Conceptual foundation — theory, methodology, terminology. Version 0.7.1 · August 2026 · CC BY 4.0
How to read this document
This framework uses a specific vocabulary and a specific scoring structure throughout. This section introduces both. A reader already familiar with sovereignty indices may skim it; a reader new to the framework should read it carefully.
AI-SAF framework — architecture at a glance
Order of assemblyEvidence then Sub-indicators then Pillars then Headline
Step 1Evidence— three dimensions per sub-indicator
Capability — what is actually in place
- Chips installed
- models running
- laws in force
- clouds certified
Feeds the headline score
Commitment — what is pledged
- Enacted law
- budgeted funding
- signed MoUs
- published roadmaps
Feeds the T+3 trajectory
Dependency type — each dependency coded as
- Bottleneck — replaceable at cost
- Structural — no realistic replacement
Shapes where to invest
Step 2Sub-indicators— example: Infrastructure, AI-SAF-N (17 pts) · each tagged [R] or [A]
- Sovereign cloud / cloud choice5 points, resilience
- Local compute (own + pooled ≤2)4 points, resilience
- Energy mix and price3 points, resilience
- Cryptographic control + TEE3 points, resilience
- Network independence2 points, resilience
5 sub-indicators, 17 points — the whole of this pillar’s AI-SAF-N weight.
Step 3Pillars — weights— each variant sums to 100 · third column N − C · Infrastructure, step 2
- DataAI-SAF-C 14AI-SAF-N 10difference −4
- ModelsAI-SAF-C 16AI-SAF-N 16difference 0
- Infrastructure — the pillar worked through in step 2 aboveAI-SAF-C 14AI-SAF-N 17difference +3
- HardwareAI-SAF-C 10AI-SAF-N 17difference +7
- ManufacturingAI-SAF-C 1AI-SAF-N 12difference +11
- SoftwareAI-SAF-C 10AI-SAF-N 8difference −2
- Human capitalAI-SAF-C 13AI-SAF-N 12difference −1
- RegulatoryAI-SAF-C 12AI-SAF-N 8difference −4
- CultureAI-SAF-C 10AI-SAF-N: no national weight for this pillardifference: not applicable
Largest shift — Manufacturing: 1 point under AI-SAF-C, 12 under AI-SAF-N. Document 1’s own rationale: “C: awareness only; N: fabs, packaging, minerals”.
Step 4Headline — after modifiers
Modifiers — applied after pillar aggregation
AI-SAF-N, fixed order:
- rule-stability ×0.85–1.00 (Hw, Models)
- geopolitical-alliance ×0.70–1.15 (Hw, Models, Infra)
- operating-model −2…+2
AI-SAF-C: scale discount ×0.85 / ×0.92 (Data, Human capital, Culture)
Index score 0–100
+ R / A subtotals — the two-number profile below
- AI-SAF-C business
- AI-SAF-N national
The two axes
- Resilience“What still works if a supplier cuts us off tomorrow?”
- Autonomy“Who decides our technology path?”
Reported side by side, never averaged: sovereignty is high only when both are.
Commitment data does not touch the headline: it drives the three-year (T+3) projection.
The pillars and weights
Every AI-SAF assessment — a company under AI-SAF-C or a country under AI-SAF-N — scores the subject on eight shared pillars. A ninth, Culture and Operating Model, applies to companies only.
| Pillar | What it measures | AI-SAF-C | AI-SAF-N |
|---|---|---|---|
| 1. Data | Language and proprietary data, where data is kept, the laws covering it, and what leaves at inference time | 14 | 10 |
| 2. Models | Access to general-purpose AI models, the ability to adapt them, and a disciplined portfolio across providers and jurisdictions | 16 | 16 |
| 3. Infrastructure | Cloud you control, data-centre capacity, reliable power, and confidential computing | 14 | 17 |
| 4. Hardware | Access to AI chips, more than one chip design, and reserves | 10 | 17 |
| 5. Manufacturing | Chip-factory capacity, advanced packaging, critical minerals, and the supply chain behind them | 1 | 12 |
| 6. Software | The AI software stack, CUDA dependence, and how much of the tool set you control | 10 | 8 |
| 7. Human Capital | Researchers, engineers, training pipelines, and retention | 13 | 12 |
| 8. Regulatory | Following the rules thoroughly (companies) or the power to make them (countries) | 12 | 8 |
| 9. Culture and Operating Model | How decisions get made and how disciplined operations are (companies only) | 10 | — |
| Total | 100 | 100 |
The two axes — and how they reach the score
Each pillar score feeds two separate qualities. Resilience: can you keep your important AI systems running if an outside supplier cuts off access? Autonomy: do you get to decide your own technology path? The two are separate — a subject can hold a full working copy of a model (high resilience) yet be unable to improve it without outside help (low autonomy), and the reverse.
