Evidence Base
50 entries: 37 incidents and instruments, 2024–2026, plus 13 research references and peer indices. Each is traced to its sources. This is the source list behind the framework documents.
Sovereignty incidents — cloud & data
Microsoft France CLOUD Act testimony (10 June 2025)
Anton Carniaux, Director of Public and Legal Affairs at Microsoft France, testified under oath to a French Senate inquiry into public buying and digital sovereignty that he could not guarantee French citizens’ data held in Microsoft’s EU data centres would never be handed to US authorities without France’s consent. Asked directly, he said “No, I cannot guarantee that.” The law that makes this possible is the US CLOUD Act of 2018.
Microsoft / ICC email block of Karim Khan (February–May 2025)
After the US Treasury imposed sanctions in February 2025 on International Criminal Court Chief Prosecutor Karim Khan — in response to ICC investigations into Israeli officials — Khan’s Microsoft email was switched off. The ICC then moved its office and teamwork software to OpenDesk, a free, open-source platform from Germany’s Centre for Digital Sovereignty (ZenDiS). Microsoft has disputed some accounts of how events unfolded.
Apple Intelligence EU delay (October 2024 → April 2025)
Apple Intelligence features arrived worldwide with iOS 18.1 in October 2024 but were held back for EU users until iOS 18.4 in April 2025, expressly because of the Digital Markets Act’s rules requiring products to work with rivals’ systems.
Italian Garante DeepSeek ban (30 January 2025)
Italy’s data protection authority (the Garante) ordered DeepSeek — Hangzhou DeepSeek AI and Beijing DeepSeek AI — to stop handling Italian users’ personal data after the companies claimed they “did not operate in Italy” and that European rules did not apply. The Garante called the companies’ response “completely insufficient.” The order covered the app-store versions; the website stayed reachable. Authorities in Belgium, Ireland, France, Portugal, and Spain opened their own investigations.
Meta Llama multimodal EU withdrawal (18 July 2024)
Meta said it would not release its upcoming multimodal Llama model (one that handles text, images, and more) in the European Union, blaming “the unpredictable nature of the European regulatory environment.” Its specific complaint was about GDPR duties around using EU users’ data to train AI, and it came after the Irish Data Protection Commission asked Meta to hold off on plans to use public Facebook and Instagram content for training.
Sovereignty incidents — hardware, export controls, supply chain
Fable 5 / Mythos 5 restoration (30 June – 1 July 2026) [Added v0.7.1]
On 30 June 2026 the US Department of Commerce lifted the 12 June export-control directive. Fable 5 was restored to all customers worldwide on 1 July, ending a 19-day suspension; Mythos 5 was reintroduced only to approved US organisations following government review. Anthropic stated that the jailbreak cited by the government was narrow and that comparable capabilities could be elicited from other publicly available models not subject to similar controls. Reported aftermath includes closer collaboration between Anthropic and US agencies on model testing, threat sharing, and jailbreak-risk standards, and continued policy debate over whether model-access export controls become a repeated instrument.
US chip-export posture codification (January – July 2026) [Added v0.7.1]
On 13 January 2026 the Commerce Department revised the licence-review posture for Nvidia H200- and AMD MI325X-class chips from presumption of denial to case-by-case review. In June 2026 BIS affirmed that its licensing requirements for advanced AI chips reach subsidiaries of Chinese-headquartered companies located outside China. In July 2026 Commerce said it would grant Nvidia export licences for the H20. Reported uptake has lagged policy: as of mid-May 2026, no H200 chips had shipped to the Chinese companies approved to buy them.
Anthropic Fable 5 / Mythos 5 access suspension (12 June 2026)
On 12 June 2026 the US government, citing national-security export-control authority, issued a directive ordering Anthropic to suspend all access to its frontier Fable 5 and Mythos 5 models by any foreign national — whether inside or outside the United States, and including Anthropic’s own foreign-national employees. Anthropic disabled both models for all customers to comply, three days after Fable 5’s public release. Reported triggers were concern that the Mythos-class model could surface restricted cyber-attack and software-vulnerability information (raised after Amazon researchers elicited such output, escalated by CEO Andy Jassy) and suspected access by a China-linked group. The suspension cut off enterprises and governments worldwide overnight and reignited “sovereign AI” calls in Europe and India.
