vibencode
Service 04 of 06

Sovereign AI

Where is the data allowed to live?

Asked by: Security, legal, or whoever signs off the risk
What we hear

“None of our data can leave the country.”

What it becomes

Model weights on your hardware in your region, under your keys, with retention you set and an audit trail on every call.

What building inside a sovereignty constraint involves

Residency is the word people arrive with, and it is rarely the whole requirement. Underneath it sit three separate questions, usually answered by three different people: where the data physically rests, how long anything is kept, and who holds the keys that could decrypt it. Get those written down and signed and the architecture mostly follows. Get them wrong and you find out during an audit, at which point the fix is not a configuration change but a rebuild. Most of the list below is settling the rule before designing to it.

  1. 01Establish the real requirement (residency, retention, access, audit, and who actually holds the keys) rather than the assumed one.
  2. 02Choose the deployment: on-premises, private cloud or hybrid, with the trade-offs written down and costed.
  3. 03Design for the constraint from the first line. Retrofitting sovereignty is close to rebuilding.
  4. 04Prove it: an audit trail on every call, and evidence in a form an auditor will accept.
  5. 05Hand over operations, including what happens when a model has to be replaced.
What you end up with
  • Sovereignty assessmentThe clause you are actually held to, on one page, signed by the people who own it.
  • Deployment architectureOn-premises, private cloud or hybrid: costed, with the trade-offs stated rather than implied.
  • Operational handoverYour infrastructure team running it, including what happens the day a model has to be replaced.

Residency was the word everyone used. Retention and key custody were what they meant.

Week one is spent finding out which of the three you are actually held to. See our recent work
How an engagement usually runs
Weeks 1–2

Establish the rule

What is actually required, written on one page and signed off by the people who own it.

Weeks 3–4

Choose the deployment

On-premises, private cloud or hybrid: costed, with the trade-offs stated rather than implied.

Weeks 5–8

Build inside the constraint

With the audit trail as a first-class part of the system rather than a log somebody greps.

Week 9 onward

Prove it, then hand over

Tested against real audit questions, then operated by your own infrastructure team.

What we need from you
  • The actual rule, not the summaryThe clause, the regulator, the contract. “It cannot leave the country” is a starting point rather than a requirement, and the gap is the cost.
  • Someone who can decideLegal, security and infrastructure disagreeing in week eight costs more than any architecture choice made in week three.
  • Honest hardware and budget limitsRunning weights in-region has a floor. Better to design to the real number than to discover it once the architecture is set.
  • The audit you will eventually faceWho asks, and what they accept as evidence. Retrofitting an audit trail is close to rebuilding, so it is designed in from week one.
Questions we get asked
What actually is sovereign AI?

Running AI systems entirely inside a boundary you control: the region the data rests in, the hardware the weights run on, the keys that could decrypt any of it, and a retention period you set rather than inherit. It is less a capability than a constraint, and the work is proving the constraint holds in a form an auditor will accept rather than asserting it on a slide.

Does this mean self-hosting an open-weight model?

Sometimes. Sometimes the answer is a managed service in the right region under the right contract. Which of the two applies is a finding, not an assumption, and it comes out of the first fortnight.

Is a sovereign deployment slower or worse?

Usually somewhat more expensive and somewhat less convenient. Whether it is worse depends entirely on what happens to you if residency turns out to be wrong.

Can you work with our existing infrastructure team?

That is the intended arrangement rather than a concession. They will be operating this afterwards, so they should be building it alongside us.

Is this a service of its own, or a constraint on the others?

Honestly, both. Mostly the second. It shapes an implementation or an agent system rather than replacing one. This page is the workstream that establishes the constraint, designs to it and proves it holds.

What about the DPDP Act, the EU AI Act, or our sector’s rules?

We build to the rule you are actually held to, with your legal team in the room. We do not give legal advice. We take their reading of it and make the system demonstrably match, in a form an auditor will accept.

If the problem is somewhere else

Sovereignty shapes what you build rather than being the thing you build. The assistant or the agent system still comes from somewhere else. This is the workstream that establishes the rule, designs to it, and proves it holds.

Where is the data allowed to live?

Describe the constraint in your own words. We will tell you what it costs.