From v0.7.1 this distinction is carried into the arithmetic. Every sub-indicator in both field guides is tagged [R] or [A]. The headline score is still the single 0–100 sum, but each assessment also reports the R-subtotal and A-subtotal as a two-number profile. Full definitions and practical tests are in §1.1.
Scoring
The main score runs 0 to 100; higher means more sovereign. It is the eight (or nine) pillar scores added together, before modifiers. Each pillar’s maximum equals its weight. Sub-indicator scores break each pillar into three to six parts, each worth a set number of points; the Field Guides give every rubric.
Three things sit alongside the pillar scores:
- Modifiers are adjustments applied after the pillar scores are worked out. AI-SAF-N has four — rule-stability (×0.85–1.00 on Hardware and Models), geopolitical-alliance (×0.70–1.15 on Hardware, Models, and Infrastructure), operating-model (±2 on the headline), and critical-minerals (scored inside Manufacturing) — applied in the fixed order given in the National Field Guide, Part II. AI-SAF-C applies a scale discount to three pillars for firms under 2,000 employees (×0.85 below 500 employees; ×0.92 from 500 to 2,000).
- Capability and commitment are the two angles from which each sub-indicator is scored. Capability is what is actually in place today, judged against hard facts; it feeds the main score. Commitment is what has been promised — budgets, policies, laws — and feeds the three-year projection.
- Dependency type labels each dependency as a bottleneck (replaceable at reasonable cost) or a structural constraint (no realistic replacement). It does not change the score; it shows which dependencies are worth spending money to fix.
Levels of analysis
AI-SAF-C is for a single company; AI-SAF-N for a country or bloc (the EU can be scored as a group). A sector score is just the AI-SAF-C scores of the sector’s biggest players combined. Product-level scoring is an internal management tool, not a comparison instrument. Scores from different levels are not comparable: a national 72 is not “higher” than a corporate 68 — they measure related but different things.
Executive summary
AI sovereignty has many parts, so one scoring system cannot fairly judge both governments and companies. Governments set the rules and prices in chip diplomacy; companies follow those rules and take the prices they are given. Governments plan ten to twenty years out; companies three to five. Governments answer to citizens; companies to shareholders and regulators. Because each side reacts differently to the same pressure, a single score for both looks exact but means little. The framework therefore uses two versions sharing the same eight pillars: AI-SAF-C for companies (weighting cloud choice, model choice, compliance depth, culture, and speed, with a ninth Culture pillar) and AI-SAF-N for governments (weighting chip access, sovereign cloud, fabs, and rule-making).
The framework measures resilience (“what still works if a supplier cuts us off tomorrow?”) and autonomy (“who decides our technology path?”), reported as a two-number profile alongside the headline score. Its most original idea — Version Deadlock, the trap of losing the ability to move to the next version of a technology you depend on — is developed in Part III, where the 2026 Fable 5 / Mythos 5 suspension now serves as the first live AI case, from cut-off through restoration.
Part I. Fundamental concepts
1.1 A two-dimensional definition
AI sovereignty is measured on two separate scales, each scored on its own.
Resilience. Can you keep your important AI systems running if an outside supplier cuts off some or all of your access? The key question: “What still works if a supplier cuts us off tomorrow?” A simple test: if the company behind a top AI model shut off your access tomorrow, how much of your work would keep going? That depends on whether you have a backup model you can run yourself, and whether your systems are wired so tightly to one vendor’s way of working that nothing else fits. Think of the power grid: a resilient grid keeps the lights on when one supplier fails, dimming gradually instead of going dark.
Every major AI-sovereignty event of 2024–2026 was a test of this scale — Microsoft France’s CLOUD Act testimony (June 2025), the H20 revenue-share deal (August 2025), the DeepSeek bans (early 2025), the EU delays of Meta’s multimodal Llama and Apple Intelligence. The sharpest test came on 12 June 2026, when a US export-control directive forced Anthropic to suspend all access to its frontier Fable 5 and Mythos 5 models for every foreign national overnight — three days after Fable 5’s public release. Access was restored 19 days later, on 1 July, after the directive was lifted — but the restoration came from the supplier’s side, not from anything the cut-off subjects did, a distinction Part III treats formally (see Evidence Base, Part B).
Autonomy. Can you set your own technology direction — which models you use, how you adapt them, where you take them next? The key question: “Who decides?” This is about power and strategy, and it does not automatically rise or fall with resilience.