The source document adds a note qualifying this claim.
DeepSeek-V4 with day-0 Huawei Ascend adaptation (April 2026) [Added v0.7.1]
DeepSeek released V4 in preview on 24 April 2026 with open weights under the MIT licence (reported 1.6-trillion-parameter Mixture-of-Experts design with ~1M-token context; figures pending verification against the technical report). Huawei Ascend (950PR/950DT), Cambricon, Hygon, and Moore Threads completed day-0 adaptation at launch — an architectural decision to treat the domestic Chinese stack as a first-class target rather than a fallback, and the strongest evidence to date that a top-tier Chinese model no longer requires NVIDIA’s CUDA.
The source document adds a note qualifying this claim.
NVIDIA Vera Rubin platform (CES 2026, 5 January 2026)
NVIDIA formally launched the Vera Rubin platform at CES 2026. Rubin GPU: 336 billion transistors (two-reticle design), 50 PFLOPS NVFP4 inference, 35 PFLOPS NVFP4 training (vendor figures quoted as 5× and 3.5× Blackwell), 288 GB HBM4, 22 TB/s memory bandwidth. Vera CPU: 88 custom Olympus Arm v9.2 cores with Spatial Multi-Threading (176 threads), 1.5 TB LPDDR5x, NVLink-C2C at 1.8 TB/s. Vera Rubin NVL72 rack: 72 Rubin GPUs and 36 Vera CPUs delivering 3.6 EFLOPS NVFP4 inference and 2.5 EFLOPS NVFP4 training, 20.7 TB HBM4 capacity, 1.6 PB/s HBM bandwidth, 260 TB/s NVLink 6 rack-scale bandwidth. Full production reported Q1 2026; partner availability H2 2026. First cloud deployments announced at AWS, Google Cloud, Microsoft (Fairwater AI superfactories), OCI, CoreWeave, Lambda, Nebius, Nscale. Per-rack price reported in trade press at up to $8.8 million.
The source document adds a note qualifying this claim.
Biden AI Diffusion Rule / Trump rescission (15 January → 13 May 2025)
The Biden administration issued the “AI Diffusion Rule” on 15 January 2025 (published in the Federal Register), set to take effect on 15 May 2025. The rule sorted the world into three tiers and capped each country’s imports of advanced chips. On 13 May 2025, two days before it would have kicked in, the Trump administration’s Commerce Department Bureau of Industry and Security (BIS) scrapped it, with Under Secretary Jeffrey Kessler telling BIS enforcement staff not to apply it. At the same time, BIS put out three new guidance documents — on controlling advanced-computing chips, on training AI for weapons-of-mass-destruction uses, and on tactics used to dodge supply-chain controls.
CrowdStrike global outage (19 July 2024)
A broken update to CrowdStrike’s Falcon Sensor security software (channel file 291, timestamped 2024-07-19 04:09 UTC) set off what is widely called the largest IT outage in history. About 8.5 million Windows devices — roughly 1% of all Windows machines — crashed, throwing airlines, banks, hospitals, shops, and emergency services into chaos worldwide. Insurers estimated the cost to U.S. Fortune 500 companies at $5.4 billion. Delta Air Lines reported losses of about $500 million and sued CrowdStrike on 25 October 2024. In May 2025, a Georgia judge let Delta press claims of gross negligence, computer trespass, and limited fraud.
Sovereignty incidents — manufacturing & critical materials
China rare-earth enforcement wave (June – July 2026) [Added v0.7.1]
Despite the November 2025 pause, enforcement stayed active through 2026. On 22 June 2026 MOFCOM placed 10 US companies under new export restrictions; by 24 July it had blocked dual-use shipments to 14 EU firms. Announcement No. 26 (24 June 2026) formalised the handling of violations involving strategic-mineral dual-use controls. Two Japanese nationals were detained in Dalian (May 2026) over alleged rare-earth-related smuggling — among the first foreign-national detentions tied to these controls. The IEA warned that full enforcement could put $6.5 trillion of downstream production at risk.
