[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:zh":3,"public-menus:all":38,"post:sovereign-ai-control-of-models-data-infrastructure-and-dependencies:zh":205,"related:post:sovereign-ai-control-of-models-data-infrastructure-and-dependencies:zh:1":3925},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","zh","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":3924},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1777,"featuredImage":1778,"featuredImageAlt":1779,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1780,"publishedAt":1781,"createdAt":1782,"updatedAt":1783,"seoLocalePaths":1784,"categories":1793,"author":1810,"translations":1815},"495","主权人工智能：模型、数据、基础设施与依赖关系的控制","sovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u003Cp>主权人工智能是指一个国家、公共机构、组织或其他明确权威机构对其所依赖的人工智能系统保持有效控制的能力：包括其数据、模型、基础设施、软件栈、运营者、法律风险敞口和战略依赖。主权并不等同于将数据托管在一个国家、运行一个开放模型、使用欧盟云服务提供商或将服务器与互联网断开连接。这些做法可以支持主权，但决定性的问题是：该组织能否在不对某个外部行为者产生不可接受的依赖的情况下，做出、执行并维持关键的人工智能决策。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--info my-6 rounded-xl border p-5 border-blue-300 bg-blue-50 dark:border-blue-900 dark:bg-blue-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">直接回答\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">一个实用的主权人工智能架构所控制的远不止模型的位置。它要问的是：\u003Cbr>\u003Cbr>\u003Cstrong>谁控制数据？谁控制模型？谁控制算力？谁控制软件栈？谁持有密钥？适用哪国法律和公司控制？哪个供应商能够禁用、更改系统或调整定价？如果该供应商变得不可接受，工作负载能否迁移？\u003C\u002Fstrong>\u003Cbr>\u003Cbr>因此，主权存在于一条依赖链之中，而不是一个简单的“是\u002F否”属性。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">该术语并非一个通用的技术标准\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">“主权人工智能”被政府、供应商和业界使用，其含义相互重叠但并不完全相同。欧盟委员会目前将更广泛的\u003Cstrong>技术主权\u003C\u002Fstrong>定义为：通过开发和掌控关键技术、数据和基础设施，同时减少对非欧盟供应商的依赖，从而独立行动的能力。NVIDIA 的供应商框架则强调本地数据、模型、基础设施和框架。本文采用对这些控制维度进行明确的架构性综合，而不是将某一家供应商的定义作为通用标准来呈现。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">主权并不要求技术自给自足\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">目标未必是消除每一个外国组件。当前欧盟政策明确将更强的自主性与对合作伙伴保持开放的市场结合起来。主权架构减少的是\u003Cstrong>战略依赖\u003C\u002Fstrong>：那些可能消除有效选择、将关键数据\u002F控制暴露于不受欢迎的司法管辖之下，或使系统在没有某个外部供应商的情况下无法持续运行的依赖。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">当前来源说明——2026年10月8日\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">2026年6月3日，欧盟委员会通过了其技术主权一揽子计划，并提出了《云与人工智能发展法案》（CADA）。委员会当前的 CADA 框架描述了四个云\u002F人工智能主权保证级别，从欧盟数据位置，到独立于第三国和软件供应链透明度，再到欧盟所有权\u002F控制，以及在最高级别上，无第三国干预的完整供应链控制。这有力地证明，主权比数据驻留更为广泛。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cnav class=\"editorjs-toc\" data-editorjs-toc=\"true\" aria-label=\"目录\">\u003Cstrong class=\"editorjs-toc__title\">目录\u003C\u002Fstrong>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-0\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-7\" class=\"editorjs-toc__link\">主权人工智能的真正含义\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-11\" class=\"editorjs-toc__link\">最简单的例子\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-17\" class=\"editorjs-toc__link\">简单例子止步之处\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-21\" class=\"editorjs-toc__link\">当前欧洲技术主权框架\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-25\" class=\"editorjs-toc__link\">CADA将主权变为分级保证问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-30\" class=\"editorjs-toc__link\">主权AI的主要控制维度\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-32\" class=\"editorjs-toc__link\">数据主权必要但不充分\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-36\" class=\"editorjs-toc__link\">模型主权关乎控制和可替代性\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-40\" class=\"editorjs-toc__link\">开源是主权工具，而非主权本身\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-44\" class=\"editorjs-toc__link\">基础设施主权深入到云区域之下\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-48\" class=\"editorjs-toc__link\">计算主权是容量加控制\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-52\" class=\"editorjs-toc__link\">硬件和半导体依赖仍然存在\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-56\" class=\"editorjs-toc__link\">软件栈主权\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-60\" class=\"editorjs-toc__link\">提供商抽象是一种主权机制\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-64\" class=\"editorjs-toc__link\">多模型路由可以降低战略依赖\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-68\" class=\"editorjs-toc__link\">身份和加密密钥控制是主权层\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-72\" class=\"editorjs-toc__link\">运营主权意味着运行系统的能力\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-76\" class=\"editorjs-toc__link\">司法管辖区不等于物理位置\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-80\" class=\"editorjs-toc__link\">主权 AI 是一个供应链问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-84\" class=\"editorjs-toc__link\">主权 AI 不需要气隙\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-89\" class=\"editorjs-toc__link\">主权 AI 与私有 AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-92\" class=\"editorjs-toc__link\">自托管AI并不自动意味着主权\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-96\" class=\"editorjs-toc__link\">供应商框架：NVIDIA的四大技术支柱\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-100\" class=\"editorjs-toc__link\">实用的企业主权成熟度模型\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-105\" class=\"editorjs-toc__link\">当退出不再可信时，供应商锁定就变成主权风险\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-109\" class=\"editorjs-toc__link\">可信退出计划包含哪些内容\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-111\" class=\"editorjs-toc__link\">可移植性并不等同于主权——但它是主权最有力的机制之一\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-115\" class=\"editorjs-toc__link\">开放标准和协议边界降低替换成本\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-119\" class=\"editorjs-toc__link\">主权是一项治理决策，而不仅仅是技术设计\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-123\" class=\"editorjs-toc__link\">采购在很大程度上决定了实际主权\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-127\" class=\"editorjs-toc__link\">混合AI可以比全本地设计更具主权性\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-131\" class=\"editorjs-toc__link\">主权不能替代安全\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-135\" class=\"editorjs-toc__link\">主权与监管合规是不同的\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-139\" class=\"editorjs-toc__link\">原始实现证据：面向主权的构建模块\u003C\u002Fa>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-1\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-141\" class=\"editorjs-toc__link\">Aaasaasa AI Client：提供商、模型、运行时和权限是可分离的\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-146\" class=\"editorjs-toc__link\">真相源研究引擎：本地证据权威\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-151\" class=\"editorjs-toc__link\">构建主权依赖图\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-155\" class=\"editorjs-toc__link\">何时需要更强的人工智能主权\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-158\" class=\"editorjs-toc__link\">常见的主权人工智能失败模式\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-160\" class=\"editorjs-toc__link\">常见误解\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-162\" class=\"editorjs-toc__link\">实用的主权人工智能设计序列\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-164\" class=\"editorjs-toc__link\">主权AI架构检查清单\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-166\" class=\"editorjs-toc__link\">限制和权衡\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-172\" class=\"editorjs-toc__link\">什么会改变这个答案？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-176\" class=\"editorjs-toc__link\">相关规范知识\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-182\" class=\"editorjs-toc__link\">常见问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-184\" class=\"editorjs-toc__link\">术语表\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-186\" class=\"editorjs-toc__link\">结论\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-190\" class=\"editorjs-toc__link\">主要和当前来源\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fnav>\n\u003Ch2 id=\"section-7\">主权人工智能的真正含义\u003C\u002Fh2>\n\u003Cp>主权从根本上讲是依赖关系下的决策权。一个组织可能在技术上拥有其数据，但仍然依赖某个控制模型访问、定价、身份、加密密钥、软件更新或唯一可用推理端点的供应商。\u003C\u002Fp>\n\u003Cp>因此，主权架构要问的是：哪些依赖是可以接受的，哪些必须保持可替代性，哪些能力必须直接控制。\u003C\u002Fp>\n\u003Cp>欧盟委员会当前的技术主权定义很有用，因为它结合了两个理念：开发\u002F控制关键技术，以及减少外部依赖。这比将主权视为简单的地理托管更接近工程现实。\u003C\u002Fp>\n\u003Ch2 id=\"section-11\">最简单的例子\u003C\u002Fh2>\n\u003Cp>考虑两家公司，它们都将客户文档存储在德国。\u003C\u002Fp>\n\u003Cp>公司 A 将每个提示和文档发送到一个专有云模型。模型版本可能变化，供应商控制推理服务和密钥，而应用程序没有经过测试的备用方案。\u003C\u002Fp>\n\u003Cp>公司 B 也使用云模型，但将其数据和检索层置于自己的控制之下，可以路由到本地托管的开放权重模型，拥有应用程序密钥和身份，记录供应商\u002F模型依赖关系，并拥有经过测试的迁移路径。\u003C\u002Fp>\n\u003Cp>两者都可能满足数据位置要求。公司 B 拥有实质上更多的主权，因为如果外部供应商变得不可用或不可接受，它保留了更多有意义的选择。\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">实用的主权评估\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 定义权威主体\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">明确谁的主权重要：组织、公共行政部门、国家、欧盟、业务部门或受监管环境。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 识别关键人工智能能力\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">列出模型、推理、检索、数据、工具、身份、存储和运营服务。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 映射依赖关系\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">对于每项能力，识别供应商、司法管辖区、所有权、许可、更新路径和技术锁定。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 分类控制程度\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确定哪些是直接控制、合同控制、可替代或实际上属于外部控制。