Owning the Stack: Digital Sovereignty, Public AI Infrastructure, and the Builders Who Will Actually Deliver It
Back to home

Owning the Stack: Digital Sovereignty, Public AI Infrastructure, and the Builders Who Will Actually Deliver It

14 min read

Sovereignty was never just about where the server sits

Digital sovereignty predates AI by decades, but the arrival of foundation models has turned a compliance conversation into a strategic one. Analysts at S&P Global now describe compute as having joined energy and transportation as a critical utility, with sovereignty resting on control of five pillars: the control plane, encryption and key management, the supply chain, the software stack, and access to reliable, affordable power for data centres. The practical definition that has settled across telecom, cloud and policy circles by 2026 is broader than data residency — it is control across the entire AI lifecycle: compute, model ownership, data governance, operations and network management.

That distinction matters because it exposes a shortcut many governments have taken. Storing data in-country while running inference through a foreign hyperscaler's model, on infrastructure whose parent company answers to foreign law, satisfies almost none of the five pillars. A cloud provider's sovereign badge does not remove the exposure if the underlying jurisdiction, encryption keys or model weights sit elsewhere. Real sovereignty requires that the controls travel with the workload, embedded in the architecture from the start rather than bolted on for a compliance audit.

The AI Now Institute traces the sovereignty debate back to 1970s anti-imperialist political economy — the study of how global power and dependence shape national development. That lineage is worth remembering. Digital sovereignty was never really a technical category. It has always been about who gets to make decisions about a nation's own future, and AI has simply raised the stakes on a much older question.

The subsidy reflex — and why it stops short

Faced with that question, the default government response over the past two years has been remarkably consistent worldwide: negotiate discounted or free access to a foreign frontier model, badge it as a national AI programme, and declare progress. This is not without value — it puts capable tools in the hands of citizens and civil servants quickly, and the political optics are good. But it is access, not infrastructure. It builds usage data for someone else's platform and leaves the country's compute, model weights and monetisation entirely offshore.

The more serious national programmes emerging in 2026 go three layers deeper than subsidised access.

USD 650B+

Projected global AI infrastructure spending in 2026, spread across increasingly fragmented national compute pools

88%

Share of enterprise AI API spending controlled by three foundation model providers as of early 2026

£ 500M

UK Sovereign AI Unit, allocating GPU-hours rather than cash grants directly to domestic startups

18,000

Subsidised GPUs offered to startups and researchers under India's national AI Mission

Sources: Tech Insider (UK Sovereign AI Fund analysis, Jun 2026); PremAI, "Scaling Sovereignty Beyond the 0.1%" (Jul 2026); Capacity, sovereign AI infrastructure coverage (Jun 2026)

The pattern across the more credible programmes — the UK's Sovereign AI Unit, France's €109 billion private AI commitment anchored by its stake in Mistral, Germany's Deutsche Telekom Industrial AI Cloud, India's compute-mission — is that governments are shifting from paying for seats to owning pieces of the stack: national compute clusters, domestic chip ecosystems, open foundation models, and public-interest datasets. The UAE has taken this furthest with G42 and MBZUAI's Arabic-centric open models; Saudi Arabia's HUMAIN, backed by its sovereign wealth fund, spans compute, model development and application deployment as one programme rather than three separate ministries pulling in different directions.

A useful diagnostic: if a country's "sovereign AI strategy" can be fully described as a procurement deal with a foreign vendor, it is not yet an infrastructure strategy. The test is whether the country would still have functioning AI capability if that vendor withdrew tomorrow.

Two playbooks: China's scale, Switzerland's openness

No two national approaches illustrate the range of sovereign AI strategy better than China and Switzerland — a superpower building an entirely parallel stack, and a small, wealthy democracy betting on radical openness as its form of control.

China's approach is state-directed and vertically integrated. The "Eastern Data, Western Compute" initiative concentrates national supercomputing hubs in provinces with cheaper energy, and the country had reached an estimated 788 intelligent EFLOPS of domestic AI compute capacity by 2026 — the most self-sufficient sovereign AI ecosystem in the world, built on Huawei's Ascend chip line now supplying roughly 65% of the country's AI chips domestically. On top of that stack sit multiple frontier-class open-weight models — Alibaba's Qwen, DeepSeek, Baidu's ERNIE — that China is now actively exporting: Beijing has offered thousands of AI training placements to developing countries and proposed cooperation centres with BRICS, ASEAN, the African Union and Latin America, explicitly pitching infrastructure and open-source access to nations that, in China's own framing, have supplied data and users to the digital economy without owning any of the compute or platforms themselves.

Switzerland's model could hardly look more different in scale, yet it shares the same underlying instinct: don't rent sovereignty, build it as public infrastructure. Apertus, released by EPFL, ETH Zurich and the Swiss National Supercomputing Centre, is a fully open large language model — architecture, weights, training data and methodology all published under an Apache 2.0 licence — trained on 15 trillion tokens across more than a thousand languages, with 40% of that data deliberately non-English. Crucially, Apertus was built to serve languages "so far been underrepresented in LLMs, such as Swiss German and Romansh" — a design choice its technical lead describes as treating the model as public digital infrastructure, the same category as utilities or transport. Swisscom now runs it on a national Sovereign Swiss AI Platform for businesses and developers, and the project has moved into a second release, Apertus 1.5, explicitly framed as a long-term open alternative to proprietary commercial models.

