Sovereign AI is a control problem
Boris Toledano
COO & Co-founder
Sovereign AI is the power to control the rules your AI runs under. Read on to find out what actual sovereignty is, the questions you should be asking, and how to achieve it.
TL;DR
- Sovereign AI comes down to choice and control. You need to choose your components and govern the information that passes through them. A vendor’s nationality alone tells you little about either.
- Data residency is one link in a longer chain. A request can cross models, retrieval services, tools and logs. Where data is stored doesn’t answer who can access it or how it may be used.
- A provider’s commitments depend on its dependencies. Understand which systems it operates itself and which promises rely on other suppliers’ terms. Keep a realistic path to change providers.
- Zero data retention needs a clear contractual scope. Establish what the commitment covers across queries, outputs, logs and downstream systems.
- Retrieval deserves the same scrutiny as the model. Agents need fresh, relevant information, but their searches can reveal business intent. Assess the usefulness of what they find alongside how their queries are handled.
- Linkup puts these principles into practice at the retrieval layer. Our own search indexes, regional processing, zero data retention and custom configurations help organizations connect AI to outside information on terms that fit their requirements.
Sovereignty means choosing how your AI works
For an enterprise buying AI, a practical question has arisen: can this system do the job within the boundaries we need?
Sovereignty has moved from policy papers into procurement. Governments are funding national compute, hyperscalers are selling sovereign cloud regions, and model labs are opening regional deployments. Enterprises in financial services, defense, healthcare, telecoms and the public sector now write sovereignty requirements into their RFPs.
Some treat sovereignty as a nationality test: domestic models, clouds, data centers and vendors. Others treat it as a dropdown in a cloud console, where picking an EU region settles the matter. Both address part of the question. Neither, on its own, establishes how much control an organization has over its AI.
Linkup uses a different definition. A sovereign AI system is one whose owner can define the boundaries it operates within, and keep enforcing them as suppliers, technology and circumstances change.
In practice, that comes down to two things: keeping the choice of which components you use, and keeping control over the context that passes through them. Under that definition, sovereignty is a property of architecture.
Linkup works where those requirements meet. The connection between AI systems and outside information. We operate our own search indexes, offer regional processing and zero data retention, and build custom configurations for specific requirements.
The four theses on sovereign AI
Much of the disagreement about sovereign AI comes down to what the word means. Four positions recur:
- National champion. Build domestic infrastructure, models and talent. Mistral illustrates this ambition in Europe: developing local capability and bargaining power.
- Operational sovereignty. Palantir’s Alex Karp emphasizes control over data, context and model weights - the assets that make an organization’s AI valuable.
- Managed dependency. Brookings argues for “managed interdependence”: choosing partners deliberately while maintaining the ability to switch suppliers.
- Critical IT first. Cory Doctorow argues that sovereignty starts with the infrastructure organizations already depend on. AI belongs within that wider discussion.
Where Linkup lands: these perspectives lead us to a practical test: control your context, keep your choice of supplier, and understand what changing one would involve. That is the approach we bring to retrieval.
Raising the stakes: AI needs control at every step
Europe has debated digital sovereignty for more than a decade: how to protect data, certify cloud services and govern data transfers across borders. Generative AI has made those questions more complex.
A traditional cloud workload stores and processes data. An AI system also brings in outside information, reasons over it and increasingly acts on the result. As copilots become agents, a single request can pass through several layers:
- The enterprise’s application and orchestration layer.
- Model providers.
- Retrieval or search services and external tools.
- Observability and logging systems.
- The cloud and compute beneath them.
Each of these layers may be run by a different company under a different jurisdiction.
That chain changes the question buyers need to ask. “Where is my data stored?” only covers one link.
The full question is broader. Who can access the data? What may be done with it? What happens when one provider changes its terms?
This applies beyond Europe. Organizations in the US, Asia, Gulf, India and elsewhere want access to global AI capabilities while keeping control over strategic data.
Linkup helps bring that control to retrieval, with regional processing and zero data retention options that customers can match to their requirements.
Choose providers for the control they give you
The instinctive response to dependency is self-sufficiency. If foreign infrastructure is a risk, build domestic infrastructure at every layer.
There are good reasons to invest in domestic infrastructure, talent and technology. They create capability and give buyers more options. As a definition of sovereignty, though, self-sufficiency runs into the supply chain. For example, a European model depends on an international supply chain:
- GPUs designed in California and manufactured in Taiwan, using equipment from the Netherlands.
- Data centers with networking equipment sourced globally.
- Open-source software built by contributors across many countries.
- APIs and data sources hosted around the world.
The error is conflating provenance with control. A vendor's passport tells you little about whether you can audit it, constrain it or replace it. A component built abroad doesn't compromise a system if it sits inside boundaries the owner enforces.
Linkup operates its own search indexes on hyperscaler infrastructure. We depend on a cloud provider for underlying compute, while operating the indexes and retrieval service ourselves. That gives customers a clear view of which layer we control and how it supports our processing and retention options.
Most organizations will use a mix of domestic and international technology. They will face a series of practical decisions: Which dependencies can they accept? Which must they control? Can they change a dependency when they need to?
Those are the questions the rest of this article helps make operational.
Ensure dependencies you can manage
No bank thinks it has lost sovereignty because it buys chips instead of making them. What matters is how much control it keeps over that dependency.
Consider two systems. The first uses only vendors headquartered in its home country. But it runs on a proprietary platform that would take years to leave. It keeps sensitive prompts indefinitely and provides little information about the other companies handling its data.
