Sovereign AI

Who Owns the Word "Sovereign"? The Second Sovereignty Problem

The first sovereignty problem was a frontier model switched off worldwide by a decision made in another hemisphere. The second is quieter and closer to home: sovereign has become the most valuable word in Caribbean AI sales, and it costs a vendor nothing to say.

Adrian Dunkley /Aug 8, 2026 /12 min read
Abstract neural mesh held inside a glowing protective boundary, a visual metaphor for localised and sovereign AI kept under Caribbean control

Original artwork · maestro AI Labs · The label and the thing it describes

3 words
Sovereign, local, regionally hosted. None of them carries a testable definition in most Caribbean procurement today
1 rule
A single firewall rule settles the question a whole sales cycle has been arguing about
0 code
Nobody in the buying organisation needs to read a line of it to interpret the result
Adrian Dunkley · Founder & CEO, Maestro AI Lab / StarApple AI

Two years ago these products were sold to Caribbean institutions as AI-powered. Today the same products are sold as sovereign, because ministries and boards started asking where the data goes and the new word tested well in the room. The engineering stayed exactly where it was. In most of the procurements I have been asked to look at since, sovereign meant a locally built interface with every prompt travelling to a data centre in North America or Europe.

The first problem, briefly

The lab has already written the structural version of this argument in The Coming Shift to Localised LLMs. A capability the region had begun to lean on can be withdrawn by a decision nobody here participates in, and no service level agreement survives a government order. That piece makes the case for building the floor beneath your operations on infrastructure you control.

This piece is about what happened next, commercially. The moment sovereignty became a purchasing criterion, it became a sales word, and the region now has a market where the label and the thing it describes have come apart.

Three products, one word

Sovereignty over a capability means you can decide, on your own terms, whether it keeps running and who sees what passes through it. In a purchase decision that resolves into three conditions which have to hold together rather than separately. The party you contract with owns the model or licenses weights on terms it controls. Inference executes on hardware that party or you operate. And the location of that hardware is written into the agreement, because a regulator asking where customer data is processed is asking for a document rather than a reassurance.

Against that definition, three distinct products are sold under one heading.

PropertySovereign AISelf-hosted open weightsForeign model, local interface
Where inference runsVendor or buyer hardware, named regionYour own servers or tenancyProvider data centres abroad
Who holds the kill switchThe vendor, under your contractYouThe provider, and its regulator
Custody of the weightsVendor, transferable on exitYou, on diskProvider, not transferable
What the bill countsCompute or capacityHardware and operationsTokens or credits, with margin
What breaks itVendor defaultYour own operationsOutage, policy change, export control, repricing

The middle column is the one this region systematically under-buys, and the reason is commercial rather than technical. Open-weight families are downloadable, run on modest hardware once quantised, and settle the residency question by inspection, because the machine is somewhere a person can be walked to. Nobody has a sales team for that, because there is no recurring licence inside it.

Fine-tuning belongs in the third column, not the first. Fine-tuning a hosted foreign model on Caribbean data means the training corpus has crossed the same border, and the resulting weights sit with the provider. The separating question is whether you can take the fine-tuned artefact with you when the contract ends.

How to test the claim in an afternoon

Ask the vendor to run the product on a network where outbound traffic to the major foreign model providers is blocked at the firewall, or on your own equipment where you control what leaves the building. Give notice. Let them prepare, because this is a test rather than an ambush.

A model running on infrastructure you control keeps answering with the outside world cut off. A product that resells a foreign model returns an error or falls back to a canned response. That is the whole test. It costs one firewall rule and an afternoon, nobody in the organisation needs to read code to interpret the result, and no architecture diagram alters the outcome.

Before that, four written questions do most of the sorting, and they can go out by email to every AI vendor already under contract. Which model or model family does the service use, and under what licence are the weights used. Which operator, in which physical region, runs the inference, and will that appear in the contract. What is the current sub-processor list, and how much notice comes before it changes. And are prompts, outputs or uploaded documents retained by any third party, for how long, and may they be used for training or human review.

