Own the Intelligence Layer
The state of AI sovereignty, and why the enterprise can no longer afford to rent its capacity to think. Volume I of the Digital MBI Sovereignty Series.
Most enterprises outsourced their capacity to reason, and called it a subscription.
Over the past thirty-six months most large enterprises have quietly outsourced something they have never outsourced before: the capacity to reason over their own information. They did it without a board decision, without an architecture review, and in most cases without a line item. It arrived as a per-seat subscription and it looked like software.
It is not software. It is an operating input, closer in character to electricity or capital than to a productivity suite. And the terms on which most enterprises have acquired it are unusually poor.
Three structural facts define the market. It is concentrated: three providers account for roughly 88 percent of enterprise spend on large language model APIs. It is unstable: the leader in that market has changed twice in three years, and one major provider issued eight deprecation notices covering models and developer platforms inside a single seven-week window in 2026. And it is repricing in real time: one provider published a scheduled 50 percent list increase on a flagship tier, another shipped a tokenizer generating roughly 30 percent more tokens for identical text at unchanged per-token rates, and consumption billing has been introduced alongside per-seat licensing across the major platforms.
An enterprise that has built its workflows, its institutional memory and its client commitments on a rented layer has accepted concentration risk, deprecation risk and repricing risk simultaneously, in a category it cannot easily exit. The returns have not compensated for the exposure.
The diagnosis matters more than the numbers. Pilots do not fail because the models are weak. They fail because the enterprise rented the reasoning and left the context outside it. Microsoft's 2026 Work Trend Index, covering 20,000 knowledge workers, found organizational factors account for more than twice the AI impact of individual factors, 67 percent against 32 percent. The constraint is not intelligence. It is what the intelligence can reach, what it remembers, and what it returns to the enterprise.
AI sovereignty is the capacity of an enterprise to direct, substitute, govern and accumulate value in its own intelligence layer, independent of any single external provider.
It is not on-premises computing, not building foundation models, and not vendor avoidance. It is the deliberate placement of a boundary: everything inside it compounds as an owned asset, everything outside it is a substitutable input bought at market rates.
1. Intelligence has become an operating input
Gartner forecasts worldwide AI spending of $2.59 trillion in 2026, up 47 percent, with $453.2 billion in AI software. Enterprise spend on generative AI specifically reached $37 billion in 2025, up 3.2 times year over year. Numbers of that magnitude usually signal a technology cycle. This one differs in a way that matters for governance.
Enterprise software has historically been a system of record. It stored what the enterprise knew and enforced how it worked. Intelligence is not a system of record. It is a system of judgment. It sits between the enterprise and its own information, and it participates in producing new information: the analysis, the recommendation, the drafted deliverable, the reasoning that explains why one alternative was selected over another.
When you rent a system of record you rent storage. When you rent a system of judgment you rent the interface through which institutional knowledge is created, and you concede the exhaust it produces.
The market has begun to name this. Gartner elevated “Sovereign AI Accelerates” to its top data and analytics trends in June 2026. NVIDIA reported sovereign AI revenue above $30 billion for fiscal year 2026, more than triple the prior year. The European Commission's InvestAI initiative is mobilizing up to €200 billion, and Japan's METI allocated roughly ¥1.23 trillion to chips and AI for fiscal 2026. Sovereignty has moved from policy rhetoric to procurement line item at national scale. What has not happened in most enterprises is the translation of that logic down to the firm.
The knowledge base is also walking out of the building: 679,500 open US engineering positions against 141,000 graduates a year, 1.7 million infrastructure workers leaving their jobs annually, and one in four civil engineers approaching retirement without an identified successor. For a professional services firm that is not a staffing problem. It is a balance sheet event that never appears on the balance sheet. Thirty years of judgment about how a specific bridge type behaves in a specific climate under a specific agency's review process leaves on a Friday afternoon and is gone.
Meanwhile the peer set is committing capital to the layer itself rather than to tools. WSP announced a seven-year partnership with Microsoft in February 2025, a combined commitment exceeding $1 billion, framed around building virtual experts across roughly 73,000 professionals. Arcadis took an equity position in an AEC-specific agent platform in August 2026 to gain influence over its roadmap. Both are sovereignty moves. One buys scale in the layer, the other buys governance over it. Neither is a license purchase.
