Global AI Assurance · Layer 10
AI Sovereignty Decision Engine
Sovereignty is not a hosting preference. For every AI workload there are eleven questions, and the answers together decide whether the workload may run on that path at all. The engine resolves them before deployment rather than during an examination.
What data does the workload touch?
Customer financial and identity data
Whose data is it?
Domestic retail customers
Which country is it subject to?
Home jurisdiction only
Which model performs the work?
On-shore hosted model
Where is inference performed?
In-country inference
Where are prompts and logs stored?
In-country prompt and log retention
Who can access the model and its telemetry?
Named internal operators only
Which jurisdiction can compel access?
Home authority only
Where is the evidence retained, and for how long?
In-country vault, seven-year retention
May the workload cross a border at all?
No
What happens if the approved model becomes unavailable?
Approved on-shore fallback model in place
Disposition
Sovereign
No path exists by which a foreign authority could compel access, and a fallback exists in the same jurisdiction.
Four dispositions
Sovereign
Data, inference, logs and evidence remain within the jurisdiction, with no foreign compellability path.
Approved
Cross-border operation permitted on a documented basis, with the transfer mechanism recorded per flow.
Restricted
Permitted for a narrowed purpose or data class only, with a named condition and an expiry.
Prohibited
No lawful or defensible route exists. The workload does not run on this path.
Illustrative dispositions. Actual outcomes depend on the institution's licences, data classes, contracts and the regimes it is supervised under.
The engine sits inside the Sovereign AI Governance OS and shares its residency architecture.
Sovereign AI Governance OS