The Arc of AI Sovereignty
Four levels of control, from renting intelligence to owning it.
Enterprise AI is moving through an important transition.
For the first phase of the AI era, the primary question was simple: How quickly can we give our people access to intelligence?
The next question will be very different:
How much of that intelligence do we actually own and control?
I think about this as the Arc of Sovereignty.
Sovereignty is not binary. An organization does not simply have it or not have it. There is a spectrum determined by where models execute, where memory and context persist, who controls the infrastructure, and ultimately who has authority over the policies governing AI behavior.
Most enterprises today sit somewhere along this curve.
Level 0: Intelligence outside the boundary
At the beginning of the arc are organizations primarily consuming AI through enterprise SaaS products: an OpenAI or Anthropic enterprise account, a Copilot-style product, or another externally operated AI service.
The organization is consuming intelligence, but much of the AI execution environment is operated outside its own compute boundary.
Depending on the architecture, inference, agent harnesses, memory, context, knowledge systems, and other components may be controlled or operated by the external provider.
This is the lowest level of sovereignty.
The enterprise may have contractual protections, security controls, and administrative policies, but it does not own the underlying execution environment.
Level 1: Own the context, rent the intelligence
The next stage occurs when an enterprise begins moving the AI system around the model inside its own boundary.
Agent harnesses, tools, persistent memory, knowledge graphs, databases, policies, and application logic can now live within infrastructure controlled by the enterprise.
But inference still points outward.
Models may be accessed through Amazon Bedrock, Azure-hosted frontier models, or other external inference APIs.
This represents a meaningful increase in sovereignty because the organization’s proprietary context and orchestration layer can remain under greater internal control.
But there is still an external dependency at the point where intelligence is actually executed.
You own the context but rent the intelligence.
Level 2: Own the execution, rent the infrastructure
The next step is bringing the model itself inside the organization’s compute environment.
Enterprises begin deploying open-weight or privately controlled models onto GPUs provisioned specifically for their workloads.
Those GPUs might exist inside AWS, Azure, Google Cloud, or another infrastructure provider. They might be dedicated nodes, reserved clusters, or other identifiable compute resources.
The important change is that the enterprise is no longer simply sending prompts to someone else’s model API.
It is operating the model weights and controlling the execution environment.
This creates substantially greater control over inference, data flows, model selection, observability, policy, and agent behavior.
But the physical infrastructure still belongs to someone else.
The enterprise owns the execution but rents the substrate.
Level 3: Own the intelligence
At the furthest end of the arc is full sovereign execution.
The organization operates open-weight or privately controlled models on infrastructure it controls directly.
Models, inference, memory, knowledge graphs, agent harnesses, policies, secrets, tools, data, and compute all exist within an environment governed by the organization itself.
There is no requirement that a hyperscaler or external AI provider sit in the critical execution path.
At this point, sovereignty becomes architectural rather than contractual.
The organization determines where intelligence executes, what it can access, how it behaves, and when it can communicate outside the boundary.
This is what it means to own your intelligence.
The future is hybrid
Importantly, I don’t believe every enterprise will simply march from Level 0 to Level 3 and move everything on-premises.
The future will be much more dynamic.
An enterprise may have thousands of agents operating simultaneously, each with different sovereignty requirements.
One swarm of agents might use frontier models through external APIs because those models provide the best performance for relatively low-sensitivity tasks.
Another swarm might operate inside an isolated enclave against a locally deployed model because it needs access to highly confidential corporate information.
A third might execute inside a physically controlled environment because it handles national-security, intellectual-property, financial, or other highly sensitive workloads.
The important question therefore isn’t:
Cloud or on-prem?
It is:
Which intelligence should execute where, against what data, under whose authority, and with what policy?
That is a fundamentally different infrastructure problem.
The sovereign execution environment
This is the problem we are building ACRA at Valarian to solve.
ACRA is designed to create a sovereign execution environment that can persist across this entire spectrum.
Rather than forcing an enterprise into a single model provider, hyperscaler, inference architecture, or compute environment, the execution layer should remain portable.
Organizations should be able to serve and swap models, select different harnesses and tools, define policies around what agents can access and why, and schedule workloads onto the appropriate compute substrate.
That substrate might be cloud infrastructure today, dedicated GPUs tomorrow, and infrastructure physically owned by the enterprise in the future.
More importantly, different environments can coexist.
An organization might allow one group of agents to call external inference APIs under one set of policies while another group operates inside a tightly isolated enclave against a local model with access to entirely different data, tools, secrets, and permissions.
The execution environment becomes the consistent control layer across all of them.
Sovereignty is a direction, not a destination
The relationship between enterprises, AI models, and compute will continue to change.
The best model today will not necessarily be the best model tomorrow. The preferred cloud provider will change. GPU economics will change. Open models will improve. New forms of specialized compute will emerge.
Enterprises therefore should not define sovereignty around a particular vendor.
I believe they should define it around control.
Control over models.
Control over context.
Control over policy.
Control over execution.
Control over compute.
And, ultimately, control over the intelligence operating on behalf of the organization.
The first era of enterprise AI was about gaining access to intelligence.
I’m now certain the next era will be about owning it.