OpenAI, Google and Meta, held 86 per cent of enterprise large-language-model use by mid-2025, all under US jurisdiction (Tully et al. 2025). For a state procuring a frontier model, the choice runs to two export-control regimes (Epoch AI 2025).
Coe and Yeung specify what the lead firm’s coordination consists of. In a global production network, one globally significant lead firm holds the organisational coordination and control of the suppliers, partners and customers around it, integrating them through asymmetric corporate power (Coe and Yeung 2015, 39–41). This grounds the three coordination-control lenses. Allocation asks who decides which buyers receive scarce compute first. Operation asks who runs the live network. Visibility asks who can see and monitor it. A state that wins none of the three does not coordinate its own capability; the vendor does. The captive form grounds the four captive-lock-in lenses: updates, continuity, refresh, and step-in and exit. Table 1 gives all seven as questions answerable for any real procurement policy, with what it takes to win each.
Table 1. The seven circulation lenses
| Grouping | Lens | The circulation question | What wins the lens |
|---|---|---|---|
| Coordination control (Coe and Yeung 2015, 39–41) | Allocation | Who governs scarce compute and priority under pressure? | Reserved capacity, a public queue, or dedicated resources adequate to the workload |
| Operation | Who runs the cloud, model and security stack? | Public authority with the staff, access and technical means to direct it | |
| Visibility | Can public authority see the circulation it claims to govern? | Records, monitoring and audit rights over the stack | |
| Captive lock-in (Gereffi, Humphrey, and Sturgeon 2005, 85–88) | Updates | Who governs model, firmware and platform changes? | Maintained access, or independent capacity to maintain |
| Continuity | What happens if the vendor withdraws, suspends or is blocked? | A fallback that survives the interruption | |
| Refresh | Who governs accelerator replacement and upstream supply? | A replacement route the state controls | |
| Step-in and exit | How far, and at what cost, can the state switch or take over? | Portable assets and a usable substitute |
Source: author’s operationalisation of Coe and Yeung (2015) and Gereffi, Humphrey, and Sturgeon (2005).
The rule is explicit. A lens is won when public policy holds it for the AI capability the state’s arrangement is meant to deliver; otherwise it is held by the vendor or upstream. Control won at one layer only, or held on paper with no means to use it, is recorded as partial and counts as not won. A state wins coordination control by winning two of its three lenses, and escapes captive lock-in by winning three of its four. It holds control over circulation when it wins both groupings. A state that wins exactly one grouping is a boundary case, and the grid records it as such. The rule generates three states of the circulation axis and no more: neither grouping, one, or both. That is the resolution the lenses can support, and the figures claim no finer one.
Two features of the rule need stating. First, a majority can carry a decisive weakness. A state can escape captive lock-in on updates, continuity and exit while refresh is held abroad. That configuration is not a defect of the rule; it is the definition of the cap. Practical sovereignty is precisely governed circulation with refresh still external, which is why it sits below full-stack control. Second, the unit is the arrangement a state’s policy actually governs, and the verdict is read from the public record: statutes, frameworks, contracts and announcements. Where a state has published a partnership and not a right, the record shows the vendor holding the lens. A sovereignty claim rests on the rights a state is willing to publish.
The territory axis records the four layers separately: substrate, location, operator and accelerator. Territory is high when frontier-class AI compute is installed on the state’s soil and low otherwise; the operator and accelerator layers are reported because they bear on who holds the circulation lenses. The substrate and accelerator layers are the ceiling. Outside the United States and, in part, China, no state holds them, and the rule does not pretend otherwise. Table 2 crosses the two axes.
Table 2. The territory and circulation grid
| Low territory | High territory | |
|---|---|---|
| High control over circulation (both groupings won) | Circulation sovereignty: policy control and credible exit without a domestic frontier campus | Practical sovereignty: circulation a state governs, backed by domestic capacity, capped below full-stack control |
| Low control over circulation (neither grouping won) | Compute-desert dependence: model or API use is the whole arrangement, with no policy control over territory or circulation (Lehdonvirta, Wu, and Hawkins 2024, 834) | Sovereignty-as-a-service: significant domestic territory atop vendor-governed circulation (Grohmann and Barbosa 2026; Slobodian and Tarnoff 2026, chap. 3) |
Source: author. A state that wins exactly one grouping sits on the boundary between the rows.
Practical sovereignty rests on a managed interdependence. Existing usage treats managed interdependence loosely, as “not isolation” (Singh and Sengupta 2025, 1); I give it a specific construction: interdependence a state governs on purpose through policy rights over the circulation that serves its territory. Keohane and Nye named its complex form, Farrell and Newman its weaponised form: asymmetric networks a hub state turns against those that depend on it (Keohane and Nye 2012, 19–21; Farrell and Newman 2019, 45). Both describe interdependence a state lives within. Recent policy analysis reaches a neighbouring idea, negotiated interdependence (Barasa et al. 2026). Managed interdependence adds the rights that make it governable: the seven lenses a state can win.
The grid is a typology, and I hold it to the standards of one. A typology clarifies a concept through explicit dimensions and categorical distinctions (Collier, LaPorte, and Seawright 2012, 218–19); each lens has a condition under which control is absent, which is what keeps the concept from stretching to cover everything (Sartori 1970, 1041–42). The eight cases are a plausibility probe in Levy’s (2008, 6) sense: chosen to span the grid and to fill every cell the rule generates, not sampled to estimate an effect. What they test is the prediction of Section 4.
6. Eight States on the Grid
Each state’s position follows from its territory across the four layers and from the lens verdicts in Table 3. The eight cases fill every cell the rule generates, including the two boundary positions, and they include the United States. I place it because a cap is only legible when the ceiling is on the same grid. US dominance remains the background condition of every case that follows. Practical sovereignty is easiest for a state already holding the most compute, a concentration the framework maps and does not seek to address (Ahmed, Wahed, and Thompson 2023, 884). The cases run from the floor of the grid to its ceiling.
Table 3. Seven-lens matrix for eight states
| Lens | KEN | AUS | CAN | UAE | SUA | EU | CHN | USA |
|---|---|---|---|---|---|---|---|---|
| Allocation | V | V | W | V | W | W⁶ | W | W |
| Operation | V | W¹ | W | V | W | W⁶ | W | W |
| Visibility | V | W¹ | W | V | W | W⁶ | W | W |
| Updates | V | V | W | V | P² | P⁷ | W | W |
| Continuity | V | V | W | V | P² | P⁷ | W | W |
| Refresh | V | V | V | V | V | V | V | W³ |
| Step-in and exit | V | P¹ | W | V | V | W⁴ | W⁵ | W |
| Coordination control | 0/3 | 2/3 | 3/3 | 0/3 | 3/3 | 3/3 | 3/3 | 3/3 |
| Escape from lock-in | 0/4 | 0/4 | 3/4 | 0/4 | 0/4 | 1/4 | 3/4 | 4/4 |
| Groupings won | 0 | 1 | 2 | 0 | 1 | 1 | 2 | 2 |
| Territory | Low | Low | Low | High | High | High | High | High |
Source: author’s assessment of the public record as of 6 September 2026 (sources in Sections 6.1–6.8). Bold marks a grouping won. W = won by public policy; V = held by the vendor or upstream; P = partial, won at one layer or proposed, counts as not won. Superscripts refer to the notes.2

Figure 1. Categorical placement of the eight states
Source: author. Placement is categorical: it follows from the rule in Section 5 and Table 3 and conveys no distances within a cell. Where a cell holds two states, the state with more lenses won in Table 3 is listed first. Positions are current; states move as policy develops.
