Daily AI Roundupby Bles Software
Guides / sovereign ai

Sovereign AI in 2026: What Countries Actually Control

Sovereign AI is national control over AI compute, data and models. Here is what the 2026 spending, export rules and primary documents show about how much control it really buys.

Direct answer

Sovereign AI is national control over the AI stack, and in 2026 the spending is real while the control is partial

Sovereign AI is the ability of a country or an organisation to develop, run and govern AI using compute, data and models it controls, rather than renting all of it from foreign providers. In 2026 the money behind that ambition is real: governments have committed tens of billions and the programmes are under construction. The control is a different question. The Center for a New American Security tracks 185 sovereign AI projects and finds most of them running on American technology, and the export rules that govern access to that technology are written in Washington, carry conditions, and carry expiry dates. Sovereign AI in 2026 is best read as a spectrum of reduced dependency, not a binary that a country either has or does not have. Sources: Center for a New American Security; McKinsey and Company; Bureau of Industry and Security, Federal Register.

Published by Bles Software16 primary sourcesEditorial method

What sovereign AI means, and the four things people mean by it

The definitions in circulation broadly agree. McKinsey describes sovereign AI as a country's or an organisation's capacity to independently develop, deploy and govern artificial intelligence using its own infrastructure, data and workforce. Red Hat frames the same idea as a shift from renting AI to owning it. Oracle puts it as a government's or organisation's control over AI technologies and the data associated with them. CNAS, which is a research institution rather than a supplier, uses a tighter test: a government-backed AI initiative tied explicitly to national strategic interests and backed by material public investment in domestic compute, models or data ecosystems. Sources: McKinsey and Company; Red Hat; Oracle; Center for a New American Security.

The agreement matters less than the ambiguity underneath it. Sovereignty is claimed over four layers, and a programme can hold one while depending completely on another. You can put the data centre inside your borders and still buy every accelerator in it from one foreign supplier. Almost every dispute about whether something is really sovereign turns out to be a disagreement about which layer is being counted. Sources: Center for a New American Security.

LayerWhat full sovereignty would requireWhat the 2026 evidence shows
ComputeDomestic design, manufacture and operation of the acceleratorsCNAS finds NVIDIA supplying the GPUs for 45 percent of tracked infrastructure projects, and judges a fully independent stack outside China hard to envision near term
Legal accessNo foreign permission needed to buy or keep running the hardwareGulf access runs on U.S. export authorisations with security conditions, ongoing compliance monitoring and, for the UAE entities, an expiry date
ModelsWeights that can be inspected, retrained and run locallyThe most durable win. Open-weight national models are downloadable and self-hostable, and are the layer countries have actually captured
Data and jurisdictionData stored and processed under domestic law onlyWidely achieved and widely marketed, and the layer most often used to describe an entire stack as sovereign

How much is actually being spent, and by whom

CNAS tracks 185 sovereign AI projects worldwide and splits them by layer: 59 percent target infrastructure, 32 percent target models, and 9 percent target data. The spending is far more concentrated than the project count suggests. The top ten spenders account for roughly 90 percent of all disclosed investment, and the UAE and Japan alone account for nearly two-thirds of it. The global picture is not many nations building capacity. It is a handful of well-capitalised states building a great deal of it while everyone else announces. Sources: Center for a New American Security.

The clearest measure of the money is on the seller's side. On its February 25, 2026 earnings call, NVIDIA chief financial officer Colette Kress reported sovereign AI revenue of more than 30 billion dollars for fiscal 2026, more than triple the prior year, naming Canada, France, the Netherlands, Singapore and the UK. Against total fiscal 2026 revenue of 215.9 billion dollars, sovereign AI was roughly 14 percent of the company, and it grew several times faster than the business as a whole. The most precise available number for what national AI sovereignty cost in 2026 is a line item in an American supplier's accounts. Sources: The Motley Fool.