China rare-earth export controls (9 October → 9 November 2025 pause)
China’s Commerce Ministry (MOFCOM) announcements Nos. 55–58, 61 and 62 (9 October 2025) sharply widened China’s controls on exporting rare-earth metals. After the Trump–Xi meeting in Busan, MOFCOM announcements Nos. 70 and 72 (7–9 November 2025) put those controls on hold until 10 November 2026. China refines roughly 89% of the world’s rare earths and controls almost the entire supply chain for high-performance rare-earth magnets. The earlier licensing rules of 4 April 2025, covering seven heavy rare-earth elements (scandium, yttrium, samarium, gadolinium, terbium, dysprosium, lutetium), stay in force. In November 2025, EU Commissioner Stéphane Séjourné announced plans for an EU critical-minerals centre to buy and stockpile these materials jointly.
Nexperia state supervision and supply standoff (September 2025 → ongoing) [Added v0.7.1]
In September 2025 the Netherlands invoked the Goods Availability Act to place Nexperia — the Nijmegen-headquartered semiconductor maker majority-owned by China’s Wingtech — under temporary state supervision on national-security grounds. China responded with export controls on China-produced Nexperia chips, disrupting automotive production worldwide from October 2025. By March 2026 the Dutch and Chinese arms were operating as separate, often hostile entities (on 3 March 2026 Nexperia B.V. cut Chinese staff off from global IT systems). Partial de-escalation followed — China walked back export controls and The Hague relinquished oversight — but the entities had not reunited as of mid-2026. A textbook two-directional sovereignty incident: European assertion of control over a chip asset, answered by Chinese leverage over the downstream supply chain.
The source document adds a note qualifying this claim.
Intel Magdeburg fab cancellation (24 July 2025)
Intel’s new CEO, Lip-Bu Tan, formally cancelled Intel’s planned €30+ billion “Silicon Junction” chip factory in Magdeburg, Germany (first announced in March 2022), along with a €4.6 billion assembly-and-test plant near Wrocław, Poland — part of a 15% staff cut down to about 75,000 employees. Intel said it had “decided not to move forward with previously planned projects in Germany and Poland” because “the company invested too much, too soon — without adequate demand.” Intel gave up roughly €10 billion in German EU Chips Act subsidies and $1.9 billion in EU state aid earmarked for Poland.
Sovereign stack responses
EuroHPC AI Gigafactories call (30 July 2026) [Added v0.7.1]
The EuroHPC Joint Undertaking opened the formal call for seven AI Gigafactories on 30 July 2026: €10 billion in public funding intended to mobilise at least €20 billion more in private investment, each site to hold at least 100,000 advanced AI chips. Bids close 12 November 2026; awards are expected in early 2027, with operations targeted about 18 months after selection. Ten member states signalled hosting interest (Germany, Italy, France, Poland, Czechia, Denmark, Finland, Greece, Portugal, Spain).
First EU sovereignty-criteria cloud procurement (April 2026) [Added v0.7.1]
The European Commission awarded a €180 million sovereign-cloud contract to four European provider groups (Post Telecom, StackIT, Scaleway, Proximus), reported as the first EU procurement run on explicit sovereignty criteria.
The source document adds a note qualifying this claim.
INSAIT BgGPT 3.0 (March 2026)
INSAIT released BgGPT 3.0 in three sizes — 4 billion, 12 billion, and 27 billion parameters — built on Google’s Gemma 3 and further trained on more than 100 billion words of Bulgarian text. It can handle images as well as text, remembers up to about 131,000 tokens of context at once, was pre-trained on data through May 2025, and had its instruction tuning finished through October 2025. It comes in full precision, a compressed (GPTQ W4A16) version, and the GGUF format. The earlier BgGPT (2023) was based on Gemma 2 and used about 85 billion Bulgarian and 15 billion English words, trained with the “Branch-and-Merge” method that INSAIT researchers published at the EMNLP 2024 conference. INSAIT runs its own dedicated systems for projects with Bulgaria’s National Revenue Agency and National Audit Office.
