Driven by rising costs and concerns over data sovereignty, enterprises are increasingly pursuing “AI sovereignty” by diversifying their AI supply chains with open-source alternatives, says Lewis Liu
“Every single enterprise in this country… these people are livid. They’re saying: ‘I am paying for tokens that create no value. These people are stealing the weights and alpha of my business.'” Those were the words of Alex Karp on CNBC earlier this month, the CEO of Palantir, the controversial US surveillance and data company. Tellingly, he framed the outburst not as his own complaint but as “the voice of American business being channelled through me.” Regular readers know I rarely agree with Karp. But on this, I think he is genuinely voicing the private frustration of many CEOs and business leaders, not just across Europe and Asia, but increasingly in the US too.
This all comes down to a concept the market is still busy defining: AI sovereignty. My own working definition is simple: it’s the degree to which you control your own AI destiny. And in my view, it rests on two fundamental pillars: supply chain resilience and data.
Let’s start with cost, the most basic pillar of AI sovereignty. At a simple level, AI spending has ballooned, yet many enterprises still have little to show for the unprecedented sums they have invested. One large technology company reportedly exceeded its AI budget by $500m in a single quarter, with no discernible benefit to the business. But the broader complaint I hear is not that AI is useless. It is that the economics do not yet add up. Token costs, AI-generated slop, and the transfer of work from junior employees to senior reviewers can outweigh the value AI creates.
Token costs #
Token costs are the easiest part of this equation to measure, and they are already pushing more Western companies towards Chinese open-source models. According to recent data from OpenRouter, a platform that provides access to multiple AI models, usage of Chinese models in January was roughly one-third that of US models. By July, Chinese model usage was five times higher than that of American ones, representing a seismic shift in usage patterns. The message from Western companies is clear: this is being driven by cost. Chinese models can be more than ten times cheaper. Just last week, open-source Kimi-3, a model produced by Chinese AI company Moonshot, was released. This model outperforms Anthropic’s latest Fable-5 model across a large number of benchmarks. Fable-5 is marketed as “too dangerous” for the wider world and costs a fortune to run. Kimi-3, on the other hand, is free.
Data sovereignty is becoming an equally important concern, and one I am hearing about with increasing frequency in the United States. Distrust of American frontier labs such as Anthropic and OpenAI has long been prevalent in China and Europe, a subject I have written about before. What has changed is the speed with which US enterprises have begun to fear that these companies may be “stealing their alpha”, to use Karp’s phrase.
I wrote recently about Anthropic’s shift from AI’s “ethical golden child” to a company that enterprises increasingly fear. Since then, that sentiment appears to have accelerated significantly.
In conversations with C-suite executives, the concern can be distilled into a simple question: if generative AI was built, in their view, through widespread theft of intellectual property and copyrighted material, why should they trust a contract promising that their own data will not be used for training? Is a “no training on client data” clause genuinely credible?
Anthropic’s position has been further complicated by recent allegations that its models contained surveillance-related backdoors, although there are complex geopolitical factors surrounding that case. From my perspective, it remains difficult to verify whether any frontier lab has breached its contractual commitments. But that may no longer matter. The trust has already eroded. As my co-founder put it: “These people are terrified that Anthropic and OpenAI are going to take their entire world away from them.”
This is accelerating the push towards Chinese open-source models. As a start-up, we currently use a combination of Anthropic, OpenAI and Gemini. Yet enterprise clients, including blue-chip American corporations, are proactively asking us to develop an open-source strategy in case they decide to prohibit US frontier models on data-sovereignty grounds, as some European companies are already doing. You know a fundamental paradigm shift is under way when some American businesses begin to view Chinese security risk as less threatening than the risk of US AI companies extracting their proprietary advantage.
Three priorities #
So how should businesses respond? In my conversations with CEOs, general counsels, and CTOs at some of the world’s largest companies, I generally distil the advice into three priorities.
First, build resilience into your AI supply chain. I am not arguing that companies should stop using Anthropic or OpenAI; they remain the principal model providers for my own venture. But businesses should ensure they can switch providers without rebuilding their entire AI stack. That means developing a credible and adaptable open-source strategy, alongside access to a diverse range of models.
Frontier labs have limited incentive to minimise token usage within applications: greater consumption generally benefits their economics. Application companies, by contrast, have every incentive to reduce token costs because their margins depend on efficiency. Enterprises should therefore avoid becoming dependent on a single provider, model or pricing structure.
Second, align data governance with competitive risk. Businesses must be deliberate about what information they send to frontier-model providers. The key question is simple: could this provider eventually compete with us, directly or indirectly? If the answer is yes, companies should be extremely cautious about which data they expose and should maintain a viable alternative. This requires a data-governance strategy built around competitive dynamics: which information can be sent to which model, which AI agent provider should receive it, and which data should never leave the organisation.
Third, capture and retain your informational “alpha”. Kirkland & Ellis, for example, is reportedly spending $500m to capture the collective knowledge of its partners. Karp is right that this knowledge is a form of alpha, particularly for organisations whose advantage rests on proprietary expertise, judgement and experience. Companies need systems that can capture, scale and compound that knowledge, then make it available to their own AI tools while keeping it inaccessible to everyone else.
Together, these three principles form the foundation of AI sovereignty: a resilient supply chain, disciplined control of data and the ability to preserve and compound proprietary knowledge for your organisation alone.
On a final ironic meta-note, I normally copy-edit my columns on Claude or ChatGPT, but I guess my content hit a nerve. Both models, especially Claude, consistently gaslit me when I explicitly just asked it to copy edit this column and just took out huge parts of my argument (including the security issue around Claude and the superior pricing dynamics of Chinese models) because I guess it didn’t agree with Claude’s worldview. Imagine this running deep in a workflow where it is much harder to trace. Sovereign AI is needed indeed, even if it is just to keep our own minds sovereign. I ended up running my copy edit through DeepSeek instead.