6.1 Kenya: Territory Sold, Circulation Held Abroad
Kenya occupies the compute-desert dependence cell, the floor of the grid, a cell I build from Lehdonvirta, Wu, and Hawkins’s ‘compute desert’ (2024, 834): it stands in for the compute South that hosts no AI-capable accelerator-enabled region of its own. Territory is thin at every layer. The Konza National Data Centre, its flagship public facility, was conceived with Huawei, built under a Chinese concessional loan, equipped on the vendor’s hardware, and paid for with debt to the vendor’s home state (Konza Technopolis Development Authority n.d.; Moss 2019). The facility sits on Kenyan soil; the hardware, the build and the financing behind it remain foreign. This is the pattern of digital colonialism, control held through the hardware, software and connectivity a foreign vendor and its home state supply (Kwet 2019, 4; Shonubi 2026, 12–13).
The record has moved since 2024, and it has moved along one axis. In March 2026 the National Treasury issued a request for proposals for a transaction advisor to structure the Konza National Data Centre’s cloud expansion as a public–private partnership, with the project agreement, and so the operation of the expanded facility, still to be negotiated (National Treasury 2026, sec. 5). The next layer of Kenyan territory is to be financed and developed with a private partner. A national AI accelerator programme run with the ICT ministry and UNDP offers selected teams access to AI compute at the Technopolis Development Authority (CIO Africa 2026). These are plans for territory and a public queue for what the territory will hold. They name no one who governs refresh, updates or exit, and the compute they promise is not yet installed at scale. Konza runs a government cloud; AI reaches the country through foreign APIs, so allocation and operation sit offshore. It loses coordination control. The provider holds updates, refresh and exit, so a change of terms would land with limited domestic fallback. It is caught in captive lock-in. It wins neither grouping. Kenya holds the territory it was sold, and every lever over what runs through it is held abroad. The expansion moves Kenya along the territory axis and not along the circulation axis.
6.2 Australia: One Grouping Won by Policy
Australia is the case the rule discriminates most sharply, and the case that tests it hardest. Territory is high at the location and operator layers for general-purpose cloud and thin at the frontier: it hosts multi-billion-dollar AWS and Microsoft investments, yet develops no frontier-class model and runs no leading-edge training cluster, a gap its 2025 National AI Plan adopts by choice (Egan 2026). On the territory axis it is low.
On the coordination lenses it wins two. The Hosting Certification Framework reserves its Strategic tier for providers that let the government specify ownership and control conditions (DTA 2021, 2), and its certified capabilities run to facilities, power, physical security, personnel and monitoring (DTA 2021, 5–6). Operation and visibility of the hosting layer are public by policy, which is authority ownership alone would not give. Allocation is the lens the vendor most wants, and Australia has not taken it. The framework creates no public priority over scarce AI compute; a certified provider allocates its own capacity. The one reservation is the Australian Signals Directorate’s dedicated AWS cloud, scoped to defence and intelligence workloads (Australian Government 2024), which secures allocation for that community and for no one else. Allocation is the vendor’s. Two of three: coordination control won.
On captive lock-in it wins nothing. No domestic model means no fallback, so updates and continuity are the vendor’s. Refresh is the accelerator vendor’s. Exit exists at the hosting layer, among certified providers, and nowhere at the AI layer. Zero of four. Australia wins exactly one grouping and sits on the boundary below circulation sovereignty. It is the proof that policy can win a grouping before territory is built, and the proof that one grouping is not sovereignty. The leg still to secure is the AI layer: a domestic or open-weight model it can maintain would convert updates and continuity at a stroke, and would move Australia into the cell without a single new campus.
6.3 Canada: Rights Bought Before Territory
Canada occupies the circulation sovereignty cell, and it shows what the cell means. Territory is low. Canada hosts no frontier-class training cluster. The first Sovereign AI Factory, opened by TELUS at Rimouski in September 2025 and built, owned and operated in Canada on Nvidia hardware, sold out (RCR Wireless News 2025; TELUS 2026). The 60,000-GPU British Columbia cluster that the government and TELUS are now negotiating is due to scale through 2032 (TELUS 2026; Government of Canada 2026), and the public supercomputer is promised for 2031 (ISED 2026, 11). What Canada has built first is rights.
Coordination control is won by policy. Allocation runs through a public queue: the Sovereign AI Compute Strategy’s Compute Access Fund, expanded by a further C$700 million under the June 2026 national strategy, allocates subsidised compute to Canadian firms and researchers (ISED 2026, 11, 41). Operation is a funding condition: the strategy requires that the infrastructure it finances be operated under Canadian control and Canadian law, and the Rimouski facility meets it (ISED 2026, 34; RCR Wireless News 2025). Visibility follows from the same condition. Three of three, on a base that is still being poured.
Captive lock-in is escaped at the model layer. Cohere is a frontier-adjacent model vendor under Canadian jurisdiction; its Command A weights are published (Cohere 2025), and the federal government committed up to C$240 million to a Cohere compute facility as the first act of the compute strategy (BetaKit 2024). Updates, continuity and exit are won: a domestic vendor, open weights, and domestic operators to run them on. Refresh is not. Every accelerator is imported, and the strategy’s chip-design and fabrication line is an intention (ISED 2026, 34). Three of four. Both groupings, low territory: circulation sovereignty.
Two details keep the verdict honest. The Cohere facility is being built with CoreWeave, an American operator, which drew protest from Canadian data-centre firms (BetaKit 2024): the operator layer is foreign even inside the flagship sovereign project. And the coordination wins are secured over the arrangement the strategy funds, not over the commercial cloud the hyperscalers run in Canada. Canada has won the rights and is now buying the territory to make them durable. That is the order in which this paper’s argument says a state should proceed.
6.4 The UAE: A Frontier Campus inside Someone Else’s Network
The UAE falls in the sovereignty-as-a-service cell. Grohmann and Barbosa (2026, 416) built the concept for the pattern in which sovereignty is provisioned by the platform, on the platform’s terms; Slobodian and Tarnoff (2026, chap. 3, “Chasing Uncle Sam,” para. 14) use the phrase for reliance on privately supplied sovereign functions. Territory is high at the location layer, a frontier campus, and foreign at the operator and accelerator layers. Stargate UAE is a one-gigawatt cluster with its first 200 megawatts due in 2026; G42, an Abu Dhabi firm, builds it, OpenAI and Oracle operate it, and Nvidia supplies the GB300 systems, with Cisco and SoftBank as further partners (OpenAI 2025). It loses coordination control: the operators allocate and run the cluster, and the state sees what they show it. It is caught in captive lock-in: the chips stay inside the US export-control perimeter, governed by the Regulated Technology Environment and approved under Bureau of Industry and Security guidelines (Malin 2025), so updates, refresh and continuity stay with the vendor and its home state. It loses both groupings.
