Assessment of national AI sovereignty. Version 0.7.1 · August 2026 · CC BY 4.0
About this document
This field guide is the hands-on manual for AI-SAF-N, the national version of the AI Strategic Autonomy Framework, for a government body, ministry, or regional bloc measuring its AI sovereignty and building strategy from the result. For the concepts — the two variants, capability × commitment, gap analysis, Version Deadlock — see Document 1. Dated market detail lives in Document 4, State of Play.
How each pillar is presented. Each pillar opens with what it measures and why, then a rubric: sub-indicator, points, R/A tag, evidence expected. Whole-number scores; the pillar score is the sum; report R and A subtotals with the headline.
Contents: Part I — the eight pillars. Part II — the four modifiers and their fixed order of application. Part III — worked examples: Bulgaria, France, UAE. Part IV — case study: INSAIT and BgGPT.
Part I. The eight pillars
| # | Pillar | Weight | National focus |
|---|---|---|---|
| 1 | Data | 10 | National corpus, residency, legal regime, public-sector egress |
| 2 | Models | 16 | The L0–L4 ladder; reasoning bonus |
| 3 | Infrastructure and energy | 17 | Sovereign cloud, local and pooled compute, grid |
| 4 | Hardware architecture | 17 | Export tier, indigenous design, supplier spread |
| 5 | Manufacturing | 12 | Fabs, advanced packaging, critical minerals |
| 6 | Software stack | 8 | CUDA dependence, framework diversity, FOSS contribution |
| 7 | Human capital | 12 | Top-venue researchers, retention, pipeline |
| 8 | Regulatory (participation) | 8 | Rule-making seats, own binding law, institutions, summits |
| Total | 100 |
For languages with less material online, data limits sovereignty more than models do: open-weights models are now cheap and common, while a genuine national corpus is not. Combined totals across the big open collections (CulturaX, HPLT v2, FineWeb-2, deduplicated) sort languages into tiers: Low (5–40B tokens — Bulgarian, Estonian, Welsh: not enough to train mid-sized models from scratch; continued pre-training is forced), Medium (40–250B — Polish, Greek, Vietnamese, Hebrew), High (250B–1.5T — German, French, Arabic: from-scratch training feasible). On the legal side, the EU regime (GDPR + Data Act, with Chapter VII targeting third-country access + AI Act) is the world’s strictest; India’s DPDP rules are gentler; China’s PIPL is strictest on government data.
Public-sector data egress complements residency: whether sensitive government and critical-sector data is sent to foreign-controlled models at all, and whether a sovereign-inference option (certified sovereign cloud plus a domestic or open model) exists and is mandated.
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| Corpus authenticity | 4 | A | Volume and cleanliness of local text; share real rather than AI-generated |
| Residency and legal regime | 3 | R | Where data sits; governing law; CLOUD Act exposure |
| Instruction and evaluation data | 1 | A | Coverage in INCLUDE / Global-MMLU; local instruction data |
| Public-sector and proprietary-data egress | 2 | R | 0 = no rule; 1 = binding procurement bar on sensitive data to foreign models; 2 = sovereign-inference option mandated for sensitive workloads |
Pillar 2. Models — 16 points
The pillar that separates countries most. The five-level ladder (anchors L0–L4 = 0/4/11/13/16):
| Level | Points | National example, 2026 | Note |
|---|---|---|---|
| L0 | 0 | Governments on foreign frontier APIs | CLOUD Act and directive exposure |
| L1 | 4 | Open-weights models run on-prem, unadapted | Control of the hardware, nothing more |
| L2 | 11 | BgGPT (Gemma 3 → Bulgarian); Meltemi; Sarvam-M; TAIDE | Adapt or keep training someone else’s base model |
| L3 | 13 | EuroLLM; Teuken; Poro; Aya-Expanse; EXAONE | Own model and tokeniser, on foreign compute |
| L4 | 16 | Fugaku-LLM; Falcon/Jais (UAE); DeepSeek/Qwen on Ascend | Fully independent, top to bottom |
Scoring rule: the ladder anchors the level; the pillar score is the assessor’s raw fraction × 16, with the anchor as the reference point. Worked examples show both (e.g. “L2 anchor 11; raw 0.55 after portfolio-depth deductions”). The jump from L2 to L3 turns on owning the tokeniser — the part that splits language into pieces — which removes a built-in bias toward foreign languages that is even harder to fix than the model itself.
Reasoning bonus: a country that has released a reasoning model in its own national language earns +2 within the pillar, capped at 16. Currently: China, South Korea, India, UAE.