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 识别不可接受的依赖\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">找出可能阻碍连续性、暴露受保护数据或消除战略选择的依赖。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 增加替代方案或更强的所有权\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在合理的情况下，使用开放标准、本地模型、可移植数据、内部密钥、多供应商路由或主权基础设施。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 测试退出和连续性\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">证明组织能够在所定义的主权要求下迁移、故障转移或继续关键运营。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 随时间重新评估\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">供应商所有权、法律、模型许可、基础设施和地缘政治条件都可能发生变化。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-17\">简单例子止步之处\u003C\u002Fh2>\n\u003Cp>在国家或欧盟层面，主权人工智能所包含的远不止一个企业部署：半导体供应、高性能计算、研究能力、人才、数据集、云基础设施、模型开发和产业生态系统。\u003C\u002Fp>\n\u003Cp>在企业规模下，同一概念会变得更窄：组织自身必须控制或能够替换哪些AI依赖项？\u003C\u002Fp>\n\u003Cp>架构应始终说明主权主体和范围。不说明对谁主权、对什么主权以及针对哪种依赖的“主权AI”，对工程而言过于模糊。\u003C\u002Fp>\n\u003Ch2 id=\"section-21\">当前欧洲技术主权框架\u003C\u002Fh2>\n\u003Cp>欧盟委员会目前将技术主权定义为欧洲在数字世界中独立行动的能力，即通过开发和掌控关键技术、数据和基础设施，同时减少对非欧盟供应商的依赖。\u003C\u002Fp>\n\u003Cp>2026年技术主权一揽子计划明确覆盖从芯片到基础设施、软件、云和AI的整个价值链。这很重要，因为AI系统可能在模型层以下存在依赖：加速器、虚拟机监控程序、容器平台、云控制平面或专有库都可能成为战略依赖。\u003C\u002Fp>\n\u003Cp>欧盟委员会还在利用AI工厂和AI超级工厂扩大欧洲算力。当前AI超级工厂政策描述的是在欧洲建设和运营的基础设施，以增强韧性、战略自主权以及在欧洲基础设施上开发先进AI的能力。\u003C\u002Fp>\n\u003Ch2 id=\"section-25\">CADA将主权变为分级保证问题\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">当前拟议的CADA级别\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">控制信号\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">级别1\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据在位于欧盟的基础设施中处理和存储\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">级别2\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商证明独立于第三国，并保证软件供应链透明度\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">级别3\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商为欧盟所有并受其控制，并满足额外主权标准；可存在第三国提供商的认可路径\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">级别4\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">软件供应链完全透明且受控，无第三国干预\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>拟议的CADA框架在概念上尤其有用，因为它拒绝二元主权标签。它将主权视为在位置、法律\u002F公司控制和供应链控制方面不断提高的保证。\u003C\u002Fp>\n\u003Cp>它也是拟议的欧盟监管\u002F采购框架，而非通用的全球技术标准。不应在不理解实际风险模型的情况下，将这四个级别机械地照搬到私有架构中。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">数据驻留只是第一层\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">工作负载可以完全在欧盟境内处理数据，却仍依赖受第三国控制的提供商、专有软件栈、外国密钥管理平面或不可替代的模型API。驻留回答的是\u003Cstrong>在哪里\u003C\u002Fstrong>；主权还要问\u003Cstrong>谁控制\u003C\u002Fstrong>以及\u003Cstrong>如果依赖条款改变会发生什么\u003C\u002Fstrong>。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-30\">主权AI的主要控制维度\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">维度\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">主权问题\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁拥有、存储、分类、移动、删除和授权使用数据？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁控制模型权重\u002F访问、版本管理、许可证、微调和退役？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">算力\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">训练\u002F推理在哪里运行，谁控制容量？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">云\u002F基础设施\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁拥有并运营控制平面、硬件和托管层？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">软件栈\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">核心运行时\u002F编排组件能否被检查、替换或自行运营？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份与密钥\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁控制身份、凭据、加密密钥和策略执行？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">网络\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">正常运行需要哪些外部路径？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运营\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁可以管理、修补、禁用、观察和恢复系统？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">供应链\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些供应商、软件包、芯片、模型和注册表可能中断或破坏系统？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">司法管辖\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些法律机构可以强制访问或影响服务\u002F控制？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">技能与专有技术\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">组织能否在没有某一供应商人员的情况下运营或迁移系统？\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">退出\u002F可移植性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据、模型和工作负载能否在现实时间内迁移到可接受的替代方案？\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-32\">数据主权必要但不充分\u003C\u002Fh2>\n\u003Cp>数据主权涉及根据适用法律、组织权限和政策对数据的控制。位置可能很重要，但控制还包括加密、访问、保留、复用、训练权和删除。\u003C\u002Fp>\n\u003Cp>如果外部模型提供商在合同上被允许保留提示或基于提示进行训练，其主权风险不同于在更严格限制下临时处理数据的提供商——即使两者的端点位于同一地区。\u003C\u002Fp>\n\u003Cp>RAG会增加派生工件，如分块、嵌入、索引和缓存答案。主权数据控制应包括这些派生数据，而不仅是原始文档。\u003C\u002Fp>\n\u003Ch2 id=\"section-36\">模型主权关乎控制和可替代性\u003C\u002Fh2>\n\u003Cp>专有API模型可能极其强大，但对权重、训练过程、模型退役或未来定价的控制却十分有限。\u003C\u002Fp>\n\u003Cp>开放权重模型可以提供更多的运营控制，因为权重可以独立托管，但具体的许可证、分词器、训练来源、架构、微调权利和运行时要求仍然很重要。\u003C\u002Fp>\n\u003Cp>因此，模型主权并不等同于“开放模型”。相关问题是，在所需的法律和技术条件下，哪些模型工件可以被拥有、修改、评估、部署和替换。\u003C\u002Fp>\n\u003Ch2 id=\"section-40\">开源是主权工具，而非主权本身\u003C\u002Fh2>\n\u003Cp>欧盟开源战略明确将开源与更多控制、更少锁定、更强安全性和可复用数字构建块联系起来。\u003C\u002Fp>\n\u003Cp>开源可以减少依赖，因为源代码可以由替代供应商检查、修改和运营。开放标准也可以降低迁移成本。\u003C\u002Fp>\n\u003Cp>但是，仅在一个不可替代的云控制平面上运行的开源软件仍然可能留下重大依赖。同样，在无法独立采购、支持或运营的硬件上运行开放模型权重，可能只能提供部分主权。\u003C\u002Fp>\n\u003Ch2 id=\"section-44\">基础设施主权深入到云区域之下\u003C\u002Fh2>\n\u003Cp>“托管在欧洲”这一说法并未完全描述基础设施控制。相关问题包括公司所有权、管理访问权限、密钥控制、法律管辖权、支持人员、软件供应链，以及如果外国母公司或供应商改变条款，服务能否继续。\u003C\u002Fp>\n\u003Cp>当前拟议的CADA级别正是做出了这种区分：欧盟数据位置是比第三国独立性、欧盟所有权\u002F控制或完整软件供应链控制更低的保证级别。\u003C\u002Fp>\n\u003Cp>对于某些工作负载，公共云仍可能与所需的主权级别一致；对于其他工作负载，可能需要自运营基础设施或特殊治理的云安排。\u003C\u002Fp>\n\u003Ch2 id=\"section-48\">计算主权是容量加控制\u003C\u002Fh2>\n\u003Cp>AI系统严重依赖加速器和大规模计算。如果一个组织拥有模型和数据，但没有可接受的计算路径，实际主权仍然可能失败。\u003C\u002Fp>\n\u003Cp>欧盟的AI工厂\u002F超级工厂投资明确旨在增加欧洲AI计算能力和战略自主权。这表明计算本身被视为一个主权层，而不仅仅是采购细节。\u003C\u002Fp>\n\u003Cp>在企业规模上，等价的问题是，在提供商中断、配额限制、价格冲击或政策变化的情况下，关键推理工作负载能否继续。\u003C\u002Fp>\n\u003Ch2 id=\"section-52\">硬件和半导体依赖仍然存在\u003C\u002Fh2>\n\u003Cp>即使是自托管AI，通常也依赖于全球采购的GPU、CPU、内存、网络设备、驱动程序和固件。\u003C\u002Fp>\n\u003Cp>因此，主权很少意味着完全的硬件独立。更现实的控制包括供应链可见性、库存\u002F维护策略、第二来源选项、可互操作的运行时，以及避免与特定硬件的应用合同产生不必要的耦合。\u003C\u002Fp>\n\u003Cp>欧洲技术主权一揽子计划明确包含半导体政策，因为底层硬件依赖可能会制约整个人工智能技术栈。\u003C\u002Fp>\n\u003Ch2 id=\"section-56\">软件栈主权\u003C\u002Fh2>\n\u003Cp>在硬件与应用之间，存在着驱动程序、操作系统、容器运行时、推理引擎、数据库、向量存储、编排框架和可观测性工具。\u003C\u002Fp>\n\u003Cp>主权评估应确定这些组件中哪些可以在不重新设计业务应用的情况下被替换。\u003C\u002Fp>\n\u003Cp>开放接口在这些边界处尤其有价值，因为它们降低了更换某一依赖项而无需替换整个系统的成本。\u003C\u002Fp>\n\u003Ch2 id=\"section-60\">提供商抽象是一种主权机制\u003C\u002Fh2>\n\u003Cp>提供商抽象可防止应用逻辑与某一模型供应商的API、认证流程或消息格式变得不可分割。\u003C\u002Fp>\n\u003Cp>抽象并不会使模型变得等同。不同模型具有不同的上下文窗口、工具语义、安全行为、延迟和质量。因此，面向主权的路由需要明确的能力测试和回归测试。\u003C\u002Fp>\n\u003Cp>目标是实现可信的退出，而不是假装每个提供商都可以互换。\u003C\u002Fp>\n\u003Ch2 id=\"section-64\">多模型路由可以降低战略依赖\u003C\u002Fh2>\n\u003Cp>一个能够在本地模型、区域提供商和前沿云模型之间路由合适任务的平台，比硬编码到单一端点的平台拥有更多选择。\u003C\u002Fp>\n\u003Cp>策略可以决定敏感数据保留在本地或主权基础设施上，而已批准的低风险任务可以使用外部前沿模型。\u003C\u002Fp>\n\u003Cp>这种混合设计可以提高主权，而无需每个工作负载都使用相同的本地托管模型。\u003C\u002Fp>\n\u003Ch2 id=\"section-68\">身份和加密密钥控制是主权层\u003C\u002Fh2>\n\u003Cp>一个应用可以拥有自己的服务器，却依赖一个可以暂停访问的外部身份提供商，或依赖一个受另一司法管辖区控制的密钥管理服务。\u003C\u002Fp>\n\u003Cp>因此，关键主权评估应包括IAM、PKI、HSM\u002FKMS控制、服务凭证和管理账户。\u003C\u002Fp>\n\u003Cp>“客户管理密钥”可以改善控制，但确切的密钥保管和服务架构很重要。仅凭一个标签不足以确立独立性。\u003C\u002Fp>\n\u003Ch2 id=\"section-72\">运营主权意味着运行系统的能力\u003C\u002Fh2>\n\u003Cp>如果只有一个供应商能够部署、修补、诊断或恢复软件制品，那么拥有这些制品是不够的。\u003C\u002Fp>\n\u003Cp>运营主权需要文档、内部知识、可观测系统、备份\u002F恢复流程以及足够的专业知识来维护或迁移平台。\u003C\u002Fp>\n\u003Cp>这就是为什么主权既包括服务器，也包括技能和生态系统能力。对不可替代的外部专业知识的依赖，可能与对 API 的依赖一样真实。\u003C\u002Fp>\n\u003Ch2 id=\"section-76\">司法管辖区不等于物理位置\u003C\u002Fh2>\n\u003Cp>服务器可以物理上位于一个国家，而提供商仍受另一个国家的法律拥有或控制。\u003C\u002Fp>\n\u003Cp>确切的法律后果取决于合同、公司结构、数据类型和适用法律，因此主权架构应涉及法律专业知识，而不是从数据中心地图推断法律豁免。\u003C\u002Fp>\n\u003Cp>从架构角度来看，司法管辖区是与位置、所有权、运营商访问和技术控制并列的一个依赖属性。\u003C\u002Fp>\n\u003Ch2 id=\"section-80\">主权 AI 是一个供应链问题\u003C\u002Fh2>\n\u003Cp>每一个导入的模型、容器、软件包、驱动程序和设备都会增加一个外部依赖。\u003C\u002Fp>\n\u003Cp>最强的架构知道哪些依赖是关键、哪些可以替代、哪些需要可信更新渠道，以及哪些没有现实的替代方案。\u003C\u002Fp>\n\u003Cp>所提出的最高 CADA 保证级别对软件供应链透明度和控制的强调反映了这一现实：即使生产数据从未离开该地区，主权也可能通过更新路径失效。\u003C\u002Fp>\n\u003Ch2 id=\"section-84\">主权 AI 不需要气隙\u003C\u002Fh2>\n\u003Cp>气隙 AI 解决的是连接\u002F隔离问题。主权 AI 解决的是控制\u002F依赖问题。\u003C\u002Fp>\n\u003Cp>主权系统可以保持互联网连接，并使用精心选择的外部提供商，同时保留有效控制和退出选项。\u003C\u002Fp>\n\u003Cp>相反，如果气隙系统依赖于无法替代的专有外国软件、许可证、硬件或更新流程，它仍然可能不是主权的。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">气隙 AI：AI 系统如何在没有互联网或云访问的情况下工作\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">气隙描述的是网络和传输边界。主权描述的是对更广泛依赖链的控制。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读气隙 AI 文章 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Ch2 id=\"section-89\">主权 AI 与私有 AI\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">不同的主要问题\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">私有 AI\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">主权 AI\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">主要问题\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">数据重点\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">可以使用云吗？\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">需要开源吗？\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">需要隔离吗？