A board asks the chief information officer a question that sounds simple. The organisation is about to roll out an AI tool across the business, and someone on the risk committee wants to know whether it is sovereign. What is sovereign AI, and does this product qualify? The honest answer takes twenty minutes to give, because the question has at least three meanings and the vendor's data sheet answers only the least important one.
That gap is the reason the term causes so much trouble in UK procurement. Sovereign AI has become a category label attached to products that satisfy very different definitions of it, and buyers frequently discover which definition they bought some months after signing. This post sets out a definition that survives a supplier review, why the term is so often mis-scoped, and how to work out whether your organisation genuinely needs it. The full regulatory and market picture sits in our guide to sovereign AI for UK organisations.
What is sovereign AI?
Sovereign AI means the infrastructure that processes your content, and the company operating it, both sit under the jurisdiction you require. Two conditions, and the second is the one that gets dropped.
The reason both are needed is that a service has layers, and sovereignty can hold at one layer while failing at another.
The storage layer
Where your documents sit at rest. This is the layer every security questionnaire asks about and the easiest for a vendor to evidence, which is why it is usually the layer a sovereignty claim describes. On its own it tells you little.
The processing layer
Where the content is actually read in order to compose an answer. Storage and processing are separate facts and can sit in different countries. A platform can hold your documents in London and send the reasoning step elsewhere, and nothing in a hosting-region claim would reveal that.
The control layer
Which company owns the entity operating those servers, and therefore whose law it must obey. This is the layer that decides the question, and it is not a geographic property at all. It survives no amount of regional deployment.
A service is sovereign when all three align with the jurisdiction you need. When people say a product is sovereign because it is hosted domestically, they are describing the first layer and inferring the other two.
What does sovereign AI mean when the law is extraterritorial?
The layers matter because some legal instruments follow ownership rather than geography. The clearest example is the US CLOUD Act (2018), which compels US-headquartered companies to produce customer data on demand regardless of where that data physically sits. It reaches the parent company, and through the parent it reaches subsidiaries and the data they hold anywhere. A US-owned provider operating a London data centre is within its scope, and no choice of region changes that.
This is why credible sovereignty is normally sold as a specific Enterprise tier with its own infrastructure and its own contractual commitments, rather than as a characteristic of an entire product line. The architecture that delivers it costs more to run and constrains what the vendor can do operationally, so a claim applied uniformly across cheap and expensive plans alike is describing something else.
Public statements have made the limit unusually explicit. Microsoft confirmed to the French Senate in June 2025 that it cannot guarantee EU data will never be accessed by US authorities. That is not a criticism of Microsoft: it is an accurate description of what any US-incorporated company can promise. Meanwhile Chapter V of the GDPR governs transfers of personal data rather than corporate nationality, so a service can be entirely GDPR-compliant and still sit inside a foreign jurisdiction's reach. Compliance and sovereignty are different tests.
UK sovereign AI: what changes locally
For UK buyers the question has a particular shape. Leaving the EU did not remove the extraterritorial exposure, because that exposure was never about EU membership; it follows the ownership of the supplier. What it did change is that UK organisations now assess two regimes rather than one when they operate across both markets.
The practical UK sovereign AI position for most organisations comes down to three questions. Does a regulator or a client contract actually require domestic control, as opposed to domestic hosting? Is the data involved of a kind where foreign access would be materially damaging rather than merely unwelcome? And would your organisation be able to evidence its position if asked, which is a records question rather than an infrastructure one?
Public sector procurement tends to force these questions into the open through frameworks and assurance processes. Private sector buyers more often discover them during a client audit, which is a worse time.
What sovereign AI is not
Three adjacent things are routinely presented as sovereignty and are not.
| Claim | What it actually delivers | What it leaves open |
|---|---|---|
| Data hosted in a UK or EU region | Data residency: a location choice for content at rest | Who operates the processing tier, and whose law reaches them |
| A domestic subsidiary as the contracting entity | A local commercial relationship and local support | The ultimate parent, which is where extraterritorial obligations attach |
| Certifications and compliance attestations | Evidence of controls being operated properly | Jurisdiction, which no certification confers |
Each of the three is worth having. None of them answers the sovereignty question, and a shortlist can be narrowed considerably by asking a single follow-up: which legal entity operates the servers that run the model, and under which country's law is it incorporated? The answer is one sentence long when it is good.
Do you actually need it?
Probably not, and that is the part vendors are least likely to volunteer.
Full sovereignty carries real costs. The infrastructure is more expensive, the supplier field is smaller and less mature in adjacent features, and a strict no-cross-border-failover posture means accepting an outage where a mainstream platform would degrade gracefully. Those are reasonable trade-offs when the risk justifies them and poor ones when it does not.
For most UK organisations, regional data residency combined with a defensible audit trail is the proportionate answer. Sovereignty earns its cost where a risk assessment has identified foreign-jurisdiction access as a live and material exposure: certain public sector work, some regulated financial and health data, legal matters where confidentiality obligations run to third parties, and organisations under contractual commitments to clients who have made their own assessment. The decision should be reached deliberately in either direction. Our guide to sovereign AI platforms compared sets out the six-point checklist for testing a shortlist against.
How AnswerVault approaches sovereignty
AnswerVault is a governed AI knowledge layer that connects an organisation's existing document sources, including SharePoint, Google Drive, and Confluence, and answers from approved document sets through web chat, Microsoft Teams, Slack, CLI, and API.
The honest answer differs by tier, and saying so is more useful than a single claim covering everything. The Starter, Pro, and Business tiers run on mainstream cloud infrastructure with a commercially managed AI tier, and should be assessed on a data-residency basis with region selection available from Business upwards. Presenting them as sovereign would be the exact substitution this post argues against. The Enterprise sovereign tier is the one built for the definition above: non-US infrastructure, UK corporate control over the processing tier, no cross-jurisdiction model fallback, and a contractual commitment rather than a configuration setting.
AnswerVault is ISO 27001 aligned, G-Cloud listed, and ISO 42001 certification is underway. The subprocessor list, attestations, audit rights, and the identity of the certifying entity are on our security and compliance page, which is the material a procurement team needs to test any of the above rather than take it on trust.
Where to go next
Start by establishing which of the three layers your current or prospective supplier actually controls, because until that is written down the sovereignty conversation cannot be had properly. Then decide, deliberately, whether your risk assessment requires all three or whether residency is proportionate.
Our guide to sovereign AI for UK organisations covers the regulatory background, the UK and EU landscape, and how sovereignty interacts with governance and audit obligations.
AnswerVault is built by Catapult CX, an enterprise technology consultancy. The product was originally developed for a global pharmaceutical company with strict data governance requirements; the same architecture now powers the SaaS platform.