You’ve probably read that AI makes everything look the same – the decks, the landing pages, the copy, all drifting toward one voice. It’s true, and the cause is no mystery: a default is an average. Different tools, the same few models underneath; reach for the default and you get the middle of everything the model has seen.
What’s worth your attention is what the sameness is. It’s a dependency nobody chose – and unlike most, you can’t buy your way out. Bring the model fully in-house, your hardware, nothing leaving the building, and the defaults come with it. You ran the model; you didn’t make it. You can control that all the way down only by building your own – the most expensive thing in AI, and we’re back to the price we put on this last time.
That’s one face of a larger problem, and a good way into it. Sovereign AI isn’t a new category. It’s every sovereignty question you already had, arriving at once. There are six. Data – where it sits and what gets created from it. Dependency – who you rely on, how far down it runs, and how hard it would be to leave. Operation – who runs it and keeps it available. Permission – whether you’re allowed to use it at all. Reach – what it can touch inside your business. And Formation – what shaped the model, and what it now quietly shapes in you. The last one is the face the sameness just showed you.
These map loosely onto the familiar pillars – data, operational, technical, legal, however a given framework counts them – but AI redraws the map, splitting some and adding ones the old frameworks never needed. And they don’t all sit side by side: some nest – data inside operational inside the technical stack – so holding an outer layer tends to hand you the inner ones. They’re not locked together, though. You can govern your data while renting the infrastructure under it. The nesting shifts the odds, it doesn’t remove the choice.
Any one of those you can handle. You scope it, get an answer, write it down. What makes AI the hardest case is two things at once. The dimensions don’t come apart – and the nearest thing to it is a Rubik’s cube. Turn one face to fix it and the others move whether you meant them to or not; you can’t set a single square on its own. And some faces can’t be reached at all, no matter what you own.
Turn one face, and the others move
We’ve already put a price on this: bring an open model in-house and you trade capability and operational burden for control. But a price assumes you can weigh one thing against another while it holds still. Here, nothing does.
You bring the model in-house. Open weights, your hardware, your building – more control over the infrastructure, the aspect everyone starts with. It’s real work and it’s worth doing, but it’s the achievable part, and people mistake it for the whole. Watch what one turn does to the other five.
Two faces come into place as you hoped. Data turns: nothing leaves. Or rather, the inputs don’t – the half everyone checks. The other half is what the model makes from your data: embeddings, vector stores, fine-tuned weights, retrieval indexes. New, derived from the sensitive material, and “nothing leaves the building” doesn’t govern them unless you govern them on purpose. The face turns most of the way. Dependency turns too: nobody can withdraw the model or switch you off, because you hold the file – and you could move it, run it anywhere, keep it running without anyone’s permission.
That’s the face you were looking at. Now the ones you weren’t.
Operation turned out of place – the safety, patching and evaluation the provider did quietly are now yours, staffed by people you may not have yet. That much is familiar from any repatriation.
And turning Dependency into place cost you on the way. You don’t get the same thing running under your own roof – you get a lesser one, the model your team quietly preferred, given up. Gartner describes the trade-off bluntly: “the degree of sovereignty achieved is often inversely related to the functionality received.”
And Formation didn’t move at all. Whatever went into that model, and whatever it learned to prefer, was fixed before you touched it and stays fixed after.
One decision. Two faces mostly set – and even the easy one, Data, left a residue you now have to chase. One face turned the wrong way, a capability bill on the side, and one face the turn never reached. This isn’t a tradeoff you can evaluate one dimension at a time – the pieces move each other while you compare them. Choosing turns the cube.
And there’s a way to turn a face so hard you knock the table over. Push Data and Dependency all the way – nothing in, nothing out, connected to nothing – and you haven’t won sovereignty, you’ve built the air-gapped pizza chain from earlier in this series that isolated itself into irrelevance. AI earns its keep by reaching: to your data, your users, the systems it works across. Solving a face shouldn’t destroy the ground the whole thing stands on.
Why the frameworks don’t help here
There’s no shortage of frameworks for this, and the better ones are good: they break sovereignty into dimensions, have you score each, decide where you genuinely need control, and accept dependence elsewhere. The serious ones say plainly that maximum control isn’t the goal. But the method rests on one assumption – that you can take the dimensions one at a time. And you can’t solve a cube one face at a time; the moves interact by nature. You’ve just watched it: one decision set two faces, turned a third the wrong way, ran up a capability bill, and never reached Formation. A score before and a score after would both be accurate, and neither would tell you what you traded.
That’s the first reason AI is the hardest case. The second is worse: some faces have a core you can’t score, because the information isn’t yours to see.