\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Cp>当主要需求是保密性而非战略自主性时，私有AI可以完全满足要求。当提供商控制、司法管辖、连续性或依赖风险本身成为需求的一部分时，主权就变得相关了。\u003C\u002Fp>\n\u003Ch2 id=\"section-92\">自托管AI并不自动意味着主权\u003C\u002Fh2>\n\u003Cp>自托管可以直接控制推理位置，并且通常可以控制模型文件和日志。\u003C\u002Fp>\n\u003Cp>但自托管技术栈仍可能依赖于某个专有运行时、某个GPU供应商、外部许可证服务器、外国更新基础设施，或某个禁止所需修改或再分发的模型许可证。\u003C\u002Fp>\n\u003Cp>因此，自托管是一种可能的主权控制手段，而不是整个技术栈主权的证明。\u003C\u002Fp>\n\u003Ch2 id=\"section-96\">供应商框架：NVIDIA的四大技术支柱\u003C\u002Fh2>\n\u003Cp>NVIDIA当前的主权AI技术指南围绕四大支柱组织该主题：数据\u002F基准、模型、硬件基础设施和框架。\u003C\u002Fp>\n\u003Cp>这是一个有用的技术分解，尤其对于国家模型建设项目而言。NVIDIA还围绕本地数据集、特定国家的语言\u002F文化以及位于国境内部的基础设施来界定主权AI。\u003C\u002Fp>\n\u003Cp>由于NVIDIA是主要的基础设施供应商，这应被解读为供应商视角，而非中立的全球标准。本文中更广泛的依赖\u002F控制模型还额外包括所有权、司法管辖、身份、供应链和退出权。\u003C\u002Fp>\n\u003Ch2 id=\"section-100\">实用的企业主权成熟度模型\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">原创架构综合\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">以下五个级别是本文提出的实用工程模型。它们\u003Cstrong>不是\u003C\u002Fstrong>欧盟委员会的CADA级别，也不是行业标准。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">级别\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">架构状态\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">S0 — 外部依赖\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI能力依赖于一个外部提供商，可移植性或控制力很低\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">S1 — 数据受控\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">组织控制源数据、访问和保留，但严重依赖外部模型\u002F平台服务\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">S2 — 可移植应用\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据和应用保持受控；模型\u002F提供商边界被抽象化，迁移在技术上现实可行\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">S3 — 受控运行时\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">关键推理、身份、密钥、检索和运营可以在组织控制或经批准的主权基础设施上运行\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">S4 — 战略韧性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">关键栈具有经过测试的替代方案、供应链可见性、内部运营能力以及明确的连续性\u002F退出计划\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>工作负载默认不需要最高级别。所需的控制应取决于后果、监管、保密性、连续性需求和战略重要性。\u003C\u002Fp>\n\u003Cp>成熟度模型的意义在于揭示依赖仍然存在于何处——而不是把主权变成营销徽章。\u003C\u002Fp>\n\u003Ch2 id=\"section-105\">当退出不再可信时，供应商锁定就变成主权风险\u003C\u002Fh2>\n\u003Cp>锁定并不总是坏事。团队接受专有依赖，是因为它们提供了速度、质量、支持或经济性。\u003C\u002Fp>\n\u003Cp>当依赖具有战略关键性，且组织无法在其所需的连续性窗口内现实地迁移时，它就成了主权问题。\u003C\u002Fp>\n\u003Cp>因此，退出需要被设计和测试，而不仅仅是在合同中描述。\u003C\u002Fp>\n\u003Ch2 id=\"section-109\">可信退出计划包含哪些内容\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">领域\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">退出证据\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">以可用、有文档记录的格式导出\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提示词\u002F配置\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">存储在应用控制的源代码\u002F配置中\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在需要时识别并评估替代模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商 API\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">适配器边界限制提供商特定代码\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">RAG\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">语料库、元数据和索引可在提供商之外重建\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">应用不永久耦合于单一外部身份控制平面\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">密钥\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">理解密钥所有权\u002F导出\u002F轮换模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">基础设施\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">部署可迁移至经批准的替代环境\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可观测性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">日志\u002F指标\u002F追踪可导出，且不仅限于提供商\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运营知识\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行手册和人员能力存在于供应商之外\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">许可\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">迁移在法律上被允许\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">恢复\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">回退\u002F连续性路径已经过测试\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-111\">可移植性并不等同于主权——但它是主权最有力的机制之一\u003C\u002Fh2>\n\u003Cp>一个能够迁移数据但无法复现模型行为的系统，可能仍被锁定。\u003C\u002Fp>\n\u003Cp>一个能够切换模型端点但无法迁移身份、检索数据或审计记录的系统，可能仍存在关键依赖。\u003C\u002Fp>\n\u003Cp>主权要求关键能力的可移植性，而不仅仅是导出某一个数据库。\u003C\u002Fp>\n\u003Ch2 id=\"section-115\">开放标准和协议边界降低替换成本\u003C\u002Fh2>\n\u003Cp>诸如普通 HTTP API、OAuth\u002FOIDC、OpenTelemetry 和可互操作的数据格式等标准，即使实现仍为专有，也能降低依赖。\u003C\u002Fp>\n\u003Cp>AI 特定协议也能在选定的边界上提供帮助，但没有任何协议能够消除提供商特定行为或法律依赖。\u003C\u002Fp>\n\u003Cp>标准的主权价值是实际的：它是否能让组织在不重写整个平台的情况下替换某个组件？\u003C\u002Fp>\n\u003Ch2 id=\"section-119\">主权是一项治理决策，而不仅仅是技术设计\u003C\u002Fh2>\n\u003Cp>组织必须决定哪些依赖是可接受的，以及谁可以批准它们。\u003C\u002Fp>\n\u003Cp>AI 治理可以对模型\u002F提供商进行分类，按风险层级定义主权要求，要求退出证据，并为第三国或云使用设定条件。\u003C\u002Fp>\n\u003Cp>因此，主权要求应出现在架构决策、采购、风险管理和运营测试中，而不仅仅出现在政策声明中。\u003C\u002Fp>\n\u003Ch2 id=\"section-123\">采购在很大程度上决定了实际主权\u003C\u002Fh2>\n\u003Cp>合同可以规定数据使用、保留、支持、可移植性、模型弃用通知、子处理者、访问管辖权和终止协助。\u003C\u002Fp>\n\u003Cp>但合同承诺不能替代技术可移植性。如果不存在替代实现，退出条款在运营上可能仍然薄弱。\u003C\u002Fp>\n\u003Cp>面向主权的采购应同时评估法律控制和技术可替代性。\u003C\u002Fp>\n\u003Ch2 id=\"section-127\">混合AI可以比全本地设计更具主权性\u003C\u002Fh2>\n\u003Cp>主权有时被错误地等同于“一切都在本地运行”。\u003C\u002Fp>\n\u003Cp>混合架构可以将敏感数据和权威知识保留在受控基础设施上，同时为经批准的任务使用外部前沿模型，并采用基于策略的路由和经过测试的回退方案。\u003C\u002Fp>\n\u003Cp>如果可以在不丧失关键组织能力的情况下移除外部模型，那么混合平台可能比名义上本地化但锁定于单一专有运行时的技术栈拥有更强的实际主权。\u003C\u002Fp>\n\u003Ch2 id=\"section-131\">主权不能替代安全\u003C\u002Fh2>\n\u003Cp>控制基础设施并不能自动使其安全。主权环境仍然需要漏洞管理、最小权限、事件响应、备份、安全供应链和可审计性。\u003C\u002Fp>\n\u003Cp>如果检索或授权不正确，本地控制的模型仍可能将一个租户的数据泄露给另一个租户。\u003C\u002Fp>\n\u003Cp>主权回答的是谁控制系统；安全回答的是该控制是否被安全地行使。\u003C\u002Fp>\n\u003Ch2 id=\"section-135\">主权与监管合规是不同的\u003C\u002Fh2>\n\u003Cp>一个由欧盟托管、欧盟控制的AI技术栈仍然可能违反《人工智能法案》、GDPR或特定行业要求。\u003C\u002Fp>\n\u003Cp>同样，一个合规的系统可以使用外部提供商，但仍然只有有限的技术主权。\u003C\u002Fp>\n\u003Cp>监管和主权可以相互加强，但它们是独立的架构\u002F治理维度。\u003C\u002Fp>\n\u003Ch2 id=\"section-139\">原始实现证据：面向主权的构建模块\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">证据边界\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">以下项目展示了面向控制的架构模式，例如提供商抽象、本地推理、本地证据存储和明确的权限边界。它们\u003Cstrong>并非\u003C\u002Fstrong>作为国家主权AI技术栈、认证主权云或完整供应链独立性的证明来呈现。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch3 id=\"section-141\">Aaasaasa AI Client：提供商、模型、运行时和权限是可分离的\u003C\u002Fh3>\n\u003Cp>Aaasaasa AI Client将代理\u002F客户端、提供商、提供商特定模型、连接位置和权限策略分离。提供商可以包括Ollama、LM Studio\u002FOpenAI兼容服务和专用云路径。\u003C\u002Fp>\n\u003Cp>该架构明确区分本地运行时和本地推理：本地代理运行时可以使用云模型，而Direct Ollama聊天可以执行本地推理。\u003C\u002Fp>\n\u003Cp>这种分离与主权相关，因为提供商依赖成为一个显式配置层，而不是硬编码到业务应用程序中。\u003C\u002Fp>\n\u003Cp>中央权限也是应用\u002F会话策略，而不是模型的属性。即使模型\u002F提供商选择发生变化，这也能将操作权限保持在应用的控制之下。\u003C\u002Fp>\n\u003Ch3 id=\"section-146\">真相源研究引擎：本地证据权威\u003C\u002Fh3>\n\u003Cp>真相源研究引擎围绕持久化来源、快照、哈希、声明和来源追溯进行设计，而不是让模型输出成为权威。\u003C\u002Fp>\n\u003Cp>这种模式在知识层与主权相关：即使推理模型可以被替换，组织证据仍然是一个独立受控的工件。\u003C\u002Fp>\n\u003Cp>因此，该项目展示了一个有用的依赖原则：将权威数据\u002F证据与解释它的模型保持可分离。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">已验证模式\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">主权相关性\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">多模型\u002F提供商路径\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">减少对单一推理提供商的硬编码依赖\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地 Ollama 推理\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">创建组织控制的推理选项\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行时位置与提供商分离\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">使真实依赖可见\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">中央应用权限配置文件\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">权限保持在模型\u002F供应商之外\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">持久化来源\u002F证据身份\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">知识在模型替换后仍然存在\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">云路径仍然可用\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">展示混合架构，而不是虚假的“仅本地”定位\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">没有经过验证的主权基础设施认证\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">防止过度声称全栈主权\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-151\">构建主权依赖图\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">层级\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">主要提供商\u002F依赖\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">控制状态\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">替代方案\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">退出时间\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">例如提供商\u002F模型快照\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自有\u002F许可\u002F仅 API\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">指定替代方案\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">推理\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">云\u002F本地运行时\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">直接\u002F合同\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">第二运行时\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">嵌入\u002F重排序\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型\u002F运行时\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">直接\u002F外部\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">替代模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据库\u002F对象存储\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">直接\u002F提供商\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可移植导出\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">IdP\u002FKMS\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">直接\u002F外部\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">回退\u002F迁移路径\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">基础设施\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">云\u002F硬件\u002F集群\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自有\u002F租赁\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">替代环境\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具集成\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">SaaS\u002F内部服务\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">外部\u002F内部\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">回退\u002F手动流程\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可观测性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">日志\u002F追踪\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可移植\u002F仅提供商\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">替代栈\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已测量\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>该表的价值不在于确切的列；它迫使战略依赖变得可见且可测试。