Global AI Assurance · Sovereignty engine
Enterprise Sovereignty Profile
The second sovereignty problem is the organisation. A group can select sovereign-capable models and still hold an architecture that breaks a host requirement, because the conflict sits in the centralised platform rather than in the model.
The profile is built per legal entity, then read across the group, and it names the conflicts rather than averaging them away.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
Fifteen fields per legal entity
Five conflict tests
Each one has produced a real supervisory finding somewhere. None of them is answered by a data residency clause in a master agreement.
Does a centralised inference path cross a border that a host regime restricts?
Is evidence for a locally supervised system held where the local supervisor cannot compel it?
Does any single provider carry enough of the estate to make substitution implausible?
Is a locally required human approval performed by a person outside that jurisdiction?
Does a group policy assume the parent's regime governs an activity a host regime also governs?
The supervisor's version of the same question
A host authority does not ask about the group's architecture. It asks about its own perimeter.
Query
Show me every foreign AI system processing regulated data belonging to entities under my jurisdiction.
127
Foreign AI systems in scope
23
Classified critical
8
Running on frontier models
14
Sovereign deployment required
3
Evidence held outside jurisdiction
7
Remediation outstanding
Illustrative sample. Not any jurisdiction's data.
Entity, AI, data, authority, action, jurisdiction, control, evidence, outcome. The object does not change.
The same kernel, other subjects