The trade is explicit. The emirate supplies energy, capital and siting, and in return is integrated into US techno-economic networks as a node for American firms to offer “compute as a service” (Soliman 2025, 4). The contractual terms are not public. That is a finding, not a gap. A state that publishes a partnership and not a right has told the grid where the rights sit. The seat buys standing in the network to negotiate from within captive terms. The open leg is circulation, which policy could reach without new territory.
6.5 Saudi Arabia: The Same Chips, a Different Operator
Saudi Arabia is the UAE’s control case. The chips are the same: both campuses run on Nvidia’s GB300 systems, and the November 2025 authorisations of up to 35,000 chips to each state’s champion carry the same security and reporting conditions (Malin 2025; OpenAI 2025). The export-control perimeter is the same. The row is different because the operator is different: OpenAI and Oracle operate Stargate UAE, and the Saudi operator is the state. HUMAIN, launched by the Public Investment Fund in May 2025 and chaired by the Crown Prince, absorbed the kingdom’s model-development team and builds, owns and operates its own campuses: two under construction at Riyadh and Dammam with initial capacities of up to 100 megawatts each, within a plan for eleven 200-megawatt centres (CNBC 2025; Capacity 2026). Territory is high at the location layer and, unlike Stargate UAE, domestic at the operator layer.
Coordination control is therefore won as China’s is, through a state whose relation to the operator is ownership. HUMAIN allocates its own capacity, runs its own network and answers to the fund that owns it. Three of three.
Captive lock-in is not escaped. The first tranche of 18,000 Blackwell chips, and the 35,000 approved after it, arrive under US licence and US conditions (Capacity 2026; Malin 2025). HUMAIN’s chief executive describes US government approval as a formality the company will go through (Capacity 2026), which is an exact description of who holds refresh. The model layer is partly domestic, ALLaM and HUMAIN Chat, and partly rented, with xAI’s Grok under a framework agreement and Groq’s inference hardware in the kingdom (CNBC 2025); updates and continuity are partial. Exit is the vendors’. One grouping won: boundary, high territory.
The pair is the framework’s cleanest natural experiment. Two Gulf states buy the same American chips inside the same American perimeter. One hands the campus to foreign operators and lands in sovereignty-as-a-service; the other owns the operator and wins a grouping. The difference between them is the operator, which is to say who governs the circulation the chips run inside.
6.6 The European Union: One Grouping Won on Public Compute
The European Union is the case the grid is most likely to be read against, so I state the verdict and its basis plainly. Territory is high: the Union hosts frontier-class compute, public and private. JUPITER, inaugurated at Jülich on 5 September 2025 as Europe’s first exascale system, is fully owned by the EuroHPC Joint Undertaking, hosted by a public research centre and equipped with about 24,000 Nvidia GH200 superchips (EuroHPC JU 2025). Its location and operator layers are European. Its accelerator layer is American, as every case’s is.
Coordination control is won over the arrangement the Union’s policy funds, on the standard Section 6.3 applied to Canada. Allocation runs through a public queue: access to JUPITER and the other EuroHPC systems is granted through the EuroHPC access calls, and the AI Factories built around them give start-ups and small firms a route to that compute (EuroHPC JU 2025; European Commission 2025a, 4–5). Operation and visibility follow from public ownership and public hosting. Three of three. The commercial cloud is another matter. Three non-EU hyperscalers hold over 70 per cent of the Union’s cloud market (European Commission 2026b, explanatory memorandum), and the public right over allocation and operation there is still a proposal in the Cloud and AI Development Act, as is the common assessment framework that would give the Union sight of what it hosts (European Commission 2026b). A proposal is partial and counts as not won. The coordination win is real and it is bounded: it covers the compute the Union owns, and it stops at the market the hyperscalers run.
Captive lock-in is not escaped. The Data Act has applied since 12 September 2025; its Chapter VI governs switching between data-processing services, permits only reduced switching charges in the transition and prohibits them from 12 January 2027 (European Parliament and Council 2023, arts. 23–30, 50). Exit is a public right in law. Updates and continuity are partial. Open-weight vendors exist under member-state jurisdiction, Mistral among them (Mistral AI 2025), and the Action Plan sets European models as an aim of the AI Factories (European Commission 2025a, 2, 7); the Union’s own arrangement has not adopted a domestic model as Canada’s compute strategy adopted Cohere. Refresh is the vendor’s: the Union makes about ten per cent of the world’s chips, a gap the European Chips Act and a planned successor address (European Commission 2026a, 3). One of four. One grouping won, high territory: the boundary, level with Saudi Arabia.
The two boundary cases won the same grouping by different routes. Saudi Arabia won coordination through a state-owned operator; the Union won it through public ownership of the machines and a public queue. Both hold a domestic model effort short of the frontier, and both refresh on American chips. Grohmann and Barbosa built their concept for the Union’s commercial cloud, where regulatory pressure is answered by branded sovereign clouds configured and sold by the firms sovereignty was meant to be exercised over (2026, 416–18); that market is still theirs. The Commission grades its own exit lever insufficient on its own, the Data Act opening the path without building the road toward a sovereign EU cloud sector (European Commission 2026b, 3). It is right, and the rights CADA would create over allocation and operation would extend the coordination the Union holds over its public compute to the market it does not govern, and the exit right the Data Act already gives is the first lock-in lens on the way out. Policy is closing the gap that infrastructure has not.
6.7 China: Both Groupings Won, Capped at Refresh
China shows what winning both groupings looks like, and where the cap sits. Territory is high at the location and operator layers (Lehdonvirta, Wu, and Hawkins 2024, 831). Coordination control is held at home: the operators are Chinese firms subject to a state whose relation to them is not arm’s-length, and allocation, operation and visibility follow (Lehdonvirta, Wu, and Hawkins 2025, 1444–46; Yang 2025, 262). Three of three.
Captive lock-in is escaped at the model layer. The OpenAI block of mid-2024 (Chen 2024) was answered with R1, Qwen3 and GLM-5.2 (DeepSeek-AI 2025; Qwen Team 2025; Zhipu AI 2026): open weights, domestically produced, several substitutes deep. Updates, continuity and exit are won. Yang (2025, 261–62) reads the open-weight turn as an instrument of the state’s cyber-sovereignty project, and that is the right reading: openness here is a circulation strategy, not a concession. Refresh is not won. US export controls deny the most advanced chips (BIS 2023, 73474, 73493); the January 2026 shift to case-by-case licensing of the H200 (BIS 2026) confirms who holds the lever by moving it; domestic substitutes remain lower-quality (Srnicek 2025, “An Interregnum,” conclusion, para. 9). Three of four.
Both groupings won, refresh external: practical sovereignty, capped below the full stack by the US-controlled accelerator and tooling layer. Whether that control is exercised for citizens is Section 8’s question, and the answer there is not the answer here.