\u003C\u002Fp>\n\u003Cp>然后，架构审查可以区分便利依赖与威胁连续性、机密性或监管目标的依赖。\u003C\u002Fp>\n\u003Ch2 id=\"section-155\">何时需要更强的人工智能主权\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">驱动因素\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">为什么可能需要更强的控制\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">关键公共基础设施\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">连续性和战略自主可能超过提供商便利性\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">国防\u002F安全敏感工作负载\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">外国控制\u002F管辖权和供应链风险可能不可接受\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">高度机密的企业数据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据\u002F模型\u002F提供商控制可能需要更强的保证\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">长期工业平台\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">退出和硬件\u002F软件生命周期在多年内很重要\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">受监管的公共采购\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可能需要正式的主权保证级别\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">国家语言\u002F文化模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地数据集\u002F模型控制可以保持战略能力\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商集中风险\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">替代模型\u002F运行时路径提高韧性\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">正常低风险生产力使用\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">最大主权可能不必要且不经济\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>主权应当适度。目标不是在所有地方最大化本地所有权；而是保留足够的控制以应对后果和威胁模型。\u003C\u002Fp>\n\u003Ch2 id=\"section-158\">常见的主权人工智能失败模式\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">失败模式\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">实际失败之处\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“数据留在欧洲，因此主权”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">位置与所有权、管辖权和供应链控制混淆\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">一个专有模型 API，没有经过测试的替代方案\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">关键推理依赖于一个外部行为者\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">开放权重模型，专有锁定运行时\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型开放性未提供完整的操作控制\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自托管推理，仅云身份\u002FKMS\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">控制平面仍然依赖外部\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地数据但仅提供商向量\u002F索引格式\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">知识层无法干净迁移\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">多提供商抽象但没有评估\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">切换在技术上可行但在行为上不安全\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">有退出条款但没有迁移测试\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">合同可移植性不是操作可移植性\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">外国硬件被视为非主权的证明\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">主权被错误地定义为绝对自给自足\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">主权标签没有定义主体\u002F范围\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">没有人知道指的是谁的控制或哪些依赖\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部所有权但没有操作技能\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">系统无法独立维护\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">开源但没有维护能力\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">源代码可用性存在，但实际控制不存在\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">气隙被视为主权\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">连接隔离与依赖控制混淆\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-160\">常见误解\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">误解\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">纠正\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“主权人工智能意味着每个组件都必须国产。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">主权通常关乎有效控制、韧性和减少战略依赖，而不是完全自给自足。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“欧盟数据驻留等于欧盟主权。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">驻留是一个保证层；所有权、管辖权和供应链控制可以更进一步。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“开源等于主权。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">开源改善了控制和可移植性，但并未消除基础设施、硬件或操作依赖。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“自托管等于主权。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">自托管控制位置\u002F运行时，但不自动控制许可证、芯片、身份、供应链或更新路径。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“气隙等于主权。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">气隙控制连接性；主权控制更广泛的依赖链。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“私有 AI 等于主权 AI。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">隐私侧重于受保护的处理；主权侧重于战略\u002F操作控制。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“多云等于主权。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">两个云可能仍然共享相同的管辖权、技术依赖或专有控制平面。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“使用欧洲公司保证主权。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">公司位置有帮助，但技术、法律和供应链控制仍需审查。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“提供商抽象使每个模型都可替换。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">行为差异需要在路由或迁移之前进行评估。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“主权只适用于政府。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">该术语通常是国家\u002F地区的，但企业也对关键 AI 依赖有有意义的主权要求。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-162\">实用的主权人工智能设计序列\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">从战略依赖向外设计\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 定义主权主体\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">说明控制权是要求用于企业、公共机构、国家、欧盟领域还是其他权威机构。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 定义关键能力\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确定哪些AI功能不能丢失或受外部控制。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 分类数据和司法管辖区\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">映射数据位置、法律控制、保留和允许的处理。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 映射模型依赖关系\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">记录权重\u002FAPI所有权、许可证、版本、微调和替换选项。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 映射基础设施和控制平面\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">记录计算、云、密钥、身份、网络和操作员访问。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 映射软件和供应链\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">识别专有运行时、开源、软件包、注册表、更新和关键供应商。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 选择控制机制\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在合理的情况下应用本地推理、区域提供商、开放标准、开源或更强的所有权。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 构建提供商\u002F模型抽象\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在可移植性重要的地方，避免业务应用程序硬编码单一供应商。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">9\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">9. 独立保存权威数据\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确保知识、来源和业务记录在模型替换后仍然存在。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">10\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">10. 定义退出标准\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">为关键依赖设置最大可接受的迁移\u002F连续性时间。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">11\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">11. 测试替换和恢复\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">运行现实的故障转移\u002F迁移演练，而不是信任架构图。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">12\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">12. 定期重新评估\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">供应商所有权、政策、价格、法律、模型支持和技术生态系统会发生变化。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-164\">主权AI架构检查清单\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">问题\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">预期证据\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">对谁而言是主权？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">指定的权威机构\u002F司法管辖区\u002F组织\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些能力是战略性的？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">关键性分类\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据在哪里处理\u002F存储？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">经验证的数据流图\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁可以在法律上\u002F技术上访问数据？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">司法管辖区 + IAM + 操作员模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁控制模型访问\u002F权重？