The R/A tagging rule. Every sub-indicator in the field guides carries an [R] or [A] tag. The assignment rule: if the sub-indicator measures the ability to keep operating under interruption (fallbacks, reserves, diversification, egress control, incident response), it is [R]; if it measures the ability to set direction (own models and data, rule-making, indigenous design, talent, governance), it is [A]. Each assessment reports both subtotals. The profile matters as much as the headline: “68 (R 40 / A 28)” and “68 (R 28 / A 40)” call for opposite investment strategies.
1.2 Why a single index will not suffice
A single 100-point scale cannot judge a government and a company at the same time, because the same pillar measures opposite things at the two levels. Take Regulatory: France scores high because it makes the rules — it helped write the EU AI Act and can pass its own national AI laws. BNP Paribas scores high on the same pillar for the opposite reason: following rules well (DORA, GDPR, SR 11-7, ISO/IEC 42001). Each is a sensible measure on its own level; combined, they cancel. Hardware works the same way: a government scores by controlling exports and hosting fabs; a company scores by spreading purchases across suppliers.
The asymmetries run deeper: governments can make money from regulation (the 15% H20 deal) while companies are the ones regulated; governments negotiate chip access while companies receive an allocation; states may own fabs, firms almost never; governments host summits, companies sign codes of practice. Two side-by-side measures make these differences visible; one combined score hides them. This is the framework’s core design decision, and it is why the package contains two field guides rather than one.
1.3 Four levels of analysis
| Level | Subject | Typical horizon | Primary risk |
|---|---|---|---|
| National | State, EU, regional bloc | 10–20 years | Political cut-off; technology denial |
| Sectoral | Industry (banks, energy, telecoms) | 5–10 years | New rules; sector-wide risk |
| Corporate | Single firm or group | 3–5 years | Supplier lock-in; price shocks; compliance failure |
| Product | Product team, specific project | 6–18 months | Service or licence changes; retirement |
AI-SAF-C serves the corporate level and, aggregated, the sectoral level; AI-SAF-N the national level. Product-level scoring borrows the vocabulary but its numbers should not be compared between companies.
1.4 The temporal dimension
Sovereignty is a direction of travel, not a fixed position. Someone scoring 55 today but climbing is in better shape than someone at 70 but slipping. An honest assessment needs four reference points: today’s score (T0); the likely score three years out if nothing changes; the likely score three years out under a specific set of planned actions; and speed relative to peers. In a fast-moving field, anyone who stands still is losing ground without doing anything wrong, because the bar for “good enough” keeps rising.
Trajectory matters more than level
Today's score is a snapshot — the slope over the next three years shows who is actually building sovereignty.
- Peer-group median (the moving bar)
- Subject A — higher start, losing ground
- Subject B — lower start, catching up
Read the slope, not just the dot: by T+3 the higher starter (Subject A) falls below the peer bar, while the lower starter (Subject B) closes the gap and overtakes.
1.5 Decomposition: capability × commitment
Every sub-score splits into two parts — an idea adapted from the ECFR European Sovereignty Index:
- Capability — what is actually in place: training data held, researchers employed, chips installed and running, rules signed and in force, clouds actually certified.
- Commitment — what has been promised: strategy papers, announced budgets, laws in progress, agreements signed but not yet in effect.
A country that has promised much but built little is in a very different position from one with the opposite mix. Both numbers are shown for every pillar; the main score uses capability, and commitment drives the three-year projection. A promise with nothing built is just a promise; lots built with no plan is coasting.
1.6 Dependency ratios
Each pillar is also broken down to show exactly where you depend on others, because not every dependence is equally risky:
| Dependency axis | Indicator | Reading |
|---|---|---|
| Compute | Share of AI computing on foreign-owned platforms | Hard to fix once it passes roughly 70% (author judgement) |
| Models | Share of top models in use built abroad | Replaceable while open-weights substitutes exist |
| Semiconductor | Share of chips made abroad | Structural for more than 90% of countries (author judgement) |
| Software | Share of the core toolkit under foreign control | Replaceable in part |
| Data | Share of training data from foreign sources | Degrading over time as AI-generated text spreads |
Each dependence is labelled a bottleneck (replaceable at reasonable cost) or a structural constraint (no realistic replacement in sight). The goal is not to remove every dependence — impossible — but to spot the ones you cannot replace and steer spending toward them. The thresholds above are calibration judgements, not published constants; treat them as defaults an assessor may overrule with evidence.
