Sovereign AI means the AI system runs where your data already is, under your jurisdiction's law and your organisation's control, rather than sending your data to someone else's infrastructure. The intelligence moves; the data does not. The term is being applied loosely enough that it is worth being specific about what it actually requires.
This guide sets out what sovereignty actually requires at each layer of the stack, the four deployment topologies and what each genuinely costs, and the questions that separate a real sovereignty claim from a hosting arrangement with a national flag on it.
A vendor can truthfully say "your data stays in-country" while several other things about the deployment remain entirely outside your control. Sovereignty is a property of the whole stack, and each layer can be sovereign or not independently.
The layer everyone means when they say sovereignty, and the easiest to satisfy. Necessary and nowhere near sufficient — data at rest in Singapore that is processed by a model serving from another region has not stayed in Singapore in any sense that matters.
Where the model actually runs when your data is in context. The question that resolves it: when a document is processed, does its content leave this facility for any purpose, including inference, logging, monitoring or abuse detection? Abuse-detection pipelines are the common exception clause — content is transmitted for safety scanning even where the primary inference is local.
Who holds administrative credentials, who can read logs, and under which country's legal process those people can be compelled. Data physically stored in one jurisdiction may still be reachable through legal process directed at a provider incorporated elsewhere — for government health agencies this frequently turns out to be the decisive consideration.
Who holds the encryption keys, and can the provider decrypt without you. Provider-managed keys mean provider-accessible data regardless of where it sits. Customer-managed keys in customer-controlled hardware is a materially different position.
The layer most often ignored, and the one with the longest tail. The scenario worth planning for is not a technical failure — it is commercial or political: a provider changes terms, is acquired, exits a market, or falls out with your government. Model independence means the orchestration layer can route to different models, including locally served open-weight models, without the workflows being rewritten.
Deployment options, from least to most constrained. The right choice is per workflow, not per organisation.
Hosted with regional residency — the vendor's cloud, with data stored in a chosen region. Sovereign in the residency layer only.
Sovereign cloud with in-country tenancy — dedicated tenancy in national infrastructure with in-country processing and defined operational control. The common landing point for government health agencies and large pharma.
On-premise — inside your own data centre, on your hardware, behind your firewall. Strong across every layer; costs are real hardware, operational burden and an update path you own.
Air-gapped — no outbound connectivity at all. The strongest position and the most constrained, eliminating whole categories of risk rather than mitigating them, at the cost of frontier model access and automatic updates.
Where Eclypse sits: the platform supports all four topologies on the same orchestration layer, so a workflow's constraint decides its posture rather than the whole estate inheriting the strictest one. See AI for government health agencies for how this plays out in a sovereign deployment.
Six questions, asked in writing. The precision of the answers is itself the signal: where does inference physically run; does content leave the boundary for any purpose; who holds the keys and the credentials; what happens if your model provider withdraws; can you substitute models without rewriting workflows; and what is the update path. Vendors who have genuinely built for this answer specifically; vendors who have not answer in adjectives.
Sovereignty is a set of trade-offs made per workflow, not a posture adopted once. See enterprise AI agents for how these topologies constrain agent deployment specifically.
An AI deployment where processing happens within a defined jurisdiction, under the controlling organisation's authority, with the data not leaving that boundary. It spans data residency, processing locality, operational control, key custody and model supply.
No. Residency covers only where data is stored. Sovereign AI additionally covers where processing happens, who can access the system, who holds keys, and model-provider dependency.
No. Air-gapped is the most constrained of four topologies — hosted with regional residency, sovereign cloud, on-premise, and air-gapped. Most institutions should run different workflows in different topologies.
Ask where inference runs, whether content leaves for logging or abuse detection, who holds keys and admin credentials, and what the model substitution path is — in writing.
Our proprietary AI orchestration platform for healthcare: one engine, a registry of reusable task modules and domain agents, and a governed knowledge base — deployed inside your walls and run by your team.