Sovereign AI knowledge management has crossed the line from abstract concern to a procurement requirement. If you are shortlisting a platform that will read, index, and answer questions from your organisation's documents, the hard part is no longer the demo. It is evidencing, to a regulator or a risk committee, that the answers and the documents behind them stay within a jurisdiction you control.
This guide is the toolkit we wish every buyer arrived with. It turns the sovereignty conversation into something you can score, question, and put in a contract. It is written for the people who own that decision, the chief technology officer (CTO), the chief information security officer (CISO), compliance, and procurement, in UK and EU regulated organisations.
✓ Thanks, your guide is open below. We've noted your email, look out for a short sovereignty briefing over the next couple of weeks.
Sovereign AI knowledge management is less a product feature than a specification. This guide gives you the specification, and the questions that prove whether a vendor meets it. Work through it in order; sections 4 and 5 are the ones to take into a vendor meeting.
1. How to use this guide
Sovereignty procurement fails in a predictable way: the buyer asks "are you sovereign?", the vendor answers "yes", and everyone discovers eighteen months later that the answer was scoped to a tier nobody bought. This guide replaces that single question with a structured evaluation. Start by mapping your regulatory drivers, the Digital Operational Resilience Act (DORA), the Network and Information Systems Directive 2 (NIS2), UK GDPR, and any sector-specific rules, to the three sovereignty attributes in section 2. That mapping tells you whether residency is enough or whether you genuinely need a sovereign tier. Then use the checklist and the RFP questions to hold vendors to it.
2. The three attributes of sovereign AI
"Sovereign AI" is a phrase doing more work than it can carry. Used precisely, it has three distinct attributes. A platform might satisfy one, two, or all three, and buyers need to know which.
- Jurisdictional sovereignty. The entity operating the platform is incorporated where its laws protect customer data from compelled foreign disclosure. A UK subsidiary of a US parent does not qualify.
- Infrastructure sovereignty. The compute and storage are operated by a provider with no obligation to answer foreign discovery orders. AWS London does not qualify (Amazon is US-incorporated); Hetzner, OVHcloud, Scaleway, and IONOS do.
- Model sovereignty. The models answering queries run on sovereign infrastructure, or via a provider that itself passes the two tests above. A British front end calling a US-hosted model endpoint is not sovereign end-to-end.
Sovereign AI is the combination of all three. A vendor claiming sovereignty on the strength of one is not lying, it is selling a partial guarantee. Your job is to find out which parts.
3. The CLOUD Act, in plain terms
The US CLOUD Act (2018) compels US-headquartered companies to produce customer data on demand from US authorities, regardless of where that data physically sits. It reaches every US-parent company with storage or processing capability. Two features make it uncomfortable for UK organisations:
- It applies regardless of region. A London data centre does not remove the obligation, because the obligation runs through the corporate parent, not the hardware. Microsoft confirmed under oath to the French Senate in June 2025 that it cannot guarantee EU customer data will never be accessed by US authorities, which is why "EU-hosted" stopped being a sufficient answer that month.
- It applies without guaranteed notification. The request goes to the US parent; gag provisions can stop the vendor telling you.
The CLOUD Act does not reach a UK-incorporated vendor running on European sovereign infrastructure with models hosted there too. Where a vendor offers both a standard cloud tier and a dedicated sovereign tier, the difference is not cosmetic, and the CLOUD Act conclusion depends entirely on which tier you buy. Pin the question to a specific tier and get the scope in writing.
4. Residency versus sovereignty, a decision table
Residency and sovereignty are sold together but solve different problems. Keeping them separate in your procurement paper is the highest-leverage thing you can do. Residency answers where; sovereignty answers who.
| Question | Data residency | Data sovereignty |
| What it controls | Where the data physically sits | Which legal regime can compel disclosure |
| How it's delivered | A region setting, effectively a radio button | An architecture, corporate + infrastructure + model layers |
| Defends against CLOUD Act? | No | Yes, if all three attributes hold |
| Enough for DORA Article 28 "where"? | Partial | Yes |
| Enough where a regulator asks "who could reach this?" | No | Yes |
The working test: if the vendor's parent received a lawful request from a non-UK authority tomorrow, what would happen? Residency tells you nothing. Sovereignty tells you the request has no standing.