6.8 The United States: The Ceiling
The United States is the ceiling every other case is capped below, and I place it on the grid so the cap can be read. Territory is high at every layer. It hosts the leading cloud operators and the model vendors that held 86 per cent of enterprise use in mid-2025 (Tully et al. 2025); its accelerator vendor holds 92 per cent of the GPU market (Srnicek 2025, “The Generative AI Stack,” para. 2); and it writes the export-control law every other case runs within (BIS 2023, 2026). Fabrication, the last foreign layer, began closing when Blackwell reached volume production at TSMC’s Arizona fab in 2025 (Deutscher 2025).
All seven lenses are won, and the seventh is the one no other state holds. Allocation, operation and visibility are exercised over vendors that answer to US law; the Fable and Mythos directive of June 2026 is the US government allocating a circulation it does not own (Anthropic 2026). Updates, continuity and exit follow from hosting the vendors. Refresh is won because the United States governs the refresh it denies to others: the licensing lever that moved for China in October 2023 and January 2026 is a US lever (BIS 2023, 2026). Seven of seven. Practical sovereignty at the full stack, the only case in the top-right cell without a cap.
The ceiling is not autarky. Advanced packaging still runs through Taiwan and TSMC’s US build-out is in progress (TSMC 2025); the EUV lithography beneath every leading-edge fab comes from a Dutch firm (Barczentewicz 2026), one the United States reaches through the same network dependencies it uses on everyone else (Beaumier and Cartwright 2024, 4, 14). The United States holds refresh from the hub of the network that makes its chips, with much of the making abroad (Farrell and Newman 2019, 45). That is what full-stack control looks like in practice: governed circulation all the way down.
7. The Argument: Sovereignty Follows Circulation
The eight cases share one structure. Kenya hosts a facility and governs none of its circulation. The UAE hosts frontier accelerators and governs none of its circulation. Saudi Arabia hosts the same accelerators, owns the operator, and governs half. The EU hosts frontier compute, governs the public share of it, and is legislating to govern the rest. Australia hosts a thin base and governs half its circulation by policy. Canada hosts a thinner base and governs its circulation by policy and a domestic vendor. China hosts a deep base and governs its circulation down to the accelerator. The United States governs the accelerator too. Read together, the same test decides each case: whether the state governs the circulation its infrastructure depends on, which is to say whether its capability would survive the shocks of Section 4. Where a state governed circulation, holding territory delivered sovereignty. Where it did not, holding territory delivered a building.
It follows that sovereign-AI procurement raises a state’s sovereignty only when it increases control over circulation. A purchase can leave the vendor holding allocation, updates and exit. It changes what the state owns. It leaves what the state governs untouched. The state acquires an asset and calls it sovereignty. This is how dependence is repackaged. Domestic territory and a sovereign label deliver no power over the two circulation groupings, coordination control and captive lock-in. Instead they reproduce an old structural-power pattern: dependence on a foreign vendor dressed as independence. The pattern holds because formal sovereignty and substantive dependence coexist without strain, and it now has a sales channel. Grohmann and Barbosa call it discursive capture: the concept emptied and sold back to the state under its own name (2026, 416).
Even though control over circulation determines sovereignty, territory is not worthless. Domestic infrastructure confers real control over the assets a state hosts. It gives jurisdiction over what is located on its soil, security review, resilience against disruption, and weight at the bargaining table (DSIT 2025, sec. 1.1; Hawkins, Lehdonvirta, and Wu 2025, 12–14). Territory is the base beneath control over circulation. It makes that control durable and harder for a vendor to reverse. It gives a state something concrete to trade. However, territory cannot stand in for governance. A state can own a data centre. The vendor still decides what runs on it. This is why the two axes do different work. Territory is the axis of durability and bargaining weight; it raises what a state can protect and what it can offer. Control over circulation is the axis sovereignty tracks, and a state can win half of it on a thin domestic base, as Australia has.
A state may reasonably want a degree of sovereignty short of the maximum. It can trade control over circulation for access. My framework describes that choice and does not dictate it. For a state that does pursue sovereignty, the ceiling is fixed by a layer it cannot reach in the near term: full-stack control that runs down to fabrication, the substrate. Below that ceiling lies practical sovereignty, the circulation a state governs, backed by enough territory to make that governance durable. Control over circulation turns hosted infrastructure into capability a government directs. Winning that conversion is what a sovereign-AI policy is for. Practical sovereignty is not full independence. It is the most an AI-territory capacity can buy for every state but one, and it is a near-term promise a state can keep.
8. Whom Sovereignty Is For
The seven lenses answer who can act on a dependency. They do not answer whose interests the action serves. A state can win allocation and direct scarce compute away from public research. It can win visibility and use it to watch its population. It can win operation over a model and use it to decide what the model may say. Mügge distinguishes the ambition to strengthen a jurisdiction from the ambition to give citizens authority over the development and use of AI, and finds the EU strategy he examined built for the first and silent on the second (Mügge 2024, 2206–7, 2211). I raised his question in the introduction and I answer it here. State control over circulation is necessary for AI sovereignty. Whom that control serves is a separate question, and the same lenses can answer it. The two can come apart completely, and the case in which they come apart furthest is the case that scores highest on the grid.
The lenses can be turned inward, on the relationship between a state and its citizens. Allocation asks which public needs receive scarce compute and who can contest the priorities; a state that wins allocation from a vendor and hands it to a ministry has changed who decides, and whether anyone can be heard is the citizen’s half of the lens. Operation asks who runs the systems that decide access to welfare, education, housing and justice. Visibility cuts both ways: public sight of administration is one exercise, state sight of a population is another, and the same lens scores both. Updates is the power to change a public system’s behaviour; citizens need notice and a route to challenge consequential changes, and a model whose behaviour shifts overnight is unaccountable whoever pushed the update. Continuity is the citizen’s right to the underlying service when the AI fails; a sovereign model that goes dark should not take the benefits office with it. Refresh is the continuing public cost of the capability, in money and in the labour and materials Crawford traces beneath it (2021, 31–33); Kenya’s refresh is financed by debt to the vendor’s home state, and that is a citizen’s bill. Step-in and exit ask whether a person can obtain review or an alternative route, and requiring a citizen to accept an AI decision as the price of an essential service empties exit of meaning at the level where it matters most.
My normative position is direct. Publicly financed sovereignty should expand citizens’ capacity to shape and contest the systems that govern them, protect their access to essential services through interruption, and put its benefits and costs to public scrutiny, including the costs borne by workers and territories outside the procuring state. Mügge’s beneficiary question does not stop at the border. A state may choose external dependence to obtain a capability its citizens need. Ukraine did, and its citizens kept their registers. That choice is legitimate when the state has clear purpose, names the dependency and shows the fallback. Managed interdependence earns its public justification through those practices. A sovereign label bought on territory alone supplies none of them.
9. Objections and Replies
A critic who does not accept my interpretation of sovereignty will object that physical control of chips and data centres on national soil is the strongest form of sovereign control there is. A host state has hard powers inside its borders: it can inspect facilities, seize hardware, and cut the power and network a facility needs to run. In this view, possession beats paperwork. A vendor’s allocation and update rights are contractual, and a determined host can override them by force of law. A sovereign campus can also run a model it already holds on its own soil, and resident weights keep serving inference even when the vendor stops updating them. Control over circulation is a merely contractual paper right.
