Global AI Assurance · Sovereignty engine
Model Sovereignty and Jurisdiction Profile
A frontier model is not only a capability. It is a corporate owner, a development location, a hosting estate, an inference path, a set of subprocessors, a contractual regime and a lawful access exposure. All of that travels with it into the institution.
The profile answers one operational question: can this model legally and operationally be used for this workload, in this jurisdiction, for this data.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
Seven sections per model
Assessed as a neutral profile. Cabier does not publish a per-provider score and does not rank models.
Model
Origin
Infrastructure
Data
Legal
Security
Sovereignty
Ten sovereignty dimensions
Read together, they produce a classification. The classification is a constraint on use, not a verdict on a company.
Fully sovereign
Compute, inference, data and evidence all remain within the required jurisdiction, under entities subject only to it.
Sovereign-capable
A configuration exists that meets the requirement, but it is not the default and must be contracted and verified.
Controlled foreign dependency
Foreign control exists and is documented, with compensating controls and a named residual risk.
Restricted
Usable only for narrower data classes or purposes than the workload requires.
Prohibited
No available configuration satisfies the sovereignty requirement for this workload.
Sovereignty as a routing variable
Model selection stops being a comparison table. It becomes a decision with a disposition and a reason attached.
Request: analyse highly confidential government material in a residency-binding jurisdiction.
Model option A, in-country private deployment
Permitted · S1Compute, inference, data and evidence all remain in jurisdiction; no foreign compulsion path identified.
Model option B, regional cloud, sovereign configuration available
Sovereign deployment required · S2Default routing crosses the border. Permitted only on the contracted sovereign configuration, verified before use.
Model option C, global managed service
Restricted · S3Foreign control documented with compensating controls. Usable for unclassified material only, not for this workload.
Model option D, provider outside recognised transfer route
Prohibited · S5No configuration removes the lawful-access exposure for the data classes in scope.
Illustrative. Options are neutral configurations rather than named products, and every read is a statement about a workload rather than about a provider.
A sovereign-capable model deployed by a group with a centralised inference path still creates a conflict.
Then test the organisation itself