Part II. Pillars and weights
2.1 The eight shared pillars
The backbone is eight pillars, stable against the 2024–2026 incident record and covering the design space of the publicly comparable instruments in active use (Stanford HAI AI Index, OECD.AI, IMF AIPI, Tortoise, CSET/ETO, ECFR, GAIA-X, NIST AI RMF, ISO/IEC 42001).
| # | Pillar | Scope |
|---|---|---|
| 1 | Data | Corpus control, linguistic identity, residency, no-train discipline, data egress at inference |
| 2 | Models | The L0–L4 ladder from foreign API to from-scratch training; fine-tune capacity; reasoning; portfolio and jurisdiction diversification |
| 3 | Infrastructure and energy | Sovereign cloud, AI factories, network and energy independence, confidential computing |
| 4 | Hardware architecture | CPU ISA (x86/ARM/RISC-V) and AI accelerators, export-tier access, indigenous designs |
| 5 | Manufacturing (foundry) | Leading-edge foundry access, advanced packaging, critical minerals, domestic capacity |
| 6 | Software stack | CUDA exposure, training frameworks, inference runtimes, MLOps, open-source contribution |
| 7 | Human capital | Researchers at top venues, ML engineers, education pipeline, retention, AI literacy |
| 8 | Regulatory and legal | AI-SAF-C: depth of compliance. AI-SAF-N: rule-making capacity |
The Data pillar covers not only the data a subject holds but also proprietary, corporate, or personal data that flows out to third-party models at inference time — prompts, retrieved context, fine-tuning sets and logs — scored through data-egress, no-train/data-rights and (for firms) IP-leakage sub-indicators. Uncontrolled egress of proprietary data is now a primary sovereignty exposure; it is cross-referenced to the Models pillar’s run-it-yourself fallback rather than counted twice.
2.2 The ninth pillar: Culture and operating model
AI-SAF-C only. Corporate execution does not reduce to technology and compliance. The CrowdStrike incident (19 July 2024: 8.5M Windows machines down, Fortune 500 losses above $5B) showed that the gap between hours and days of recovery was determined by runbook and incident-response maturity, not cloud choice. Every comparable business framework (McKinsey, BCG, Gartner, Deloitte, MIT CISR) treats culture as a distinct dimension. The ninth pillar measures board oversight, applied AI literacy, deployment speed, model-change governance, and disciplined experimentation. States do not have an organisational culture in this sense; the pillar does not appear in AI-SAF-N.
2.3 Weights by variant
Weights reflect the asymmetry between firm and state. The two largest movements — Manufacturing (1 corporate, 12 national) and Culture (10 corporate, absent national) — are mirror images: firms live or die by how they operate; states live or die by fab capacity.
| Pillar | AI-SAF-C | AI-SAF-N | Weight rationale |
|---|---|---|---|
| 1. Data | 14 | 10 | C: corpus + residency + contractual and egress discipline; N: residency emphasis |
| 2. Models | 16 | 16 | Portfolio and jurisdiction spread, fine-tune, open fallback, reasoning |
| 3. Infrastructure | 14 | 17 | Sovereign cloud, AI factories, CLOUD Act exposure |
| 4. Hardware | 10 | 17 | C: reserved GPU, diversification; N: access + design |
| 5. Manufacturing | 1 | 12 | C: awareness only; N: fabs, packaging, minerals |
| 6. Software | 10 | 8 | CUDA exposure, MLOps, FOSS share |
| 7. Human capital | 13 | 12 | C: AI-literate engineer ratio; N: talent stack + retention |
| 8. Regulatory | 12 | 8 | C: compliance depth; N: rule-making |
| 9. Culture | 10 | — | Corporate only |
| Total | 100 | 100 |
2.4 Interpreting the headline score
| Band | Level | Meaning |
|---|---|---|
| 85–100 | Sovereign hegemon | Sets the rules; others depend on it |
| 65–84 | Strategically autonomous | Operates under interruption; sets its own trajectory |
| 45–64 | Partially autonomous | Resilient to some shocks, vulnerable to others |
| 25–44 | Dependent with reserves | Critically dependent but has partial alternatives |
| 0–24 | Fully dependent | No sovereignty; strategic vulnerability |
Calibration notes. Small states (<10M population) cannot realistically exceed ~70 on AI-SAF-N because Manufacturing is structurally out of reach; enforceable participation in pooled EU compute (AI Factories / Gigafactories) partially rebuts this on the Infrastructure side. Every EU bank scores ≥35 on compliance depth alone; for mid-cap EU banks the 35–45 range rebases to 45–60. The AI-SAF-C scale discount is defined in the Corporate Field Guide, Part III.
Part III. The Version Deadlock framework
Version Deadlock is the trap where you can no longer keep your technology up to date, because access to the next version of something essential has been cut off. Depending on a supplier here and now can be managed with contracts, stockpiles, and switching plans; losing the ability to keep up is slow, hard to spot, and often impossible to undo. It happens to countries and companies alike.
