In This Article
I am putting this framework in writing because I was saying it out loud on a stage, in front of people who make procurement decisions worth more than most agencies bill in a year, and I would rather they read it first than reconstruct it from my slides. It is called the AI sovereignty framework, and it exists because every other version of this conversation I have sat through starts in the wrong place.
It starts with compliance. GDPR mapping, data residency clauses, the EU AI Act, a checklist someone in legal built to keep the company out of the news. Useful, for sure. But compliance tells you whether you are allowed to do something. It does not tell you whether you actually control it or not. Those are different questions, and enterprises keep answering the second one with the answer to the first.
So here is the reframe I am bringing from the summit. Forget compliance as the entry point. Start with ownership instead.
What This Framework Is NOT
This is not a data residency checklist, and it is not a regulatory compliance matrix. If you came here looking for a GDPR mapping exercise or an EU AI Act readiness score, plenty of consultancies sell that, and it has its place. This is also not a vendor-neutral technology comparison, because I am not neutral about vendor lock-in, I think most of it is sold to enterprises as convenience when it is actually dependency with a nicer name. And this is not a framework for startups choosing their first stack. It is built for organizations that already have twelve years of integrations, three acquisitions’ worth of legacy tooling, and a board asking uncomfortable questions about what happens if a critical AI vendor triples its price or gets acquired by a competitor.
If your AI strategy question is “are we compliant,” this piece will frustrate you. If it is “who actually controls this,” keep reading. You will not be sorry to spend few minutes here.
The Five Questions
Every enterprise AI decision I have sat in for the past years, across a Portugal Homes rebuild that grew revenue close to five times over, inside global structures at Adecco Group and Atlas Copco, and now advising organizations and nations that are none of the above, eventually collapses into the same five questions. I did not invent them to sound clever. I built them because I got tired of watching sovereignty get discussed in the abstract while the actual decision, the one that determines whether a company controls its own future, got made by whoever signed the contract fastest.
- Do you own it? Not “do you have a license to use it.” Ownership, as it is, if the vendor disappeared tomorrow, would the asset still be yours?
- Can you move it? Portability. Not in theory, in practice, this quarter, without a six-month migration project run by the vendor’s own consultants. Is it possible?
- Can you replace it? If a better option appears next year, is switching a project or a multi-year easy?
- Can you audit it? Do you actually know what is happening inside the system, or are you trusting a vendor’s dashboard and a quarterly summary call?
- Can you survive without this vendor? The blunt one. The one that makes procurement teams uncomfortable in meetings, which is exactly why I ask it first now instead of last.
Those five questions are easy for executives to grasp, and that matters more than most frameworks admit. I have watched beautifully engineered maturity models die in a boardroom because nobody past the technical team could hold the whole thing in their head. Five yes-or-no questions survive a twenty-minute board update. That is not a compromise on rigor, that is the point.
The Five Layers
Sovereignty is not one decision, it is five different decisions, and enterprises tend to have real ownership in one or two layers while quietly renting the rest. I run every client through these five, in this order, because each one exposes dependency the previous one hid.
Infrastructure
Where does it actually run, and under whose terms. This is the layer everyone assumes they have already solved because they picked a “trusted” cloud provider, and it is usually the layer with the least real ownership in it. A single-region contract with a single hyperscaler is not infrastructure sovereignty, it is infrastructure convenience with a service level agreement attached. Ask the five questions here specifically about compute, not about the application layer sitting on top of it.
Models
Fine-tuned, proprietary, or rented by the token. Most organizations I audit are running on models they cannot export, cannot fully audit, and would need to rebuild from near zero if the underlying provider changed terms, pricing, or availability overnight. That is not a hypothetical, it has already happened to clients I have worked with, twice in the last seven months alone, with API pricing shifts that broke budget models built six months earlier.
Data
Not where it is stored, even if that matters too. Whether you control the pipeline that shapes it, labels it, and feeds it back into whatever sits on top. I ask clients to trace a single data point from ingestion to the model’s output and count how many vendor hands it passes through on the way. Most have never actually mapped this. The audit question matters most here, because data sovereignty without traceability is a compliance document, not a control system.
Knowledge
This is the layer nobody budgets for and it is the one I now spend the most advisory time on. What does the internet, and increasingly what does an AI agent crawling your public domain, actually know about you, and did you decide that or did it accumulate by accident. I built the Knowledge Exposure Audit specifically because enterprises kept discovering, after the fact, that a decade of unmanaged public content had quietly become their most exposed and least governed asset. You cannot claim knowledge sovereignty over content you have never inventoried.
Governance
The layer that ties the other four together, or fails to. Who decides how AI is used, retrained, and retired inside the organization, and does that authority sit with people who understand the first four layers or with whoever wrote the policy document three reorganizations ago. Weak governance is how a company can technically own its infrastructure, models, and data, and still have no real sovereignty, because nobody with authority is asking the five questions on a regular cadence.
The Truth
Here is the part that tends to get quiet in the room. Most enterprises do not have an AI sovereignty problem, they have an AI convenience addiction, and convenience was sold to them as strategy. Every layer of dependency I have described above got adopted because it was faster to sign the contract than to build the capability. Nobody sits down and decides to lose control of their knowledge layer. It happens one integration, one “quick win” pilot, and one procurement shortcut at a time, and three years later a CIO is asking me why switching AI vendors would take longer than the last ERP migration.
I say this as someone who has recommended plenty of vendor relationships in twenty-five years of doing this. Vendors are not the enemy. Unexamined dependency is. The point of running the five questions layer by layer is not to arrive at total self-sufficiency, almost nobody needs that and almost nobody can afford it. The point is to make dependency a decision you made on purpose, with your eyes open, instead of a default you drifted into.
Using This Before You Need It
I built the AI Assessment Center so organizations could run this self-diagnostically before a vendor renewal forces the conversation, and I would rather clients bring me a sovereignty gap they already know about than discover one mid-negotiation with no leverage left. If you have not mapped where your organization sits on infrastructure, models, data, knowledge, and governance, the AI Search Readiness Audit and the diagnostics inside NovaX are the two starting points I point people toward most often, depending on whether the more urgent gap sits in visibility or in the underlying stack itself.
I talked about a version of this at the sovereignty session I spoke at last week, and the reaction from that room is a large part of why I sharpened it into this five-by-five structure since. The questions have not changed. My patience for the compliance-first version of this conversation has.
Own it, move it, replace it, audit it, survive without it. Run every layer of your AI stack through those five, honestly, and you will know exactly where your sovereignty is real and where it is a slide in someone else’s sales deck.