Key facts
| Core definition | Data, keys, operations and personnel inside one legal jurisdiction |
| Spectrum | Region pinning → VPC → on-prem → air-gapped, plus bring-your-own-cloud |
| Key custody | BYOK via cloud KMS or HSM; offline custody for air-gapped sites |
| Air-gap operation | No internet path; updates ship on physical media with periodic model refresh |
| Residency regions | UAE, Saudi (Enterprise), EU, US and APAC options with pinning |
| Audit | Per-request logs plus key/admin events, exportable to SIEM |
| Contractual frame | Terms at /legal/terms and service commitments at /legal/sla |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified) |
TL;DR
- Sovereignty is control plus jurisdiction, not just a data-centre location.
- The spectrum runs from region pinning to air-gapped, with real cost differences.
- Keys, personnel and update logistics decide whether a claim is credible.
- Most enterprises need residency with strong controls, not full sovereignty.
- Decide per workload class instead of mandating one tier everywhere.
How it works, step by step
- Write the sovereignty requirement as plain questions: who accesses, who operates, under whose law.
- Classify workloads and identify which ones genuinely require full sovereignty.
- Choose the deployment point on the spectrum for each class.
- Verify key custody, personnel access and update logistics for the chosen tier.
- Confirm audit, retention and deletion behaviour inside the boundary.
- Pilot the strictest workload first and document the evidence.
- Review the decision annually against regulatory and platform changes.
Try it yourself
Open the sovereign AI readiness score →
The four properties of credible sovereignty
- Jurisdiction: data is stored and processed inside one legal boundary, and the operator answers to that jurisdiction.
- Key control: encryption keys are held locally in a KMS or HSM, with revocation under national or enterprise control.
- Operational control: updates, monitoring and support operate without foreign administrative access.
- Personnel: anyone who can reach production data is subject to local law, clearance or contractual constraints, and every access is logged.
A deployment that has only the first property is residency. All four together are what buyers mean by sovereignty.
The deployment spectrum
- Region pinning: data stays in-geography; fastest and least expensive; suitable when the driver is data protection rather than national control.
- VPC: the service runs inside your cloud account with your networking and KMS; strong account-boundary control.
- On-prem: the platform runs in your data centre; control moves closer, operational burden rises.
- Air-gapped: no external network path, updates via physical media; maximum isolation, maximum logistics.
- Bring-your-own-cloud: the control plane is managed while inference runs in your account, which some procurement models require.
When sovereignty is worth the cost
Full sovereignty is operationally expensive and slow to change. It earns its cost for classified systems, citizen-data platforms, defence and critical infrastructure, and obligations that mandate national control. It is usually overkill for internal productivity tools, marketing content and analytics on non-sensitive data — those get most of the benefit from region pinning plus BYOK, scoped keys, audit export and PII controls. Portfolio the workloads: strictest tier for the strictest data class, lighter tiers elsewhere, all behind the same OpenAI-compatible API so code and evaluation suites transfer.
Assessing a vendor honestly
Ask for the architecture, not the adjective: where each store lives, where keys are generated and held, who can access production, how updates arrive, and what evidence exists for each answer. Verify with configuration exports and audit samples. Record gaps — Plugsky's SOC 2 Type II and ISO 27001 status is readiness in progress rather than completed certification, and specialist endpoints such as audio, images and fine-tuning are coming soon. Contractual commitments should sit in /legal/terms and /legal/sla, with sovereign deployment obligations written into the enterprise agreement rather than implied by the word sovereign.
Honest comparison
| Tier | Region pinning | VPC | On-prem | Air-gapped |
|---|---|---|---|---|
| Data location | In-geography | Your cloud account | Your data centre | Your isolated network |
| Key control | BYOK to regional KMS | Your cloud KMS | Your KMS or HSM | Offline key custody |
| Foreign access | Region-constrained support | Account-boundary constrained | Contracted support only | None |
| Update path | Standard releases | Standard releases | Controlled releases | Physical media |
| Time to deploy | Hours | Days to weeks | Weeks to months | Months |
| Best for | Data protection drivers | Account-boundary requirements | Regulated and sensitive systems | Classified and critical systems |
Frequently asked questions
What is sovereign AI in simple terms?
It is an AI system that operates entirely inside one jurisdiction: data, keys, operations, updates and the people who can access it, with no foreign access path. It is a spectrum, not a binary property.
Do we need sovereign AI for GDPR?
Usually not full sovereignty. GDPR is about lawful processing and transfers; EU region pinning with SCCs, DPA terms, audit and deletion often satisfies it at much lower cost. Sovereignty matters when national control is a requirement.
Is air-gapped the same as sovereign?
Air-gapped is the strongest isolation within sovereignty, removing external network paths entirely. Sovereignty can also be achieved with in-country operation that remains network-connected but controlled.
What makes a sovereignty claim credible?
Evidence across four properties: jurisdiction, local key custody, operational control and constrained personnel access — each verifiable through architecture documents, configuration exports and audit samples.
How much does sovereignty cost?
It raises cost through dedicated capacity, local operations, reduced failover options and slower updates. Choose the strictest tier only for workloads that legally or materially require it.
Can we start small and expand?
Yes. Begin with a pilot on the strictest workload class using non-sensitive data, verify the boundary and audit trail, then expand by classification level with documented evidence at each step.
What does Plugsky offer across the spectrum?
Region pinning including GCC, EU, US and APAC regions, plus VPC, on-prem, air-gapped and bring-your-own-cloud tiers, all behind the same OpenAI-compatible API.
What is Plugsky's certification status?
SOC 2 Type II and ISO 27001 are documented as readiness in progress rather than completed certification. Treat compliance as pending, verify current evidence, and use private deployment and BYOK as compensating controls.