The sub-processor schedule is the strongest of the paper checks, because it is contractual rather than technical. A foundation-model provider listed there for inference has answered the question without any demonstration. No list at all, or a clause allowing substitution at the vendor's discretion without notice, has answered it a different way.

The checks that survive a prepared vendor

Ask a model what it is and a system prompt can instruct it to deny the answer. Inspect the network from the client and a backend call routes around you. Compare outage dates and a multi-provider failover design defeats the comparison. Two things stay expensive to fake: an egress-blocked demonstration, and a sub-processor schedule the vendor's own lawyers signed, where a misrepresentation is a contractual breach rather than a marketing exaggeration. If you only have appetite for two checks, take those.

What a wrong label costs a business

Four exposures follow, and they arrive on different clocks.

Residency you cannot evidence, which surfaces on the day a compliance officer is asked for a data flow diagram and the vendor cannot say where inference happens. Under Jamaica's Data Protection Act 2020, Barbados' Data Protection Act 2019 and the equivalent statutes across CARICOM, a prompt containing customer personal data becomes a regulated cross-border transfer the moment it is sent. Trinidad and Tobago's Data Protection Act 2011 remains largely unproclaimed, which produces the mirror-image problem: thinner statutory recourse, and therefore heavier reliance on contract terms most buyers never ask for.

Continuity you do not hold, because the product inherits every decision made upstream, from a deprecated model version to a regional access restriction to an export control order, and the vendor's service agreement will accurately describe the resulting outage as outside its control. Costs you cannot negotiate, because a vendor with no cushion upstream has nothing to argue with when the price moves. And a governance record that says something the organisation cannot support if anyone asks.

None of that makes a foreign-model product a bad purchase. For drafting, translation, summarising public documents and marketing work, renting a frontier model through a capable local integrator is frequently the right call, and the integrator earns its margin in workflow, support and accountability. The damage comes from approving that product in a board paper that describes it as something else.

What it costs a household

The same vocabulary has reached consumer apps: local AI, private AI, runs on your device. Three habits cover most of it.

Read the privacy policy for named third parties rather than reassuring adjectives, because a policy promising encryption while naming no processors has told you nothing about who reads what you type. If an app says it runs on your phone, switch off mobile data and wi-fi and ask it a question, which takes ten seconds and settles it. And keep national identification numbers, medical detail and banking credentials out of free assistants, on the working assumption that what you type may be retained and may be reviewed by a person.

For anything involving money, treat proprietary AI and sovereign AI in an investment pitch as a warning rather than a credential. Securities regulators across the region have been issuing public alerts about schemes using AI-generated video of recognisable public figures to sell fraudulent products, and the technology vocabulary in those pitches is doing the same work that offshore and hedge fund did in an earlier generation of the same fraud. That is the part of this that stops being a procurement question and becomes a consumer protection one, and it is the reason the word needs a definition anyone can check rather than a definition only engineers can argue about.

Where this argument is weak

Publishing a test degrades it. Any vendor reading this page can now prepare answers to the paper questions and write a system prompt that survives being interrogated. The trade is still worth making, because the buyers who need this have no framework at all today while the vendors who would game it were already ahead of them, and because the two checks that matter cost money to fake rather than effort.

The larger weakness is that everything above treats sovereignty as a property of one vendor relationship, when the real exposure is almost always accumulation. A business with a properly assessed core system, an unlogged transcription tool that joins meetings, a browser extension two people installed, and a chatbot from a fourth supplier has one good contract and an unmapped surface. In the organisations the lab has worked with across the region this year, a complete inventory of AI systems in use has generally not existed before we sat down and built one, and the length of the finished list has been the first surprise rather than the last finding. The vendor test is necessary. The inventory is what actually protects you, and it should probably come first.