Canada shows what one of those national commitments looks like in its own paperwork. The AI Sovereign Compute Infrastructure Program allocates roughly 890 million Canadian dollars to an infrastructure build layer across seven fiscal years from 2026 to 2027 onward, restricts eligibility to Canadian not-for-profits, post-secondary institutions and consortia they lead, and requires a Canadian-located, Canadian-governed system in which data residency, operational control and decision-making authority remain in Canada. The conditions are about ownership and jurisdiction. They say nothing about who makes the chips. Sources: Innovation, Science and Economic Development Canada.

For scale, Stanford's 2026 AI Index puts United States private AI investment at 285.9 billion dollars against China's 12.4 billion. Sovereign programmes are large in absolute terms and small next to the private buildout they exist to offer an alternative to. Sources: Stanford Institute for Human-Centered AI.

The dependency the word is doing its best to hide

CNAS states the constraint plainly: most sovereign AI projects rely heavily on foreign, overwhelmingly American, technology, and in the near term it is hard to envision any sovereign compute project outside of China wholly independent of the U.S. technology stack. That is not a vendor's caveat. It is the finding of the most detailed public census of these programmes that exists. Sources: Center for a New American Security.

The Gulf programmes are the sharpest illustration, because the terms are public. On November 19, 2025 the U.S. Department of Commerce announced authorisation for G42 in the UAE and Humain in Saudi Arabia to buy the equivalent of up to 35,000 NVIDIA Blackwell GB300 chips. The announcement states the approvals are conditioned on both companies meeting rigorous security and reporting requirements, that the Bureau of Industry and Security will monitor compliance on an ongoing basis, and that the Department will continue to support the export of what it calls the American AI technology stack. The supplier's own government describes the foundation of Gulf sovereign AI as American. Sources: U.S. Department of Commerce.

The 2026 follow-up is more striking still. A final rule published in the Federal Register on July 14, 2026, effective July 10, moved the UAE out of Country Groups D:3 and D:4 and into A:5, giving approved UAE entities license-free access to advanced computing items. The rule text then sets the terms. If the two UAE-based AI companies fail to become U.S. companies on or before April 6, 2027, they must apply for authorisation through a separate process to maintain their approved status, and absent subsequent notice the authorisation for G42 and Core42 automatically expires on that date. The condition attached to the Gulf's flagship sovereign AI firms keeping open access to chips is that they become American companies. Sources: Bureau of Industry and Security, Federal Register; Skadden, Arps, Slate, Meagher and Flom.

None of that makes the programmes pointless. Domestic capacity, local jurisdiction and trained operators are worth having, and NVIDIA's account of nations deploying AI for strategic priorities describes real systems doing real work. It does mean the word sovereign carries more weight than the documents underneath it support. Sources: NVIDIA.

Europe: the biggest published plan and the smallest committed cheque

The European Commission's AI gigafactories programme is the most documented attempt to build sovereign capacity at continental scale. The InvestAI Facility set out to mobilise 20 billion euros, a 2025 call for expressions of interest returned 77 proposals across 16 member states and 60 sites, and the Commission frames the goal as full-stack technological sovereignty, including domestic design and, in its own careful phrasing, in due course the future manufacturing of indigenous EU AI processors. Sources: European Commission.

The formal call opened on July 30, 2026, for up to seven gigafactories against a headline of roughly 30 billion euros: 5 billion from the Commission, 5 billion from member states and 20 billion expected from private investors. The number that matters most is smaller. Brussels can currently commit about 1 billion euros, with the rest depending on the next multiannual financial framework. Construction is expected to begin in early 2027 and the facilities to be operational around mid-2028. A senior EU official summarised the bind directly: Europe wants to build its own capacity and also wants to do some AI right now. Sources: Euronews.

That gap between a published plan and a committed budget is the most useful thing to watch in European AI sovereignty. Announcements are cheap and compute is not, and funding contingent on a future budget negotiation adds a political dependency on top of the technical ones. Sources: Euronews.

