Most states will never possess full-stack AI autonomy, and the sooner their planners accept it the better their odds. The point is not that ambition is misplaced. It is that the frontier stack, the chips, the fabrication, the cloud, the foundation models, the tooling, the standards, the security review, and the long-duration capital behind all of it, is reproducible in full by almost no one. A handful of states hold one layer or two. Taiwan holds advanced fabrication. The Gulf holds capital. The European Union holds regulation. The vast majority hold no decisive frontier bottleneck.
The interesting case is that majority. Not the near-peer that makes itself hard to abandon by becoming indispensable to others, but the ordinary medium state that holds no frontier layer at all and knows it. It is dispensable. It will remain dependent on foreign infrastructure for the parts of governance that now run through models. The interesting question is not how such a state escapes dependence. It cannot. The question is whether it can stay sovereign inside dependence it will never eliminate.
Renting a mind is not like renting a machine
Industrial dependence has always been survivable. A state that buys its aircraft, its steel, its turbines from abroad does not thereby change what its finance ministry can understand about the economy or what its health ministry can know about a disease. The dependence sits downstream of the state’s own judgment. It constrains what the state can build, not what it can see.
Renting cognition is not wholly new, but it is a sharp intensification. States have long taken in things that sit upstream of their own judgment: credit ratings, foreign intelligence feeds, the settlement rails their payments clear through. What changes with models is scope and mutability. When a ministry’s analysis, a court’s evidence handling, a central bank’s fraud detection, and a hospital’s diagnostics all run through models the state neither trained nor controls, the dependence moves upstream of judgment across many domains of government at once, and the provider can revise its defaults remotely, after the contract is signed. The provider’s defaults become the state’s priors. Nothing is conquered. The flag stays, parliament sits, the courts convene. But increasingly the state reasons through infrastructure whose governing conditions it does not set, and a provider that changes its terms is changing, quietly, what the state is able to decide.
That is why the standard sovereign-AI slogan, build your own so you depend on no one, is the wrong instruction for the country that cannot build its own. It sets an unreachable bar and calls everything short of it failure. The reachable bar is different. The stronger recent treatments already sense this: they abandon autarky and redefine the goal as resilience, switch providers, refuse lock-in, hold selective domestic capacity, keep contingency in reserve.1 They are right, and they stop at the level of capability. Dependence that has moved upstream of judgment is not only a capability problem. It is a constitutional one. Once foreign models sit beneath what a state can perceive and decide, the power to substitute them is no longer procurement prudence; it is part of the state’s capacity to govern itself. That is the bar worth naming precisely, and it is why two very different strategies both answer to the word “sovereign.”
Two ways to hold a dependence
The first way buys entry by binding yourself to a single stack’s home jurisdiction. The clearest live specimen is the arrangement around G42 in Abu Dhabi. Microsoft’s 2024 investment came wrapped in a first-of-its-kind Intergovernmental Assurance Agreement, a binding private framework developed with the American and Emirati governments that commits the parties to meet or exceed United States standards on cybersecurity, physical security, export controls and technology transfer, data protection, and customer vetting.2 It is a serious instrument, and it does convert raw dependence into something governed and inspectable. But look at where the conditions point. The Emirati side retains a golden-share style veto over national-security decisions on paper, while the operative constitution of the arrangement, the part that decides what may be built and who may touch it, runs toward Washington’s export-control regime and licensing discretion. This is dependence made conditional. It is not dependence made reversible. The state has bought access to the frontier by deepening its alignment to one pole.
That trade has its theorist. Anton Leicht argues that the middle power’s real choice is between a permanent periphery and binding itself to American frontier AI, and that the binding is worth its price: offering sites, energy, capital, and data-center capacity in exchange for access, and accepting deeply entrenched technological dependence and even geopolitical submission as the cost of staying inside the AI economy.3 He is right that the periphery is real and right that access cannot simply be refused. But his account ends where the harder problem begins. It answers the question of entry and treats the price as paid once, at the door. The dependence that decides sovereignty is the one that keeps rewriting its own terms after the state is already inside, and against that, alignment to a single pole is not protection but exposure.