3.1 The four types
| Type | Concrete scenario | Early-warning indicators |
|---|---|---|
| Model | Losing access to the next version of a core model, or to the model itself: the Fable 5 / Mythos 5 suspension (June 2026); EU hold-ups of Meta’s multimodal Llama (2024) and Apple Intelligence (2024–25); the DeepSeek bans (2025) | Retirement notices; versions blocked in certain countries; price rises faster than inflation |
| Hardware | Export limits on newer chips: the Biden Diffusion Rule (Jan 2025, scrapped May 2025); the H20 15% and H200 25% revenue-share deals (2025); case-by-case licence review (2026) | Export-rule changes; sanctions; supply chains redrawn; one-off deals |
| Software | CUDA licensing changes; key components moved behind closed doors; governance shifts. The CrowdStrike outage (July 2024) was an accidental test of over-reliance on one piece of software | Licence changes; features gated to big customers; single-supplier reliance |
| Data | A supplier cutting off training data or a licensed dataset; rulings such as NYT v. OpenAI (ongoing), Bartz v. Anthropic (fair use 2025; $1.5B settlement approved July 2026), Kadrey v. Meta (2025), Getty v. Stability (UK, 2025) | Stricter renewal terms; terms-of-service changes; residency rules |
3.2 Common mitigation strategies
Model: keep the last working version on your own systems; adapt an open-weights model (Llama 4, Gemma 3, Qwen 3, DeepSeek) as a live fallback; contract for minimum support periods; spread across providers and jurisdictions — two or three top providers plus your own open copy in-house. Hardware: buy from several suppliers; keep reserves; qualify alternative accelerators before you need them; use confidential computing to run on others’ clouds with your data sealed. Software: favour open-source tools under multi-party governance (PyTorch Foundation); contribute back; use source-code escrow; keep vLLM, SGLang, llama.cpp as inference fallbacks. Data: build your own collection pipeline; gather text in your own language; use synthetic data only as a supplement (models trained mostly on it degrade — Shumailov et al., Nature 2024); bar suppliers from training on your data; align contracts with EU Data Act Chapter VII.
3.3 Version-Deadlock-related modifiers
Rule-stability. The defining feature of 2025–2026 is one-off deals struck case by case, where the rules can change at any time in either direction: exports banned, then taxed at 15%, then licensed; a frontier model suspended by directive, then restored 19 days later. The modifier prices exposure to this volatility — not the strictness of any one rule — and lowers the Hardware and Models scores of anyone at the mercy of unpredictable decisions in a supplier jurisdiction (×0.85 high exposure – ×1.00 none). It applies as a modifier in AI-SAF-N; AI-SAF-C captures the same risk inside its Models pillar through jurisdiction diversification.
Geopolitical-alliance. AI-SAF-N only. The closest US allies get better chip access. That access is not a strength they built, so it multiplies the relevant scores (×0.70–1.15 on Hardware, Models, Infrastructure) rather than adding points. Note that the alliance multiplier and the rule-stability modifier pull against each other for close US allies — alignment buys access and simultaneously deepens exposure to the supplier’s rule volatility. Both must always be applied; the National Field Guide fixes the order.
3.4 Historical analogues
Three cases from outside AI set up the categories, and one from AI itself now completes them.
Windows XP in business computing (escaped). From roughly 2007 to 2014, companies kept running XP long after the security risks said to move, because their key business programs worked on XP but not Vista. The real upgrade cost was rewriting those programs. The deadlock was broken from the supplier’s side: Microsoft released Windows 7 with an XP compatibility mode. The lesson: some Version Deadlocks are ended by the supplier — and waiting for that is a gamble that their interests stay aligned with yours.
Russian-designed nuclear reactor fuel (slow-clock). VVER reactors across Eastern Europe use fuel rods shaped for that design. Since 2022, operators have been moving away from Rosatom; alternatives exist (Westinghouse), but qualification for a given reactor takes years. The lesson: an alternative that exists on paper but needs five to ten years to qualify is not an alternative within the time-frame that matters.
Soviet industrial licensing (fatal). From the 1960s the USSR acquired Western industrial and computing technology by licence (Tolyatti, the ES EVM computers copying IBM designs). By the late 1970s, COCOM restrictions tightened access to the next generation — and decades of leaning on licensed designs had hollowed out the home-grown ability to design from scratch. The outside limit and the inside decay arrived together. The most important lesson of the three: fatal deadlocks are rarely caused by the moment access is cut; they are caused by the long, comfortable stretch beforehand, when the ability to build your own was allowed to waste away.
