Why I Wrote This
I’ve been thinking for a while about how the AI infrastructure conversation tends to get framed as a technology or economics story, when the more consequential framing is a security and governance one. The question of who controls the compute, the model weights, and the data pipelines that underpin public services is, at its core, a question about whether governments retain the ability to act autonomously under adversarial pressure. That felt worth examining properly, so I wrote a longer piece for Dispatch setting out the argument in full.
What follows is a summary of the key threads. The full article is here.
The Structural Dependency Problem
The starting point is a set of numbers that don’t get enough attention. The United States and China together hold more than 90% of global AI data-centre capacity. Three US hyperscalers hold approximately 70% of the European cloud market, and European providers’ share has declined from around 29% in 2017 to roughly 15% today. That is not a market in equilibrium. It is a market consolidating in one direction, and the governments running sensitive workloads on that infrastructure are subject to the terms of service, export control decisions, and foreign policy calculations of the infrastructure owner.
This is not a hypothetical concern. In June 2025, Microsoft’s legal director for France testified under oath to a French Senate inquiry that Microsoft could not guarantee French public-sector data held in French data centres would be protected against US government demands under the 2018 CLOUD Act. The CLOUD Act requires US companies to produce data stored anywhere in the world upon receiving a valid government demand. No contractual arrangement resolves that tension. Any government running sensitive workloads on US-domiciled platforms operates under that constraint regardless of where the servers physically sit.
Sovereignty Theatre vs Operational Control
One of the arguments I spend time on in the Dispatch piece is the distinction between genuine sovereignty and what I call sovereignty theatre. Legal title to a domestic server rack does not produce sovereignty if the software stack, model weights, or training pipeline remain subject to foreign jurisdiction or vendor control. What matters is operational control and jurisdictional enforceability.
The NCSC has identified data poisoning and model manipulation as live threat categories, and NIST’s adversarial machine learning taxonomy confirms that attacks targeting training data are a credible and documented attack surface. A 2024 security assessment of 25 widely used open source AI and LLM projects found that 20 out of 25 had dependencies with known vulnerabilities, and none implemented signature, checksum, or provenance verification for third-party data sources. Governments deploying AI systems built on that foundation, particularly where those systems process sensitive national data, are accepting security debt they may not have formally acknowledged.
The NCSC’s guidance also identifies prompt injection as among the most widely reported weaknesses in large language models, capable of triggering unintended consequences including data exfiltration. These are not edge cases. They are the baseline threat environment for any AI system deployed at scale.
What Allies Are Already Building
The case for sovereign AI infrastructure is not speculative. CISA has deployed active AI use cases including deep learning-assisted malware reverse engineering, unsupervised machine learning for critical infrastructure anomaly detection, and AI-automated analysis of terabytes of daily federal network log data. The NSA has published guidance on AI and machine learning supply chain risks and issued a joint advisory on agentic AI adoption in April 2026. The NCSC has published secure AI development guidance co-developed with CISA and agencies from 17 other countries.
These programmes share a common characteristic: they are built on domestically controlled infrastructure with defined data pipelines and accountable governance chains. That is not a coincidence.
A Credible Alternative Model
For nations outside the US-China duopoly, the only credible path to genuine AI sovereignty likely runs through publicly owned national AI infrastructure. The analogy to 20th century public utilities is precise rather than rhetorical. Electrical grids and telecommunications networks were not left subject to external control because democratic governments recognised that population-level dependency made them too consequential.
India’s BHASHINI platform is a useful reference point. It serves over 100 million inferences per month across 22 or more languages on a vendor-agnostic architecture that keeps data and switching rights public. It does not claim comprehensive sovereignty, but it demonstrates that public-interest AI at national scale is achievable outside hyperscaler dependency. The critical design choice is maintaining portability and public data ownership.
The strongest counterargument is economic: national-scale compute is expensive, slower to deploy, and unlikely to match hyperscaler model quality in the near term. That is a legitimate constraint. But the Dispatch piece argues that the cost of inaction is also real, and that framing the choice as build-everything-or-do-nothing misses the available middle ground.
Read the Full Piece
The full Dispatch article covers the governance framework requirements, the Gartner forecasts on cross-border AI data exposure, and a more detailed treatment of what a credible national AI infrastructure model needs to include beyond data residency mandates. You can read it here.

Leave a Reply