DimensionChinaSwitzerlandEU (Broader)
Ownership modelState-directed, national championsUniversity-led public consortiumFederated, multi-country (GAIA-X, EuroHPC)
Compute base~788 EFLOPS; domestic Ascend chips (~65%)CSCS "Alps" supercomputer19 EuroHPC AI Factories; JUPITER (exascale, DE)
Model opennessOpen-weight, restricted governance layerFully open — weights, data, methodologyMixed — Mistral (partly open), national clouds
Language coverageBilingual-focused, domestic norms1,000+ languages incl. Romansh, Swiss GermanVaries sharply by member state
Export postureActive diffusion to Global SouthGlobal public-good release via Hugging FaceLargely inward-facing, regulation-led

Sources: ginc.org China National AI Strategy brief (Jan 2026); Digital in Asia, China AI Strategy 2026; ETH Zurich, EPFL and Swisscom Apertus releases (Sep 2025–Jul 2026); TechPlusTrends EU Sovereign AI Infrastructure Guide (Apr 2026)

The two playbooks converge on one point that should reframe how smaller nations think about their own strategy: neither superpower scale nor Silicon Valley capital is a prerequisite for sovereignty. China wins through state-backed scale and generous diffusion; Switzerland wins through radical transparency and a public-good release strategy that lets any country — Malaysia included — inspect, fork and rebuild the model rather than merely renting access to it. That second path is the one genuinely open to mid-sized economies.

Why startups and SMEs are the real sovereignty engine

The uncomfortable finding from recent sovereignty analysis is that most of the capital now flowing into "sovereign AI" is concentrating rather than distributing. Four large technology groups have combined AI capital expenditure approaching $700 billion, and closed frontier labs already account for the overwhelming majority of the $80 billion annualised AI-startup revenue run rate. If national sovereign AI funds simply replicate that concentration at a smaller scale — a handful of national champions absorbing most of the compute and capital — the country has not solved dependency. It has relocated it inward.

The programmes achieving genuine distribution share a common design choice: they give founders infrastructure, not cash. The UK's Sovereign AI Unit backs domestic startups with subsidised compute and visa support rather than grants alone, and portfolio founders cite direct access to sovereign compute as what let them move fundamentally new R&D from early experimentation into production. India's AI Mission subsidises access to 18,000 GPUs for exactly this purpose. The Netherlands' Sovereign AI-Grid offers pay-per-use European compute rather than a one-off allocation. Europe's SME association has argued explicitly that SMEs represent the majority of the continent's tech ecosystem and have a strategic role in scaling compute capacity — but face structural barriers, chiefly access to capital-intensive infrastructure, that market forces alone will not remove without deliberate policy design.

National champions alone don't diffuse capability

One flagship model ≠ an ecosystem A single sovereign foundation model, however capable, only becomes sovereignty for a whole economy if hundreds of smaller companies can fine-tune, deploy and build commercial products on top of it. Without that layer, the country has swapped a foreign monopoly for a domestic one.

Startups find the niches governments miss

Legal, dialect, sector-specific use cases The UAE's playbook explicitly banks on this: subsidised super-cluster access lets startups train niche models — Gulf-dialect chatbots, sector-specific legal assistants — that larger markets have no commercial reason to build. The same logic applies to Malaysia's dialect and sectoral diversity.

SMEs are where compute democratisation is tested

SMEs are the majority of most tech ecosystems Europe's DIGITAL SME Alliance frames this directly: without a federated, full-stack cloud offer that SMEs can actually afford to use, sovereignty legislation like the EU's Cloud and AI Development Act risks becoming a compliance exercise for large firms only.

The most quietly important sentence in this year's sovereignty commentary may be this one: sovereignty is only solved if it scales down, not just up. A country with one dazzling national model and a thousand founders still renting foreign infrastructure to build anything useful with it has not achieved digital sovereignty. It has achieved a flagship.

The layer everyone skips: language

Almost every national AI sovereignty document leads with chips, data centres and megawatts. Very few lead with language — and yet language is the layer where sovereignty is actually felt by an ordinary citizen, a civil servant, or a small business owner who is not going to read a semiconductor export-control briefing. A model trained overwhelmingly on English and a handful of major languages does not serve a farmer in Sabah, a clerk in a district office, or an elderly patient describing symptoms in a dialect no benchmark has ever measured.