Spending thresholds: DeepSeek-V3’s reported ~$5.6M in rented compute sets the floor for replicating a top model; roughly $500M/year is the bar for matching a full national ecosystem.
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| Ladder level (anchored) | 12 | A | Highest level achieved, evidenced by shipped models in use |
| Portfolio depth and open fallback | 4 | R | More than one usable model; self-hosted deployment in government |
Pillar 3. Infrastructure and energy — 17 points
Every major sovereignty incident of 2024–2026 ran through this pillar. The scoring anchors for sovereign cloud, in descending order of protection: SecNumCloud 3.2 (immune from foreign-reach law — the established top bar); the CADA Cloud Sovereignty Framework levels once finalised (the proposed EU-wide four-level ladder — track the trilogue; see Framework Part V); GAIA-X Level 3; EU-operated subsidiaries of foreign providers (BSI C5 tier — the AWS European Sovereign Cloud sits here: EU-run, still US-owned). Do not score against EUCS: its sovereignty tier was removed in March 2024 and never returned; CADA is where that debate moved.
Local compute credits AI-accelerator capacity on the subject’s own territory at full rate, plus up to 2 of its 4 points for enforceable pooled EU capacity — a signed EuroHPC AI Factory or Gigafactory hosting or consortium agreement conferring allocation rights the subject can invoke. The Gigafactories call opened on 30 July 2026 (seven sites, €10B public funding, awards early 2027): a signed award will qualify; a bid does not. Mere programme membership scores 0. Pooled capacity is labelled a bottleneck, never a structural asset.
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| Sovereign cloud / cloud choice | 5 | R | Certification against the anchors above; European jurisdiction |
| Local compute | 4 | R | Own-territory accelerator capacity; enforceable pooled allocation (≤2) |
| Network independence | 2 | R | Several providers plus own interconnects |
| Energy mix and price | 3 | R | Diversified sources; competitive price; grid headroom |
| Cryptographic control + TEE | 3 | R | HSMs, key management, attested confidential computing |
Pillar 4. Hardware architecture — 17 points
The fastest-changing pillar: US export rules went through seven major turns between 2022 and 2026, and the 2026 watchword is deal-by-deal diplomacy — bans became revenue-share deals became case-by-case licences. Vendor and alternative-chip detail: Document 4.
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| CPU ISA diversification | 5 | R | Mix of x86 / ARM / RISC-V; home-grown designs (SiPearl, DARE) |
| AI accelerators — access | 7 | R | Export tier; reserved capacity; supplier spread |
| AI accelerators — indigenous design | 5 | A | Realistic only at EU scale; Rhea-, EXAONE-, or TPU-class effort |
Pillar 5. Manufacturing — 12 points
The most lopsided pillar: only Taiwan, South Korea, the US, and (to a limited degree) China can make advanced chips in volume; for everyone else this is the dependency that cannot be reduced, only diversified. Current fab, packaging, and HBM state of play: Document 4. Critical minerals are scored inside this pillar (2 points): the share of gallium, germanium, heavy rare earths, high-purity silicon, and refined copper a country (or its allies) can refine at home. Ore in the ground does not count — refining is the chokepoint, as China’s 2024–2026 export-control campaign demonstrates.
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| Supplier diversification | 4 | R | Access to at least two foundry partners |
| Local advanced packaging | 3 | R | Chiplet assembly, test, packaging at national or EU level |
| Own foundry capacity | 3 | A | A real fab under own control |
| Critical minerals | 2 | R | Domestic/allied refining share of Ga, Ge, rare earths, Si, Cu |
Pillar 6. Software stack — 8 points
CUDA still dominates but its grip is loosening; multi-party-governed open source (the PyTorch Foundation model) is much harder for any one company to weaponise than single-vendor software — a modest structural plus for the EU. Runtime and framework state of play: Document 4.
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| CUDA exposure | 2 | R | Share of national AI workloads that run only on CUDA |
| Training-framework diversification | 2 | R | PyTorch, JAX, and alternatives in real use |
| Inference-runtime diversification | 2 | R | vLLM / SGLang / llama.cpp deployed |
| MLOps lock-in | 1 | R | Vendor-agnostic deployment patterns |
| Open-source contribution | 1 | A | Upstream contributions from national institutions |
Pillar 7. Human capital — 12 points
The ultimate bottleneck. Reference sources: the MacroPolo Global AI Talent Tracker 2.0 (March 2024, NeurIPS 2022 data — note the correct edition is 2.0) for talent flows; the Stanford AI Index for the annual picture; CSRankings and top-venue author counts for national standing. Headline 2026 context — US ~75% of global GPU compute, 50 notable US models vs 30 Chinese in 2025, Switzerland and Singapore leading per-capita researcher density — is kept in Document 4 with the other dated figures.
