AI-SAF-N Field Guide — National variant

Assessment of national AI sovereignty. Version 0.7.1 · August 2026 · CC BY 4.0

About this document

This field guide is the hands-on manual for AI-SAF-N, the national version of the AI Strategic Autonomy Framework, for a government body, ministry, or regional bloc measuring its AI sovereignty and building strategy from the result. For the concepts — the two variants, capability × commitment, gap analysis, Version Deadlock — see Document 1. Dated market detail lives in Document 4, State of Play.

How each pillar is presented. Each pillar opens with what it measures and why, then a rubric: sub-indicator, points, R/A tag, evidence expected. Whole-number scores; the pillar score is the sum; report R and A subtotals with the headline.

Contents: Part I — the eight pillars. Part II — the four modifiers and their fixed order of application. Part III — worked examples: Bulgaria, France, UAE. Part IV — case study: INSAIT and BgGPT.

Part I. The eight pillars

#PillarWeightNational focus
1Data10National corpus, residency, legal regime, public-sector egress
2Models16The L0–L4 ladder; reasoning bonus
3Infrastructure and energy17Sovereign cloud, local and pooled compute, grid
4Hardware architecture17Export tier, indigenous design, supplier spread
5Manufacturing12Fabs, advanced packaging, critical minerals
6Software stack8CUDA dependence, framework diversity, FOSS contribution
7Human capital12Top-venue researchers, retention, pipeline
8Regulatory (participation)8Rule-making seats, own binding law, institutions, summits
Total100

For languages with less material online, data limits sovereignty more than models do: open-weights models are now cheap and common, while a genuine national corpus is not. Combined totals across the big open collections (CulturaX, HPLT v2, FineWeb-2, deduplicated) sort languages into tiers: Low (5–40B tokens — Bulgarian, Estonian, Welsh: not enough to train mid-sized models from scratch; continued pre-training is forced), Medium (40–250B — Polish, Greek, Vietnamese, Hebrew), High (250B–1.5T — German, French, Arabic: from-scratch training feasible). On the legal side, the EU regime (GDPR + Data Act, with Chapter VII targeting third-country access + AI Act) is the world’s strictest; India’s DPDP rules are gentler; China’s PIPL is strictest on government data.

Public-sector data egress complements residency: whether sensitive government and critical-sector data is sent to foreign-controlled models at all, and whether a sovereign-inference option (certified sovereign cloud plus a domestic or open model) exists and is mandated.

Sub-indicatorPointsR/AEvidence expected
Corpus authenticity4AVolume and cleanliness of local text; share real rather than AI-generated
Residency and legal regime3RWhere data sits; governing law; CLOUD Act exposure
Instruction and evaluation data1ACoverage in INCLUDE / Global-MMLU; local instruction data
Public-sector and proprietary-data egress2R0 = no rule; 1 = binding procurement bar on sensitive data to foreign models; 2 = sovereign-inference option mandated for sensitive workloads

Pillar 2. Models — 16 points

The pillar that separates countries most. The five-level ladder (anchors L0–L4 = 0/4/11/13/16):

LevelPointsNational example, 2026Note
L00Governments on foreign frontier APIsCLOUD Act and directive exposure
L14Open-weights models run on-prem, unadaptedControl of the hardware, nothing more
L211BgGPT (Gemma 3 → Bulgarian); Meltemi; Sarvam-M; TAIDEAdapt or keep training someone else’s base model
L313EuroLLM; Teuken; Poro; Aya-Expanse; EXAONEOwn model and tokeniser, on foreign compute
L416Fugaku-LLM; Falcon/Jais (UAE); DeepSeek/Qwen on AscendFully independent, top to bottom

Scoring rule: the ladder anchors the level; the pillar score is the assessor’s raw fraction × 16, with the anchor as the reference point. Worked examples show both (e.g. “L2 anchor 11; raw 0.55 after portfolio-depth deductions”). The jump from L2 to L3 turns on owning the tokeniser — the part that splits language into pieces — which removes a built-in bias toward foreign languages that is even harder to fix than the model itself.