AWS European Sovereign Cloud general availability (15 January 2026)
The AWS European Sovereign Cloud became generally available on 15 January 2026, with its first data-centre region in Brandenburg, Germany, backed by a €7.8 billion commitment. It is run through EU-only German subsidiaries with EU-citizen managing directors (Stéphane Israël and Stefan Hoechbauer) and an EU-only advisory board. But the legal entity is still wholly owned by Amazon.com Inc., and commentators have pointed out that CLOUD Act exposure arguably remains.
S3NS SecNumCloud 3.2 qualification (17–19 December 2025)
S3NS, a joint venture between Thales and Google Cloud, won SecNumCloud 3.2 certification from France’s cybersecurity agency ANSSI on 17 December 2025 for its PREMI3NS service. The service is run entirely by S3NS staff in France, with a “quarantine zone” that screens Google’s updates — making it the first major cloud service built on U.S. technology to earn SecNumCloud certification.
EuroHPC AI Factories (December 2024 → October 2025)
The EuroHPC Joint Undertaking (a joint EU supercomputing program) has chosen 19 AI Factories across 16 EU member states, in three rounds: seven in December 2024 (Finland, Germany, Greece, Italy, Luxembourg, Spain, Sweden), six in March 2025 (Austria, Bulgaria, France, Germany, Poland, Slovenia), and six in October 2025 (Czech Republic, Lithuania, Netherlands, Romania, Spain, Poland). On top of that, 13 smaller AI Factory “Antennas” were chosen in Belgium, Cyprus, Hungary, Ireland, Latvia, Malta, Slovakia, Iceland, Moldova, North Macedonia, Serbia, Switzerland and the UK. The combined EU-and-member-state commitment is more than €2.6–2.7 billion.
Mistral AI Series C (9 September 2025)
Mistral AI raised €1.7 billion in a Series C funding round led by ASML (which put in €1.3 billion for about an 11% stake once all shares are counted), valuing the company at €11.7 billion afterward. DST Global, Andreessen Horowitz, Bpifrance, Lightspeed, Nvidia and others also took part. It is the largest single private investment in a European AI model company so far, and puts France at Level 4 on the AI-SAF-N Models scale.
Stargate UAE (announced 22 May 2025; first phase Q3 2026)
Stargate UAE is a 1-gigawatt cluster of AI computing power being built by G42 (run by OpenAI and Oracle, with NVIDIA supplying Grace Blackwell GB300 systems, Cisco providing the networking, and SoftBank taking part) inside a planned 5-gigawatt UAE–US AI Campus. The first 200-megawatt phase is due to be finished in Q3 2026, according to Khazna Data Centres (December 2025). Reported investment is close to $20 billion. It was announced with UAE President Sheikh Mohamed bin Zayed Al Nahyan and U.S. President Donald Trump present.
Regulatory instruments
EU AI Act — Digital Omnibus deferral and GPAI enforcement (27 July / 2 August 2026) [Added v0.7.1]
The Digital Omnibus on AI (proposed 19 November 2025) entered into force on 27 July 2026, deferring the AI Act’s high-risk obligations: stand-alone Annex III systems to 2 December 2027, and AI embedded in Annex I regulated products to 2 August 2028. The GPAI provisions were not deferred: on 2 August 2026, Article 50 transparency obligations, Commission penalty powers over GPAI providers, and full national market-surveillance authority took effect as originally scheduled.
EU Technological Sovereignty Package: CADA and Chips Act 2.0 (3 June 2026) [Added v0.7.1]
On 3 June 2026 the European Commission adopted the Cloud and AI Development Act proposal (COM(2026) 502) and the Chips Act 2.0 proposal (COM(2026) 504). CADA aims to triple EU data-centre capacity within five to seven years, creates data-centre acceleration zones, and establishes a Cloud Sovereignty Framework grading cloud services on four assurance levels — from EU data location (level 1) to full supply-chain control free of third-country interference (level 4) — applicable to public-sector procurement. Chips Act 2.0 targets permitting within 12 months, investment conditions, and “Grand Challenges” including AI chips; the European Court of Auditors projects the EU at ~11.7% of the global chip value chain by 2030 versus the 20% target. Both proposals are in trilogue.