2. Four forces that make rented intelligence fragile
The case does not rest on predicting which provider wins. It rests on four properties of the market that hold regardless.
2.1 Concentration without stability
Three providers hold roughly 88 percent of enterprise LLM API spend, and in the same market the leader has changed twice in three years, with the current leader moving from 12 percent to 40 percent share. High concentration is ordinarily paired with high stability, which is what makes it tolerable. This market has the concentration without the durability.
The response to that instability is the most revealing data point available. Open-weight models closed the capability gap from 174 Elo points in May 2023 to 49 points in March 2026 while getting dramatically cheaper — and their share of enterprise API spend fell from 19 percent to 11 percent. The binding constraint on portability is not capability and it is not price. Our reading, flagged as inference rather than finding, is that enterprises stayed on frontier APIs because they had built nothing that would let them switch.
2.2 Deprecation as a recurring operating cost
Model retirement is now scheduled rather than exceptional. One leading provider publishes minimum notice of six months for generally available models, three months for specialized variants, and as little as two weeks for preview models. Under that policy the model generation that initiated enterprise generative AI procurement in 2023 switches off in October 2026, along with every fine-tuned derivative built on it. Models released in late 2025 were retired inside twelve months. Deprecation does not arrive as a drumbeat; it arrives in clusters — eight notices in seven weeks, three of them on a single day.
Sovereignty does not eliminate deprecation cost, it contains it. If model selection is an abstracted routing decision inside your own layer, a deprecation is a configuration change plus a regression run. If it is implicit in a thousand prompts inside a vendor's tool, it is an unbudgeted migration project.
2.3 Price is not a stable unit of comparison
Almost no procurement process controls for tokenizer efficiency, which means per-token list price is not a reliable basis for comparing cost across model generations or vendors. Both things are true: the cost of a unit of intelligence is collapsing while the enterprise AI bill is rising, because consumption grows faster than unit price falls and the composition of that bill is set by the vendor rather than the buyer. Sovereignty converts an opaque, vendor-determined bill into a legible, buyer-determined one.
2.4 Regulatory divergence is a design constraint
| Date | Event | Jurisdiction |
|---|---|---|
| 10 Nov 2025 | CMMC requirements enter contracts via DFARS final rule | US, defense |
| 11 Dec 2025 | Executive order on a national AI policy framework | United States |
| 27 Jul 2026 | AI Omnibus enters into force; AI Office powers expanded | European Union |
| 2 Dec 2027 | High-risk obligations apply, Annex III | European Union |
| 2 Aug 2028 | High-risk obligations apply, Annex I | European Union |
3. What sovereignty is, and is not
Sovereignty is not autarky. A sovereign enterprise typically uses more providers, not fewer, because it is architecturally able to. It is not a compliance project either — residency and certification are purchasable; sovereignty is the architecture that makes them options rather than obstacles. Michael Baker runs on a hyperscale cloud, licenses frontier models, and partners deeply with platform vendors. The distinction is which layer we treat as substitutable and which layer we treat as ours.
The sovereign enterprise rents compute, rents models, and owns everything in between.
4. The AI Sovereignty Maturity Model
The model has two parts. Stages describe where an enterprise sits overall. Layers describe where it is exposed. Most organizations are uneven, and the unevenness is the actionable finding.
| Stage | What the enterprise controls | Characteristic failure |
|---|---|---|
| 1. Ambient | Nothing. Employees use consumer tools on personal accounts. | Institutional knowledge exits the perimeter invisibly. |
| 2. Licensed | Seats. Policy exists on paper. | Adoption measured in licenses, not outcomes. Shadow usage persists. |
| 3. Integrated | The data boundary, inside a governed tenant. | Governs its data but still rents reasoning, memory and interface. |
| 4. Owned | The intelligence layer: routing, context, agents, telemetry. | Operating burden, reliability engineering and key-person risk. |
| 5. Sovereign | The compounding asset: portable institutional memory. | Failure mode is abandonment, not architecture. |
Stage 3 is where most well-run enterprises quietly stop. Connecting corporate content to a vendor-hosted assistant inside a compliant tenant is genuine, valuable work. It solves data residency. It does not solve sovereignty. On the day the terms change, a Stage 3 enterprise discovers it governed its data and rented everything that made the data useful.