The faces you can’t turn
Three of the six can be settled with effort. Data, Operation and Permission take work, but the answers exist and you can go and find them. Where the data sits and who runs it are the first two. Permission is the third: the legal right to use the model as you intend – the licence terms that quietly restrict commercial or specific uses, export controls on where it can go, the AI regulations that allow some deployments and forbid others. It’s usually knowable, though the answer can shift under you when a rule or a licence changes. Dependency is mostly in this group too, once you hold the file.
The other faces don’t work like that. Two of them – Reach and Formation – have a core you can’t score, and that’s where the real difficulty lives.
Reach – what it touches. You can score plenty in advance: blast radius, permissions, which systems and tools an agent may access. What you can’t do is pre-enumerate the compositions. Give an agent access and it composes across what it’s allowed – a contract here, a support history there, an internal page nobody remembered was open. And it doesn’t only read: it acts – sending, buying, changing records, triggering workflows – so the exposure isn’t just what it saw, but what it did in your name. Each was permissioned correctly on its own; the combination was permissioned by nobody, and it forms at inference time, differently every request. You can log what it did after the fact. You can’t know, in advance, every combination it will make.
Formation – how it was made. Not just the corpus – the whole process that shaped how the model behaves: what it was trained on, yes, but also the filtering, the fine-tuning, the reward modeling, the safety training, the thousand choices about what it would refuse and what it would favor. All of it was decided before you saw the model, almost none of it is documented, and you can run it offline in your own building and still have no idea how it came to prefer what it prefers. This face survives every deployment decision you’ll ever make.
Formation – what comes out. You hand it your material, ask for a draft, and what comes back reads fine – professional, balanced, unobjectionable. But nothing that writes is neutral. It carries assumptions about what a reasonable position sounds like, how much to hedge, what’s controversial and what’s obvious – and those were formed by choices that weren’t yours. The frontier models come from a small number of places, none of them likely to be yours, and each carries the defaults of where it was built. Whichever you pick, the assumptions aren’t your organization’s – and they arrive looking like plain good sense rather than a point of view.
That’s a cultural dependency, and it hardens into a cognitive one. Cultural, because the norms in the output are somebody else’s. Cognitive, because after enough drafts you stop noticing: the model’s framing becomes the version you edit from rather than one option among several. You read the output as the plain version of your own thinking. It’s the plain version of someone else’s – and once that’s what your policies, guidance and customer replies sound like, it’s what your organization sounds like. There’s a name starting to attach to this – cognitive sovereignty, the question of whose worldview shapes your decisions – and it’s big enough to deserve its own treatment. Set every other side into place, and this one stays exactly as it came.
So what do you do?
At the extreme, you close every face. Train your own model, on your own corpus, with your own choices about what it refuses and how it sounds. You control what goes in and how it’s shaped far more deeply than any other option allows – though even then, not every behavior it develops is one you chose or can foresee. The most complete sovereignty available at the model layer.
Almost nobody will, and the reason isn’t timidity. It’s a corpus in the trillions of tokens to license or build, a cluster running for months, a team who’s done it before, and a bill in the millions – at the end of which you have a model honestly worse than the one you could call over an API for a fraction of the cost. This is the face the sameness pointed at, and this is its price: real, and out of reach for almost everyone.
Short of that, one face has a genuine answer. Genuinely open source – where sufficiently detailed data information and the training code are published, not just the weights – lets you see what went in. Provenance stops being unanswerable and becomes merely expensive. The same trade applies, just smaller: the genuinely open models sit behind the frontier, and you take on the operational work the provider was doing.
For most organizations the answer will land in the middle. Open weights close three faces that matter to many organizations: your data doesn’t leave, nobody can withdraw the model, no foreign jurisdiction reaches your runtime. Three of the six, answered properly, at a capability cost that’s real but survivable.
What it doesn’t close is the training. You inherit a corpus you can’t see and the assumptions that came with it, and you take on the operations the provider was quietly running. Fine-tuning helps – it moves tone, format and domain a long way – but it layers behavior on top of what’s already in there. It doesn’t reach down and unlearn the corpus. That’s the residual, and knowing exactly what you left open beats believing you closed it.
And whatever you turn, the model stays connected – that was never the thing to give up. A sovereign model still reaches your data, your people, the ecosystem it works in; sovereignty is holding those connections on your own terms, not trading them away for a bunker. The faces you close are about control, not retreat.
Which is the whole argument. Not can we be sovereign here, but which faces did we actually turn, and can we live with the ones we couldn’t.
Originally published on LinkedIn
