Free guide · Sovereignty

The Sovereign AI Buyer's Guide

A procurement toolkit for UK and EU organisations evaluating a sovereign AI platform, the CLOUD Act in plain terms, a residency-versus-sovereignty decision table, a seven-point scored checklist, and a copy-paste RFP question bank.

Sovereign AI knowledge management has crossed the line from abstract concern to a procurement requirement. If you are shortlisting a platform that will read, index, and answer questions from your organisation's documents, the hard part is no longer the demo. It is evidencing, to a regulator or a risk committee, that the answers and the documents behind them stay within a jurisdiction you control.

This guide is the toolkit we wish every buyer arrived with. It turns the sovereignty conversation into something you can score, question, and put in a contract. It is written for the people who own that decision, the chief technology officer (CTO), the chief information security officer (CISO), compliance, and procurement, in UK and EU regulated organisations.

What's inside

  • The three attributes that actually define sovereign AI, and why one of them is usually missing
  • The US CLOUD Act in plain terms, why "EU-hosted" stopped being enough in June 2025
  • A residency-versus-sovereignty decision table you can drop into a procurement paper
  • A seven-point evaluation checklist, scored, with what "good", "partial", and "fail" look like for each
  • A copy-paste RFP question bank, the exact questions to send a vendor
  • The UK and EU sovereign-AI vendor landscape, and the red-flag claims to distrust

Get the guide

Enter your work email and the full guide opens on this page, no PDF, no wait. We'll also send occasional sovereignty and AI-governance briefings; unsubscribe any time.

✓ Thanks, your guide is open below. We've noted your email, look out for a short sovereignty briefing over the next couple of weeks.
Sovereign tier

Want this scored against your own regulatory drivers?

Book a 30-minute sovereignty review. Tell us your framework exposure (DORA, NIS2, UK GDPR, sector rules) and we'll map it to the three sovereignty attributes and where a sovereign tier is actually required.