New Delhi AI Impact Summit and Declaration (16–21 February 2026) [Added v0.7.1 — promoted from Part J]
The India AI Impact Summit ran 16–21 February 2026 at Bharat Mandapam, New Delhi, with representatives of 118 countries. The New Delhi Declaration on AI Impact, adopted 18–19 February, was endorsed by 92 countries and international organisations, structured around seven pillars (“Chakras”). Outcomes include the Charter for the Democratic Diffusion of AI, the Global AI Impact Commons, and India’s GPU expansion (20,000 added to an existing 38,000, targeting 100,000 by end-2026).
Council of Europe Framework Convention on AI, CETS No. 225 (in force 1 November 2025)
Adopted by the Council of Europe’s Committee of Ministers on 17 May 2024 and opened for countries to sign on 5 September 2024 in Vilnius. It is the first international AI treaty that is legally binding. It came into force on 1 November 2025, once the United Kingdom, France, Norway and others had ratified it (the trigger was five signatories, including at least three Council of Europe members). Early signatories include the EU, the US, the UK, Andorra, Georgia, Iceland, Norway, Moldova, San Marino and Israel. It was negotiated by the 46 Council of Europe member states, the EU, and 11 non-member states (Argentina, Australia, Canada, Costa Rica, Holy See, Israel, Japan, Mexico, Peru, US, Uruguay).
EU AI Act — GPAI obligations applicable (2 August 2025)
Regulation (EU) 2024/1689 (the AI Act) was adopted on 13 June 2024, published in the EU’s Official Journal on 12 July 2024, and came into force on 2 August 2024. The bans on certain uses and the AI-literacy duties took effect on 2 February 2025. The duties on providers of general-purpose AI (GPAI) models kicked in on 2 August 2025, and the Commission can enforce them from 2 August 2026. GPAI models already on the market before August 2025 must fully comply by 2 August 2027. Fines for GPAI providers can reach 3% of yearly worldwide revenue or €15 million, whichever is higher (AI Act Article 101).
GPAI Code of Practice (published 10 July 2025; endorsed 1 August 2025)
The General-Purpose AI Code of Practice was published by the European Commission’s AI Office on 10 July 2025, and the Commission and the AI Board formally backed it on 1 August 2025. It has three chapters (Transparency; Copyright; Safety and Security) covering 12 commitments. xAI signed only the Safety and Security chapter. Amazon, Google, Microsoft, OpenAI, Anthropic and others signed all three. Meta refused to sign.
Paris AI Action Summit (10–11 February 2025)
The third international AI summit, held at the Grand Palais in Paris, produced the “Statement on Inclusive and Sustainable Artificial Intelligence,” signed by 61 countries and bodies including France, China, India, Japan, Australia, Canada and the EU. The United States and United Kingdom refused to sign; U.S. Vice President JD Vance criticised European AI rules in a Tuesday speech, while the UK government said the statement lacked enough substance on global governance. India, the co-chair, was named as host of the next event, the New Delhi AI Impact Summit (February 2026).
Copyright and legal rulings
Bartz v. Anthropic — Final settlement approval (20 July 2026) [Added v0.7.1]
On 20 July 2026 Judge Araceli Martínez-Olguín (N.D. Cal.) granted final approval of the $1.5 billion class settlement — the largest copyright class settlement on record — paying roughly $3,000 per work across an estimated 500,000 works. The settlement does not release future output-based claims.
Getty Images v. Stability AI (UK) — Judgment [2025] EWHC 2863 (Ch), 4 November 2025
Mrs Justice Joanna Smith DBE of the High Court of England and Wales (Chancery Division) gave judgment in Getty Images (US) Inc & Ors v Stability AI Ltd on 4 November 2025. The court threw out Getty’s secondary copyright claim — ruling that a Stable Diffusion model’s internal settings (its “weights”) are not an “infringing copy” under sections 22–23 of the UK’s 1988 copyright law (the CDPA) — and found only limited trademark infringement involving reproduced watermarks. Getty had already dropped its main claim, that the training itself infringed copyright, because the training had happened outside the UK. This is the first significant UK ruling on copyright and AI training.