The second way keeps the capability foreign but engineers the dependence so it can be inspected, wrapped, substituted, and left. France offers the cleanest working model. Its “cloud de confiance” doctrine sits on the ANSSI SecNumCloud qualification, whose 3.2 revision adds explicit immunity criteria against extraterritorial law, and it is delivered through French-law joint ventures, S3NS built on Google technology, Bleu on Microsoft’s, that legally isolate the operation from the foreign parent.4 The technology is American. The custody, the legal exposure, and the operational control are domestic. The design goal is stated plainly by the regulator: no foreign kill switch, no extra-European access to the data, guaranteed localization.
The European Union has turned the same instinct into hard law. Since September 2025 the Data Act has given every cloud customer in the Union a statutory right to switch providers and receive technical cooperation to port their data, and from January 2027 it forbids switching and egress charges entirely, removing the single most effective lock-in mechanism a provider has, the exit toll.5 Portability stops being a favor and becomes an entitlement.
Singapore shows the capability side of the same posture. Its state-backed SEA-LION models are not an attempt to replace the frontier labs. They are, in the words of the program’s own director, an effort to remain a “smart consumer” of global systems and to “engage on equal footing,” with open, forkable licensing as the deliberate hedge, backed by a national multimodal programme and a multi-year public compute and research commitment.6 The point is not a sovereign model that beats OpenAI. The point is enough domestic capacity that the state understands what it is renting and could keep essential functions running if the terms changed.
These are not three national choices among which a state picks one. They are layers of a single posture: legal custody, statutory portability, and a domestic capability floor, each covering an exit the others leave open.
What none of this buys
Here is the honesty these prescriptions usually skip. None of it is autarky, and pretending otherwise sets the reader up to be disappointed by the first hard fact.
The head of France’s own cyber agency said it directly when the trusted-cloud qualification drew fire: the badge does not mean the absence of dependence. By the agency chief’s own public estimate, the two flagship hybrid offerings could sustain operations for perhaps six to twelve months if they lost access to their American parents’ updates.7 The Data Act kills the egress fee, but proprietary formats, bespoke interfaces, and identity binding survive the fee ban, so a right to leave on paper is still not an exit you can execute unless you have kept your data and workloads portable in fact. Singapore’s flagship regional model is itself adapted from a Chinese-origin foundation, which means its hedge against one dependence runs partly through another. But even together these protections reach only some layers of the dependence. Beneath legal custody, statutory portability, and model forkability sits the hardware, the accelerators and the fabrication that decide whether there is any compute to run the fallback on at all, and no exit clause reaches it. Software can be forked; the machine that runs it still has to be sold to you, and that sale is another government’s decision. That the deepest layer stays out of reach does not refute the posture; it defines its limits. The claim is not that every dependence can be reversed. It is that reversibility at the layers a state can reach, custody, portability, forkable weights, a domestic inference floor, is worth more than submission across all of them. A hedge that fails at the hardware base can still hold at every layer above it. And even a clean exit is not a return to the same state. Swap the model and the function survives, but the judgment shifts, since two systems will classify the same evidence, price the same risk, and triage the same patients differently. Portability preserves what the state can do, not how it decides, which is the thing the dependence touched in the first place.
So the reachable condition is not independence. It is reversibility, maintained continuously, layer by layer, contract by contract. What that reversibility races against is speed: dependence becomes command at the point where a provider can impose a change faster than the state can substitute away from it. France’s six-to-twelve-month figure is not trivia. It is that race made numerical, the runway a trusted-cloud arrangement buys before a withdrawal of access turns into control over what depends on it. And that runway is not fixed. It shortens as the frontier pulls away, because the fallback a state would exit into falls further behind the system it is exiting with every month the gap widens, so the exit is cheapest to architect now and dearer every quarter it is deferred. Reversibility is not a state you arrive at and hold. It is a property that decays from two directions at once: from the moment procurement stops enforcing it, and from the speed of the very divergence it exists to hedge. That is a weaker claim than the sovereign-AI literature likes to make. It is also the only one a country that cannot build the stack can actually keep.