There is also a case the lab loses honestly. For a small team with no infrastructure staff and no on-call rota, self-hosting is worse engineering than a well-chosen wrapper, and arguing otherwise would be selling rather than advising. The right answer there is a wrapper with an accurate description, a sub-processor schedule on file, and a written manual fallback for anything the business cannot run by hand.

What to do on Monday

List every AI product in use across the organisation, including the ones nobody procured, and put a named owner against each. Send the four written questions to every vendor on that list, on the same day. Reserve the egress-blocked demonstration for the systems that touch customer or regulated data, because it takes real effort from both sides and should be spent where the answer changes a decision. And for anything embedded in a process you cannot run by hand, write the fallback down now and name the person who invokes it.

Every check in this article can be run against the lab's own deployments. Clients do run them, and that is the correct relationship to have with any vendor making a claim of this kind, this one included.

Frequently asked

An AI system where the party you contract with controls the model and the hardware performing inference, and can name and evidence the jurisdiction where that inference happens. Three conditions have to hold together: the vendor owns the model or licenses weights on terms it controls, inference runs on infrastructure the vendor or the buyer operates, and the location appears in the contract rather than in a sales meeting. A product satisfying two of the three is a different category with a better story.
An egress-blocked demonstration. Run the product on a network where outbound access to the major foreign model providers is blocked at the firewall, or on your own equipment where you control what leaves the building. A model running locally keeps answering. A product reselling a foreign model returns an error or a canned fallback. One firewall rule, one afternoon, no code to read.
No. For drafting, translation, summarising public documents and marketing work, renting a frontier model through a capable local integrator is frequently the best purchase available, and the integrator earns its margin in workflow, support and accountability. The failure is the description, because a board approving a rebranded product in the belief that it is sovereign has accepted a residency, continuity and pricing profile nobody assessed.
No. Fine-tuning a hosted model means the training corpus has also crossed the border, and the resulting weights sit on the provider's infrastructure under the provider's terms, so residency, continuity and pricing exposure are unchanged. Fine-tuning open weights you can download and re-host is a different arrangement, and the separating question is whether you can take the fine-tuned artefact with you when the contract ends.
Because it determines whose law applies to whatever is in the prompt. A prompt containing customer records, board papers or medical history becomes a cross-border transfer the moment it is sent, and the retention terms, disclosure obligations and enforcement powers of the receiving jurisdiction attach to it. Data protection statutes across CARICOM treat that transfer as a regulated act requiring a lawful basis and documentation.
Read the privacy policy for named third parties rather than reassuring adjectives. If the app claims to run on your device, switch off mobile data and wi-fi and see whether it still answers. Keep identification numbers, medical detail and banking credentials out of free assistants. And treat sovereign or proprietary AI in an investment pitch as a warning sign, because securities regulators across the region have been issuing alerts about schemes built on that exact language.
Localised AI infrastructure for Caribbean and Latin American founders, businesses and regulated entities: open-weight model deployment on infrastructure the client or the lab operates, retrieval over regional corpora, in-region evaluation and safety testing, and hybrid architectures where a frontier model is reserved for the rare hard task with the escalation logged. Every check in this article can be run against those deployments.
I am not asking anyone to stop buying foreign models. I use them, and the lab builds systems that call them. I am asking buyers to know which of the three things they bought, because the version of this that ends badly is not a bad product. It is an institution that told its regulator the data stays here, in good faith, because that is what the brochure said. Adrian Dunkley · Founder & CEO, Maestro AI Lab / StarApple AI

Related reading: the structural case for building the floor locally sits in The Coming Shift to Localised LLMs: Sovereignty After Fable 5. The risk-register version of this diagnostic, mapped to ISO/IEC 42001:2023 and the NIST AI Risk Management Framework, is published by the Caribbean AI Risk Management Council.

Get notified when we publish

New posts and research from the maestro team, straight to your inbox.