Fable 5 / Mythos 5 — the first live AI case (June–July 2026). On 12 June 2026 a US export-control directive forced Anthropic to suspend all access to its frontier Fable 5 and Mythos 5 models for every foreign national, overnight, three days after Fable 5’s public release. On 30 June the directive was lifted; Fable 5 returned globally on 1 July, while Mythos 5 was reintroduced only to approved US organisations. The episode compresses the analogues’ lessons into 19 days. For subjects that had kept a fine-tuned open model in reserve, it was a Recoverable event; for those that had not, it was three weeks of dead stop and would have been Slow-clock had the directive held. And like Windows XP, the ending came from the supplier’s side — the US government reversed itself; no cut-off subject restored its own access. It is the clearest warning the framework has had that a frontier model can be switched off by the jurisdiction that hosts it, that the switch can be thrown and un-thrown inside a month, and that the comfortable years of pure API dependence are exactly when the in-house ability to switch must be paid for.
3.5 Taxonomy of Version Deadlock states
Two questions build the grid. Does another supplier of the version you need exist? Have you kept your own ability to switch, or has it wasted away?
- Recoverable — an alternative exists and you have kept your ability to switch. Migration is doable at reasonable cost and time. Windows XP → 7 sits here.
- Slow-clock — an alternative exists, but your ability to switch has wasted away; rebuilding the skills to qualify and integrate it takes years. Russian reactor fuel sits here.
- Vulnerable but recoverable — no alternative exists, but you have kept the ability to build one, at real cost. Whether you do comes down to political will.
- Terminal — no alternative, and no ability left to build one; the gap widens faster than you can close it. Soviet computing by the mid-1980s. The only useful policy is never to land here.
Restoration is not recovery. Two of the cases above — Windows XP and Fable/Mythos — ended because the supplier side reversed course. The taxonomy classifies what the subject can do; a deadlock ended by supplier grace leaves the subject’s own position exactly where it was. Scoring a subject “Recoverable” because a directive was lifted is an assessment error: the correct reading is the state the subject would have been in had the restriction held. Assessors should record supplier-side restorations as evidence about the supplier’s rule-stability, not about the subject’s resilience.
3.6 Detection: leading vs lagging indicators
The visible signs — a licence refused, retirement notices, prices that shut you out — show up late; by then the deadlock has set in. The early signs are harder: how many generations behind the edge you are and whether the gap is widening; whether your own ability to switch is growing or wasting; supplier signals about its plans. Your own switching ability is the hardest to measure and the most important; rough proxies include researchers active in the relevant area, alternative suppliers qualified in the last cycle, and how long qualification takes when you try. Reaction speed must be tuned to the field: the AI edge moves in months, business software in years, nuclear fuel in decades.
3.7 Policy implications
The point is not whether you depend on others — almost everyone does, for almost everything — but whether you can keep improving while you depend on them. Cutting ties completely is rarely possible. Spreading across suppliers buys time but does not solve the problem. Keeping your own ability to switch is the overlooked lever: the single most important choice during the easy years is to pay, at real expense, to maintain the home-grown ability you would need if access ended. That upkeep wins no political credit, because it produces nothing visible exactly when it matters most — and, going by the Soviet case, it is the difference between a deadlock you can escape and one you cannot. The EU’s AI Factories and Gigafactories programmes, national open-model efforts (Bulgaria’s BgGPT and peers), and certified sovereign cloud are all best understood as insurance against a future Version Deadlock. The full account is in the companion paper “Version Deadlock: Technological Evolution Under Constrained Dependency” (April 2026).
Part IV. Gap-analysis methodology
The framework’s most useful job is not the score but pointing to where the next investment does the most good: “Given where you stand, what you can spend, and how long you have, which pillar gives the biggest gain per unit of money or effort?”
4.1 A four-step process
- Score today — fill in the scale with hard evidence, splitting capability from commitment; note the direction of travel.
- Project three years out at current effort — the bar rises, so standing still usually means falling behind.
- Work out payoff per pillar — points gained per standard chunk of investment (€1M, 10 FTE, or 12 months); pick the pillars that pay most and fastest.
- Choose the mix — the set of moves giving the best three-year position for the budget, counting knock-on effects (people multiply every other pillar’s payoff).
4.2 Typical priorities
Companies: first people (the multiplier), then L2 on Models (adapting an open model — realistic, big payoff), then software stack and data. Manufacturing and Hardware take country-sized investment to move. Countries: infrastructure and people pay most but need 5–10 years of steady commitment; Models and Regulatory can move faster but hit lower ceilings.
4.3 Methodological rigour — design and current status
The framework is designed to the standard for composite indicators set out in the OECD/JRC Handbook on Constructing Composite Indicators: min-max normalisation to a common scale; imputation only where no more than 15% of data is missing; principal-component cross-checks on the aggregate; and Monte Carlo sensitivity runs that nudge every weight to test whether profile readings — and the ordering of any two subjects more than a few points apart — survive.