The reply is the one Section 4 established: location and control have come apart, and seizure of a model is the test. A seized model runs on without updates or security fixes, on accelerators no vendor will refresh. Section 3 adds that force is the wrong modality: it acts on the territory, and the circulation is not there. There is one case where seizure converts territorial power into durable capability. Where the model is open-weight, the state holds the technical staff to maintain it, and the accelerator base can be refreshed at home, a host that seizes resident hardware can keep the system running and improving on its own terms. That case genuinely qualifies my position, and it qualifies it in a way I accept: territorial investment can be the act that creates the capacities the thesis requires. No state has yet run the seizure case. China comes closest without seizure, pairing open weights with a domestically refreshed accelerator base that is still lower-quality than the one export controls deny it (Section 6). Where the weights are closed or the accelerators cannot be refreshed at home, the ageing-weights problem returns. Sovereign control by “reducing reliance on foreign providers” (European Commission 2026b, 2026c) still requires control over the circulation that produces model updates and hardware refresh.
A second objection attacks the argument’s form. If control over circulation is whatever keeps capability running, then any capability that survives a shock will be redescribed as controlled circulation, and the thesis cannot fail. The reply is that the lenses are fixed before the shock and the outcome is observed after it. Table 1 names the seven controls and what wins each. Table 3 codes each case on the public record as it stands. The thesis then predicts which arrangements survive a vendor’s action, and three findings would break it. First, arrangements coded vendor-held that repeatedly keep their functions through vendor withdrawal and hardware replacement without acquiring new controls; frozen-model deployments on stable tasks are where to look, over the horizon the procurement promised. Second, arrangements that win both groupings and fail through a single uncovered lens; that would show the majority rule aggregating badly, and the fix would be to make that lens a necessary condition, as I already treat refresh. Third, domestic assets alone predicting continuity across matched disruptions while the circulation verdicts add nothing; that would favour the territorial reading within the tested scope. None has been observed, and the four shocks in Section 4 ran the other way. An unexpected survival under vendor-held circulation would stay an unexpected survival. It would not become a control after the fact.
The third objection attacks the measure. The framework counts chokepoint capacity as sovereign control, yet control of a chokepoint can be soft: its holder may lack the ability or the will to enforce it. Dutch control of ASML, the only producer of the EUV lithography systems on which leading-edge chipmaking depends (Barczentewicz 2026), yields only what Rogers (2026, 26) calls ‘soft sovereignty’: recognition of authority with limited actual leverage. On this view the framework overstates sovereignty wherever it scores a capacity the state never exercises.
The reply is that this restates my argument’s own condition. Coercion through a circulation requires two things: jurisdiction over a hub, and the institutional capacity to use it (Farrell and Newman 2019, 56–57; Drezner, Farrell, and Newman 2021, 32). The ASML case fails the second. The Dutch hold the hub but cannot wield it alone, because ASML is dependent all the way down on US licences, components and software (Rogers 2026, 26), and the United States can connect dependencies across the semiconductor network to reach it (Beaumier and Cartwright 2024, 4, 14). A lens is won when policy holds it and can use it; a hub that cannot be used alone is not a won lens, and the matrix would not score it as one. Where a holder could enforce a chokepoint but declines for wider strategic reasons is a separate case. My framework measures circulation power capacity. Discretion to use it is a state’s choice.
10. Conclusion: Practical Sovereignty as Managed Interdependence
The controversy asked what delivers AI sovereignty: hosting AI domestically or controlling its circulation. This paper’s contribution is the framework and the test it now carries. I carried Foucault’s distinction into AI sovereignty, resolved sovereign control into the coordination-control and captive-lock-in groupings a state must win, built the grid that locates any state’s procurement on two axes, and set the prediction that decides between the territorial and circulation readings. Four shocks since 2024 illustrate the framework. The territorial view keeps Weber’s warrant, and Ukraine and Han mark where it stops: force reaches territory and leaves circulation untouched. Territory delivers sovereignty when it comes with control over circulation. Procurement without that control repackages dependence as sovereignty, and the hyperscalers now sell the repackaging under the concept’s own name. The realistic maximum for all but the largest compute powers is practical sovereignty: the circulation a state governs, capped below the full stack only a hegemon holds, a managed interdependence.
Control has a second measure. The seven lenses that record what a state holds against a vendor also record what its citizens hold against the state, and a publicly financed sovereignty can be held to that measure.
The grid is a political-economy instrument that can be extended. Apply the lenses, on the public record, to any state’s procurement, and it returns a cell, the lenses that put it there and the lenses that would move it. The stakes are the national budgets now being allocated. A state buying territory without policy rights buys the appearance of sovereignty at full price. A state that buys the rights without asking whom they serve has bought sovereignty for itself and called it sovereignty for its people.
References
Ahmed, Nur, Muntasir Wahed, and Neil C. Thompson. 2023. “The Growing Influence of Industry in AI Research.” Science 379 (6635): 884–86. https://doi.org/10.1126/science.ade2420.
Anthropic. 2026. “Statement on the US Government Directive to Suspend Access to Fable 5 and Mythos 5.” June 12, 2026. https://www.anthropic.com/news/fable-mythos-access.
Aradau, Claudia, and Tobias Blanke. 2010. “Governing Circulation: A Critique of the Biopolitics of Security.” In Security and Global Governmentality: Globalization, Governance and the State, edited by Miguel de Larrinaga and Marc G. Doucet, 44–58. London: Routledge. Citations refer to the accepted manuscript, https://kclpure.kcl.ac.uk/portal/files/58161530/Governing_circulation_ARADOU_Published_2010_GREEN_AAM.pdf.
Ashraf, Afzal, and Vito Veneziano. 2026. “AI Sovereignty without Power? Reviewing Strategic Agency, Infrastructural Dependence and Digital Imperialism.” AI & Society. Published online June 16, 2026. https://doi.org/10.1007/s00146-026-03116-4.
Australian Government. 2024. “Australian Government Partners with Amazon Web Services to Bolster National Defence and Security.” Minister for Defence, media release, July 4, 2024.
Barasa, Hilda, Peichin Tay, Keegan McBride, Alexander Iosad, and Jakob Mökander. 2026. “Sovereignty in the Age of AI: Strategic Choices, Structural Dependencies and the Long Game Ahead.” Tony Blair Institute for Global Change, January 19, 2026. https://institute.global/insights/tech-and-digitalisation/sovereignty-in-the-age-of-ai-strategic-choices-structural-dependencies.
Barczentewicz, Mikołaj. 2026. “Europe’s Sovereignty Stack: CADA, Compute, and the Limits of Autarky.” ICLE Issue Brief, June 15. International Center for Law & Economics. https://laweconcenter.org/resources/europes-sovereignty-stack-cada-compute-and-the-limits-of-autarky/.
BetaKit. 2024. “Cohere Secures Federal Backing to Build Multibillion-Dollar Canadian AI Data Centre.” December 6, 2024. https://betakit.com/?p=380588.
Beaumier, Guillaume, and Madison Cartwright. 2024. “Cross-Network Weaponization in the Semiconductor Supply Chain.” International Studies Quarterly 68 (1): sqae003. https://doi.org/10.1093/isq/sqae003.