The second mixes domestic and international suppliers. Sensitive workloads stay in designated regions, and inference providers retain nothing. Contracts and technical controls limit how data may be used. Interfaces are portable, dependencies are documented, and critical components can be replaced.
The second system gives its owner more control and is more sovereign - but nationality alone would never have told you so.
The same reasoning applies to retrieval. A provider that uses someone else’s search index needs to account for that supplier’s processing practices and terms. Operating an index gives the provider more direct control over that part of the service.
This is an important reason Linkup operates its own indexes. It supports our ability to make choices about query handling and offer customers regional processing and zero data retention.
The goal is to use capable technology with dependencies you understand and can manage. Good retrieval and clear controls belong in the same decision.
Five tests for a sovereign AI system
A marketing assistant and an agent supporting a defense intelligence tool won’t need identical boundaries. Asking a vendor whether it is "sovereign" gets you a marketing answer. Five tests get you an engineering one:
- Know how your data is used. Understand where prompts, queries, documents and outputs are processed, how long they are kept, whether they may be used for training and which providers see them. Include search queries in that assessment.
- Choose where workloads run. Pin workloads to approved regions and restrict access through your own identity and network controls. You don't need to own the servers, but you do need to know who runs them.
- Decide which models are involved. You decide which model handles which workload, and you can swap providers without rebuilding the application. A system welded to a single model, domestic or not, has little room to move.
- Set boundaries for your agents. Establish operational control, by setting which sources and tools your agents may reach, what information they may send and which actions require human approval. These policies connect the organization’s requirements to the agent’s day-to-day work.
- Keep a realistic path to change providers. Avoid dependency control. Understand which data you can export, which components can be replaced and what a transition would take. Apply this test to every provider, including Linkup.
No organization needs the strictest answer on every test. It needs to know which answers matter for each workload and choose deliberately.
Questions to ask your “sovereign” retrieval provider
An EU region, a GDPR page and an ISO 27001 report don’t tell you the full path your queries take. Buyers still need to understand which systems handle their data and whose commitments apply. Four questions help establish that picture.
- Where is every part of my request processed? That means the model call, but also retrieval, tool calls and logs. “It depends on the component” is a starting point: ask for the location of each.
- Which layers that touch my data do you operate yourselves? A provider’s commitments depend on its own systems and its suppliers’ terms. If it uses a third-party model or search index, ask how those dependencies affect what it can promise.
- Is zero data retention in the contract? Establish exactly what the commitment covers: queries, documents, outputs, logs and any exceptions. It should be in the agreement, with clear responsibilities across the systems handling the request. A dashboard setting alone doesn’t establish that commitment.
- Which third parties see my queries, and on what terms? Ask for a subprocessor list and the processing and retention terms that apply to each. This makes the dependencies behind the service visible.
A provider that answers all four clearly has built for sovereignty. One that hesitates on the second or third has probably built for the label.
Sovereignty can't be bought off the shelf
It follows that no single product makes an organization sovereign. Each vendor can offer a piece:
- A cloud provider: regional infrastructure.
- A model provider: regional inference and zero retention.
- A data provider: defined processing and retention options.
- A security vendor: policies enforced while the system runs.
Whether the resulting system is sovereign depends on how those parts are assembled and governed.
Treating sovereignty as a procurement checkbox gets this backwards. The work starts with the workload. What data does it touch, and how sensitive is that data? Which jurisdictions apply, and which capabilities are critical? Which dependencies are tolerable, and which must stay replaceable? What would the business do if a key provider vanished tomorrow? Infrastructure choices should follow from those answers.
How Linkup fits into your sovereign AI architecture
Retrieval is part of the sovereignty boundary. At Linkup, we work at a layer that sovereignty discussions tend to skip: the connection between AI systems and outside information.
Production agents rarely run on model weights alone. Before they act, they search the web, pull documents, check facts, research companies and people, and monitor markets. These steps bring in information the agent needs. They also send queries outside the enterprise environment, raising their own sovereignty questions:
- Where is the query processed, and in which geography?
- Is it retained?
- Which downstream systems see it?
- Which sources is the agent allowed to reach?
Retrieval sits between the model and the open web, so responsibility for these questions can fall between teams. The data layer deserves the same scrutiny as the model and cloud layers. Retrieval calls should be assessed against the workload’s residency and retention requirements alongside model calls.
That view has shaped how we build Linkup. We operate our own search indexes in several regions, giving customers choices about where their queries are processed. Owning the indexes gives us direct control over a core part of query handling and supports our zero data retention offering.
For customers who don’t want language models involved in handling their retrieval queries, we build custom plans that keep models out of our retrieval stack.
The compute underneath runs on hyperscaler infrastructure. We are explicit about that dependency: we operate the indexes and retrieval service, while relying on a cloud provider for the underlying compute.
These choices make retrieval part of an organization’s sovereignty architecture. Customers can evaluate the information Linkup supplies alongside the processing and retention commitments that apply to their deployment.
Sovereignty requirements differ across Europe, the Gulf, India and other markets. The underlying need is consistent: useful AI, with clear choices about where information travels, who handles it and how long it remains.
For organizations connecting agents to the web, Linkup brings those choices to retrieval: our own search indexes, regional processing, zero data retention and custom configurations for specific requirements.
Start with a task your agent needs to perform. Test whether Linkup finds the information it needs, then work with us to match the deployment to your processing and retention requirements.
Explore Linkup for your AI workflow.