Status, stated plainly: as of v0.7.1 these checks are a design commitment, not a completed exercise. The sensitivity runs and PCA cross-checks have not yet been executed and published; they are a precondition for a 1.0 release, alongside the reproducibility test below. Until then, the worked examples should be read as calibrated illustrations, not validated measurements.
Reproducibility between assessors. Where a sub-indicator calls for qualitative judgement, two assessors working independently from the same evidence should land within one scoring band; a wider gap is treated as a defect in the rubric, not the assessors. Score sheets record the evidence relied on so a third party can re-derive the number.
Data sources (catalogued in Evidence Base, Parts G and H): CSET/ETO Supply Chain Explorer (Hardware, Manufacturing); the Epoch AI notable-models database via Stanford HAI (Models); the SecNumCloud 3.2 registry, GAIA-X Level 3 labels, and the EU cloud sovereignty instruments (Infrastructure); CulturaX, HPLT v2, FineWeb-2, INCLUDE, and Global-MMLU (Data); CSRankings, top-venue author counts, MacroPolo Global AI Talent Tracker 2.0, and the Stanford AI Index (Human capital).
Part V. Areas of genuine uncertainty
Every framework has a point past which its own advice turns into guesswork. Being upfront about where that point lies is part of doing the job honestly.
How the AI Act’s split timeline plays out. Partially resolved since the last revision: GPAI obligations and Article 50 transparency duties became enforceable on schedule on 2 August 2026, while the Digital Omnibus on AI (in force 27 July 2026) deferred high-risk obligations to December 2027 (Annex III) and August 2028 (Annex I). The open question is now enforcement practice, not the calendar — and how the deferral feeds the three-year commitment projections in AI-SAF-C Regulatory.
Where the Cloud and AI Development Act lands. The Commission’s CADA proposal (3 June 2026) introduces a four-level Cloud Sovereignty Framework for public procurement, effectively superseding the stalled EUCS debate. If it survives trilogue near its proposed form, it becomes the EU-wide anchor for the Infrastructure pillar, displacing SecNumCloud as the reference ladder; if it is diluted, SecNumCloud 3.2 stays the top bar. Assessors should track the trilogue.
Whether the big cloud companies’ own chips loosen NVIDIA’s grip. If TrendForce’s forecast (NVIDIA’s inference share falling to 20–30% by 2028) is right, CUDA lock-in should matter less in the Software pillar. No decisive evidence either way yet.
Whether export controls on model access become an instrument. The Fable 5 / Mythos 5 episode ended after 19 days, but the precedent stands: the US demonstrated it can and will switch off a frontier model for all foreign nationals by directive. Whether this becomes a repeated tool or stays a one-off, and how far its extraterritorial reach holds up, bears directly on the rule-stability modifier and the Models weight. The DeepSeek V4 question, by contrast, is resolved: V4 shipped with day-0 adaptation to Huawei Ascend (April 2026), confirming that a top Chinese model no longer needs CUDA — advantage China over Europe on the Software pillar.
Life after Magdeburg. Intel’s July 2025 cancellation cost the EU Chips Act credibility; Chips Act 2.0 (proposed 3 June 2026) is the policy response, and ESMC Dresden is proceeding. Whether proposal turns into capacity affects Germany’s Manufacturing score — a capability-vs-commitment test case.
How much announced money is actually spent. The headline numbers (Stargate $500B, France €109B, the €30B Gigafactories initiative) mix private pledges, partner-country money, and multi-year spending. The framework treats them as rough sizes and separately tracks disbursement.
The framework’s own additive form. Pillar scores sum linearly, so a strong Regulatory score can arithmetically offset a near-zero Models score. The framework’s own thesis is non-compensatory — sovereignty fails at the choke point. The additive headline therefore overstates sovereignty for unbalanced profiles; the dependency-type labels and the R/A profile are the non-compensatory reading, and assessors should flag any profile where a structural-constraint pillar scores under a quarter of its weight, whatever the headline says. A future revision may adopt partially non-compensatory aggregation; the trade-off is transparency.
Conclusion
AI sovereignty is not about owning the whole technology chain. It is about being able to keep running — and keep improving — if the chain is broken. Every major event of 2024–2026 tested exactly that: the CLOUD Act admission, the H20 and H200 revenue deals, the DeepSeek wave, the Meta and Apple delays, Magdeburg, China’s mineral controls, the sovereign-cloud responses — and, above all, the June 2026 suspension of Fable 5 and Mythos 5, the first time a government switched off access to a frontier model itself. That it was switched back on 19 days later, by the same government, only sharpens the lesson: access is not ownership, and restoration is not recovery.
