All posts
SovereigntyJuly 30, 20265 min read

What sovereignty is, and how to measure it

The Sovereignty Series · Part 3 of 5

A working definition of AI sovereignty, and a maturity model for locating your enterprise on the path from rented to owned. Part III of the Sovereignty Series.

By Dr. Rod Malehmir, PhD, CTO Michael Baker International

Sovereignty is not on-premises computing, and it is not vendor avoidance. It is where you place the boundary.

Having named the forces at work, this part defines the term precisely and offers a maturity model enterprises can use to locate themselves honestly.

3. What sovereignty is, and is not

Sovereignty is not autarky. A sovereign enterprise typically uses more providers, not fewer, because it is architecturally able to. It is not a compliance project either — residency and certification are purchasable; sovereignty is the architecture that makes them options rather than obstacles. Michael Baker runs on a hyperscale cloud, licenses frontier models, and partners deeply with platform vendors. The distinction is which layer we treat as substitutable and which layer we treat as ours.

The sovereign enterprise rents compute, rents models, and owns everything in between.

4. The AI Sovereignty Maturity Model

The model has two parts. Stages describe where an enterprise sits overall. Layers describe where it is exposed. Most organizations are uneven, and the unevenness is the actionable finding.

StageWhat the enterprise controlsCharacteristic failure
1. AmbientNothing. Employees use consumer tools on personal accounts.Institutional knowledge exits the perimeter invisibly.
2. LicensedSeats. Policy exists on paper.Adoption measured in licenses, not outcomes. Shadow usage persists.
3. IntegratedThe data boundary, inside a governed tenant.Governs its data but still rents reasoning, memory and interface.
4. OwnedThe intelligence layer: routing, context, agents, telemetry.Operating burden, reliability engineering and key-person risk.
5. SovereignThe compounding asset: portable institutional memory.Failure mode is abandonment, not architecture.
The five stages.

Stage 3 is where most well-run enterprises quietly stop. Connecting corporate content to a vendor-hosted assistant inside a compliant tenant is genuine, valuable work. It solves data residency. It does not solve sovereignty. On the day the terms change, a Stage 3 enterprise discovers it governed its data and rented everything that made the data useful.

LayerRentedGovernedSovereign
ModelWhatever the tool ships.Single approved provider, version pinning.Multi-provider routing; substitution is a config change.
DataContent leaves through individual accounts.Tenant boundary and residency enforced.Lineage-tracked, provider-independent estate.
KnowledgeDocuments and people's heads.RAG over document stores.Curated, versioned, graph-linked context substrate.
AgentUnmanaged personal automations.Vendor-platform agents, cataloged.Enterprise registry with identity and portability.
GovernanceNo policy, no telemetry.Written policy, tenant logging, periodic audit.Compliance evidence generated, not assembled.
EconomicPer-seat rent, value unmeasured.License optimization and adoption reporting.Usage correlated to margin, win rate and delivery.
The six-layer diagnostic.
  • The floor rule. An enterprise's true stage is its lowest layer, not its average. Sovereign model routing over an ungoverned knowledge layer produces confident answers grounded in nothing. Sovereignty is a chain.
  • Knowledge is the layer that compounds. Model, Data, Governance and Economic maturity protect value. Knowledge maturity creates it. An enterprise that advances every layer but Knowledge has built a very well-governed way of renting someone else's memory.