Reasoning bonus: a country that has released a reasoning model in its own national language earns +2 within the pillar, capped at 16. Currently: China, South Korea, India, UAE.

Spending thresholds: DeepSeek-V3’s reported ~$5.6M in rented compute sets the floor for replicating a top model; roughly $500M/year is the bar for matching a full national ecosystem.

Sub-indicatorPointsR/AEvidence expected
Ladder level (anchored)12AHighest level achieved, evidenced by shipped models in use
Portfolio depth and open fallback4RMore than one usable model; self-hosted deployment in government

Pillar 3. Infrastructure and energy — 17 points

Every major sovereignty incident of 2024–2026 ran through this pillar. The scoring anchors for sovereign cloud, in descending order of protection: SecNumCloud 3.2 (immune from foreign-reach law — the established top bar); the CADA Cloud Sovereignty Framework levels once finalised (the proposed EU-wide four-level ladder — track the trilogue; see Framework Part V); GAIA-X Level 3; EU-operated subsidiaries of foreign providers (BSI C5 tier — the AWS European Sovereign Cloud sits here: EU-run, still US-owned). Do not score against EUCS: its sovereignty tier was removed in March 2024 and never returned; CADA is where that debate moved.

Local compute credits AI-accelerator capacity on the subject’s own territory at full rate, plus up to 2 of its 4 points for enforceable pooled EU capacity — a signed EuroHPC AI Factory or Gigafactory hosting or consortium agreement conferring allocation rights the subject can invoke. The Gigafactories call opened on 30 July 2026 (seven sites, €10B public funding, awards early 2027): a signed award will qualify; a bid does not. Mere programme membership scores 0. Pooled capacity is labelled a bottleneck, never a structural asset.

Sub-indicatorPointsR/AEvidence expected
Sovereign cloud / cloud choice5RCertification against the anchors above; European jurisdiction
Local compute4ROwn-territory accelerator capacity; enforceable pooled allocation (≤2)
Network independence2RSeveral providers plus own interconnects
Energy mix and price3RDiversified sources; competitive price; grid headroom
Cryptographic control + TEE3RHSMs, key management, attested confidential computing

Pillar 4. Hardware architecture — 17 points

The fastest-changing pillar: US export rules went through seven major turns between 2022 and 2026, and the 2026 watchword is deal-by-deal diplomacy — bans became revenue-share deals became case-by-case licences. Vendor and alternative-chip detail: Document 4.

Sub-indicatorPointsR/AEvidence expected
CPU ISA diversification5RMix of x86 / ARM / RISC-V; home-grown designs (SiPearl, DARE)
AI accelerators — access7RExport tier; reserved capacity; supplier spread
AI accelerators — indigenous design5ARealistic only at EU scale; Rhea-, EXAONE-, or TPU-class effort

Pillar 5. Manufacturing — 12 points

The most lopsided pillar: only Taiwan, South Korea, the US, and (to a limited degree) China can make advanced chips in volume; for everyone else this is the dependency that cannot be reduced, only diversified. Current fab, packaging, and HBM state of play: Document 4. Critical minerals are scored inside this pillar (2 points): the share of gallium, germanium, heavy rare earths, high-purity silicon, and refined copper a country (or its allies) can refine at home. Ore in the ground does not count — refining is the chokepoint, as China’s 2024–2026 export-control campaign demonstrates.

Sub-indicatorPointsR/AEvidence expected
Supplier diversification4RAccess to at least two foundry partners
Local advanced packaging3RChiplet assembly, test, packaging at national or EU level
Own foundry capacity3AA real fab under own control
Critical minerals2RDomestic/allied refining share of Ga, Ge, rare earths, Si, Cu

Pillar 6. Software stack — 8 points

CUDA still dominates but its grip is loosening; multi-party-governed open source (the PyTorch Foundation model) is much harder for any one company to weaponise than single-vendor software — a modest structural plus for the EU. Runtime and framework state of play: Document 4.

