In May 2025, Karim Khan, chief prosecutor of the International Criminal Court, opened his laptop in The Hague and found himself locked out of his Microsoft email account. According to * The Associated Press*, the Trump administration had sanctioned Khan over the court’s arrest warrants for Israeli officials. Microsoft, a U.S. company subject to U.S. law, was caught in the middle. The company president, Brad Smith, later
The lesson was clear: Wherever your data physically sits, your infrastructure answers to whoever has legal authority over the company that runs it.
That lesson is now reshaping decisions far from The Hague. For two decades, “the cloud” was a convenient fiction that allowed companies and governments to treat computing as somebody else’s problem, humming away in a building they never had to think about. AI has ended that abstraction.
A frontier model runs on particular machines, in a particular building, drawing power from a particular grid, under the laws of the country where it operates. Whoever controls that stack can tax it, subpoena it, or shut it down. Once billions have been poured into concrete and power lines, the system remains fixed in place.
The race now centers on building AI compute that its owners can reliably keep.
Money is pouring into sovereign AI, even as a shared definition remains elusive. The phrase was everywhere at the U.N.’s recent AI for Good Global Summit in Geneva, invoked by national research institutes, standards bodies, and startups alike. Ask any two of them to define it, and their answers are unlikely to match.
Some definitions focus on keeping data inside national borders. Others emphasize building homegrown models capable of rivaling American and Chinese systems. Hakim Hacid, chief researcher at the UAE’s Technology Innovation Institute, offered the most comprehensive answer from the stage.
Real sovereignty, he argued, means a country can develop, deploy, regulate, and secure AI at every stage of the process, from the chips and models to the rules that govern them. “Depending on other entities nowadays is imposing a high risk on every industry,” he said. His remarks repeatedly returned to the first stage, the one drawing the fiercest competition: the compute itself.
Philippe Metzger, secretary-general of the International Electrotechnical Commission, which sets many of the technical standards underpinning digital systems, has watched this confusion up close. He cautions against placing too much faith in any single solution. Drawing on his years as a Swiss telecom regulator, he described how the liberalization of the 1990s eventually led governments to realize that they had lost control of their own networks, prompting efforts to regain it.
“There is a strong focus now of concern about not being able to control anymore as a country your digital space,” he tells Fast Company.
Metzger sees international standards as a way to provide countries with a more stable foundation. He also emphasizes the limits of national control: “We know very well that the systems are interconnected, and there will always be interfaces that are international.” Full sovereignty, he explains, remains an ongoing pursuit.
Whatever the term ultimately means, the demand it describes is already appearing in purchase orders.
Saar Dickman runs Dynamic Infrastructure, which uses AI to monitor public assets such as bridges, tunnels, and transit systems. The company turns routine inspection imagery into what Dickman calls a medical record for each structure. Because those assets are government owned, the location and governance of the underlying AI have always been central concerns. “It comes up in nearly every serious procurement conversation now, and usually early,” he says.
“Transit agencies and state DOTs ask two questions before almost anything else: Will this data ever leave U.S. soil, and who has legal access to it?”
Those questions have grown sharper. A couple of years ago, Dickman says, agencies focused on encryption and certifications. Now they want to know where the servers physically sit and which courts and laws would govern any attempt to access them. What they are buying, he adds, is certainty over access.
“You can put a server anywhere,” Dickman says. “What agencies are really buying is certainty about who can reach what’s on it.”
Samir Tabar hears a version of the same concern from enterprise customers. Tabar is CEO of WhiteFiber, a Nasdaq-listed company that builds and operates its own AI data centers. He is also CEO of Bit Digital, the digital-assets firm from which WhiteFiber was carved out. The distinction he sells comes down to architecture.
A public cloud separates its customers through software. Each customer receives a fenced-off portion of a shared system, a dedicated region, and a contractual guarantee that its workload is isolated from the thousands of other tenants using the same hardware. A company that owns its buildings can also provide physical separation. Customers can decide which building houses their hardware, who is allowed through the door, and whether the machine ever connects to an outside network.
That is not a feature the hyperscalers have chosen to withhold. Renting the same hardware to many customers at once is the foundation their business is built on, and a private room for one is a different kind of building.
The pressure behind all of these decisions, in Tabar’s telling, is simple scarcity. On WhiteFiber’s most recent earnings call, he told investors that “demand for AI infrastructure continues to exceed the available supply. Customers need power, high-density capacity, speed, and partners who can actually execute.”
For a company that can move quickly, he said, that shortage is the whole opportunity. Being able to bring a site online fast is “why we have such a pregnant pipeline of demand and customers who are banging on our doors,” he added, rather than waiting on the years it takes to build a data center from the ground up. But more important than any vendor’s pitch is the legal exposure behind this scramble for sovereignty. Under the CLOUD Act of 2018, U.S. authorities can compel American companies to hand over data they control, wherever in the world it is physically stored—which means that data sitting in a European data center run by an American firm is not necessarily beyond the reach of a U.S. court. For companies training models on regulated or proprietary data, that is the difference between a compliance question and a liability.