| Layer | Rented | Governed | Sovereign |
|---|---|---|---|
| Model | Whatever the tool ships. | Single approved provider, version pinning. | Multi-provider routing; substitution is a config change. |
| Data | Content leaves through individual accounts. | Tenant boundary and residency enforced. | Lineage-tracked, provider-independent estate. |
| Knowledge | Documents and people's heads. | RAG over document stores. | Curated, versioned, graph-linked context substrate. |
| Agent | Unmanaged personal automations. | Vendor-platform agents, cataloged. | Enterprise registry with identity and portability. |
| Governance | No policy, no telemetry. | Written policy, tenant logging, periodic audit. | Compliance evidence generated, not assembled. |
| Economic | Per-seat rent, value unmeasured. | License optimization and adoption reporting. | Usage correlated to margin, win rate and delivery. |
- The floor rule. An enterprise's true stage is its lowest layer, not its average. Sovereign model routing over an ungoverned knowledge layer produces confident answers grounded in nothing. Sovereignty is a chain.
- Knowledge is the layer that compounds. Model, Data, Governance and Economic maturity protect value. Knowledge maturity creates it. An enterprise that advances every layer but Knowledge has built a very well-governed way of renting someone else's memory.
5. The intelligence layer: what you actually own
If the model is rented and the compute is rented, what precisely is the owned asset? Four components, and the first two are widely underestimated.
5.1 The context substrate
Every AI system is a function of what you put in front of it. The industry assumed larger context windows would solve this. They did not. Anthropic's engineering work documents “context rot,” the measurable degradation of recall as token count grows. Microsoft Research found graph-grounded retrieval outperforming vector retrieval even when the vector system was given million-token context windows. More context is not better context. Curated context is better context.
| Property | Why it matters |
|---|---|
| Diffable | Knowledge becomes version-controlled with attribution and history. |
| Dual-readable | Human-editable and machine-parseable in the same file. |
| Structured without noise | Headings and links carry hierarchy; no markup to wade through. |
| Model-agnostic and durable | It is text. It survives every model generation and moves between providers. |
One caution, because the counter-evidence is the design principle. The llms.txt convention grew nearly ninefold to roughly 36,000 files by May 2026, and server log analysis across 137,000 domains found 97 percent received zero requests. Markdown-first knowledge creates value when it sits inside the agent's retrieval path, not when it is published and hoped for. A substrate is something your systems read by default. A document is something someone might find.
5.2 The knowledge graph, the agent layer, and telemetry
Retrieval over documents answers questions a document already answers. Most valuable enterprise questions span sources and require relationships — which is what a knowledge graph holds. Above it sits the agent layer: portable definitions, enterprise-held identity, capability limits and lifecycle management. Beneath all of it runs telemetry, so every interaction is observable, attributable and joinable to a financial outcome. Those four components are the owned asset.
6. Case in point: why Michael Baker built Titan
Michael Baker International is an 86-year-old engineering and consulting firm of roughly 6,000 people. We are not a technology vendor, and this decision was not taken because building was appealing. It was taken because the alternative did not answer the question we were being asked.
| Issue | Why |
|---|---|
| The economics inverted at scale | Cost fixed per person while value concentrated in a minority of heavy users — precisely the wrong shape. |
| The data question had no good answer | Not residency, which is purchasable. Accumulation. Every interaction produced signal, and none of it accrued to us. |
| We could not measure anything that mattered | We could report adoption. We could not report impact. |
So we built Titan, an internal enterprise AI platform we own end to end. It routes across multiple frontier models so model selection is a governed decision. It keeps interaction data inside our own tenant, so accumulation accrues to the firm. It provides an enterprise-owned agent registry, so agents built by our people are our assets. And it instruments everything, so usage can be joined to financial and project outcomes. We deliberately did not build models, did not build infrastructure, and did not attempt to replace the productivity suite.
What it returned
- Adoption moved from single digits toward the mid-twenties as a share of the workforce — a leading indicator, not a result. The mechanism was the platform combined with a peer champion network of domain experts.
- Unit economics changed shape. Cost moved from a fixed function of headcount to a variable function of use.
- Agent creation became organic and substantial. Hundreds of purpose-built agents now exist, created predominantly by non-developers.
- Institutional knowledge began to accumulate as structure, by default rather than by effort. We consider this the strategic return.
- We can answer the client question. When a state agency asks where its information goes, the answer is architectural and demonstrable rather than contractual.