Where sovereignty is actually being won: open weights

The model layer is the one where national programmes have produced something durable, and it is the least discussed. India is the clearest case, and it is also the reason Google's own related questions on this topic ask what Sarvam AI does. Sarvam publishes its models openly: Sarvam-105b at 106 billion parameters and Sarvam-30b at 32 billion are both downloadable from Hugging Face, alongside quantised variants and a translation model, with tens of thousands of downloads recorded on the repositories. Sources: Hugging Face.

Open weights are the one form of sovereignty that does not expire. A downloaded model cannot be revoked by a change in export policy, cannot be deprecated by a vendor, and can be run on whatever hardware a country can obtain, including hardware it may only obtain later. Compare that with compute access, which the Federal Register shows can be granted, conditioned and dated. A country that owns weights and rents compute is in a materially better position than one that owns a building and licenses a model. Sources: Hugging Face; Bureau of Industry and Security, Federal Register.

This is also the layer where the CNAS exception lands. The one place the report can imagine genuine independence from the U.S. stack is China, and the Roundup's own archive recorded the reason on July 9, 2026, when a Chinese open-weight model reached the top of the open-weight charts trained on all-Huawei silicon. Domestic silicon plus open weights is the only combination anyone has demonstrated that closes both gaps at once. Sources: Center for a New American Security; Bles Software.

Sovereignty washing, and why the search results look the way they do

There is now a name for the marketing version. Writing for the AI Now Institute in February 2026, Rafael Grohmann describes vendors who sell sovereignty by installing a local cloud in a country and telling it that it is sovereign now because the cloud and the data centres are in its own territory, while they remain owned by the vendor. His broader argument is that the state-versus-big-tech framing obscures who actually gains, and that being a technologically dependent country means not being sovereign in that area, whatever the contract says. Sources: AI Now Institute.

This is visible in the search results themselves, which is worth naming because it shapes what most people read on this topic. Of the organic results on the first page of Google for this term in the United States on August 24, 2026, most are published by companies that sell sovereign AI infrastructure or services, including Red Hat, Oracle, NVIDIA and HPE. One result, the CNAS index, is independent research. Those vendor definitions are reasonable and we cite three here. They are simply not written by anyone with a reason to tell you how much of the stack you will still be renting. Sources: Red Hat; Oracle; Center for a New American Security.

What the Roundup's own archive shows about how this story arrives

We checked our own published record. Across 59 days of the Daily AI Roundup public journal, from June 27 to August 24, 2026, we published 324 story cards. Twenty-seven of them, appearing on 23 separate days, covered chips, GPUs, semiconductors or export controls. Exactly one used the word sovereign, on July 1, 2026. Sources: Bles Software.

That ratio is the finding. Sovereignty is not an occasional policy story that surfaces at summits. It is a near-daily story that arrives wearing other labels: an export decision, a supplier's capex, a chip startup's valuation, a lab designing its own accelerator. Anyone tracking this topic by searching for the word will see roughly one event in twenty-seven. The useful watchlist is not sovereignty announcements. It is who can buy which accelerators, under what conditions, and for how long. Sources: Bles Software; Bureau of Industry and Security, Federal Register.

What to check before accepting a sovereignty claim

The same five questions work whether you are assessing a national programme or a vendor pitching a sovereign cloud to your company. They are ordered by how often the answer is uncomfortable.

  • Whose permission is required to keep the hardware running, and does that permission have an expiry date or a compliance condition attached?
  • Who owns the accelerators and who operates the facility, as distinct from where the building sits?
  • Do you hold model weights you can download, inspect and retrain, or do you hold an API contract?
  • Which layer does the sovereignty claim actually cover: compute, legal access, models, or only data residency?
  • If the supplier relationship ended tomorrow, what would still run, and for how long?

Common questions

Who controls sovereign AI? In most programmes, control is split. The host country typically controls the site, the data and the legal jurisdiction. A foreign supplier controls the accelerators, and a foreign government controls whether those accelerators can be sold and kept in service. The Gulf authorisations are the clearest published example of that split. Sources: U.S. Department of Commerce; Bureau of Industry and Security, Federal Register.