Despite all that, Tabar is quick to note that the hardest part of the job is not the technology at all. What separates the companies that can actually deliver, he argues, is the unglamorous work of building fast. On the same earnings calls, he pointed to a shuttered industrial building his team turned into a working data center in about six months. “Who else does that?” he asked.
It’s the builder’s answer to the issue diplomats and lawyers keep circling. A country can pass a sovereignty law in an afternoon. Securing the power, equipment, and years of construction needed to support it follows a far less flexible timetable.
Here is what turns the race into a scramble. Most of the countries chasing sovereignty cannot actually make the thing they’re chasing.
The United States and China together control close to 90% of the world’s most advanced AI computing power, according to the Center for a New American Security’s Sovereign AI Index. And that dominance isn’t only about who owns the data centers. It reaches all the way back to who makes the chips inside them and even to the small number of companies that design those chips in the first place.
Gaëlle Foucault, a postdoctoral researcher at the Université de Montréal who studies how AI is governed, laid out the problem at the summit. Sovereignty, she said, depends on every link in that chain, and “if you control none of the links in that chain, sovereignty stays quite theoretical.”
The hardest link to forge is the chip itself. Sharada Mohanty, an AI researcher and founder who spent a workshop trying to sketch an open-source GPU, described a system rigged against newcomers: Even a working design has to be fabricated at one of a handful of advanced foundries, each of which can say no. That bottleneck is why a nation can announce billions in AI investment and still not possess sovereignty in any real sense. It can buy the buildings and the power, but it cannot yet make the silicon.
That dependence runs all the way up the chain. Even Dickman’s company, for all its insistence on controlling where its data lives, runs its AI on Nvidia-accelerated computing—the same scarce hardware nearly every serious AI operation depends on. Control over the building is one thing. Control over the chips inside its walls is still quite concentrated.
This is where the story becomes geopolitical and dependency begins to create leverage. Dean Jackson, a contributing editor at Tech Policy Press who studies platform power, agrees with Dickman’s emphasis on who can legally reach a system. He adds that law and geography remain intertwined.
“It is easier for a government to demand access to a server it can seize than one it has to issue warrants and demand letters to receive from abroad,” he says. “Leverage depends in large part on law enforcement.”
Governments have begun treating the entire stack as national-security terrain. Jackson points to the CHIPS Act of 2022 as an early attempt to rebuild the United States’ limited domestic chip-manufacturing capacity. A more direct intervention followed. In August 2025, the U.S. government took a stake of roughly 10% in Intel, funded largely with repurposed CHIPS money, one of several positions it has taken in companies it considers strategically vital.
The leverage runs both ways, though. Cutting Europe off from American platforms would hurt American companies just as badly, Jackson notes, which makes the whole standoff “quite realpolitik for talk about two nominal allies.”
The risk of leaning on a single provider isn’t hypothetical. Ukraine’s heavy reliance on Starlink became a strategic vulnerability the moment Elon Musk declined to extend coverage for a planned attack on Russian-occupied Crimea. “When Musk restricted Starlink use in Ukraine,” Jackson says, “you can bet Kyiv wished it had a domestic alternative.”
Sovereignty can create its own constraints. It is jurisdiction specific, and the infrastructure designed to satisfy one legal regime may fail under another. Dickman learned this lesson the expensive way. His U.S.-first architecture, built to satisfy American agencies, helped him win domestic deals and later cost him a European one.
“Our U.S.-based governance and residency setup didn’t satisfy European requirements,” he says. “Sovereignty cuts both ways: What makes you trusted in one jurisdiction can disqualify you in another.” Dynamic Infrastructure has since established European infrastructure, ensuring the platform operates in accordance with the client’s legal requirements.
Even the people selling private infrastructure will tell you it isn’t for everyone. Building and running your own compute is expensive and demanding, and a midsized company running the occasional model on ordinary data is almost always better off renting from a hyperscaler. The math changes only when the law requires it or when the data is too sensitive to ever sit on a shared machine. That describes far fewer companies than the current noise around sovereignty would suggest.
Which is the clearest sign that this is not a stampede out of the cloud. Forrester, the market research company, expects roughly 15% of enterprises to move toward private AI this year, a number that matters precisely because it is not half of them. What is happening is slower and more deliberate than a mass migration. Company by company, agency by agency, one workload at a time, people are asking a question they used to leave to someone else: Where does this run, and who can reach it?
For years, the cloud allowed everyone to pretend that computing happened nowhere in particular. AI has made the physical reality impossible to ignore. The models that matter run in real buildings, in real countries, wired into real power grids, and that has essentially turned a technical decision into a territorial one.