Kadrey v. Meta — Summary Judgment (25 June 2025)
In Kadrey v. Meta Platforms, Inc., No. 23-CV-03417-VC (N.D. Cal.), 2025 WL 1752484, Judge Vince Chhabria ruled in Meta’s favour on fair use for the books of 13 plaintiffs, without a full trial. The ruling was narrow and tied to the specific facts: the plaintiffs had not built a strong enough case that the training hurt the market for their books. Judge Chhabria pointedly said his ruling did not give AI training on copyrighted works a green light more generally.
Bartz v. Anthropic — Summary Judgment (23 June 2025)
In Bartz v. Anthropic PBC, No. 3:24-cv-05417 (N.D. Cal.), Judge William Alsup ruled — without a full trial — that training AI models on copyrighted books was “exceedingly transformative” and counted as fair use. But he found that Anthropic downloading and keeping pirated copies from illegal book sites (Library Genesis, Pirate Library Mirror) was NOT fair use, and that part went on toward trial. On 26 August 2025, Anthropic filed notice of a proposed settlement covering the whole group of plaintiffs.
Research and technical references
Stanford AI Index 2026 (April 2026)
The 2026 edition of the Stanford Institute for Human-Centered AI (HAI) AI Index Report was published in April 2026. The ninth yearly edition; it covers research, technical performance, responsible AI, economics, science, medicine, education, policy, and public opinion. The key 2026 findings the framework draws on: the capability gap between the top US and Chinese models has all but closed; 44 countries now run government-backed supercomputers; 80 of the 95 most notable 2025 models were released without their training code; the Foundation Model Transparency Index average score dropped to 40 (from 58); and almost the entire global AI industry still depends on TSMC’s chip factories in Taiwan.
DeepSeek-V3 Technical Report (27 December 2024)
DeepSeek-AI team, “DeepSeek-V3 Technical Report,” arXiv:2412.19437 (initial 27 December 2024, updated 18 February 2025). DeepSeek-V3 is a “Mixture-of-Experts” model — one that has 671 billion parameters in total but only switches on 37 billion at a time — trained on 14.8 trillion tokens of text. The reported training cost: 2.664 million H800 GPU-hours for the main training, 119,000 for extending its context length, and 5,000 for final tuning, for a total of 2.788 million GPU-hours; at $2 per H800 GPU-hour, that comes to about $5.576 million. That figure leaves out earlier research, trial-and-error experiments, and the cost of the underlying hardware spread over time. Its technical innovations include FP8 mixed-precision training, a way of balancing the load without an extra penalty term, and predicting several tokens at once.
Borji — Note on Shumailov et al. (arXiv, October 2024)
Ali Borji, “A Note on Shumailov et al. (2024): AI Models Collapse When Trained on Recursively Generated Data,” arXiv:2410.12954 [cs.LG], October 2024. Argues that model collapse is “a statistical phenomenon and may be unavoidable” any time you repeatedly fit a pattern to data and then draw new samples from it.
Shumailov et al. — Model collapse (Nature, 24 July 2024)
Ilia Shumailov, Zakhar Shumaylov, Yiren Zhao, Nicolas Papernot, Ross Anderson and Yarin Gal, “AI models collapse when trained on recursively generated data,” Nature 631, no. 8022 (24 July 2024): 755–759, DOI 10.1038/s41586-024-07566-y. Shows that carelessly training models on content earlier models generated causes “irreversible defects” in later versions: the rare, unusual cases gradually vanish. The effect showed up across several kinds of model (large language models, variational autoencoders, and Gaussian mixture models). The authors issued a correction in Nature 640, E6 (2025), DOI 10.1038/s41586-025-08905-3.
Benchmark frameworks (peer indices)
Tortoise Global AI Index (5th edition, 19 September 2024)
Covers 83 countries using 122 measures grouped under 3 headings (Implementation, Innovation, Investment) and 7 sub-headings (talent, infrastructure, operating environment, research, development, commercial ecosystem, government strategy). It draws on 24 public and private data sources. The United States ranked 1st, China 2nd, Singapore 3rd, the United Kingdom 4th, and France 5th. Saudi Arabia came top on the government-strategy sub-heading.