Which countries have sovereign AI? By CNAS's count there are 185 government-backed projects, but disclosed investment is concentrated, with the top ten spenders holding roughly 90 percent and the UAE and Japan alone nearly two-thirds. NVIDIA separately named Canada, France, the Netherlands, Singapore and the UK as its main sovereign customers in fiscal 2026. Having a programme and having capacity are different things. Sources: Center for a New American Security; The Motley Fool.

What does Sarvam AI do? It is an Indian AI company that builds and openly publishes large language models, including Sarvam-105b and Sarvam-30b, which are downloadable from Hugging Face. It is cited in sovereign AI discussions because openly published national models are the part of the stack a country can genuinely keep. Sources: Hugging Face.

What does sovereign AI mean for a company rather than a country? The same four layers, at smaller scale. Most enterprise sovereign offerings deliver data residency and a local legal entity, which is real compliance value. Very few deliver control of the compute or the weights. Ask which layer you are buying before you accept the label, because the definitions vendors publish cover the whole stack while the products usually cover one layer of it. Sources: AI Now Institute; Oracle.

Limits and uncertainty

This guide describes sovereign AI as of August 24, 2026, on a topic where the governing documents change faster than the concrete does. Four limits belong with it. Investment figures are disclosed figures: CNAS counts what governments and companies have announced, so undisclosed and classified spending is missing and the concentration it measures may be overstated or understated. NVIDIA's sovereign AI revenue is the company's own segment reporting, which is a good proxy for hardware sold into these programmes and not a measure of capacity actually in service. The Federal Register page for the UAE rule returned a block to the host used for this research, so the rule was read from the Federal Register's own full-text file and cross-checked against a law firm analysis of it; two published analyses of that rule disagreed on the exact expiry date, and we quote the date in the rule text rather than either summary. We have also withheld the widely circulated projections of total sovereign AI spending by 2030 and the estimates of low-income countries' share of global compute, because we could not verify either against a primary source on the day of publication.

Evidence

Primary sources

Sovereign AI IndexCenter for a New American Security · April 2026, updated August 2026, retrieved 2026-08-24
NVIDIA Q4 fiscal 2026 earnings call transcriptThe Motley Fool · call held 2026-02-25, retrieved 2026-08-24
How Nations Are Deploying AI for Strategic PrioritiesNVIDIA · 2026-07-06, retrieved 2026-08-24
Enhanced Favorable Treatment for the United Arab Emirates Under the Export Administration Regulations, final rule 2026-14132Bureau of Industry and Security, Federal Register · published 2026-07-14, effective 2026-07-10, full text retrieved 2026-08-24
Statement on UAE and Saudi Chip ExportsU.S. Department of Commerce · 2025-11-19, retrieved 2026-08-24
AI GigafactoriesEuropean Commission · retrieved 2026-08-24
AI Sovereign Compute Infrastructure ProgramInnovation, Science and Economic Development Canada · retrieved 2026-08-24
Sarvam AI model repositoriesHugging Face · retrieved 2026-08-24
Inside the AI Index: 12 Takeaways from the 2026 ReportStanford Institute for Human-Centered AI · 2026-04-13, retrieved 2026-08-24
Sovereignty, by Rafael GrohmannAI Now Institute · 2026-02-12, retrieved 2026-08-24
What is sovereign AI?Red Hat · 2026-04-15, retrieved 2026-08-24
What is sovereign AI?McKinsey and Company · 2026-03-06, retrieved 2026-08-24
Sovereign AIOracle · retrieved 2026-08-24
BIS Liberalizes Export Licensing Rules for Shipments to the UAESkadden, Arps, Slate, Meagher and Flom · July 2026, retrieved 2026-08-24
Daily AI Roundup public journal archiveBles Software · daily since 2026-06-27, retrieved 2026-08-24
Daily AI Roundup tracks the model, agent, infrastructure, security, and policy changes that matter. The public site shows the source map. Subscribers get the complete analysis by email.Get the full intelligence free