5. The seven-point evaluation checklist
Score each vendor against the seven points below. A vendor that scores "good" on all seven can evidence sovereignty. A vendor that scores "fail" or "partial" on any is offering something narrower, usually residency, sometimes just the hope that the CLOUD Act is never tested for their customer.
| Criterion | What "good" looks like | Red flag |
| 1. Corporate structure | Operating entity and parent both incorporated in a protective jurisdiction; no US covenants or board reach | US parent, or "UK subsidiary of…" |
| 2. Infrastructure provider | Compute and storage owned by a UK/EU operator (Hetzner, OVH, IONOS, Scaleway) | "We use AWS London" |
| 3. Model hosting | Models self-hosted or on sovereign-region endpoints under the same protection | Queries routed to a US model API |
| 4. Data boundaries | Vendor produces a diagram of every network boundary from input to model query to response | Cannot or will not draw it |
| 5. Tier clarity | Sovereignty scope stated per tier, in plain contract language | "The platform is sovereign" (unscoped) |
| 6. Evidence artefacts | Contracts, hosting agreements, corporate-structure docs available during evaluation | "We'll sort that at contract stage" |
| 7. Certification alignment | ISO 27001, ISO 42001, SOC 2, Cyber Essentials Plus, maintained under audit | Certifications "in progress" with no dates |
One practical note: the test is not whether a vendor can answer each point in a sales meeting. It is whether the answer survives landing on a compliance officer's desk six months later, with the contracts attached. Ask for the artefacts during evaluation, buyers who do get faster procurement cycles and fewer renewal surprises.
6. The RFP question bank
Copy these straight into your request for proposal. They are written to be hard to answer vaguely.
- Where is your operating entity incorporated, and where is your ultimate parent? List any US subsidiaries, investors with US-jurisdiction covenants, or US-resident directors.
- Name the company that owns and operates the compute and storage our data will use. Where is that company incorporated?
- Which AI models will answer our queries, and who operates the endpoint they run on? Is any query data transmitted to a US-incorporated model provider?
- Provide a data-flow diagram showing every network boundary our data crosses, from user input through model query to response.
- Is sovereignty a property of every tier you offer, or of a specific tier? State, in the contract, exactly which layers are sovereign at the tier we would buy.
- Which artefacts (contracts, hosting agreements, corporate-structure documents) can you provide during evaluation so we can evidence sovereignty to our regulator?
- List your current certifications with issue and expiry dates. For any "in progress", give the target date and the standard.
- Confirm in writing that our data, and our users' queries, are never used to train AI models, by you or by any model provider you use.
7. The vendor landscape, and the red flags
The sovereign AI market in 2026 divides into three groups, and most workable stacks combine two of them:
- Hyperscaler sovereign offerings (Microsoft Sovereign Cloud, Oracle EU Sovereign Cloud, Google Sovereign Controls), strong on residency, partial on sovereignty, because the parent is still US-incorporated.
- European sovereign infrastructure operators (T-Systems, OVHcloud, Scaleway, IONOS, Hetzner), the category that usually passes a rigorous CLOUD Act review; strong on infrastructure, thinner on AI application tooling.
- UK-owned specialist AI platforms, product-focused vendors building sovereign AI as their explicit positioning, typically running on European sovereign infrastructure. This is the category AnswerVault sits in.
The red flags, in one place: sovereignty implied as a property of the brand rather than a named layer; a "yes" to sovereignty that isn't scoped to a tier; an inability to draw the data-flow diagram; certifications perpetually "in progress"; and the reassuring phrase "we would notify you where permitted", which is not the same as "the request has no standing".
8. Where AnswerVault fits
AnswerVault is a governed AI knowledge layer that connects SharePoint, Google Drive, and Confluence and answers with sentence-level citations through web, Teams, Slack, CLI, and API. It is built by Catapult CX, a UK-incorporated consultancy. Its sovereignty picture is tier-scoped and stated plainly: the standard tiers run on AWS with inference on Azure OpenAI (residency, not sovereignty), while the Enterprise sovereign tier is a bespoke deployment on non-US infrastructure (Hetzner, OVH, IONOS, or Scaleway) with sovereign-region or self-hosted inference, scope written into the contract. It is ISO 27001 aligned with ISO 42001 underway, and listed on G-Cloud for direct award. The product's origins are in pharmaceutical knowledge management, where governance was the first requirement, not a later addition.
The fuller explanation lives on the sovereignty topic hub. When you're ready to score it against your own regulatory drivers, book a 30-minute sovereignty review and we'll do the mapping with you.
AnswerVault is built by Catapult CX. This guide is provided for procurement purposes and is not legal advice; confirm your own regulatory position with your compliance and legal teams.