Switzerland treated this as foundational rather than optional: 40% of Apertus's training data is deliberately non-English, and the model was purpose-built to serve Swiss German and Romansh — languages with no commercial incentive for any foreign lab to prioritise. Malaysia has, in its own way, arrived at the same conclusion. The Bahasa Melayu-LLM effort led by MIMOS and MRANTI was explicitly framed under the National AI Roadmap as preserving the country's linguistic identity, not merely improving a chatbot's fluency. YTL AI Labs' ILMU model — now ranking first in the world on the MalayMMLU benchmark, ahead of global frontier models — went further still, training specifically to handle "rojak" speech: the everyday blending of Bahasa Melayu, English, Mandarin, local dialects and Manglish within a single sentence. Its developers point to a specific, recognisable failure mode of global models: mid-conversation, a large frontier model will sometimes drift into a completely unrelated third language because code-switching in minor-language markets sits outside what it was optimised for.

ModelLanguage focusWhat it protects
Apertus (Switzerland)1,000+ languages; 40% non-English dataSwiss German, Romansh — near-zero commercial incentive elsewhere
HyperCLOVA X (South Korea)Korean-first benchmark optimisationKorean-language nuance global models under-serve
Jais / Falcon (UAE)Arabic-centric open weightsGulf Arabic dialects and regional context
ILMU / BM-LLM (Malaysia)Bahasa Melayu, code-switched "rojak" speechMalaysian linguistic identity across dialects and mixed-language daily use

Sources: ETH Zurich, Swisscom Apertus releases (2025–26); Digital in Asia, Sovereign AI in Asia 2026; MyForesight, Malaysia's Strategic AI Plan; The Edge Malaysia, ILMUchat coverage (Jun 2026); FMT, ILMU/MalayMMLU coverage (Jul 2026)

The reason language keeps getting sidestepped is structural, not accidental: it is expensive to fix, it produces no dramatic groundbreaking photo-op the way a new data centre does, and its absence is invisible to policymakers who mostly interact with AI in English or another dominant language. But the omission compounds. A country that builds sovereign compute and a sovereign cloud while leaving the language layer to whichever foreign model happens to handle the local tongue best has built sovereignty for its data centres and left its actual population dependent on someone else's linguistic judgment calls — including, as Southeast Asian regulators discovered when several countries had to jointly ban a foreign model's image-generation feature in early 2026, judgment calls a foreign vendor can also get badly wrong.

Preserving a national language in AI is not a cultural nicety bolted onto a compute strategy. It is the part of the stack that determines whether sovereignty reaches the people the strategy claims to be for — the district clerk, the Sabahan farmer, the elderly Cantonese-speaking patient — rather than stopping at the server room door.

What should builders and decision-makers actually do next?

None of these moves requires superpower-scale budgets — they require treating compute, openness, language and market access as one connected system rather than six separate line items competing for the same press release.

Move 01: Fund compute-hours, not just cash grants Cash grants get spent on foreign cloud invoices. GPU-hour allocations on sovereign or partner infrastructure keep the spend, the workload data, and the resulting IP inside the country. Model: UK Sovereign AI Unit; India's AI Mission GPU allocation

Move 02: Release the national model as a genuinely open foundation A closed national model recreates the same dependency it was built to escape, just with a domestic landlord. Open weights let SMEs fine-tune for dialect, sector and use case without renting compute abroad. Model: Apertus (Apache 2.0); Alibaba's Qwen open releases

Move 03: Fund the language layer as core infrastructure, not a grant category Corpus collection for dialects and code-switched speech should be budgeted alongside data centre capex, not left to an underfunded cultural-preservation line item that competes for scraps. Model: Apertus's 40% non-English training allocation; ILMU's rojak-speech optimisation

Move 04: Mandate SME-accessible pricing on sovereign cloud capacity A sovereign cloud priced like a hyperscaler's enterprise tier only serves large incumbents. Tiered, pay-per-use access designed for founders is what actually diffuses sovereignty past the flagship project. Model: Netherlands' Sovereign AI-Grid; MeluXina (Luxembourg), serving SMEs directly

Move 05: Build procurement pathways that favour local models for public services Public-sector deployment is the fastest way to create paying, referenceable customers for domestic AI startups — and it puts the sovereign model to work where it matters most: civil service, healthcare, education. Model: Malaysia's BM-LLM fine-tuned on government and public-service data

Move 06: Treat regional diffusion as strategy, not charity Whether through open-source release or training-seat diplomacy, exporting a sovereign model builds influence, developer goodwill and adoption data — the same feedback loop foreign vendors currently capture from smaller markets. Model: China's Global AI Governance Action Plan; Apertus's global Hugging Face release

A subsidised seat on someone else's model is access. A sovereign compute layer is infrastructure. A thousand founders who can build on it, in the languages their own citizens actually speak, is sovereignty. Most countries have only built the first.

For founders, the implication is direct: the compute-as-infrastructure and open-model moves above are not distant policy debates — they are the emerging terms on which national programmes will fund, or decline to fund, your next round. Understand what your government's sovereign AI programme actually gives away versus what it merely leases, and build where the terms let you keep the IP. For policymakers, the test is simpler still: if the national AI strategy can be fully described as a procurement contract, it isn't a sovereignty strategy yet — and if it doesn't mention the languages your own citizens speak at home, it hasn't finished being written.