The framework’s biggest departure from existing public tools is admitting that the same pillar name means opposite things for a company and a country, and keeping two variants instead of forcing one score. The second is splitting capability from commitment inside every pillar. The third, new in this revision, is carrying the resilience/autonomy distinction into the arithmetic. A business uses AI-SAF-C (Document 2); a government body uses AI-SAF-N (Document 3). This document stays the reference for the method, the terms, and the thinking behind both.
Appendix: Master glossary
- AI-SAF / AI-SAF-C / AI-SAF-N
- The AI Strategic Autonomy Framework and its business and national variants; eight shared pillars at different weights; AI-SAF-C adds a ninth (Culture).
- Base model
- A large language model trained from scratch on trillions of tokens (GPT, Claude, Gemini, Gemma, Llama, DeepSeek, Qwen).
- Branch-and-Merge
- INSAIT’s training method (EMNLP 2024) for adapting a model to a new language without catastrophic forgetting.
- CADA / Cloud Sovereignty Framework
- The EU Cloud and AI Development Act (proposed 3 June 2026); its Cloud Sovereignty Framework grades cloud services on four assurance levels, from EU data location (L1) to full supply-chain control free of third-country interference (L4).
- Capability × commitment
- Splitting every sub-score into what is actually in place today versus what has been promised.
- Chokepoint exposure
- Vulnerability at the make-or-break steps of the chip supply chain (EUV lithography, leading-edge logic, HBM, EDA software, key chemicals).
- CLOUD Act
- The US Clarifying Lawful Overseas Use of Data Act (2018), authorising federal access to data held abroad by US companies.
- CUDA
- NVIDIA’s software layer for its chips; the de facto standard for AI training and the main switching barrier away from NVIDIA.
- Data Act Chapter VII
- The EU Data Act provisions (fully applicable September 2025) aimed at third-country access.
- Data egress
- The flow of a subject’s own data out to a third-party model at inference time — prompts, retrieved context, tool calls, fine-tuning sets, logs.
- Digital Omnibus on AI
- The EU amending package (in force 27 July 2026) deferring the AI Act’s high-risk obligations to December 2027 / August 2028 while leaving GPAI enforcement on schedule.
- DORA
- The EU Digital Operational Resilience Act for the financial sector, applicable from January 2025.
- FRIA
- Fundamental Rights Impact Assessment, AI Act Article 27.
- GAIA-X
- European certification of cloud and data services against sovereignty criteria at three levels; L3 requires SecNumCloud-grade immunity from foreign-reach laws.
- ISA
- Instruction Set Architecture — the command set a processor understands (x86, ARM, RISC-V).
- ISO/IEC 42001
- The certifiable international AI-management standard (December 2023); nine Annex A control groups; a stepping stone to AI Act Articles 53/55.
- MoE
- Mixture of Experts — a model design activating different specialist sub-models per input.
- MRM / SR 11-7
- Model Risk Management; the US supervisory standard widely adopted in EU banking — challenger models, monitoring, model inventory, documentation.
- NIST AI RMF
- The US AI risk-management framework (Govern, Map, Measure, Manage); backbone of the AI-SAF-C crosswalk.
- No-train clause
- A contract clause barring a model provider from using your inputs or outputs to train its models.
- Open-weights
- A model whose trained weights can be freely downloaded and run (Llama, Mistral, Gemma, Qwen, DeepSeek); not always fully open-source.
- Restoration risk
- The error of reading a supplier-side reversal (a lifted directive, an extended support window) as evidence of the subject’s own recoverability. See Framework §3.5.
- RISC-V
- An open, royalty-free ISA; the strategic alternative to x86 and ARM (Tenstorrent, EU DARE, Meta MTIA).
- SecNumCloud
- France’s ANSSI certification (v3.2) — the established scheme requiring a cloud service to be beyond the reach of foreign laws such as the CLOUD Act and FISA.
- Strategic interdependence
- Deliberately depending on several partners so no single one can dictate — the realistic alternative to autarky for small and mid-sized economies.
- Synthetic collapse
- The effect shown by Shumailov et al. (Nature, 2024): repeatedly training on AI-generated data permanently strips away rare cases.
- TEE
- Trusted Execution Environment — hardware-isolated execution (Intel TDX, AMD SEV-SNP, NVIDIA Confidential Computing) enabling private inference on clouds you do not control.
- Version Deadlock
- The state in which a subject loses the capacity to evolve technologically because access to the next version of a key technology has been interrupted.
- vLLM / SGLang / llama.cpp
- Open-source inference engines; alternatives to NVIDIA’s TensorRT-LLM that run models without CUDA dependence.