Sub-indicatorPointsR/AEvidence expected
CUDA exposure2RShare of national AI workloads that run only on CUDA
Training-framework diversification2RPyTorch, JAX, and alternatives in real use
Inference-runtime diversification2RvLLM / SGLang / llama.cpp deployed
MLOps lock-in1RVendor-agnostic deployment patterns
Open-source contribution1AUpstream contributions from national institutions

Pillar 7. Human capital — 12 points

The ultimate bottleneck. Reference sources: the MacroPolo Global AI Talent Tracker 2.0 (March 2024, NeurIPS 2022 data — note the correct edition is 2.0) for talent flows; the Stanford AI Index for the annual picture; CSRankings and top-venue author counts for national standing. Headline 2026 context — US ~75% of global GPU compute, 50 notable US models vs 30 Chinese in 2025, Switzerland and Singapore leading per-capita researcher density — is kept in Document 4 with the other dated figures.

Sub-indicatorPointsR/AEvidence expected
AI researchers / top-tier4ATop-venue papers; CSRankings standing; talent based at home
ML engineers and operators3AProduction experience; qualified workforce size
Education pipeline2AStrong programs and intake volumes
Retention against brain drain2RPay competitiveness; career paths; track record
AI literacy in the population1AFormal training reach; basic digital skills

Pillar 8. Regulatory (participation) — 8 points

In the national variant this pillar measures the power to make the rules — the mirror image of the corporate variant (Framework §1.2). Reference instruments as of August 2026: the EU AI Act (GPAI obligations enforceable since 2 August 2026; high-risk obligations deferred by the Digital Omnibus to December 2027 / August 2028); the Council of Europe Framework Convention on AI (in force 1 November 2025 — the first binding international AI treaty); the summit series (Paris, February 2025; New Delhi, February 2026, whose Declaration was endorsed by 92 countries and organisations); and the sandbox obligation (at least one AI regulatory sandbox per member state).

Sub-indicatorPointsR/AEvidence expected
Rule-making seats3ASeats in bodies writing binding rules
Own binding AI law2AApplying the AI Act plus national implementing law
Institutional presence2AAn AI safety/security institute; Council of Europe participation
Summit hosting + bilateral frameworks1AHosting summits; bilateral AI agreements

Part II. Nation-specific modifiers

Four adjustments applied after the pillar scores, reflecting how unstable the rule environment has become. Apply them in this order, always, and all of them: (1) rule-stability, (2) geopolitical-alliance, (3) operating-model. (Critical-minerals is scored inside Manufacturing and needs no separate step.) Worked examples must show each step explicitly; no other adjustments — bonuses, penalties, or otherwise — are permitted outside these four. If a strength seems to deserve extra credit (abundant energy, rule-making influence), it belongs inside the relevant pillar’s sub-indicators, where it is already counted.

2.1 Rule-stability modifier (×, on Hardware and Models)

The defining feature of 2025–2026 is one-off deals and reversible directives — exports banned, then taxed, then licensed; a frontier model suspended, then restored within a month. The modifier prices exposure to that volatility.

ExposureMultiplierExample
None — compute home-grown1.00China (partly); countries with own large providers
Low — deliberately multi-supplier0.95European countries spreading purchases
Moderate — mostly US-supplied0.90Most EU states today
High — case-by-case US permission0.85UAE; countries with no alternatives

2.2 Geopolitical-alliance multiplier (×, on Hardware, Models, Infrastructure)

The closest US allies get better chip access. That access is not a built strength, so it multiplies rather than adds. Note the tension: Tier-1 alignment raises this multiplier and typically raises rule-stability exposure — the two must both be applied, which is why the order is fixed.

PositionMultiplierExamples
Tier-1 US ally1.10–1.15Japan, UK, Canada, Australia, South Korea, Netherlands, Taiwan, Singapore, France, Germany
Special partnership1.05–1.10UAE (US–UAE AI Acceleration Partnership)
Neutral1.00Bulgaria, India, most developing nations
Restricted access0.90–0.95Below-tier under export rules
Sanctioned0.70–0.80Iran, Russia, (partially) China

2.3 Critical-minerals modifier

Scored inside Manufacturing (2 of 12): domestic or allied refining capacity for gallium, germanium, heavy rare earths, high-purity silicon, and refined copper. China’s export-control campaign — gallium/germanium (December 2024), rare earths (October 2025, paused November 2025 for 12 months, with active enforcement through 2026) — shows the risk is present, not theoretical.