We do not yet have a defensible P&L attribution, and we are not going to pretend otherwise. Owning the layer is what makes the measurement possible. It does not make it instant.
What we would sequence differently
| Lesson | What we would tell another firm |
|---|---|
| Building a platform means operating a platform | Budget for reliability engineering as a standing function, not a phase of development. |
| Key person risk is real and we experienced it | Split ownership across architecture and release approval from day one. |
| We built the interface ahead of the data foundation | The Knowledge and Data layers should lead and the interface should follow. |
| Dogfooding is not optional and it is not fast | We ran Titan internally at scale well before considering any external use. It was correct. |
A limit we will state plainly: Titan routes across multiple frontier providers, which lowers switching cost but does not by itself reduce concentration risk, since those providers are the concentrated ones. Extending routing to open-weight models is on our roadmap and is not yet done.
7. The economics of owning versus renting
| Component | Favors |
|---|---|
| Accumulated institutional value | Owning, strongly |
| Switching cost over time | Owning, strongly |
| Deprecation cost predictability | Owning, moderately |
| Direct cost at enterprise scale | Owning, moderately |
| Security and key person risk | Renting, moderately |
| Operating burden and reliability | Renting, strongly |
If your competitive advantage is the accumulated judgment of your people, then the layer where that judgment is expressed is not a commodity, and you should not rent it.
8. A twelve month agenda
| Workstream | Timing | What it means |
|---|---|---|
| See | Q1 | Run the six-layer diagnostic honestly, including a shadow AI estimate. Instrument before you procure. |
| Decide the boundary | Q1–Q2 | Write down which layers are rented and which are owned. A governance decision, made once and defended. |
| Build the knowledge substrate | Q2 | Convert high-value institutional knowledge into structured, versioned text inside the retrieval path. |
| Agent registry and capability rule | Q2–Q3 | Portable definitions and lifecycle, before the agent population reaches the hundreds. |
| Abstract the model | Q3 | Governed routing validated with a real regression run. |
| Join telemetry to the P&L | Q3–Q4 | Correlate usage with margin, win rate and delivery. Retire adoption as the headline metric. |
| Fund the champion network | Continuous | Organizational readiness accounts for roughly twice the AI impact of individual readiness. |
9. What we may be wrong about
- Frontier providers may absorb the layer. If they ship enterprise-grade knowledge graphs, portable agent registries and full telemetry export as commodity features, the differentiated value of an owned layer narrows.
- Open standards may make the question moot. If MCP, A2A and their successors mature sufficiently, portability becomes a property of the ecosystem rather than an achievement of the enterprise.
- Enterprise behavior contradicts the thesis. Buyers chose dependency with full information; the competing explanation is that they rationally value support, indemnification and provenance over portability.
- Our own case study does not yet close the loop. We have argued ownership makes P&L attribution possible, and we have not yet published one.
10. Conclusion
The intelligence layer is the most consequential architectural decision most enterprises will make this decade, and the majority are making it by default, one seat license at a time. None of the four forces requires a provider to behave badly. It only requires the market to keep behaving as it currently does.
Against that, the enterprise has one durable advantage no provider can replicate: it is the only party that has its own institution. That asset either compounds inside a boundary the enterprise controls, or it accrues, interaction by interaction, to someone else. Michael Baker built Titan because we concluded that an engineering firm whose entire value proposition is accumulated technical judgment cannot rationally rent the layer in which that judgment is now expressed. The build was harder than we expected, we sequenced part of it wrong, and we would do it again.
In five years, when your most experienced people have retired and your systems answer questions in their place, who will own the thing that learned from them?
Notes on method
Figures are drawn from primary sources wherever available, with publication dates given so readers can assess currency in a market that moves quarterly. Principal sources: Menlo Ventures, 2025: The State of Generative AI in the Enterprise (Dec 2025); McKinsey, The state of AI in 2025 (Nov 2025, n=1,993); BCG CEO survey (Jul 2026, n=152); Microsoft Work Trend Index 2026 (May 2026, n=20,000); BST Global & ACEC, AI + Data Insights 2026 (May 2026); Stanford HAI, AI Index Report 2026; Gartner, Top Trends for Data and Analytics 2026; and provider pricing and deprecation documentation retrieved 7 August 2026. Framework exhibits are qualitative illustrations of the argument and should not be cited as measurements.