Synthetic nonalignment
Call the resulting posture synthetic nonalignment. The Cold War’s nonaligned movement was diplomatic. It was made of communiqués, summits, and public refusals to join a bloc. A state could sign every declaration and still be, in practice, wholly inside one patron’s orbit, because alignment then was a matter of treaties and basing rights that a leader could announce or renounce.
Alignment now is built lower down, and it cannot be announced away. A state can declare neutrality between Washington and Beijing while its ministries, its banks, its military logistics, its universities, and its public services all run on a single foreign stack. That state is not nonaligned in any sense that survives a change of terms. Its neutrality is a press release sitting on top of a dependency it has never architected.
It is not the newer answer either. The most recent proposals revive nonalignment as a coalition, an open and collaborative bloc smaller states can join for shared capability.8 That is a movement, and a movement is something you join and can be eased out of. Synthetic nonalignment asks no one’s permission and needs no coalition to hold. It is what a single state does on its own procurement authority, and open weights are what make the unilateral move possible: a model you can hold, run, and adapt without asking is one whose provider cannot quietly become your sovereign. Forkability here is not a preference for openness as a good. It is the mechanical precondition of an exit you can take alone.
Synthetic nonalignment is therefore not a diplomatic stance but an engineering and procurement discipline. It lives in things that sound too boring to be sovereignty: data-custody clauses, interoperability requirements, model portability, audit rights, fallback models, domestic inference capacity, compute reserves, sovereign-cloud joint ventures, forkable licenses, and the tested ability to switch providers. The constitution of the dependent state is being written, in part, in its supplier contracts. A provider that revises a model’s behavior, retires a version, narrows permitted use, or changes what its system will and will not answer has altered what an agency can perceive and execute, and it has done so without a single line of law being amended. Whoever drafts the exit clauses is doing constitutional work whether they know it or not.
This is the precise inverse of the binding logic modern integration runs on: states become integrated not when they agree but when exit becomes prohibitively expensive, and legitimacy follows the binding. Synthetic nonalignment is the deliberate refusal of that condition. It is the work of keeping exit affordable, provider by provider, so that no single dependence ever hardens into the thing you cannot walk away from. Where binding makes leaving unthinkable, this keeps leaving costed, drilled, and possible.
The instruments
None of the instruments is new. Multi-sourcing, interoperability mandates, exit clauses, contingency reserves: the policy literature has recommended them for a year, as prudence.1 The shift is in why they matter. Read as procurement hygiene they are optional, the first line cut when a budget tightens. Read as constitutional maintenance they are what keeps a dependent state governing itself, and they decay the moment enforcement stops.
So, for a state that will rent the frontier and still intends to stay sovereign inside that dependence: write portability and a costed exit price into every critical contract, so leaving is a known number and not a discovered catastrophe. Fund a domestic inference floor, enough sovereign compute and at least one forkable model to keep essential functions running through a change of terms, sized as insurance rather than autonomy. Wrap sensitive workloads on the French pattern, foreign capability under domestic legal custody, with no foreign kill switch as a stated requirement rather than a hope. Make multi-sourcing a rule, so no provider becomes indispensable to a critical function, because indispensability once granted is what gets priced against you later. Buy audit rights, so a dependence you cannot remove is at least one you can inspect. And drill the substitution, because the exit you never test is the exit you do not have.
None of this produces a sovereign AI. It produces a state that can say no, or at least can leave, which in an order organized around infrastructure is most of what saying no has ever meant.
