Podcast transcript
Five Cents explores Technological Sovereignty in Artificial Intelligence: who really has control when an AI system depends on someone else’s data rules, models, chips, cloud infrastructure, and legal jurisdiction?
We’ll trace those dependencies, look at what they mean for governments, businesses, and citizens, and end with a practical way to judge risk. The best place to start is with what sovereignty does, and does not, mean.
In AI, technological sovereignty is not a promise to build every chip, model, and data centre at home. It is the ability to make meaningful choices without facing unacceptable dependence.
Can you understand the system, set its rules, audit it, keep it running, and replace key suppliers if needed? That is the practical test.
It helps to separate sovereignty from nearby ideas. Self-sufficiency means producing almost everything yourself. Autonomy means reducing dependence in selected strategic areas. Resilience means surviving disruption, even while using foreign suppliers.
Sovereignty combines all of them with accountability. When something goes wrong, can an institution investigate, intervene, and enforce its own rules?
Start with data. AI systems learn from data, and they make decisions using it. Control means knowing where that data is stored and processed, who can access it, which laws apply, and whether it can be reused for training.
Keeping data inside a border can reduce some risks, but it is not a complete answer. A foreign-owned provider may still control the software, encryption keys, or administrative access.
Data also shapes whose language, experience, and needs an AI system understands. A public chatbot trained on local records may still perform poorly if the underlying model has little coverage of local languages or contexts.
And an organisation can possess vast amounts of data while lacking real control, if it cannot lawfully use it, connect it across systems, or move it away from a platform.
Then come models and infrastructure. Using a powerful external model through an interface is convenient, but it is different from being able to adapt it, run it yourself, or develop an alternative.
A provider can change prices, retire a version, alter safety settings, or suspend access. Open-weight models can improve portability, but they do not automatically solve the problem.
Training data, computing capacity, maintenance, and deployment tools may still be outside your control.
Below the model sits the physical stack: advanced chips, manufacturing equipment, cloud regions, networks, energy, cooling, storage, and security systems.
This is why AI sovereignty has become geopolitical. Access to high-performance computing can be limited by supply bottlenecks, export restrictions, or a small number of specialised suppliers.
A locally branded AI service may depend on infrastructure thousands of kilometres away, and on decisions made by companies or governments beyond its customer’s reach.
Cloud services are a good example of the trade-off. They give smaller organisations access to serious computing power without building their own facilities.
But convenience can become lock-in when applications rely on one provider’s storage, identity system, application interfaces, and billing structure.
Dependence is not automatically a failure. It becomes dangerous when switching provider, recovering from an outage, or protecting sensitive workloads would cause unacceptable disruption.
Regulation can strengthen sovereignty by creating rights over data, obligations to document systems, audit powers, and clear responsibility for harmful uses.
But rules can also deepen dependence if only the largest vendors can afford to meet them. The aim is not regulation for its own sake.
It is enforceable, interoperable rules that protect people while leaving room for competition and viable alternatives.
For public administrations, the stakes are especially high. An internal document-search tool does not need the same level of control as AI used in healthcare, welfare, justice, identity, or emergency response.
For businesses, the questions are about pricing exposure, trade secrets, continuity, and bargaining power.
For citizens, the issue becomes personal: where was my data processed, which system influenced a decision, can it be challenged, and who is accountable?
A useful assessment is straightforward. Map the full stack: data, model version, cloud, hardware, software, subcontractors, and jurisdictions.
Classify how sensitive and essential the workload is. Find single points of failure.
Then test the exit route. Can you export data and records, change models, move cloud providers, restore from independent backups, or keep operating in a reduced mode?
Keep the documentation and in-house skills needed to make those choices real.
The common mistakes are equally clear. Foreign ownership is not automatically insecure, and domestic ownership is not automatically sovereign.
Local data is not necessarily high-quality or well protected. Open models are not automatically independent.
The realistic goal is managed interdependence: use global capabilities where they help, but preserve portability, redundancy, expertise, and local accountability where failure would matter most.
The core lesson is that sovereignty is about meaningful choice, not isolation; that AI control runs from data to chips; and that critical systems need stronger exit options than convenient ones.
To continue, you can generate Five Cents episodes on AI Procurement and Vendor Lock-In, or Open-Weight Models and Public Infrastructure.
And with that, you're up to speed in a few minutes.

