Global AI Assurance · Sovereignty engine

    Model Sovereignty and Jurisdiction Profile

    A frontier model is not only a capability. It is a corporate owner, a development location, a hosting estate, an inference path, a set of subprocessors, a contractual regime and a lawful access exposure. All of that travels with it into the institution.

    The profile answers one operational question: can this model legally and operationally be used for this workload, in this jurisdiction, for this data.

    Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.

    Seven sections per model

    Assessed as a neutral profile. Cabier does not publish a per-provider score and does not rank models.

    Model

    ProviderModelVersionArchitecture where availableDeployment options

    Origin

    Developer jurisdictionCorporate ownershipDevelopment locations

    Infrastructure

    HostingInferenceCloudData centresSubprocessors

    Data

    Training-data provenance where disclosedUser-data handlingRetentionCross-border transfer

    Legal

    Applicable lawsContractual restrictionsRegulatory obligations

    Security

    Foreign accessSupply-chain exposureModel theftInfrastructure dependency

    Sovereignty

    On-prem availabilityPrivate deploymentSovereign cloudLocal inferenceData residencyEvidence residency

    Ten sovereignty dimensions

    Read together, they produce a classification. The classification is a constraint on use, not a verdict on a company.

    Data sovereignty
    Compute sovereignty
    Inference sovereignty
    Infrastructure sovereignty
    Operational sovereignty
    Legal sovereignty
    Evidence sovereignty
    Supply-chain sovereignty
    Provider dependency
    Jurisdictional exposure
    S1

    Fully sovereign

    Compute, inference, data and evidence all remain within the required jurisdiction, under entities subject only to it.

    S2

    Sovereign-capable

    A configuration exists that meets the requirement, but it is not the default and must be contracted and verified.

    S3

    Controlled foreign dependency

    Foreign control exists and is documented, with compensating controls and a named residual risk.

    S4

    Restricted

    Usable only for narrower data classes or purposes than the workload requires.

    S5

    Prohibited

    No available configuration satisfies the sovereignty requirement for this workload.

    Sovereignty as a routing variable

    Model selection stops being a comparison table. It becomes a decision with a disposition and a reason attached.

    TaskData classificationJurisdiction setSovereignty requirementApplicable lawModel capabilityProviderHostingInference locationEvidence locationLatencyCostResidual risk

    Request: analyse highly confidential government material in a residency-binding jurisdiction.

    Model option A, in-country private deployment

    Permitted · S1

    Compute, inference, data and evidence all remain in jurisdiction; no foreign compulsion path identified.

    Model option B, regional cloud, sovereign configuration available

    Sovereign deployment required · S2

    Default routing crosses the border. Permitted only on the contracted sovereign configuration, verified before use.

    Model option C, global managed service

    Restricted · S3

    Foreign control documented with compensating controls. Usable for unclassified material only, not for this workload.

    Model option D, provider outside recognised transfer route

    Prohibited · S5

    No configuration removes the lawful-access exposure for the data classes in scope.

    Illustrative. Options are neutral configurations rather than named products, and every read is a statement about a workload rather than about a provider.

    A sovereign-capable model deployed by a group with a centralised inference path still creates a conflict.

    Then test the organisation itself