BIS (Bureau of Industry and Security). 2023. “Implementation of Additional Export Controls: Certain Advanced Computing Items; Supercomputer and Semiconductor End Use; Updates and Corrections.” Federal Register 88 (205): 73458–517. https://www.federalregister.gov/documents/2023/10/25/2023-23055/implementation-of-additional-export-controls-certain-advanced-computing-items-supercomputer-and.
BIS (Bureau of Industry and Security). 2026. “Department of Commerce Revises License Review Policy for Semiconductors Exported to China.” Press release, January 13, 2026. https://bis.gov/press-release/department-commerce-revises-license-review-policy-semiconductors-exported-china.
Cabinet of Ministers of Ukraine. 2022a. “Some Issues of Ensuring the Functioning of Information and Communication Systems, Electronic Communication Systems and Public Electronic Registers under Martial Law.” Resolution 263, March 12, 2022. In Ukrainian. https://zakon.rada.gov.ua/laws/show/263-2022-п.
Cabinet of Ministers of Ukraine. 2022b. “Ministry of Digital Transformation: Amazon Web Services Supports Ukraine with USD 75 Million for Cloud Technologies to Help the Digital State and Economy Work Stably.” December 1, 2022.
CNBC. 2025. “Saudi AI Firm Humain Is Pouring Billions into Data Centers. Will It Pay Off?” August 27, 2025. https://www.cnbc.com/2025/08/27/saudi-arabia-wants-to-be-worlds-third-largest-ai-provider-humain.html.
Cohere. 2025. “Introducing Command A: Max Performance, Minimal Compute.” Cohere blog, March 13, 2025. https://cohere.com/blog/command-a.
CIO Africa. 2026. “Kenya Opens Call for High-Impact AI Use Cases.” Accessed September 5, 2026. https://cioafrica.co/kenya-opens-call-for-high-impact-ai-use-cases/.
Clark, Lindsay. 2026. “Microsoft Throws Spox under the Bus after Parliament Testimony on ICC Email Kerfuffle.” The Register, February 18, 2026. https://www.theregister.com/2026/02/18/microsoft_asks_uk_parliament_to_correct_record/.
Capacity. 2026. “How Humain Plans to Use US Chips in New Saudi Arabia AI Data Centres.” Capacity, January 14, 2026. https://capacityglobal.com/news/humain-data-centre-construction-saudi-arabia/.
Chen, Wency. 2024. “Tech War: OpenAI to Further Block Access by Mainland China, Hong Kong-Based Developers.” South China Morning Post, June 25, 2024. Archived July 5, 2024, at https://web.archive.org/web/20240705065416/https://www.scmp.com/tech/policy/article/3267971/tech-war-openai-further-block-access-mainland-china-hong-kong-based-developers.
Cobbe, Jennifer, and Jatinder Singh. 2021. “Artificial Intelligence as a Service: Legal Responsibilities, Liabilities, and Policy Challenges.” Computer Law & Security Review 42: 105573. https://doi.org/10.1016/j.clsr.2021.105573.
Cobbe, Jennifer, Michael Veale, and Jatinder Singh. 2023. “Understanding Accountability in Algorithmic Supply Chains.” In Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency, 1186–97. New York: Association for Computing Machinery. https://doi.org/10.1145/3593013.3594073.
Cochrane, Tim. 2022. “Hiding in the Eye of the Storm Cloud: How CLOUD Act Agreements Expand U.S. Extraterritorial Investigatory Powers.” Duke Journal of Comparative & International Law 32 (1): 153–210. https://scholarship.law.duke.edu/djcil/vol32/iss1/4.
Coe, Neil M., and Henry Wai-chung Yeung. 2015. Global Production Networks: Theorizing Economic Development in an Interconnected World. Oxford: Oxford University Press.
Collier, David, Jody LaPorte, and Jason Seawright. 2012. “Putting Typologies to Work: Concept Formation, Measurement, and Analytic Rigor.” Political Research Quarterly 65 (1): 217–32. https://doi.org/10.1177/1065912912437162.
CompaniesMarketCap. 2026a. “Alphabet (Google) (GOOG) – Market Capitalization.” Accessed July 6, 2026. https://companiesmarketcap.com/alphabet-google/marketcap/.
CompaniesMarketCap. 2026b. “Meta Platforms (META) – Market Capitalization.” Accessed July 6, 2026. https://companiesmarketcap.com/meta-platforms/marketcap/.
Couldry, Nick, and Ulises A. Mejias. 2021. “The Decolonial Turn in Data and Technology Research: What Is at Stake and Where Is It Heading?” Information, Communication & Society 26 (4): 786–802. https://doi.org/10.1080/1369118X.2021.1986102.
Couture, Stéphane, and Sophie Toupin. 2019. “What Does the Notion of ‘Sovereignty’ Mean When Referring to the Digital?” New Media & Society 21 (10): 2305–22. https://doi.org/10.1177/1461444819865984.
Crawford, Kate. 2021. Atlas of AI: Power, Politics, and the Planetary Costs of Artificial Intelligence. New Haven: Yale University Press.
Daskal, Jennifer C. 2015. “The Un-Territoriality of Data.” Yale Law Journal 125 (2): 326–98. https://yalelawjournal.org/article/the-un-territoriality-of-data.
DeepSeek-AI. 2025. “DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.” arXiv preprint arXiv:2501.12948, January 22, 2025. https://arxiv.org/abs/2501.12948.
Deutscher, Maria. 2025. “Nvidia Begins Volume Production of Blackwell Chips in TSMC’s Arizona Fab.” SiliconANGLE, October 17, 2025. https://siliconangle.com/2025/10/17/nvidia-begins-volume-production-blackwell-chips-tsmcs-arizona-fab/.
Donnelly, Shawn, Ricardo Ríos Camacho, and Sebastian Heidebrecht. 2024. “Digital Sovereignty as Control: The Regulation of Digital Finance in the European Union.” Journal of European Public Policy 31 (8): 2226–49. https://doi.org/10.1080/13501763.2023.2295520.
dos Santos, Theotonio. 1970. “The Structure of Dependence.” American Economic Review 60 (2): 231–36.
Drezner, Daniel W., Henry Farrell, and Abraham L. Newman, eds. 2021. The Uses and Abuses of Weaponized Interdependence. Washington, DC: Brookings Institution Press.
DSIT (Department for Science, Innovation and Technology). 2025. AI Opportunities Action Plan. January 13, 2025. https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan.
DTA (Digital Transformation Agency). 2021. Hosting Certification Framework. Version 2. Whole of Government Hosting Strategy. Canberra: Commonwealth of Australia. https://www.hostingcertification.gov.au/sites/default/files/2021-11/Hosting%20Certification%20Framework%20-%20March%202021.v2.pdf.
Egan, Janet. 2026. “Data Centres Are Australia’s Chance to Shape AI’s Future.” The Strategist (Australian Strategic Policy Institute), March 30, 2026. https://www.aspistrategist.org.au/data-centres-are-australias-chance-to-shape-ais-future/.