MacroPolo Global AI Talent Tracker 2.0 (March 2024, NeurIPS 2022 data)
Published by the Paulson Institute. Based on a sample of 186 papers and 867 authors from the NeurIPS 2022 conference (95% confidence, give or take 7%). Key findings: 75% of the top AI researchers working at US institutions did their undergraduate degrees in the US or China (up from 58% in 2019); China produces 47% of the world’s top AI researchers, counted by where they did their undergraduate degree (up from 29% in 2019); the US is still the top destination for elite talent; and about 42% of top researchers work abroad (down from 55% in 2019), meaning fewer are moving around overall. Of Chinese AI undergraduates, 51.35% go on to graduate study at home, and 30.96% stay in China for that work. In India, one-fifth of AI researchers now stay in India after graduating (up from almost none in 2019).
The source document adds a note qualifying this claim.
CSET / ETO (Emerging Technology Observatory, Georgetown University)
The Center for Security and Emerging Technology’s Emerging Technology Observatory runs several detailed dashboards: the Country Activity Tracker (CAT), the Private AI-Related Activity Tracker (PARAT), the Supply Chain Explorer, and AGORA. Together they are the most detailed public window into the chip and AI-research supply chains. Recommended as a primary source for scoring the AI-SAF Hardware and Manufacturing building blocks.
GAIA-X Labelling Framework
GAIA-X European Association for Data and Cloud AISBL, Brussels. Its Labelling Framework version 2.0 and later updates set out six groups of criteria (data protection, cybersecurity, transparency, portability and interoperability, flexibility, and operational requirements) across three levels (L1, L2, L3). Level L3 — effectively fully sovereign — requires the same protection from foreign-reach laws as SecNumCloud. It lines up directly with the Infrastructure scoring bands in AI-SAF-N and AI-SAF-C.
IMF AI Preparedness Index (AIPI)
Covers 174 economies across four equally-weighted areas: digital infrastructure, people and labor-market policy, innovation and economic links, and regulation and ethics. The underlying measures are each rescaled to a 0–1 range (using the min-max method), then the four areas are averaged. Wealthy economies average 0.68, emerging markets 0.46, and low-income countries 0.32. The data is pulled together from the Fraser Institute, ILO, ITU, UN, UNCTAD, Universal Postal Union, World Bank, and World Economic Forum.
ISO/IEC 42001:2023 — AI Management System
Published by ISO and IEC in December 2023. The first international AI management standard a company can actually be certified against. It is laid out the same way as ISO 27001 and ISO 9001 (the common “Annex SL” structure): Clauses 4–10 (Context, Leadership, Planning, Support, Operation, Performance Evaluation, Improvement) plus Annex A controls covering reducing bias, transparency, accountability, and data governance. Certification usually lasts three years, with yearly check-up audits in between. Microsoft 365 Copilot was certified in 2025.
NIST AI Risk Management Framework (AI RMF 1.0) and GenAI Profile
National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework, NIST AI 100-1 (Gaithersburg, MD: NIST, January 2023). A voluntary US framework built around four jobs: GOVERN, MAP, MEASURE, MANAGE. The Generative AI Profile (NIST AI 600-1, July 2024) tailors it for generative-AI systems, with 12 categories of risk. In practice, it is the go-to reference for managing AI risk in the US private sector.
OECD.AI Policy Observatory
Tracks national AI strategies, spending on computing power, and regulatory moves across OECD members and partner countries. It focuses on governance rather than on raw capability. It organises its data around the five OECD AI Principles (inclusive growth, human rights, transparency, robustness, and accountability). A useful companion to the indices that focus on capability.
Other peer frameworks referenced
Other frameworks worth consulting: the Stanford HAI AI Index (see Part G); the Oxford Insights Government AI Readiness Index (188 countries, focused on government capacity); the ECFR Technology Sovereignty Tracker (which maps the dependencies of the 27 EU member states); Bertelsmann Stiftung’s Sustainable Governance Indicators and EuroStack work; the Nextcloud Digital Sovereignty Index (EU-focused, centred on open-source hosting); the UNCTAD Technology and Innovation Report 2025; MIT CISR’s enterprise AI research; and the BCG, McKinsey, and Gartner enterprise AI-maturity models.