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| AI researchers / top-tier | 4 | A | Top-venue papers; CSRankings standing; talent based at home |
| ML engineers and operators | 3 | A | Production experience; qualified workforce size |
| Education pipeline | 2 | A | Strong programs and intake volumes |
| Retention against brain drain | 2 | R | Pay competitiveness; career paths; track record |
| AI literacy in the population | 1 | A | Formal training reach; basic digital skills |
Pillar 8. Regulatory (participation) — 8 points
In the national variant this pillar measures the power to make the rules — the mirror image of the corporate variant (Framework §1.2). Reference instruments as of August 2026: the EU AI Act (GPAI obligations enforceable since 2 August 2026; high-risk obligations deferred by the Digital Omnibus to December 2027 / August 2028); the Council of Europe Framework Convention on AI (in force 1 November 2025 — the first binding international AI treaty); the summit series (Paris, February 2025; New Delhi, February 2026, whose Declaration was endorsed by 92 countries and organisations); and the sandbox obligation (at least one AI regulatory sandbox per member state).
| Sub-indicator | Points | R/A | Evidence expected |
|---|---|---|---|
| Rule-making seats | 3 | A | Seats in bodies writing binding rules |
| Own binding AI law | 2 | A | Applying the AI Act plus national implementing law |
| Institutional presence | 2 | A | An AI safety/security institute; Council of Europe participation |
| Summit hosting + bilateral frameworks | 1 | A | Hosting summits; bilateral AI agreements |
Part II. Nation-specific modifiers
Four adjustments applied after the pillar scores, reflecting how unstable the rule environment has become. Apply them in this order, always, and all of them: (1) rule-stability, (2) geopolitical-alliance, (3) operating-model. (Critical-minerals is scored inside Manufacturing and needs no separate step.) Worked examples must show each step explicitly; no other adjustments — bonuses, penalties, or otherwise — are permitted outside these four. If a strength seems to deserve extra credit (abundant energy, rule-making influence), it belongs inside the relevant pillar’s sub-indicators, where it is already counted.
2.1 Rule-stability modifier (×, on Hardware and Models)
The defining feature of 2025–2026 is one-off deals and reversible directives — exports banned, then taxed, then licensed; a frontier model suspended, then restored within a month. The modifier prices exposure to that volatility.
| Exposure | Multiplier | Example |
|---|---|---|
| None — compute home-grown | 1.00 | China (partly); countries with own large providers |
| Low — deliberately multi-supplier | 0.95 | European countries spreading purchases |
| Moderate — mostly US-supplied | 0.90 | Most EU states today |
| High — case-by-case US permission | 0.85 | UAE; countries with no alternatives |
2.2 Geopolitical-alliance multiplier (×, on Hardware, Models, Infrastructure)
The closest US allies get better chip access. That access is not a built strength, so it multiplies rather than adds. Note the tension: Tier-1 alignment raises this multiplier and typically raises rule-stability exposure — the two must both be applied, which is why the order is fixed.
| Position | Multiplier | Examples |
|---|---|---|
| Tier-1 US ally | 1.10–1.15 | Japan, UK, Canada, Australia, South Korea, Netherlands, Taiwan, Singapore, France, Germany |
| Special partnership | 1.05–1.10 | UAE (US–UAE AI Acceleration Partnership) |
| Neutral | 1.00 | Bulgaria, India, most developing nations |
| Restricted access | 0.90–0.95 | Below-tier under export rules |
| Sanctioned | 0.70–0.80 | Iran, Russia, (partially) China |
2.3 Critical-minerals modifier
Scored inside Manufacturing (2 of 12): domestic or allied refining capacity for gallium, germanium, heavy rare earths, high-purity silicon, and refined copper. China’s export-control campaign — gallium/germanium (December 2024), rare earths (October 2025, paused November 2025 for 12 months, with active enforcement through 2026) — shows the risk is present, not theoretical.
2.4 Operating-model modifier (integer, −2 to +2, on the headline)
How a government organises itself to build and keep its own AI capability — durability across political change, legitimacy, exit costs, reproducibility, decision clarity. Four common forms: a public research institute (Bulgaria’s INSAIT), a state-owned company (several Chinese labs), a private national champion (France’s Mistral), a consortium (EuroHPC AI Factories). No form is favoured; any can earn +2 or −2. The modifier does take one side: a real, coherent setup of your own beats renting everything from foreign providers — disagreeing with that is disagreeing with AI-SAF as a whole.
