
Keter Notes: Sovereign AI in late 2026 - who really owns the stack?
"Sovereign AI" is now a label on almost every cloud and model offer. For a CIO or CISO the useful question is narrower: for each workload, who controls the infrastructure, the operator, the keys and the model? Below is the state of play in our four markets, and a way to decide.
European Union: compute, a draft rulebook, a crowded market
Compute. EuroHPC counts 19 AI Factories. On 30 July 2026 it opened the call for up to seven AI Gigafactories; bids are due on 12 November 2026.
Rules. The Commission adopted the Cloud and AI Development Act (CADA) proposal on 3 June 2026. It proposes four sovereignty assurance levels for cloud and AI services used by the public sector: a provider self-assessment at Level 1, an independent audit at Levels 2 to 4. It is a proposal, not law.
Market. AWS European Sovereign Cloud has been generally available since 15 January 2026. Microsoft made disconnected operations available in February. The Commission awarded its own sovereign cloud tender, worth up to EUR 180m over six years, to four provider groups. Mistral made regional endpoints generally available in August.
Poland: two AI Factories and Polish open-weight models
Poland hosts two EuroHPC AI Factories. The Gaia project in Kraków officially started on 11 May 2026 with a budget of about EUR 70m. PIAST-AI in Poznań planned comprehensive services for the third quarter of 2026; in May its partners were still reviewing GPU procurement, and we have seen no go-live announcement. Polish open-weight models are production-relevant: Bielik v3 and the PLLuM family. Check the licences: some PLLuM models are non-commercial.
United Kingdom: the state as builder and first customer
A GBP 750m national supercomputer is under construction at the University of Edinburgh. On 31 August 2026 the first four competitions of a GBP 100m Sovereign AI procurement scheme opened: NHS productivity, compute efficiency, defence integration and agent security.
Japan: sovereignty through procurement
The Digital Agency is trialling three domestic foundation models on a domestic cloud, within a government AI pilot deployed for 180,000 employees. Blind A/B testing runs from September to November 2026 and will inform procurement for the next fiscal year.
Who owns the stack: four questions
EU data residency is not sovereignty. Ask of every platform:
Location: where do the service, the infrastructure and the data sit?
Operator: who runs it, and under whose control?
Keys: who holds the encryption keys?
Model: can you inspect and export the weights, and what does the licence allow?
When sovereignty matters
The data is classified, export-controlled or core intellectual property.
You are a public body, or supply one, in a field where the CADA draft would require audited assurance levels.
Your client or regulator expects domestic model and cloud options, as in Japan.
The workload must run disconnected.
When a managed platform is enough
Regional and contractual controls satisfy your risk owners. In-region inference removes a common blocker for regulated European workloads.
Utilisation is too uncertain to justify owning GPUs. Break-even against managed APIs depends on utilisation and must be modelled per workload.
The task needs frontier quality that open-weight models do not reach on that task.
There is a middle path. NVIDIA reports that LLM inference inside confidential virtual machines retains 96.1 to 98.2 percent of baseline throughput. That is a vendor benchmark, so validate it on your own workload.
What to do now
Classify data and AI workloads into sovereignty tiers and map each tier to eligible platforms. Keep deployments portable: containers, open model formats, infrastructure as code. Keep the keys under your control and write an exit plan per provider. Do not buy GPUs before you know the workload.