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">许可证\u002F提供商\u002F模型所有权记录\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型可以替换吗？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">评估的替代方案和迁移路径\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁控制推理计算？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">基础设施\u002F控制平面所有权\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">谁控制身份和密钥？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">IAM\u002FKMS 保管模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些组件是专有的？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">软件依赖清单\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些依赖是开放\u002F可移植的？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">标准\u002F源代码\u002F许可证据\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">还剩下哪些第三国依赖？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">明确的依赖登记册\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在提供商丢失期间关键操作能否继续？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">连续性\u002F回退测试\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据和知识能否导出\u002F重建？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可移植性\u002F重建程序\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">员工能否在没有供应商干预的情况下操作平台？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行手册\u002F技能\u002F操作证据\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">退出需要多长时间？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">衡量的迁移目标\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">什么变化会触发重新评估？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">所有权、法律、模型、提供商和供应链审查触发条件\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-166\">限制和权衡\u003C\u002Fh2>\n\u003Cp>更强的主权可能会增加成本，因为必须直接或在受限的提供商生态系统内维护更多的基础设施、运营和专业知识。\u003C\u002Fp>\n\u003Cp>对于某些工作负载，本地或区域替代方案可能落后于前沿模型能力。因此，主权政策应支持基于风险的路由，而不是强制将较弱的模型用于每项任务。\u003C\u002Fp>\n\u003Cp>在现代半导体和软件供应链中，绝对独立很少现实。架构应识别并减少不可接受的依赖，而不是声称不可能的自给自足。\u003C\u002Fp>\n\u003Cp>如果采购规则变得过于僵化，主权也可能减少生态系统选择。当前的欧盟政策明确试图在加强自主权的同时保留开放市场和伙伴关系。\u003C\u002Fp>\n\u003Cp>如果没有团队能够修补、监控或迁移系统，那么系统在纸面上可能是“主权”的，但在操作上却很脆弱。\u003C\u002Fp>\n\u003Ch2 id=\"section-172\">什么会改变这个答案？\u003C\u002Fh2>\n\u003Cp>欧盟提出的CADA主权框架可能会在立法过程中演变，因此在采购或法律决策之前应重新检查确切的保证级别要求。\u003C\u002Fp>\n\u003Cp>提供商所有权、模型许可、地缘政治条件和半导体供应链可能会在没有任何应用程序代码更改的情况下实质性改变主权评估。\u003C\u002Fp>\n\u003Cp>稳定的架构原则是，主权取决于对关键依赖的有效控制和可信替代方案，而不是一个地理或品牌属性。\u003C\u002Fp>\n\u003Ch2 id=\"section-176\">相关规范知识\u003C\u002Fh2>\n\u003Cp>主权AI位于几个部署和控制概念之上：私有AI保护敏感处理，气隙AI隔离网络域，AI治理分配决策权，LLMOps操作模型\u002F提供商变更。\u003C\u002Fp>\n\u003Cp>提供商抽象和模型路由是减少依赖的实用机制，而真相源架构使组织证据独立于任何单一模型。\u003C\u002Fp>\n\u003Cp>企业AI架构决定了这些主权要求属于平台、应用程序、身份、基础设施和运营的哪个位置。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">答案有效性边界：相关性与可靠AI答案之间缺失的层\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">对基础设施的主权并不能使答案成真。可靠的知识仍然需要证据、权威、范围和有效性控制。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读答案有效性边界 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">AI Agent 记忆不是 RAG：如何分离记忆、检索、状态和上下文\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">将状态、知识、检索和模型上下文分开可提高可移植性，并减少对单一 AI 提供商的耦合。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读架构文章 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Ch2 id=\"section-182\">常见问题\u003C\u002Fh2>\n\u003Csection class=\"editorjs-faq my-6 rounded-xl border border-gray-200 p-5 dark:border-gray-700\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">主权 AI 常见问题\u003C\u002Fh3>\u003Cdiv id=\"faq1\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">什么是主权 AI？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">主权 AI 是指国家、公共机构或组织等特定权威实体对关键 AI 数据、模型、基础设施、软件、运营和依赖关系保持有效控制的能力。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq2\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">主权 AI 等同于数据主权吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不。数据主权只是其中一个组成部分。AI 主权还包括模型控制、算力、软件供应链、身份、运营者、司法管辖以及替换关键提供商的能力。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq3\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">主权 AI 是否要求所有内容都在本地托管？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不。如果所需控制水平、法律保障、可移植性和连续性得以保持，主权架构可以使用外部或云服务。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq4\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">主权 AI 是否要求开源模型？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不。开源或开放权重可以提高控制和可移植性，但在依赖关系和许可可接受的情况下，仍可使用专有组件。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq5\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">自托管 AI 是否自动具备主权？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不。自托管控制推理位置，但仍可能依赖外部身份、专有运行时、外国硬件、许可证或更新基础设施。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq6\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">主权 AI 与气隙 AI 有何区别？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">气隙 AI 涉及物理\u002F网络隔离和受控传输。主权 AI 涉及对整个依赖链的有效控制。两者可以独立存在。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq7\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">云 AI 服务能否具备主权？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">有可能，取决于所需的主权级别以及谁控制位置、提供商所有权、管理访问、密钥、供应链、司法管辖和退出。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq8\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">为什么提供商抽象对主权很重要？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">它减少了应用程序对单一模型提供商的耦合，并创建了技术迁移路径，尽管行为差异仍需评估。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq9\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">如何衡量实际 AI 主权？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">映射关键依赖关系，并测试如果提供商、司法管辖区或供应链依赖变得不可接受，数据、模型、工作负载和运营能否在所需时间内继续或迁移。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq10\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">关于主权 AI 最大的误解是什么？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">认为主权是单一属性，例如欧盟托管、本地推理、开源或气隙。实际上，它是一个多层控制和依赖问题。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-184\">术语表\u003C\u002Fh2>\n\u003Csection class=\"editorjs-glossary my-6 rounded-xl border border-gray-200 dark:border-gray-700 p-5\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">关键主权 AI 术语\u003C\u002Fh3>\u003Cdl>\u003Cdiv id=\"sovereign-ai\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">主权 AI\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">设计为使特定权威实体对关键数据、模型、基础设施、运营和依赖关系保持有效控制的 AI 能力。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"tech-sovereignty\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">技术主权\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">通过控制关键技术、数据和基础设施，同时减少战略性外部依赖，在数字领域独立行动的能力。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"strategic-dependency\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">战略依赖\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">其丧失、控制或变化可能实质性威胁连续性、安全性、自主权或政策目标的外部依赖。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"data-residency\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">数据驻留\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">描述数据物理或逻辑存储\u002F处理位置的要求；比主权范围更窄。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"data-sovereignty\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">数据主权\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在适用法律、组织和司法管辖权威下对数据的控制。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"model-sovereignty\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">模型主权\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">对模型访问、权重、许可、修改、版本控制、部署和替换的控制程度。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"infrastructure-sovereignty\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">基础设施主权\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">对关键工作负载所需的算力、托管、控制平面、运营和基础设施司法管辖的控制。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"operational-sovereignty\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">运营主权\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在不对外部运营者产生不可接受依赖的情况下部署、维护、观察、恢复和迁移系统的能力。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"provider-abstraction\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">提供商抽象\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">将业务逻辑与提供商特定 API 分离的应用程序架构，以便更安全地更改模型\u002F提供商依赖。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"exit-strategy\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">退出策略\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">将数据、工作负载和运营能力从外部依赖中移出的可测试计划。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"supply-chain-sovereignty\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">供应链主权\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在关键软件、模型、硬件和更新依赖中的透明度、控制和可替代性程度。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"strategic-autonomy\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">战略自主\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在没有不可接受的外部约束或依赖的情况下做出和执行关键决策的能力。\u003C\u002Fdd>\u003C\u002Fdiv>\u003C\u002Fdl>\u003C\u002Fsection>\n\u003Ch2 id=\"section-186\">结论\u003C\u002Fh2>\n\u003Cp>主权 AI 不是一个产品类别，也不是一个部署位置。它是一个架构和治理目标：对重要的 AI 能力保持有效控制。\u003C\u002Fp>\n\u003Cp>最强的主权设计将数据与模型分离，将业务应用与提供商分离，将权威与模型能力分离，将关键运营与不可替代的外部依赖分离。\u003C\u002Fp>\n\u003Cp>最简短的可靠规则是：主权不是由模型运行在哪里证明的；而是由谁控制关键堆栈、保留哪些依赖关系，以及当这些依赖变得不可接受时组织能否继续或改变方向来证明的。\u003C\u002Fp>\n\u003Ch2 id=\"section-190\">主要和当前来源\u003C\u002Fh2>\n\u003Cp>以下来源区分了欧盟官方技术主权政策、当前拟议的云\u002FAI 主权保证级别、欧洲算力倡议以及供应商技术框架。本文中的企业主权成熟度模型明确为原创综合，并非欧盟或行业标准。