Epoch AI. 2025. “Over 30 AI Models Have Been Trained at the Scale of GPT-4.” Data Insights. Updated June 2025. https://epoch.ai/data-insights/models-over-1e25-flop.
EuroHPC JU (European High Performance Computing Joint Undertaking). 2025. “JUPITER: Launching Europe’s Exascale Era.” Press release, September 5, 2025. https://eurohpc-ju.europa.eu/jupiter-launching-europes-exascale-era-2025-09-05_en.
European Commission. 2025a. AI Continent Action Plan. April 2025. https://digital-strategy.ec.europa.eu/en/library/ai-continent-action-plan.
European Commission. 2026a. “Communication on European Tech Sovereignty, Accompanied by an EU Open Source Strategy.” COM(2026) 503 final. June 3, 2026. https://digital-strategy.ec.europa.eu/en/library/communication-european-tech-sovereignty-accompanied-eu-open-source-strategy.
European Commission. 2026b. “Proposal for the Cloud and AI Development Act (CADA).” COM(2026) 502 final. June 3, 2026. https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada.
European Commission. 2026c. “Strengthening Europe’s Tech Sovereignty.” Shaping Europe’s Digital Future, June 3, 2026. https://digital-strategy.ec.europa.eu/en/policies/eu-tech-sovereignty.
European Parliament and Council. 2023. Regulation (EU) 2023/2854 of 13 December 2023 on Harmonised Rules on Fair Access to and Use of Data (Data Act). Official Journal of the European Union, December 22, 2023. https://eur-lex.europa.eu/eli/reg/2023/2854/oj.
Farrell, Henry, and Abraham L. Newman. 2019. “Weaponized Interdependence: How Global Economic Networks Shape State Coercion.” International Security 44 (1): 42–79. https://doi.org/10.1162/isec_a_00351.
Floridi, Luciano. 2020. “The Fight for Digital Sovereignty: What It Is, and Why It Matters, Especially for the EU.” Philosophy & Technology 33 (3): 369–78. https://doi.org/10.1007/s13347-020-00423-6.
Foucault, Michel. 2007. Security, Territory, Population: Lectures at the Collège de France, 1977–78. Translated by Graham Burchell. Basingstoke: Palgrave Macmillan.
Gereffi, Gary, John Humphrey, and Timothy Sturgeon. 2005. “The Governance of Global Value Chains.” Review of International Political Economy 12 (1): 78–104. https://doi.org/10.1080/09692290500049805.
Government of Canada. 2026. “Government of Canada and TELUS Advance Work to Build Sovereign AI Infrastructure.” News release, May 11, 2026. https://www.canada.ca/en/innovation-science-economic-development/news/2026/05/government-of-canada-and-telus-advance-work-to-build-sovereign-ai-infrastructure.html.
Grohmann, Rafael, and Alexandre Costa Barbosa. 2026. “Sovereignty-as-a-Service: How Big Tech Companies Co-opt and Redefine Digital Sovereignty.” Media, Culture & Society 48 (2): 416–24. First published online November 11, 2025. https://doi.org/10.1177/01634437251395003.
Han, Byung-Chul. 2017. Psychopolitics: Neoliberalism and New Technologies of Power. Translated by Erik Butler. London: Verso.
Hawkins, Zoe Jay, Vili Lehdonvirta, and Boxi Wu. 2025. “AI Compute Sovereignty: Infrastructure Control across Territories, Cloud Providers, and Accelerators.” SSRN Working Paper 5312977, June 20, 2025. https://doi.org/10.2139/ssrn.5312977.
House of Commons Business and Trade Committee. 2026. “Oral Evidence: UK Trade Deal with the US, India and EU, HC 996.” February 10, 2026. Questions 332–33. https://parliamentlive.tv/event/index/76c1f031-30d1-4a86-a27b-95e6acb7315e.
ISED (Innovation, Science and Economic Development Canada). 2026. AI for All: Canada’s National Artificial Intelligence Strategy. June 4, 2026. https://ised-isde.canada.ca/site/ised/sites/default/files/documents/ai-strategy-en.pdf.
Keohane, Robert O., and Joseph S. Nye. 2012. Power and Interdependence. 4th ed. Boston: Longman.
Konza Technopolis Development Authority. n.d. “Konza Cloud.” Accessed June 29, 2026. https://konza.go.ke/konza-cloud/.
Kwet, Michael. 2019. “Digital Colonialism: US Empire and the New Imperialism in the Global South.” Race & Class 60 (4): 3–26. https://doi.org/10.1177/0306396818823172.
Lehdonvirta, Vili, Boxi Wu, and Zoe Hawkins. 2024. “Compute North vs. Compute South: The Uneven Possibilities of Compute-Based AI Governance around the Globe.” Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society 7 (1): 828–38. https://doi.org/10.1609/aies.v7i1.31683.
Lehdonvirta, Vili, Boxi Wu, and Zoe Hawkins. 2025. “Weaponised Interdependence in a Bipolar World: How Economic Forces and Security Interests Shape the Global Reach of US and Chinese Cloud Data Centres.” Review of International Political Economy 32 (5): 1442–67. https://doi.org/10.1080/09692290.2025.2489077.
Levy, Jack S. 2008. “Case Studies: Types, Designs, and Logics of Inference.” Conflict Management and Peace Science 25 (1): 1–18. https://doi.org/10.1080/07388940701860318.
Lingsma, Tjitske. 2026. “How Sanctions Can Weaponize US Tech against the ICC.” Justice Info, March 19, 2026. https://www.justiceinfo.net/en/156691-how-sanctions-can-weaponize-us-tech-against-the-icc.html.
Malin, Carrington. 2025. “US Approves up to 70,000 Advanced AI Chips for G42, HUMAIN.” Middle East AI News, November 19, 2025. https://www.middleeastainews.com/p/us-approves-up-to-70000-advanced.
Malkin, Anton, and Tim He. 2024. “The Geoeconomics of Global Semiconductor Value Chains: Extraterritoriality and the US–China Technology Rivalry.” Review of International Political Economy 31 (2): 674–99. https://doi.org/10.1080/09692290.2023.2245404.
Mistral AI. 2025. “Mistral Small 3.” Mistral AI news, January 30, 2025. https://mistral.ai/news/mistral-small-3.
Moss, Sebastian. 2019. “Huawei to Build Konza Data Center and Smart City in Kenya, with Chinese Concessional Loan.” Data Center Dynamics, April 30, 2019. https://www.datacenterdynamics.com/en/news/huawei-build-konza-data-center-and-smart-city-kenya-chinese-concessional-loan/.
National Treasury (Kenya). 2026. Request for Proposals: Transaction Advisory Services for the Konza Cloud Expansion and Smart City Facilities. RFP No. PPPD/O&S/RFP/05/2025-2026. Nairobi: State Department for Public Investments and Assets Management, March 16, 2026. https://pppkenya.go.ke/wp-content/uploads/2020/07/RFP-TRANSACTION-ADVISORY-SERVICES-FOR-THE-KONZA-CLOUD-EXPANSION-AND-SMART-CITY-FACILITIES.pdf.
Mueller, Milton L. 2020. “Against Sovereignty in Cyberspace.” International Studies Review 22 (4): 779–801. https://doi.org/10.1093/isr/viz044.
