Skip to content
Research

Policy brief

What "sovereign" should mean for AI compute

A working definition of sovereign AI compute, a scoring method across six layers of the stack, and what it says about the options open to UK public services today.

Published
25 Sept 2026
Authors
Toby Chen, Victoria de Bruijn and Emma Walker
Topic
Framework
Status
Published · 4 min read

Summary

"Sovereign AI" is used loosely. It can mean a model trained in the UK, a service hosted in a UK data centre, or a supplier headquartered here, and these are not the same thing. A service can be hosted in the UK and still be subject to another country's law, or depend on a model the UK cannot inspect or change.

This brief proposes a definition that can be tested. It treats an AI service as a stack of six layers and asks, for each, who controls it and under which law. It then applies the test to four common ways of providing AI to public services.

Why a definition matters

Without an agreed definition, "sovereign" becomes a label any supplier can claim. Buyers in government cannot compare offers, and investment cannot be directed at the parts of the stack where the UK is most exposed.

A useful definition has to be:

  • Testable — a buyer can check it from evidence a supplier can reasonably provide.
  • Layered — it distinguishes a UK-hosted service from a UK-controlled one.
  • Proportionate — it recognises that not every use needs the strictest standard.

Six layers of control

We use the same six layers set out on our overview of the stack. For each layer we ask one question.

LayerThe question
PolicyWhich country's law governs the service, and can a foreign authority compel access?
ApplicationsWhere are prompts, outputs and logs processed and stored?
ModelsWho controls the model weights, and can the UK inspect, adapt and audit them?
RoutingCan a request leave the UK, including on failover?
ComputeWho owns and operates the hardware, and who can switch it off?
EnergyIs the service sited and powered in the UK?

Each layer is scored from 0 to 3.

ScoreMeaning
0Controlled from outside the UK
1In the UK, but under material foreign control or legal reach
2UK-controlled, with a limited foreign dependency
3UK-controlled and auditable end to end

Measuring sovereignty

For a service with layer scores s1,…,s6s_1, \dots, s_6 and weights w1,…,w6w_1, \dots, w_6 that sum to one, the sovereignty index is the weighted average, scaled to lie between 0 and 1:

S=13∑i=16wi si,∑i=16wi=1.S = \frac{1}{3} \sum_{i=1}^{6} w_i \, s_i , \qquad \sum_{i=1}^{6} w_i = 1 .

An average can hide a single point of failure: a service that is fully British except for a model controlled abroad is still exposed at that layer. So we also record the weakest link,

smin⁡=min⁡i si,s_{\min} = \min_i \, s_i ,

and propose that a service counts as sovereign only if it passes both tests:

S≥0.8andsmin⁡≥2.S \ge 0.8 \quad \text{and} \quad s_{\min} \ge 2 .

Unless stated otherwise we weight the six layers equally, wi=16w_i = \tfrac{1}{6}.

Four ways to provide AI today

We apply the test to four common arrangements.1

  • A. Overseas API. A public body calls a model hosted and operated abroad.
  • B. Overseas provider, UK region. The same kind of service, run from data centres in the UK by a company headquartered elsewhere.
  • C. UK-hosted open model. An openly licensed model, adapted and run by a UK operator on UK infrastructure.
  • D. Sovereign pooled compute. Open models adapted on British data and served from accredited UK nodes, with an audit trail — the approach we propose.
LayerABCD
Policy0123
Applications1233
Models0023
Routing0133
Compute0122
Energy0333
Index, SS0.060.440.830.94
Weakest link, smin⁡s_{\min}0022

Sovereignty index by arrangement

Equal weights across the six layers; 80% is the proposed threshold

0%20%40%60%80%100%Sovereignty index6%A. Overseas API44%B. UK region83%C. UK-hosted open94%D. Pooled compute
View data as a table
CategorySovereignty index
A. Overseas API6%
B. UK region44%
C. UK-hosted open83%
D. Pooled compute94%

Source: SovereignStrUKture scoring, table above.

Hosting in the UK moves a service a long way on energy, but only part of the way overall. Arrangement B scores full marks for energy and still fails the weakest-link test, because the model and the legal control sit abroad. Arrangements C and D pass both tests. Neither scores 3 for compute, because the chips themselves are made abroad; that is a dependency to manage rather than one any single service can remove.

How robust is this?

Equal weights are a choice. Some will argue that control of the model matters most, since a service that cannot inspect or change its model cannot fully answer for its outputs. To test this, we vary the weight on the model layer, wMw_M, and share the rest equally:

S(wM)=13(wM sM+1−wM5∑i≠Msi).S(w_M) = \frac{1}{3} \left( w_M \, s_M + \frac{1 - w_M}{5} \sum_{i \ne M} s_i \right).

Sovereignty index as model control is weighted more heavily

Weight on the model layer, with the other five layers sharing the rest equally

  • D. Pooled compute
  • C. UK-hosted open
  • B. UK region
0%20%40%60%80%100%Sovereignty index0%10%20%30%40%50%Weight on the model layerD. Pooled computeC. UK-hosted openB. UK region
View data as a table
Weight on the model layerD. Pooled computeC. UK-hosted openB. UK region
0%93%87%53%
10%94%85%48%
20%95%83%43%
30%95%81%37%
40%96%79%32%
50%97%77%27%

Source: SovereignStrUKture scoring; equation above.

The conclusions for A, B and D hold at any weighting. C is the marginal case: once the model layer carries more than about a third of the weight, C falls below the 0.8 threshold. Whether a UK-hosted open model counts as sovereign therefore depends on how much the UK can adapt and audit that model — which is exactly where we recommend investment.

Recommendations

What we will do next

We will publish the scoring guidance in full with worked examples, test it with public bodies that are procuring AI, and report where the evidence is hard to obtain. Our forthcoming brief on procuring sovereign AI will build on it.

Footnotes

  1. The four arrangements are simplified types, not assessments of particular suppliers. Real services vary, and the scores should be applied to each on its own evidence. ↩

How to cite

Toby Chen, Victoria de Bruijn and Emma Walker (2026). What "sovereign" should mean for AI compute. SovereignStrUKture. Available at https://sovuk.vercel.app/research/sovereign-compute-framework