\u003C\u002Fp>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Feu-tech-sovereignty\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">欧盟委员会 — 加强欧洲技术主权\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">欧盟当前对技术主权的定义：通过控制关键技术、数据和基础设施，同时减少对非欧盟提供商的依赖，实现独立行动。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Flibrary\u002Fcommunication-european-tech-sovereignty-accompanied-eu-open-source-strategy\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">欧盟委员会 — 关于欧洲技术主权的通讯\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">2026 年政策方案，涵盖从芯片到基础设施、软件、云和 AI 的技术价值链。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcloud-and-ai-development-act\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">欧盟委员会 — 云和 AI 发展法案\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前拟议的欧盟框架，定义了位置、第三国独立性、所有权\u002F控制权和软件供应链控制四个云\u002FAI 主权保证级别。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffactpages\u002Feu-open-source-strategy\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">欧盟委员会 — 欧盟开源战略\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前政策将开源与更大的控制、更低的锁定、安全性、复用和技术主权联系起来。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fai-factories\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">欧盟委员会 — AI 工厂\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前欧盟 AI 算力基础设施倡议，将 AI 工厂和超级工厂与欧洲能力和技术主权联系起来。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fnews\u002Feu-launches-ai-gigafactories-call-boost-europes-computing-capacity-and-unlock-more-eu30-billion\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">欧盟委员会 — AI 超级工厂征集\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">2026 年倡议，旨在扩大欧洲 AI 算力、韧性和战略自主，基础设施在欧洲建设和运营。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.eurohpc-ju.europa.eu\u002Feurohpc-joint-undertaking-launches-ai-gigafactories-call-2026-07-30_en\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">EuroHPC JU — AI 超级工厂\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">EuroHPC 当前对大规模主权 AI 计算基础设施和技术独立的框架。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nvidia.com\u002Fen-us\u002Flp\u002Findustries\u002Fglobal-public-sector\u002Fsovereign-ai-technical-overview\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NVIDIA — 构建主权AI模型\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">围绕数据\u002F基准、模型、硬件基础设施和框架组织的供应商技术框架；可作为行业视角参考，并非通用标准。\u003C\u002Fp>\u003C\u002Fa>",{"time":212,"blocks":213,"version":1776},1791489366681,[214,220,228,235,242,248,256,261,266,271,276,281,286,291,296,301,333,338,343,348,353,358,363,368,373,378,399,404,409,416,421,465,470,475,480,485,490,495,500,505,510,515,520,525,530,535,540,545,550,555,560,565,570,575,580,585,590,595,600,605,610,615,620,625,630,635,640,645,650,655,660,665,670,675,680,685,690,695,700,705,710,715,720,725,730,735,740,745,754,759,794,799,804,809,814,819,824,829,834,839,844,850,873,878,883,888,893,898,903,908,950,955,960,965,970,975,980,985,990,995,1000,1005,1010,1015,1020,1025,1030,1035,1040,1045,1050,1055,1060,1065,1070,1075,1080,1085,1090,1095,1101,1106,1111,1116,1121,1126,1131,1136,1141,1146,1175,1180,1226,1231,1236,1241,1273,1278,1283,1327,1332,1370,1375,1417,1422,1478,1483,1488,1493,1498,1503,1508,1513,1518,1523,1528,1533,1538,1543,1548,1556,1564,1569,1615,1620,1673,1678,1683,1688,1693,1698,1703,1713,1722,1731,1740,1749,1758,1767],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"主权人工智能是指一个国家、公共机构、组织或其他明确权威机构对其所依赖的人工智能系统保持有效控制的能力：包括其数据、模型、基础设施、软件栈、运营者、法律风险敞口和战略依赖。主权并不等同于将数据托管在一个国家、运行一个开放模型、使用欧盟云服务提供商或将服务器与互联网断开连接。这些做法可以支持主权，但决定性的问题是：该组织能否在不对某个外部行为者产生不可接受的依赖的情况下，做出、执行并维持关键的人工智能决策。","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct",{"body":223,"title":224,"variant":225},"一个实用的主权人工智能架构所控制的远不止模型的位置。它要问的是：\u003Cbr>\u003Cbr>\u003Cstrong>谁控制数据？谁控制模型？谁控制算力？谁控制软件栈？谁持有密钥？适用哪国法律和公司控制？哪个供应商能够禁用、更改系统或调整定价？如果该供应商变得不可接受，工作负载能否迁移？\u003C\u002Fstrong>\u003Cbr>\u003Cbr>因此，主权存在于一条依赖链之中，而不是一个简单的“是\u002F否”属性。","直接回答","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"not-standard",{"body":231,"title":232,"variant":233},"“主权人工智能”被政府、供应商和业界使用，其含义相互重叠但并不完全相同。欧盟委员会目前将更广泛的\u003Cstrong>技术主权\u003C\u002Fstrong>定义为：通过开发和掌控关键技术、数据和基础设施，同时减少对非欧盟供应商的依赖，从而独立行动的能力。NVIDIA 的供应商框架则强调本地数据、模型、基础设施和框架。本文采用对这些控制维度进行明确的架构性综合，而不是将某一家供应商的定义作为通用标准来呈现。","该术语并非一个通用的技术标准","note",{},{"id":236,"data":237,"type":226,"tunes":241},"not-autarky",{"body":238,"title":239,"variant":240},"目标未必是消除每一个外国组件。当前欧盟政策明确将更强的自主性与对合作伙伴保持开放的市场结合起来。主权架构减少的是\u003Cstrong>战略依赖\u003C\u002Fstrong>：那些可能消除有效选择、将关键数据\u002F控制暴露于不受欢迎的司法管辖之下，或使系统在没有某个外部供应商的情况下无法持续运行的依赖。","主权并不要求技术自给自足","success",{},{"id":243,"data":244,"type":226,"tunes":247},"current",{"body":245,"title":246,"variant":233},"2026年6月3日，欧盟委员会通过了其技术主权一揽子计划，并提出了《云与人工智能发展法案》（CADA）。委员会当前的 CADA 框架描述了四个云\u002F人工智能主权保证级别，从欧盟数据位置，到独立于第三国和软件供应链透明度，再到欧盟所有权\u002F控制，以及在最高级别上，无第三国干预的完整供应链控制。这有力地证明，主权比数据驻留更为广泛。","当前来源说明——2026年10月8日",{},{"id":249,"data":250,"type":254,"tunes":255},"toc",{"title":251,"maxLevel":252,"minLevel":253},"目录",3,2,"tableOfContents",{},{"id":257,"data":258,"type":42,"tunes":260},"h-meaning",{"text":259,"level":253},"主权人工智能的真正含义",{},{"id":262,"data":263,"type":218,"tunes":265},"p-meaning-1",{"text":264},"主权从根本上讲是依赖关系下的决策权。一个组织可能在技术上拥有其数据，但仍然依赖某个控制模型访问、定价、身份、加密密钥、软件更新或唯一可用推理端点的供应商。",{},{"id":267,"data":268,"type":218,"tunes":270},"p-meaning-2",{"text":269},"因此，主权架构要问的是：哪些依赖是可以接受的，哪些必须保持可替代性，哪些能力必须直接控制。",{},{"id":272,"data":273,"type":218,"tunes":275},"p-meaning-3",{"text":274},"欧盟委员会当前的技术主权定义很有用，因为它结合了两个理念：开发\u002F控制关键技术，以及减少外部依赖。这比将主权视为简单的地理托管更接近工程现实。",{},{"id":277,"data":278,"type":42,"tunes":280},"h-simple",{"text":279,"level":253},"最简单的例子",{},{"id":282,"data":283,"type":218,"tunes":285},"p-simple-1",{"text":284},"考虑两家公司，它们都将客户文档存储在德国。",{},{"id":287,"data":288,"type":218,"tunes":290},"p-simple-2",{"text":289},"公司 A 将每个提示和文档发送到一个专有云模型。模型版本可能变化，供应商控制推理服务和密钥，而应用程序没有经过测试的备用方案。",{},{"id":292,"data":293,"type":218,"tunes":295},"p-simple-3",{"text":294},"公司 B 也使用云模型，但将其数据和检索层置于自己的控制之下，可以路由到本地托管的开放权重模型，拥有应用程序密钥和身份，记录供应商\u002F模型依赖关系，并拥有经过测试的迁移路径。",{},{"id":297,"data":298,"type":218,"tunes":300},"p-simple-4",{"text":299},"两者都可能满足数据位置要求。公司 B 拥有实质上更多的主权，因为如果外部供应商变得不可用或不可接受，它保留了更多有意义的选择。",{},{"id":302,"data":303,"type":331,"tunes":332},"simple-flow",{"steps":304,"title":329,"orientation":330},[305,308,311,314,317,320,323,326],{"label":306,"description":307},"1. 定义权威主体","明确谁的主权重要：组织、公共行政部门、国家、欧盟、业务部门或受监管环境。",{"label":309,"description":310},"2. 识别关键人工智能能力","列出模型、推理、检索、数据、工具、身份、存储和运营服务。",{"label":312,"description":313},"3. 映射依赖关系","对于每项能力，识别供应商、司法管辖区、所有权、许可、更新路径和技术锁定。",{"label":315,"description":316},"4. 分类控制程度","确定哪些是直接控制、合同控制、可替代或实际上属于外部控制。",{"label":318,"description":319},"5. 识别不可接受的依赖","找出可能阻碍连续性、暴露受保护数据或消除战略选择的依赖。",{"label":321,"description":322},"6. 增加替代方案或更强的所有权","在合理的情况下，使用开放标准、本地模型、可移植数据、内部密钥、多供应商路由或主权基础设施。",{"label":324,"description":325},"7. 测试退出和连续性","证明组织能够在所定义的主权要求下迁移、故障转移或继续关键运营。",{"label":327,"description":328},"8. 随时间重新评估","供应商所有权、法律、模型许可、基础设施和地缘政治条件都可能发生变化。","实用的主权评估","auto","processFlow",{},{"id":334,"data":335,"type":42,"tunes":337},"h-stops",{"text":336,"level":253},"简单例子止步之处",{},{"id":339,"data":340,"type":218,"tunes":342},"p-stops-1",{"text":341},"在国家或欧盟层面，主权人工智能所包含的远不止一个企业部署：半导体供应、高性能计算、研究能力、人才、数据集、云基础设施、模型开发和产业生态系统。",{},{"id":344,"data":345,"type":218,"tunes":347},"p-stops-2",{"text":346},"在企业规模下，同一概念会变得更窄：组织自身必须控制或能够替换哪些AI依赖项？",{},{"id":349,"data":350,"type":218,"tunes":352},"p-stops-3",{"text":351},"架构应始终说明主权主体和范围。不说明对谁主权、对什么主权以及针对哪种依赖的“主权AI”，对工程而言过于模糊。",{},{"id":354,"data":355,"type":42,"tunes":357},"h-eu",{"text":356,"level":253},"当前欧洲技术主权框架",{},{"id":359,"data":360,"type":218,"tunes":362},"p-eu-1",{"text":361},"欧盟委员会目前将技术主权定义为欧洲在数字世界中独立行动的能力，即通过开发和掌控关键技术、数据和基础设施，同时减少对非欧盟供应商的依赖。",{},{"id":364,"data":365,"type":218,"tunes":367},"p-eu-2",{"text":366},"2026年技术主权一揽子计划明确覆盖从芯片到基础设施、软件、云和AI的整个价值链。这很重要，因为AI系统可能在模型层以下存在依赖：加速器、虚拟机监控程序、容器平台、云控制平面或专有库都可能成为战略依赖。",{},{"id":369,"data":370,"type":218,"tunes":372},"p-eu-3",{"text":371},"欧盟委员会还在利用AI工厂和AI超级工厂扩大欧洲算力。当前AI超级工厂政策描述的是在欧洲建设和运营的基础设施，以增强韧性、战略自主权以及在欧洲基础设施上开发先进AI的能力。",{},{"id":374,"data":375,"type":42,"tunes":377},"h-cada",{"text":376,"level":253},"CADA将主权变为分级保证问题",{},{"id":379,"data":380,"type":397,"tunes":398},"cada-table",{"content":381,"stretched":43,"withHeadings":14},[382,385,388,391,394],[383,384],"当前拟议的CADA级别","控制信号",[386,387],"级别1","数据在位于欧盟的基础设施中处理和存储",[389,390],"级别2","提供商证明独立于第三国，并保证软件供应链透明度",[392,393],"级别3","提供商为欧盟所有并受其控制，并满足额外主权标准；可存在第三国提供商的认可路径",[395,396],"级别4","软件供应链完全透明且受控，无第三国干预","table",{},{"id":400,"data":401,"type":218,"tunes":403},"p-cada-1",{"text":402},"拟议的CADA框架在概念上尤其有用，因为它拒绝二元主权标签。它将主权视为在位置、法律\u002F公司控制和供应链控制方面不断提高的保证。",{},{"id":405,"data":406,"type":218,"tunes":408},"p-cada-2",{"text":407},"它也是拟议的欧盟监管\u002F采购框架，而非通用的全球技术标准。不应在不理解实际风险模型的情况下，将这四个级别机械地照搬到私有架构中。",{},{"id":410,"data":411,"type":226,"tunes":415},"residency-rule",{"body":412,"title":413,"variant":414},"工作负载可以完全在欧盟境内处理数据，却仍依赖受第三国控制的提供商、专有软件栈、外国密钥管理平面或不可替代的模型API。