Five levels of control your AI can run at.
Every AI system sits somewhere between rented and owned. The Sovereignty Ladder is how we name that scale: five rungs from Exposed to Owned. The first thing a Sprint tells you is which rung you stand on today. Every stage after that is about moving you up.
The five rungs
-
01
Exposed
Models and data run in a third-party cloud under foreign jurisdiction. You rent the capability; the provider holds the keys, the logs, and the off-switch.
-
02
Constrained
The same external platform, now with EU-region hosting and a data-processing agreement. Better paperwork, but the same underlying dependency.
-
03
Contained
Workloads move into your private cloud with open-weight models. Your data stays inside your perimeter, though some tooling and operations still lean on outside services.
-
04
Operated
The whole stack runs on infrastructure you control, on-prem or in a sovereign cloud, with open weights and full source. We operate it alongside your team, day to day.
-
05
Owned
Your team runs the system end to end: your hardware, your weights, your code, and the skills to keep it running without us. Full sovereignty, and the point of every engagement.
Our four engagement stages are simply the path up this ladder: from an honest read of where you stand to a system your own team owns and operates.
| Rung | Where models run | Who holds the weights | Cost to leave |
|---|---|---|---|
| 1 · Exposed | A third-party cloud under foreign jurisdiction | The provider | Total. A rebuild |
| 2 · Constrained | The same platform, EU region, with a processing agreement | The provider | High. Months of rework |
| 3 · Contained | Your private cloud, open-weight models | You, though some tooling still calls out | Moderate. Integration work |
| 4 · Operated | Infrastructure you control, on-prem or sovereign cloud | You | Low. Every layer is portable |
| 5 · Owned | Your hardware, run by your own team | You | None. You already run it |
Running it yourself,
against renting it.
Most of the ladder comes down to one decision, made once and lived with for years. Both columns are legitimate. They fail in different ways, and the failure modes are what decide it.
| Rented cloud API | Inference you operate | |
|---|---|---|
| Where the data sits | On the provider's infrastructure, under their terms | Inside your perimeter |
| Jurisdiction | Follows the provider's ownership, not the data centre's address | Follows your own establishment |
| Cost shape | Per seat or per token, recurring, rises with use and headcount | Capital up front, then largely flat |
| Latency | A network round trip, and whatever the provider is doing that day | Local, and yours to measure |
| Works offline | No | Yes, and can be air-gapped |
| Audit trail | Whatever the provider exposes | Whatever you choose to record |
| Model changes | The provider's schedule. Behaviour can shift under you | Yours. A model version stays put until you move it |
| Cost to leave | Rises the longer you stay | Paid at the start, not at the exit |
| Who operates it | Them, which is the point of it | You, which is the cost of it |
The honest summary: renting is faster to start and cheaper to try; operating is cheaper to keep and far harder to have taken away from you.
The duty is
sector by sector.
Sovereignty is not one rule. For most Swedish organisations a specific, numbered obligation decides what an AI system has to record, and it is usually the logging duty that disqualifies a tool rather than the model itself.
| Sector | The rule that binds | What it means in practice |
|---|---|---|
| Healthcare | Patientdatalagen (2008:355); HSLF-FS 2016:40; GDPR Art 9 | Systematic log follow-up is a legal duty. Per-user access logs you can read back, not just a chat history |
| Law | Advokatsekretess, RB 8:4, sanctioned via BrB 20:3 | Client confidentiality is criminally protected. Client material must not leave a controlled environment |
| Accounting and audit | FAR and Reko, EtikU 2 tystnadsplikt | Professional secrecy over client records, with retention you can evidence |
| Public sector | OSL (2009:400); LOU | Secrecy assessment before anything moves, and a procurement route you can defend |
| Finance and insurance | DORA, in force 17 January 2025 | Third-party ICT risk is documented and reportable. Your supplier becomes your exposure |
| Manufacturing | NIS2 where in scope; trade-secret protection otherwise | No sector rule forces sovereignty. Protecting the IP usually does |
| Any personal data | GDPR Art 32 | Access control you can evidence, and a deletion path that genuinely deletes |
Nothing here is legal advice. If a row describes you, the useful next step is reading the rule with someone who knows your operation, not buying anything.
What people ask
before they move.
Does an EU region make a US provider safe?
No. The US CLOUD Act reaches US-headquartered providers regardless of where the data is stored, including their EU regions. Microsoft publicly conceded in 2025 that it cannot guarantee data sovereignty for EU customers. Ownership of the company decides jurisdiction, not the address of the building.
What is the Sovereignty Ladder?
The Sovereignty Ladder is a five-rung model for how much control an organisation actually has over its AI systems, running from Exposed, where a provider holds the keys and the off-switch, to Owned, where your own team runs the system end to end. It exists to turn a vague worry into a position you can name and act on.
Is on-premises inference actually preferred by regulators?
The European Data Protection Board's April 2025 guidance named on-premises inference the strongest available mitigation for large language model data protection. That is a regulator describing an architecture, which is unusual and worth reading directly rather than taking from us.
Do open-weight models mean giving up quality?
Less than most people expect, and the gap keeps narrowing, but the honest answer depends on the task. Document questions, drafting and summarisation are well served. Frontier reasoning and the newest multimodal work are not. The right test is your own documents, measured, before anyone commits.
Which rung should we be on?
Whichever one your material requires, and no higher. Climbing costs money and effort, and rung 5 is not a goal for an organisation whose data does not need it. Most industrial estates we assess start on rung 1 or 2, which is a normal starting point rather than a failure.
How long does it take to move up a rung?
We cannot answer that honestly without seeing the estate, which is what the two-week ML Feasibility Sprint is for. What we can say is that the constraint is almost never the model. It is data access, integration, and who will operate the thing on an ordinary Tuesday.
Find out which rung you stand on.
Start with the two-minute self-check for an estimate. When you want an audited answer, the two-week ML Feasibility Sprint includes a sovereignty assessment of your current stack.