2.4 Operating-model modifier (integer, −2 to +2, on the headline)

How a government organises itself to build and keep its own AI capability — durability across political change, legitimacy, exit costs, reproducibility, decision clarity. Four common forms: a public research institute (Bulgaria’s INSAIT), a state-owned company (several Chinese labs), a private national champion (France’s Mistral), a consortium (EuroHPC AI Factories). No form is favoured; any can earn +2 or −2. The modifier does take one side: a real, coherent setup of your own beats renting everything from foreign providers — disagreeing with that is disagreeing with AI-SAF as a whole.

Scoring: −2 no real setup, or paper-only. −1 a setup exists but under-funded, badly run, or unclear. 0 solid, funded, documented, producing results used at home; sovereignty as by-product. +1 all that, with sovereignty built in on purpose (openness, clear decision-making, reproducibility) but untested through a major upheaval. +2 proven through at least one real test — change of government, funding gap, major shock.

Calibration: Bulgaria/INSAIT +1 (coherent, resourced, explicitly open; untested through political discontinuity). France/Mistral +1 (commercial discipline plus state alignment; also untested). A small state renting everything through foreign hyperscalers: −1 or −2.

Part III. Worked examples

All three examples follow the same sequence: pillar table → rule-stability → alliance → operating-model → final. These are the author’s estimates from public information, shown to demonstrate the method.

3.1 Bulgaria — ~46

Bulgaria punches above its weight: a small economy (~$100B) whose INSAIT institute built far more national capability than size suggests, by continuing to train Google’s Gemma models into BgGPT and putting the result into government use (7,000+ staff at the National Revenue Agency).

PillarWeightRawScoreNote
Data100.707.0>100B Bulgarian tokens; NRA integration; planned BRAIN++ data lake
Models160.558.8BgGPT 3.0 on Gemma 3 = L2 (anchor 11); raw 0.55 after portfolio-depth deductions
Infrastructure170.559.4BRAIN++ AI Factory €90M + Discoverer+ (domestic); no SecNumCloud equivalent
Hardware170.254.3No indigenous design; NVIDIA via TSMC
Manufacturing120.050.6No fabs, packaging, or refining
Software80.453.6Strong open-source culture; COMPL-AI toolkit
Human capital120.657.8INSAIT at CSRankings #14 Europe, #1 Eastern Europe
Regulatory80.554.4AI Act applies automatically; limited rule-making weight
Pillar total100~45.9

3.2 France — ~70

Europe’s clearest example of sovereign AI: Mistral (valued €11.7B after the ASML-led round), SecNumCloud with qualified providers including S3NS, SiPearl building a home-grown CPU, €109B announced at the 2025 summit, and an active hand in writing the EU’s rules.

PillarWeightRawScoreNote
Data100.707.0Strong public data; excellent French corpus
Models160.8513.6Mistral Large/Medium/Le Chat; Europe’s only top-10 global firm
Infrastructure170.8013.6UAE-MGX campus + Mistral Essonne + SecNumCloud + Alice Recoque exascale
Hardware170.508.5SiPearl Rhea1 sampling; still TSMC/ARM underneath
Manufacturing120.151.8No leading edge; STMicro mature nodes; Soitec wafers
Software80.554.4Strong FOSS; orchestration US-dominated
Human capital120.8510.2Polytechnique, ENS, Inria, CNRS; returnee pipeline at Mistral
Regulatory80.907.2Summit host; AI Act leadership; SecNumCloud as exported standard
Pillar total100~66.3

3.3 UAE — ~57

The most interesting case outside the US and China: cheap energy, deep state funds, and political flexibility, channelled through G42 into genuinely cutting-edge infrastructure.