Mügge, Daniel. 2024. “EU AI Sovereignty: For Whom, to What End, and to Whose Benefit?” Journal of European Public Policy 31 (8): 2200–25. https://doi.org/10.1080/13501763.2024.2318475.
Murphy, Hannah, and Stephen Morris. 2026. “Google Caps Meta’s Gemini Use as AI Demand Strains Capacity.” Financial Times, June 27, 2026. https://www.ft.com/content/c5d52f72-71ef-40bc-bad3-61afdba8b378.
Nvidia. 2024. “What Is Sovereign AI?” Nvidia Blog, February 28, 2024. https://web.archive.org/web/20240926171129/https://blogs.nvidia.com/blog/what-is-sovereign-ai/.
OpenAI. 2025. “Introducing Stargate UAE.” May 22, 2025. https://openai.com/index/introducing-stargate-uae/.
Pava, Juan N., Caroline Meinhardt, Elena Cryst, and James A. Landay. 2026. “AI Sovereignty’s Definitional Dilemma.” Stanford Institute for Human-Centered AI (HAI), February 17, 2026. https://hai.stanford.edu/news/ai-sovereigntys-definitional-dilemma.
Pohle, Julia, and Thorsten Thiel. 2020. “Digital Sovereignty.” Internet Policy Review 9 (4). https://doi.org/10.14763/2020.4.1532.
Qwen Team. 2025. “Qwen3 Technical Report.” arXiv preprint arXiv:2505.09388, May 14, 2025. https://arxiv.org/abs/2505.09388.
RCR Wireless News. 2025. “Telus Launches Canada’s First Sovereign AI Factory.” September 26, 2025. https://rcrwireless.com/20250926/ai-infrastructure/telus-ai-factory.
Roberts, Huw. 2024. “Digital Sovereignty and Artificial Intelligence: A Normative Approach.” Ethics and Information Technology 26 (4): 70. https://doi.org/10.1007/s10676-024-09810-5.
Robinson, Dan. 2025. “International Criminal Court Kicks Microsoft Office to the Curb.” The Register, October 31, 2025. https://www.theregister.com/2025/10/31/international_criminal_court_ditches_office/.
Rogers, Dylan. 2026. “Soft Sovereignty: The Limits of Middle Power Leverage and the Semiconductor Supply Chain.” SSRN Working Paper 6511318, April 2, 2026. https://ssrn.com/abstract=6511318.
Sartori, Giovanni. 1970. “Concept Misformation in Comparative Politics.” American Political Science Review 64 (4): 1033–53. https://doi.org/10.2307/1958356.
Seferis, Emmanouil, and Tim Fist. 2026. “Detecting Compute Structuring in AI Governance Is Likely Feasible.” Proceedings of the AAAI Conference on Artificial Intelligence 40 (44): 37904–12. https://doi.org/10.1609/aaai.v40i44.41127.
Shonubi, Ololade A. 2026. “The Open-Source Paradox: Africa’s Digital Sovereignty and the Structural Limits of Artificial Intelligence Autonomy.” AI & Innovation, e70004. https://doi.org/10.1002/aiv2.70004.
Shrivastava, Swarnim. 2026. “Rethinking Sovereign AI as Strategy.” Tech Policy Press, March 3, 2026. https://www.techpolicy.press/rethinking-sovereign-ai-as-strategy/.
Singh, Shalabh Kumar, and Shubhashis Sengupta. 2025. “Sovereign AI: Rethinking Autonomy in the Age of Global Interdependence.” arXiv preprint arXiv:2511.15734, November 2025. https://arxiv.org/abs/2511.15734.
Slobodian, Quinn, and Ben Tarnoff. 2026. Muskism: A Guide for the Perplexed. New York: Harper. Kindle.
Soliman, Mohammed. 2025. “From Crude to Compute: Building the GCC AI Stack.” Washington, DC: Middle East Institute, December 2025. https://mei.edu/report/from-crude-to-compute-building-the-gcc-ai-stack/.
Srnicek, Nick. 2025. Silicon Empires: The Fight for the Future of AI. Cambridge: Polity. Kindle.
Strange, Susan. 1988. States and Markets: An Introduction to International Political Economy. London: Basil Blackwell.
TELUS. 2026. “TELUS and Government of Canada Advance Work to Scale Canada’s Sovereign AI Infrastructure.” Media release, May 11, 2026. https://www.telus.com/en/about/news-and-events/media-releases/TELUS-and-Government-of-Canada-advance-work-to-scale-Canadas-sovereign-AI-infrastructure.
TSMC. 2025. “TSMC Intends to Expand Its Investment in the United States to US$165 Billion to Power the Future of AI.” Press release, March 4, 2025.
Tully, Tim, Deedy Das, Matt Murphy, Derek Xiao, and Joff Redfern. 2025. “2025 Mid-Year LLM Market Update: Foundation Model Landscape + Economics.” Menlo Ventures, July 31, 2025. https://menlovc.com/perspective/2025-mid-year-llm-market-update/.
Verkhovna Rada of Ukraine. 2022. “On Cloud Services.” Law 2075-IX, adopted February 17, 2022, in force September 16, 2022. In Ukrainian. https://zakon.rada.gov.ua/laws/show/2075-20/ed20220217.
Weber, Max. 1946. “Politics as a Vocation.” In From Max Weber: Essays in Sociology, translated and edited by H. H. Gerth and C. Wright Mills, 77–128. New York: Oxford University Press.
Yang, Grace X. 2025. “The Openness Paradox: Open-Source AI and China’s Quest for Cyber Sovereignty.” Dialogues on Digital Society 1 (3): 261–64. https://doi.org/10.1177/29768640251376497.
Zhipu AI (Z.ai). 2026. “GLM-5.2.” Z.ai, June 13, 2026. https://docs.z.ai/guides/llm/glm-5.2.
Footnotes
-
This working draft develops a coursework essay submitted on 7 July 2026 for the AI Ethics and Society programme receiving a distinction. The argument has been extended in response to the two markers’ comments and revised for a public research audience. It has not undergone journal peer review. ↩
-
Notes to Table 3. ¹ Won at the hosting layer under the Hosting Certification Framework (DTA 2021); not at the model layer. ² ALLaM and HUMAIN Chat are domestic; frontier capability is rented from partners (CNBC 2025; Capacity 2026). ³ Won as governor of the licensing lever (BIS 2023, 2026); fabrication and packaging still partly run through Taiwan and EUV lithography through the Netherlands (TSMC 2025; Barczentewicz 2026). ⁴ Data Act, Chapter VI (European Parliament and Council 2023). ⁵ Won at the model layer through domestic open-weight substitutes; not at the hardware layer. ⁶ Won over the public arrangement the Union funds: EuroHPC systems owned by the Joint Undertaking, hosted by public centres and allocated through EuroHPC access calls (EuroHPC JU 2025; European Commission 2025a, 5); the commercial cloud market is the vendor’s, and the public right over it is a proposal (European Commission 2026b). ⁷ Open-weight vendors exist under member-state jurisdiction (Mistral AI 2025); the Union’s arrangement has not adopted a domestic model. ↩