驻留回答的是\u003Cstrong>在哪里\u003C\u002Fstrong>；主权还要问\u003Cstrong>谁控制\u003C\u002Fstrong>以及\u003Cstrong>如果依赖条款改变会发生什么\u003C\u002Fstrong>。","数据驻留只是第一层","warning",{},{"id":417,"data":418,"type":42,"tunes":420},"h-dimensions",{"text":419,"level":253},"主权AI的主要控制维度",{},{"id":422,"data":423,"type":397,"tunes":464},"dimensions-table",{"content":424,"stretched":43,"withHeadings":14},[425,428,431,434,437,440,443,446,449,452,455,458,461],[426,427],"维度","主权问题",[429,430],"数据","谁拥有、存储、分类、移动、删除和授权使用数据？",[432,433],"模型","谁控制模型权重\u002F访问、版本管理、许可证、微调和退役？",[435,436],"算力","训练\u002F推理在哪里运行，谁控制容量？",[438,439],"云\u002F基础设施","谁拥有并运营控制平面、硬件和托管层？",[441,442],"软件栈","核心运行时\u002F编排组件能否被检查、替换或自行运营？",[444,445],"身份与密钥","谁控制身份、凭据、加密密钥和策略执行？",[447,448],"网络","正常运行需要哪些外部路径？",[450,451],"运营","谁可以管理、修补、禁用、观察和恢复系统？",[453,454],"供应链","哪些供应商、软件包、芯片、模型和注册表可能中断或破坏系统？",[456,457],"司法管辖","哪些法律机构可以强制访问或影响服务\u002F控制？",[459,460],"技能与专有技术","组织能否在没有某一供应商人员的情况下运营或迁移系统？",[462,463],"退出\u002F可移植性","数据、模型和工作负载能否在现实时间内迁移到可接受的替代方案？",{},{"id":466,"data":467,"type":42,"tunes":469},"h-data",{"text":468,"level":253},"数据主权必要但不充分",{},{"id":471,"data":472,"type":218,"tunes":474},"p-data-1",{"text":473},"数据主权涉及根据适用法律、组织权限和政策对数据的控制。位置可能很重要，但控制还包括加密、访问、保留、复用、训练权和删除。",{},{"id":476,"data":477,"type":218,"tunes":479},"p-data-2",{"text":478},"如果外部模型提供商在合同上被允许保留提示或基于提示进行训练，其主权风险不同于在更严格限制下临时处理数据的提供商——即使两者的端点位于同一地区。",{},{"id":481,"data":482,"type":218,"tunes":484},"p-data-3",{"text":483},"RAG会增加派生工件，如分块、嵌入、索引和缓存答案。主权数据控制应包括这些派生数据，而不仅是原始文档。",{},{"id":486,"data":487,"type":42,"tunes":489},"h-models",{"text":488,"level":253},"模型主权关乎控制和可替代性",{},{"id":491,"data":492,"type":218,"tunes":494},"p-model-1",{"text":493},"专有API模型可能极其强大，但对权重、训练过程、模型退役或未来定价的控制却十分有限。",{},{"id":496,"data":497,"type":218,"tunes":499},"p-model-2",{"text":498},"开放权重模型可以提供更多的运营控制，因为权重可以独立托管，但具体的许可证、分词器、训练来源、架构、微调权利和运行时要求仍然很重要。",{},{"id":501,"data":502,"type":218,"tunes":504},"p-model-3",{"text":503},"因此，模型主权并不等同于“开放模型”。相关问题是，在所需的法律和技术条件下，哪些模型工件可以被拥有、修改、评估、部署和替换。",{},{"id":506,"data":507,"type":42,"tunes":509},"h-open",{"text":508,"level":253},"开源是主权工具，而非主权本身",{},{"id":511,"data":512,"type":218,"tunes":514},"p-open-1",{"text":513},"欧盟开源战略明确将开源与更多控制、更少锁定、更强安全性和可复用数字构建块联系起来。",{},{"id":516,"data":517,"type":218,"tunes":519},"p-open-2",{"text":518},"开源可以减少依赖，因为源代码可以由替代供应商检查、修改和运营。开放标准也可以降低迁移成本。",{},{"id":521,"data":522,"type":218,"tunes":524},"p-open-3",{"text":523},"但是，仅在一个不可替代的云控制平面上运行的开源软件仍然可能留下重大依赖。同样，在无法独立采购、支持或运营的硬件上运行开放模型权重，可能只能提供部分主权。",{},{"id":526,"data":527,"type":42,"tunes":529},"h-infra",{"text":528,"level":253},"基础设施主权深入到云区域之下",{},{"id":531,"data":532,"type":218,"tunes":534},"p-infra-1",{"text":533},"“托管在欧洲”这一说法并未完全描述基础设施控制。相关问题包括公司所有权、管理访问权限、密钥控制、法律管辖权、支持人员、软件供应链，以及如果外国母公司或供应商改变条款，服务能否继续。",{},{"id":536,"data":537,"type":218,"tunes":539},"p-infra-2",{"text":538},"当前拟议的CADA级别正是做出了这种区分：欧盟数据位置是比第三国独立性、欧盟所有权\u002F控制或完整软件供应链控制更低的保证级别。",{},{"id":541,"data":542,"type":218,"tunes":544},"p-infra-3",{"text":543},"对于某些工作负载，公共云仍可能与所需的主权级别一致；对于其他工作负载，可能需要自运营基础设施或特殊治理的云安排。",{},{"id":546,"data":547,"type":42,"tunes":549},"h-compute",{"text":548,"level":253},"计算主权是容量加控制",{},{"id":551,"data":552,"type":218,"tunes":554},"p-compute-1",{"text":553},"AI系统严重依赖加速器和大规模计算。如果一个组织拥有模型和数据，但没有可接受的计算路径，实际主权仍然可能失败。",{},{"id":556,"data":557,"type":218,"tunes":559},"p-compute-2",{"text":558},"欧盟的AI工厂\u002F超级工厂投资明确旨在增加欧洲AI计算能力和战略自主权。这表明计算本身被视为一个主权层，而不仅仅是采购细节。",{},{"id":561,"data":562,"type":218,"tunes":564},"p-compute-3",{"text":563},"在企业规模上，等价的问题是，在提供商中断、配额限制、价格冲击或政策变化的情况下，关键推理工作负载能否继续。",{},{"id":566,"data":567,"type":42,"tunes":569},"h-chips",{"text":568,"level":253},"硬件和半导体依赖仍然存在",{},{"id":571,"data":572,"type":218,"tunes":574},"p-chips-1",{"text":573},"即使是自托管AI，通常也依赖于全球采购的GPU、CPU、内存、网络设备、驱动程序和固件。",{},{"id":576,"data":577,"type":218,"tunes":579},"p-chips-2",{"text":578},"因此，主权很少意味着完全的硬件独立。更现实的控制包括供应链可见性、库存\u002F维护策略、第二来源选项、可互操作的运行时，以及避免与特定硬件的应用合同产生不必要的耦合。",{},{"id":581,"data":582,"type":218,"tunes":584},"p-chips-3",{"text":583},"欧洲技术主权一揽子计划明确包含半导体政策，因为底层硬件依赖可能会制约整个人工智能技术栈。",{},{"id":586,"data":587,"type":42,"tunes":589},"h-stack",{"text":588,"level":253},"软件栈主权",{},{"id":591,"data":592,"type":218,"tunes":594},"p-stack-1",{"text":593},"在硬件与应用之间，存在着驱动程序、操作系统、容器运行时、推理引擎、数据库、向量存储、编排框架和可观测性工具。",{},{"id":596,"data":597,"type":218,"tunes":599},"p-stack-2",{"text":598},"主权评估应确定这些组件中哪些可以在不重新设计业务应用的情况下被替换。",{},{"id":601,"data":602,"type":218,"tunes":604},"p-stack-3",{"text":603},"开放接口在这些边界处尤其有价值，因为它们降低了更换某一依赖项而无需替换整个系统的成本。",{},{"id":606,"data":607,"type":42,"tunes":609},"h-provider",{"text":608,"level":253},"提供商抽象是一种主权机制",{},{"id":611,"data":612,"type":218,"tunes":614},"p-provider-1",{"text":613},"提供商抽象可防止应用逻辑与某一模型供应商的API、认证流程或消息格式变得不可分割。",{},{"id":616,"data":617,"type":218,"tunes":619},"p-provider-2",{"text":618},"抽象并不会使模型变得等同。不同模型具有不同的上下文窗口、工具语义、安全行为、延迟和质量。因此，面向主权的路由需要明确的能力测试和回归测试。",{},{"id":621,"data":622,"type":218,"tunes":624},"p-provider-3",{"text":623},"目标是实现可信的退出，而不是假装每个提供商都可以互换。",{},{"id":626,"data":627,"type":42,"tunes":629},"h-routing",{"text":628,"level":253},"多模型路由可以降低战略依赖",{},{"id":631,"data":632,"type":218,"tunes":634},"p-route-1",{"text":633},"一个能够在本地模型、区域提供商和前沿云模型之间路由合适任务的平台，比硬编码到单一端点的平台拥有更多选择。",{},{"id":636,"data":637,"type":218,"tunes":639},"p-route-2",{"text":638},"策略可以决定敏感数据保留在本地或主权基础设施上，而已批准的低风险任务可以使用外部前沿模型。",{},{"id":641,"data":642,"type":218,"tunes":644},"p-route-3",{"text":643},"这种混合设计可以提高主权，而无需每个工作负载都使用相同的本地托管模型。",{},{"id":646,"data":647,"type":42,"tunes":649},"h-identity",{"text":648,"level":253},"身份和加密密钥控制是主权层",{},{"id":651,"data":652,"type":218,"tunes":654},"p-id-1",{"text":653},"一个应用可以拥有自己的服务器，却依赖一个可以暂停访问的外部身份提供商，或依赖一个受另一司法管辖区控制的密钥管理服务。",{},{"id":656,"data":657,"type":218,"tunes":659},"p-id-2",{"text":658},"因此，关键主权评估应包括IAM、PKI、HSM\u002FKMS控制、服务凭证和管理账户。",{},{"id":661,"data":662,"type":218,"tunes":664},"p-id-3",{"text":663},"“客户管理密钥”可以改善控制，但确切的密钥保管和服务架构很重要。仅凭一个标签不足以确立独立性。",{},{"id":666,"data":667,"type":42,"tunes":669},"h-operations",{"text":668,"level":253},"运营主权意味着运行系统的能力",{},{"id":671,"data":672,"type":218,"tunes":674},"p-ops-1",{"text":673},"如果只有一个供应商能够部署、修补、诊断或恢复软件制品，那么拥有这些制品是不够的。",{},{"id":676,"data":677,"type":218,"tunes":679},"p-ops-2",{"text":678},"运营主权需要文档、内部知识、可观测系统、备份\u002F恢复流程以及足够的专业知识来维护或迁移平台。",{},{"id":681,"data":682,"type":218,"tunes":684},"p-ops-3",{"text":683},"这就是为什么主权既包括服务器，也包括技能和生态系统能力。对不可替代的外部专业知识的依赖，可能与对 API 的依赖一样真实。",{},{"id":686,"data":687,"type":42,"tunes":689},"h-jurisdiction",{"text":688,"level":253},"司法管辖区不等于物理位置",{},{"id":691,"data":692,"type":218,"tunes":694},"p-jur-1",{"text":693},"服务器可以物理上位于一个国家，而提供商仍受另一个国家的法律拥有或控制。",{},{"id":696,"data":697,"type":218,"tunes":699},"p-jur-2",{"text":698},"确切的法律后果取决于合同、公司结构、数据类型和适用法律，因此主权架构应涉及法律专业知识，而不是从数据中心地图推断法律豁免。",{},{"id":701,"data":702,"type":218,"tunes":704},"p-jur-3",{"text":703},"从架构角度来看，司法管辖区是与位置、所有权、运营商访问和技术控制并列的一个依赖属性。",{},{"id":706,"data":707,"type":42,"tunes":709},"h-supply",{"text":708,"level":253},"主权 AI 是一个供应链问题",{},{"id":711,"data":712,"type":218,"tunes":714},"p-supply-1",{"text":713},"每一个导入的模型、容器、软件包、驱动程序和设备都会增加一个外部依赖。",{},{"id":716,"data":717,"type":218,"tunes":719},"p-supply-2",{"text":718},"最强的架构知道哪些依赖是关键、哪些可以替代、哪些需要可信更新渠道，以及哪些没有现实的替代方案。",{},{"id":721,"data":722,"type":218,"tunes":724},"p-supply-3",{"text":723},"所提出的最高 CADA 保证级别对软件供应链透明度和控制的强调反映了这一现实：即使生产数据从未离开该地区，主权也可能通过更新路径失效。",{},{"id":726,"data":727,"type":42,"tunes":729},"h-airgap",{"text":728,"level":253},"主权 AI 不需要气隙",{},{"id":731,"data":732,"type":218,"tunes":734},"p-airgap-1",{"text":733},"气隙 AI 解决的是连接\u002F隔离问题。主权 AI 解决的是控制\u002F依赖问题。",{},{"id":736,"data":737,"type":218,"tunes":739},"p-airgap-2",{"text":738},"主权系统可以保持互联网连接，并使用精心选择的外部提供商，同时保留有效控制和退出选项。",{},{"id":741,"data":742,"type":218,"tunes":744},"p-airgap-3",{"text":743},"相反，如果气隙系统依赖于无法替代的专有外国软件、许可证、硬件或更新流程，它仍然可能不是主权的。",{},{"id":746,"data":747,"type":752,"tunes":753},"ref-airgap",{"url":748,"title":749,"excerpt":750,"ctaLabel":751},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","气隙 AI：AI 系统如何在没有互联网或云访问的情况下工作","气隙描述的是网络和传输边界。主权描述的是对更广泛依赖链的控制。","阅读气隙 AI 文章","referralArticle",{},{"id":755,"data":756,"type":42,"tunes":758},"h-private",{"text":757,"level":253},"主权 AI 与私有 AI",{},{"id":760,"data":761,"type":792,"tunes":793},"private-comparison",{"rows":762,"title":784,"layout":397,"columns":785},[763,768,772,776,780],{"id":764,"label":765,"values":766},"question","主要问题",[767,767],"",{"id":769,"label":770,"values":771},"data","数据重点",[767,767],{"id":773,"label":774,"values":775},"cloud","可以使用云吗？",[767,767],{"id":777,"label":778,"values":779},"open","需要开源吗？",[767,767],{"id":781,"label":782,"values":783},"airgap","需要隔离吗？",[767,767],"不同的主要问题",[786,789],{"id":787,"label":788},"private","私有 AI",{"id":790,"label":791},"sovereign","主权 AI","comparison",{},{"id":795,"data":796,"type":218,"tunes":798},"p-private-1",{"text":797},"当主要需求是保密性而非战略自主性时，私有AI可以完全满足要求。当提供商控制、司法管辖、连续性或依赖风险本身成为需求的一部分时，主权就变得相关了。",{},{"id":800,"data":801,"type":42,"tunes":803},"h-local",{"text":802,"level":253},"自托管AI并不自动意味着主权",{},{"id":805,"data":806,"type":218,"tunes":808},"p-local-1",{"text":807},"自托管可以直接控制推理位置，并且通常可以控制模型文件和日志。",{},{"id":810,"data":811,"type":218,"tunes":813},"p-local-2",{"text":812},"但自托管技术栈仍可能依赖于某个专有运行时、某个GPU供应商、外部许可证服务器、外国更新基础设施，或某个禁止所需修改或再分发的模型许可证。",{},{"id":815,"data":816,"type":218,"tunes":818},"p-local-3",{"text":817},"因此，自托管是一种可能的主权控制手段，而不是整个技术栈主权的证明。",{},{"id":820,"data":821,"type":42,"tunes":823},"h-nvidia",{"text":822,"level":253},"供应商框架：NVIDIA的四大技术支柱",{},{"id":825,"data":826,"type":218,"tunes":828},"p-nvidia-1",{"text":827},"NVIDIA当前的主权AI技术指南围绕四大支柱组织该主题：数据\u002F基准、模型、硬件基础设施和框架。",{},{"id":830,"data":831,"type":218,"tunes":833},"p-nvidia-2",{"text":832},"这是一个有用的技术分解，尤其对于国家模型建设项目而言。