The third position
The coming order is usually drawn as two blocs, an American stack and a Chinese one, with every other state sorted into one column or the other, and the counsel that follows is to choose a column early and make oneself valuable inside it. That map has room for a third position it tends to omit: states whose principal strategic capability is neither building the frontier nor choosing a patron, but managing dependence across providers, and, where possible, across rival stacks, so that none can convert access into command. That fuller balancing is still more direction than destination. Singapore, hedging a Chinese-origin model base against American frontier systems, is nearer to it than most, and even it holds only fragments. Such a state is not powerful in the old sense. It owns almost nothing at the frontier. What it holds is the harder, quieter competence of never letting a supplier become a sovereign.
That competence will not be visible in summits or communiqués. It will be visible, if at all, in the fine print of procurement, in the boredom of a well-run exit clause, in a ministry that has rehearsed leaving and a provider that knows it. The next nonaligned movement, if there is one, will be built from those clauses rather than from declarations.
Sovereignty is no longer the stack you own. It is the exit you can still afford.
Notes
1. Chatham House, Digital Society Programme, “How middle powers can weather US and Chinese AI dominance: the case for ‘sovereign AI’ strategies” (February 2026): frames full-stack sovereignty as unattainable for middle powers and recommends provider switching, multi-vendor interoperability standards in government procurement, selective sovereign capacity in critical domains, and pre-negotiated contingency arrangements for rapid provider substitution.
2. Microsoft and G42, Intergovernmental Assurance Agreement announced alongside Microsoft’s 1.5 billion dollar investment in G42 (April 2024), and Microsoft’s subsequent UAE investment framework (November 2025): binding commitments on cybersecurity, physical security, export controls and technology transfer, data protection, responsible AI, and customer vetting, developed in consultation with the US and UAE governments; UAE golden-share control over national-security decisions. Microsoft corporate statements; Core42 remarks on the physical-diversion and access-control elements (July 2026).
3. Anton Leicht, “What happens to countries that don’t build frontier AI?” Asterisk, Issue 15 (July 2026): argues that states without a domestic frontier developer face a “permanent periphery,” that sovereign-AI autarky is a trap, and that middle powers should move toward American frontier AI, offering sites, energy, capital, and data-center capacity for access and accepting entrenched technological dependence and geopolitical submission as the price of avoiding the periphery.
4. ANSSI SecNumCloud qualification, version 3.2 (2022), including immunity criteria against extraterritorial legislation. S3NS (Thales / Google Cloud) SecNumCloud 3.2 qualification for its PREMI3NS trusted-cloud offer (late 2025); Bleu (Microsoft / Capgemini / Orange) in qualification. Both structured as French-law joint ventures isolating data governance from the foreign technology parent.
5. Regulation (EU) 2023/2854 (Data Act), Chapter VI cloud-switching provisions in force since 12 September 2025; Article 29 phase-out of switching charges, with a full prohibition on switching and egress charges from 12 January 2027. Extraterritorial in scope: applies to any provider serving Union customers.
6. SEA-LION, AI Singapore, under the National Multimodal LLM Programme; companion MERaLiON model (A*STAR). Program director’s framing of “smart consumers” of global systems and engaging “on equal footing,” with open, forkable licensing. National AI research and talent commitment exceeding one billion Singapore dollars, 2025 to 2030.
7. ANSSI director general, clarification on the scope of SecNumCloud qualification (January 2026): qualification does not signify the absence of technological dependence; its guarantees are the prevention of a foreign kill switch, protection against extra-European authority access, and EU localization. Estimate that the qualified hybrid trusted-cloud offers could maintain operations for six to twelve months if cut off from their US technology parents’ updates.
8. For the coalition framing, see Martin Tisné, “Towards an Open, Resilient, Non-Aligned AI,” Le Grand Continent (February 2026), which proposes a new non-aligned movement organized around open and collaborative AI in the run-up to the AI Impact Summit.