Scoring: −2 no real setup, or paper-only. −1 a setup exists but under-funded, badly run, or unclear. 0 solid, funded, documented, producing results used at home; sovereignty as by-product. +1 all that, with sovereignty built in on purpose (openness, clear decision-making, reproducibility) but untested through a major upheaval. +2 proven through at least one real test — change of government, funding gap, major shock.
Calibration: Bulgaria/INSAIT +1 (coherent, resourced, explicitly open; untested through political discontinuity). France/Mistral +1 (commercial discipline plus state alignment; also untested). A small state renting everything through foreign hyperscalers: −1 or −2.
Part III. Worked examples
All three examples follow the same sequence: pillar table → rule-stability → alliance → operating-model → final. These are the author’s estimates from public information, shown to demonstrate the method.
3.1 Bulgaria — ~46
Bulgaria punches above its weight: a small economy (~$100B) whose INSAIT institute built far more national capability than size suggests, by continuing to train Google’s Gemma models into BgGPT and putting the result into government use (7,000+ staff at the National Revenue Agency).
| Pillar | Weight | Raw | Score | Note |
|---|---|---|---|---|
| Data | 10 | 0.70 | 7.0 | >100B Bulgarian tokens; NRA integration; planned BRAIN++ data lake |
| Models | 16 | 0.55 | 8.8 | BgGPT 3.0 on Gemma 3 = L2 (anchor 11); raw 0.55 after portfolio-depth deductions |
| Infrastructure | 17 | 0.55 | 9.4 | BRAIN++ AI Factory €90M + Discoverer+ (domestic); no SecNumCloud equivalent |
| Hardware | 17 | 0.25 | 4.3 | No indigenous design; NVIDIA via TSMC |
| Manufacturing | 12 | 0.05 | 0.6 | No fabs, packaging, or refining |
| Software | 8 | 0.45 | 3.6 | Strong open-source culture; COMPL-AI toolkit |
| Human capital | 12 | 0.65 | 7.8 | INSAIT at CSRankings #14 Europe, #1 Eastern Europe |
| Regulatory | 8 | 0.55 | 4.4 | AI Act applies automatically; limited rule-making weight |
| Pillar total | 100 | ~45.9 |
3.2 France — ~70
Europe’s clearest example of sovereign AI: Mistral (valued €11.7B after the ASML-led round), SecNumCloud with qualified providers including S3NS, SiPearl building a home-grown CPU, €109B announced at the 2025 summit, and an active hand in writing the EU’s rules.
| Pillar | Weight | Raw | Score | Note |
|---|---|---|---|---|
| Data | 10 | 0.70 | 7.0 | Strong public data; excellent French corpus |
| Models | 16 | 0.85 | 13.6 | Mistral Large/Medium/Le Chat; Europe’s only top-10 global firm |
| Infrastructure | 17 | 0.80 | 13.6 | UAE-MGX campus + Mistral Essonne + SecNumCloud + Alice Recoque exascale |
| Hardware | 17 | 0.50 | 8.5 | SiPearl Rhea1 sampling; still TSMC/ARM underneath |
| Manufacturing | 12 | 0.15 | 1.8 | No leading edge; STMicro mature nodes; Soitec wafers |
| Software | 8 | 0.55 | 4.4 | Strong FOSS; orchestration US-dominated |
| Human capital | 12 | 0.85 | 10.2 | Polytechnique, ENS, Inria, CNRS; returnee pipeline at Mistral |
| Regulatory | 8 | 0.90 | 7.2 | Summit host; AI Act leadership; SecNumCloud as exported standard |
| Pillar total | 100 | ~66.3 |
3.3 UAE — ~57
The most interesting case outside the US and China: cheap energy, deep state funds, and political flexibility, channelled through G42 into genuinely cutting-edge infrastructure.
| Pillar | Weight | Raw | Score | Note |
|---|---|---|---|---|
| Data | 10 | 0.50 | 5.0 | Arabic via MBZUAI; weak open-data regime |
| Models | 16 | 0.70 | 11.2 | Falcon open-source series; Jais; +2 reasoning bonus included |
| Infrastructure | 17 | 0.85 | 14.5 | Stargate-UAE 1 GW (first 200 MW 2026); 5 GW campus; Khazna; energy strength (Barakah + solar) is inside this raw score |
| Hardware | 17 | 0.45 | 7.7 | ~35,000 GB300 via G42; access is political, not owned |
| Manufacturing | 12 | 0.15 | 1.8 | No advanced node |
| Software | 8 | 0.40 | 3.2 | Azure and Oracle dependency |
| Human capital | 12 | 0.60 | 7.2 | MBZUAI operational; imported talent; small citizen base |
| Regulatory | 8 | 0.75 | 6.0 | US–UAE AI Acceleration Partnership; assurance agreement |
| Pillar total | 100 | ~56.6 |
Part IV. Case study: INSAIT and BgGPT
BgGPT is the clearest real-world example of L2 on the Models ladder — how a small economy gains real control over its models without the cost of training from scratch.