PillarWeightRawScoreNote
Data100.505.0Arabic via MBZUAI; weak open-data regime
Models160.7011.2Falcon open-source series; Jais; +2 reasoning bonus included
Infrastructure170.8514.5Stargate-UAE 1 GW (first 200 MW 2026); 5 GW campus; Khazna; energy strength (Barakah + solar) is inside this raw score
Hardware170.457.7~35,000 GB300 via G42; access is political, not owned
Manufacturing120.151.8No advanced node
Software80.403.2Azure and Oracle dependency
Human capital120.607.2MBZUAI operational; imported talent; small citizen base
Regulatory80.756.0US–UAE AI Acceleration Partnership; assurance agreement
Pillar total100~56.6

Part IV. Case study: INSAIT and BgGPT

BgGPT is the clearest real-world example of L2 on the Models ladder — how a small economy gains real control over its models without the cost of training from scratch.

4.1 BgGPT in brief

INSAIT (Sofia, part of Sofia University) builds BgGPT, a family of Bulgarian-language models: v0.1/0.2 on Mistral-7B (March 2024); BgGPT 1.0 on Gemma 2 (November 2024); BgGPT 3.0 on Gemma 3 in 4B/12B/27B sizes (March 2026) — multimodal, ~131k context, trained on >100B Bulgarian tokens plus balanced English. Its Branch-and-Merge method (EMNLP 2024) prevents catastrophic forgetting while adding a language. On Bulgarian tasks the 27B model holds its own against models three times its size and, for Bulgarian chat, against leading commercial models on INSAIT’s benchmarks. Distributed in full precision, GPTQ W4A16, and GGUF (runnable locally via llama.cpp). First large institutional user: the National Revenue Agency, 7,000+ staff.

4.2 Why BgGPT is exactly L2

LevelAnchorWhy BgGPT is / is not at this level
L00BgGPT runs on own machines with open weights — no outside provider
L14More than a local copy: further trained on >100B Bulgarian tokens
L211Exactly this: heavy continued pre-training + instruction tuning on Gemma 3 weights, via Branch-and-Merge
L313Architecture and tokeniser are Gemma 3’s — no structural modifications
L416Starting weights come from Google; no from-scratch training

4.3 AI-SAF-N profile for INSAIT / BgGPT

Scored as an institutional profile (the institute, not the country — Bulgaria’s national profile in Part III applies portfolio-depth deductions this focused profile does not):

PillarScoreMaxRationale
Data710>100B curated Bulgarian tokens; instruction data
Models1116L2 anchor (fine-tune/CPT on Gemma 3); Branch-and-Merge
Infrastructure917H100 compute via partnerships; limited own capacity
Hardware417Full NVIDIA/CUDA dependency
Manufacturing112No foundry access
Software48PyTorch + open inference; open-source contributions
Human capital812Top-venue publications; Sofia University pipeline
Regulatory48EU membership; rule-taker internationally
Total48100Upper end of Partially autonomous

4.4 Effect on a Bulgarian enterprise

For a Bulgarian company, BgGPT opens a genuine new choice. Two options for a typical firm in a regulated industry:

PillarScenario A: foreign API onlyScenario B: local BgGPT 27B
Data3 (residency risk)8 (data stays local)
Models0 (L0 — foreign API)11 (L2 — fine-tune capable)
Infrastructure3 (cloud dependent)6 (local inference feasible)
Software1 (API wrapper)4 (vLLM / llama.cpp expertise)
Other five pillars~10~10
Total~17~39

Moving from A to B adds about 22 points — from Fully dependent to Dependent-with-reserves, nearly Partially autonomous: the single biggest improvement available to a Bulgarian company without heavy spending on data centres or a large talent build.

4.5 Strategic implications

L2 is within reach for a small economy — continued pre-training plus instruction tuning matches commercial quality for tens of millions of euros, not hundreds. People are the multiplier — INSAIT’s results come from a core team of roughly 20–30, which is why Human capital carries 12 points. Resilience stays limited until the lower layers diversify — BgGPT fixes the Models pillar; NVIDIA and CUDA dependence underneath remains, so the Version Deadlock risk shifts down a layer, to hardware export controls, where it unfolds more slowly. The template transfers — a state-backed academic centre + continued pre-training on the strongest open base + public weights is directly transposable to Portugal, Greece, Finland, the Baltics, Hungary, and most states with 5–15 million speakers, and raises an AI-SAF-N score by 5–10 points for a modest outlay.

For the master glossary, see Document 1.