4.1 BgGPT in brief
INSAIT (Sofia, part of Sofia University) builds BgGPT, a family of Bulgarian-language models: v0.1/0.2 on Mistral-7B (March 2024); BgGPT 1.0 on Gemma 2 (November 2024); BgGPT 3.0 on Gemma 3 in 4B/12B/27B sizes (March 2026) — multimodal, ~131k context, trained on >100B Bulgarian tokens plus balanced English. Its Branch-and-Merge method (EMNLP 2024) prevents catastrophic forgetting while adding a language. On Bulgarian tasks the 27B model holds its own against models three times its size and, for Bulgarian chat, against leading commercial models on INSAIT’s benchmarks. Distributed in full precision, GPTQ W4A16, and GGUF (runnable locally via llama.cpp). First large institutional user: the National Revenue Agency, 7,000+ staff.
4.2 Why BgGPT is exactly L2
| Level | Anchor | Why BgGPT is / is not at this level |
|---|---|---|
| L0 | 0 | BgGPT runs on own machines with open weights — no outside provider |
| L1 | 4 | More than a local copy: further trained on >100B Bulgarian tokens |
| L2 | 11 | Exactly this: heavy continued pre-training + instruction tuning on Gemma 3 weights, via Branch-and-Merge |
| L3 | 13 | Architecture and tokeniser are Gemma 3’s — no structural modifications |
| L4 | 16 | Starting weights come from Google; no from-scratch training |
4.3 AI-SAF-N profile for INSAIT / BgGPT
Scored as an institutional profile (the institute, not the country — Bulgaria’s national profile in Part III applies portfolio-depth deductions this focused profile does not):
| Pillar | Score | Max | Rationale |
|---|---|---|---|
| Data | 7 | 10 | >100B curated Bulgarian tokens; instruction data |
| Models | 11 | 16 | L2 anchor (fine-tune/CPT on Gemma 3); Branch-and-Merge |
| Infrastructure | 9 | 17 | H100 compute via partnerships; limited own capacity |
| Hardware | 4 | 17 | Full NVIDIA/CUDA dependency |
| Manufacturing | 1 | 12 | No foundry access |
| Software | 4 | 8 | PyTorch + open inference; open-source contributions |
| Human capital | 8 | 12 | Top-venue publications; Sofia University pipeline |
| Regulatory | 4 | 8 | EU membership; rule-taker internationally |
| Total | 48 | 100 | Upper end of Partially autonomous |
4.4 Effect on a Bulgarian enterprise
For a Bulgarian company, BgGPT opens a genuine new choice. Two options for a typical firm in a regulated industry:
| Pillar | Scenario A: foreign API only | Scenario B: local BgGPT 27B |
|---|---|---|
| Data | 3 (residency risk) | 8 (data stays local) |
| Models | 0 (L0 — foreign API) | 11 (L2 — fine-tune capable) |
| Infrastructure | 3 (cloud dependent) | 6 (local inference feasible) |
| Software | 1 (API wrapper) | 4 (vLLM / llama.cpp expertise) |
| Other five pillars | ~10 | ~10 |
| Total | ~17 | ~39 |
Moving from A to B adds about 22 points — from Fully dependent to Dependent-with-reserves, nearly Partially autonomous: the single biggest improvement available to a Bulgarian company without heavy spending on data centres or a large talent build.
4.5 Strategic implications
L2 is within reach for a small economy — continued pre-training plus instruction tuning matches commercial quality for tens of millions of euros, not hundreds. People are the multiplier — INSAIT’s results come from a core team of roughly 20–30, which is why Human capital carries 12 points. Resilience stays limited until the lower layers diversify — BgGPT fixes the Models pillar; NVIDIA and CUDA dependence underneath remains, so the Version Deadlock risk shifts down a layer, to hardware export controls, where it unfolds more slowly. The template transfers — a state-backed academic centre + continued pre-training on the strongest open base + public weights is directly transposable to Portugal, Greece, Finland, the Baltics, Hungary, and most states with 5–15 million speakers, and raises an AI-SAF-N score by 5–10 points for a modest outlay.
For the master glossary, see Document 1.