NVIDIA还围绕本地数据集、特定国家的语言\u002F文化以及位于国境内部的基础设施来界定主权AI。",{},{"id":835,"data":836,"type":218,"tunes":838},"p-nvidia-3",{"text":837},"由于NVIDIA是主要的基础设施供应商，这应被解读为供应商视角，而非中立的全球标准。本文中更广泛的依赖\u002F控制模型还额外包括所有权、司法管辖、身份、供应链和退出权。",{},{"id":840,"data":841,"type":42,"tunes":843},"h-levels",{"text":842,"level":253},"实用的企业主权成熟度模型",{},{"id":845,"data":846,"type":226,"tunes":849},"levels-note",{"body":847,"title":848,"variant":233},"以下五个级别是本文提出的实用工程模型。它们\u003Cstrong>不是\u003C\u002Fstrong>欧盟委员会的CADA级别，也不是行业标准。","原创架构综合",{},{"id":851,"data":852,"type":397,"tunes":872},"levels-table",{"content":853,"stretched":43,"withHeadings":14},[854,857,860,863,866,869],[855,856],"级别","架构状态",[858,859],"S0 — 外部依赖","AI能力依赖于一个外部提供商，可移植性或控制力很低",[861,862],"S1 — 数据受控","组织控制源数据、访问和保留，但严重依赖外部模型\u002F平台服务",[864,865],"S2 — 可移植应用","数据和应用保持受控；模型\u002F提供商边界被抽象化，迁移在技术上现实可行",[867,868],"S3 — 受控运行时","关键推理、身份、密钥、检索和运营可以在组织控制或经批准的主权基础设施上运行",[870,871],"S4 — 战略韧性","关键栈具有经过测试的替代方案、供应链可见性、内部运营能力以及明确的连续性\u002F退出计划",{},{"id":874,"data":875,"type":218,"tunes":877},"p-levels-1",{"text":876},"工作负载默认不需要最高级别。所需的控制应取决于后果、监管、保密性、连续性需求和战略重要性。",{},{"id":879,"data":880,"type":218,"tunes":882},"p-levels-2",{"text":881},"成熟度模型的意义在于揭示依赖仍然存在于何处——而不是把主权变成营销徽章。",{},{"id":884,"data":885,"type":42,"tunes":887},"h-lockin",{"text":886,"level":253},"当退出不再可信时，供应商锁定就变成主权风险",{},{"id":889,"data":890,"type":218,"tunes":892},"p-lockin-1",{"text":891},"锁定并不总是坏事。团队接受专有依赖，是因为它们提供了速度、质量、支持或经济性。",{},{"id":894,"data":895,"type":218,"tunes":897},"p-lockin-2",{"text":896},"当依赖具有战略关键性，且组织无法在其所需的连续性窗口内现实地迁移时，它就成了主权问题。",{},{"id":899,"data":900,"type":218,"tunes":902},"p-lockin-3",{"text":901},"因此，退出需要被设计和测试，而不仅仅是在合同中描述。",{},{"id":904,"data":905,"type":42,"tunes":907},"h-exit",{"text":906,"level":253},"可信退出计划包含哪些内容",{},{"id":909,"data":910,"type":397,"tunes":949},"exit-table",{"content":911,"stretched":43,"withHeadings":14},[912,915,917,920,922,925,928,931,934,937,940,943,946],[913,914],"领域","退出证据",[429,916],"以可用、有文档记录的格式导出",[918,919],"提示词\u002F配置","存储在应用控制的源代码\u002F配置中",[432,921],"在需要时识别并评估替代模型",[923,924],"提供商 API","适配器边界限制提供商特定代码",[926,927],"RAG","语料库、元数据和索引可在提供商之外重建",[929,930],"身份","应用不永久耦合于单一外部身份控制平面",[932,933],"密钥","理解密钥所有权\u002F导出\u002F轮换模型",[935,936],"基础设施","部署可迁移至经批准的替代环境",[938,939],"可观测性","日志\u002F指标\u002F追踪可导出，且不仅限于提供商",[941,942],"运营知识","运行手册和人员能力存在于供应商之外",[944,945],"许可","迁移在法律上被允许",[947,948],"恢复","回退\u002F连续性路径已经过测试",{},{"id":951,"data":952,"type":42,"tunes":954},"h-portability",{"text":953,"level":253},"可移植性并不等同于主权——但它是主权最有力的机制之一",{},{"id":956,"data":957,"type":218,"tunes":959},"p-port-1",{"text":958},"一个能够迁移数据但无法复现模型行为的系统，可能仍被锁定。",{},{"id":961,"data":962,"type":218,"tunes":964},"p-port-2",{"text":963},"一个能够切换模型端点但无法迁移身份、检索数据或审计记录的系统，可能仍存在关键依赖。",{},{"id":966,"data":967,"type":218,"tunes":969},"p-port-3",{"text":968},"主权要求关键能力的可移植性，而不仅仅是导出某一个数据库。",{},{"id":971,"data":972,"type":42,"tunes":974},"h-standards",{"text":973,"level":253},"开放标准和协议边界降低替换成本",{},{"id":976,"data":977,"type":218,"tunes":979},"p-standards-1",{"text":978},"诸如普通 HTTP API、OAuth\u002FOIDC、OpenTelemetry 和可互操作的数据格式等标准，即使实现仍为专有，也能降低依赖。",{},{"id":981,"data":982,"type":218,"tunes":984},"p-standards-2",{"text":983},"AI 特定协议也能在选定的边界上提供帮助，但没有任何协议能够消除提供商特定行为或法律依赖。",{},{"id":986,"data":987,"type":218,"tunes":989},"p-standards-3",{"text":988},"标准的主权价值是实际的：它是否能让组织在不重写整个平台的情况下替换某个组件？",{},{"id":991,"data":992,"type":42,"tunes":994},"h-governance",{"text":993,"level":253},"主权是一项治理决策，而不仅仅是技术设计",{},{"id":996,"data":997,"type":218,"tunes":999},"p-gov-1",{"text":998},"组织必须决定哪些依赖是可接受的，以及谁可以批准它们。",{},{"id":1001,"data":1002,"type":218,"tunes":1004},"p-gov-2",{"text":1003},"AI 治理可以对模型\u002F提供商进行分类，按风险层级定义主权要求，要求退出证据，并为第三国或云使用设定条件。",{},{"id":1006,"data":1007,"type":218,"tunes":1009},"p-gov-3",{"text":1008},"因此，主权要求应出现在架构决策、采购、风险管理和运营测试中，而不仅仅出现在政策声明中。",{},{"id":1011,"data":1012,"type":42,"tunes":1014},"h-procurement",{"text":1013,"level":253},"采购在很大程度上决定了实际主权",{},{"id":1016,"data":1017,"type":218,"tunes":1019},"p-proc-1",{"text":1018},"合同可以规定数据使用、保留、支持、可移植性、模型弃用通知、子处理者、访问管辖权和终止协助。",{},{"id":1021,"data":1022,"type":218,"tunes":1024},"p-proc-2",{"text":1023},"但合同承诺不能替代技术可移植性。如果不存在替代实现，退出条款在运营上可能仍然薄弱。",{},{"id":1026,"data":1027,"type":218,"tunes":1029},"p-proc-3",{"text":1028},"面向主权的采购应同时评估法律控制和技术可替代性。",{},{"id":1031,"data":1032,"type":42,"tunes":1034},"h-hybrid",{"text":1033,"level":253},"混合AI可以比全本地设计更具主权性",{},{"id":1036,"data":1037,"type":218,"tunes":1039},"p-hybrid-1",{"text":1038},"主权有时被错误地等同于“一切都在本地运行”。",{},{"id":1041,"data":1042,"type":218,"tunes":1044},"p-hybrid-2",{"text":1043},"混合架构可以将敏感数据和权威知识保留在受控基础设施上，同时为经批准的任务使用外部前沿模型，并采用基于策略的路由和经过测试的回退方案。",{},{"id":1046,"data":1047,"type":218,"tunes":1049},"p-hybrid-3",{"text":1048},"如果可以在不丧失关键组织能力的情况下移除外部模型，那么混合平台可能比名义上本地化但锁定于单一专有运行时的技术栈拥有更强的实际主权。",{},{"id":1051,"data":1052,"type":42,"tunes":1054},"h-security",{"text":1053,"level":253},"主权不能替代安全",{},{"id":1056,"data":1057,"type":218,"tunes":1059},"p-sec-1",{"text":1058},"控制基础设施并不能自动使其安全。主权环境仍然需要漏洞管理、最小权限、事件响应、备份、安全供应链和可审计性。",{},{"id":1061,"data":1062,"type":218,"tunes":1064},"p-sec-2",{"text":1063},"如果检索或授权不正确，本地控制的模型仍可能将一个租户的数据泄露给另一个租户。",{},{"id":1066,"data":1067,"type":218,"tunes":1069},"p-sec-3",{"text":1068},"主权回答的是谁控制系统；安全回答的是该控制是否被安全地行使。",{},{"id":1071,"data":1072,"type":42,"tunes":1074},"h-regulation",{"text":1073,"level":253},"主权与监管合规是不同的",{},{"id":1076,"data":1077,"type":218,"tunes":1079},"p-reg-1",{"text":1078},"一个由欧盟托管、欧盟控制的AI技术栈仍然可能违反《人工智能法案》、GDPR或特定行业要求。",{},{"id":1081,"data":1082,"type":218,"tunes":1084},"p-reg-2",{"text":1083},"同样，一个合规的系统可以使用外部提供商，但仍然只有有限的技术主权。",{},{"id":1086,"data":1087,"type":218,"tunes":1089},"p-reg-3",{"text":1088},"监管和主权可以相互加强，但它们是独立的架构\u002F治理维度。",{},{"id":1091,"data":1092,"type":42,"tunes":1094},"h-implementation",{"text":1093,"level":253},"原始实现证据：面向主权的构建模块",{},{"id":1096,"data":1097,"type":226,"tunes":1100},"impl-note",{"body":1098,"title":1099,"variant":233},"以下项目展示了面向控制的架构模式，例如提供商抽象、本地推理、本地证据存储和明确的权限边界。它们\u003Cstrong>并非\u003C\u002Fstrong>作为国家主权AI技术栈、认证主权云或完整供应链独立性的证明来呈现。","证据边界",{},{"id":1102,"data":1103,"type":42,"tunes":1105},"h-client",{"text":1104,"level":252},"Aaasaasa AI Client：提供商、模型、运行时和权限是可分离的",{},{"id":1107,"data":1108,"type":218,"tunes":1110},"p-client-1",{"text":1109},"Aaasaasa AI Client将代理\u002F客户端、提供商、提供商特定模型、连接位置和权限策略分离。提供商可以包括Ollama、LM Studio\u002FOpenAI兼容服务和专用云路径。",{},{"id":1112,"data":1113,"type":218,"tunes":1115},"p-client-2",{"text":1114},"该架构明确区分本地运行时和本地推理：本地代理运行时可以使用云模型，而Direct Ollama聊天可以执行本地推理。",{},{"id":1117,"data":1118,"type":218,"tunes":1120},"p-client-3",{"text":1119},"这种分离与主权相关，因为提供商依赖成为一个显式配置层，而不是硬编码到业务应用程序中。",{},{"id":1122,"data":1123,"type":218,"tunes":1125},"p-client-4",{"text":1124},"中央权限也是应用\u002F会话策略，而不是模型的属性。即使模型\u002F提供商选择发生变化，这也能将操作权限保持在应用的控制之下。",{},{"id":1127,"data":1128,"type":42,"tunes":1130},"h-sot",{"text":1129,"level":252},"真相源研究引擎：本地证据权威",{},{"id":1132,"data":1133,"type":218,"tunes":1135},"p-sot-1",{"text":1134},"真相源研究引擎围绕持久化来源、快照、哈希、声明和来源追溯进行设计，而不是让模型输出成为权威。",{},{"id":1137,"data":1138,"type":218,"tunes":1140},"p-sot-2",{"text":1139},"这种模式在知识层与主权相关：即使推理模型可以被替换，组织证据仍然是一个独立受控的工件。",{},{"id":1142,"data":1143,"type":218,"tunes":1145},"p-sot-3",{"text":1144},"因此，该项目展示了一个有用的依赖原则：将权威数据\u002F证据与解释它的模型保持可分离。",{},{"id":1147,"data":1148,"type":397,"tunes":1174},"impl-table",{"content":1149,"stretched":43,"withHeadings":14},[1150,1153,1156,1159,1162,1165,1168,1171],[1151,1152],"已验证模式","主权相关性",[1154,1155],"多模型\u002F提供商路径","减少对单一推理提供商的硬编码依赖",[1157,1158],"本地 Ollama 推理","创建组织控制的推理选项",[1160,1161],"运行时位置与提供商分离","使真实依赖可见",[1163,1164],"中央应用权限配置文件","权限保持在模型\u002F供应商之外",[1166,1167],"持久化来源\u002F证据身份","知识在模型替换后仍然存在",[1169,1170],"云路径仍然可用","展示混合架构，而不是虚假的“仅本地”定位",[1172,1173],"没有经过验证的主权基础设施认证","防止过度声称全栈主权",{},{"id":1176,"data":1177,"type":42,"tunes":1179},"h-map",{"text":1178,"level":253},"构建主权依赖图",{},{"id":1181,"data":1182,"type":397,"tunes":1225},"map-table",{"content":1183,"stretched":43,"withHeadings":14},[1184,1190,1195,1200,1205,1209,1212,1216,1221],[1185,1186,1187,1188,1189],"层级","主要提供商\u002F依赖","控制状态","替代方案","退出时间",[432,1191,1192,1193,1194],"例如提供商\u002F模型快照","自有\u002F许可\u002F仅 API","指定替代方案","已测量",[1196,1197,1198,1199,1194],"推理","云\u002F本地运行时","直接\u002F合同","第二运行时",[1201,1202,1203,1204,1194],"嵌入\u002F重排序","模型\u002F运行时","直接\u002F外部","替代模型",[429,1206,1207,1208,1194],"数据库\u002F对象存储","直接\u002F提供商","可移植导出",[929,1210,1203,1211,1194],"IdP\u002FKMS","回退\u002F迁移路径",[935,1213,1214,1215,1194],"云\u002F硬件\u002F集群","自有\u002F租赁","替代环境",[1217,1218,1219,1220,1194],"工具集成","SaaS\u002F内部服务","外部\u002F内部","回退\u002F手动流程",[938,1222,1223,1224,1194],"日志\u002F追踪","可移植\u002F仅提供商","替代栈",{},{"id":1227,"data":1228,"type":218,"tunes":1230},"p-map-1",{"text":1229},"该表的价值不在于确切的列；它迫使战略依赖变得可见且可测试。",{},{"id":1232,"data":1233,"type":218,"tunes":1235},"p-map-2",{"text":1234},"然后，架构审查可以区分便利依赖与威胁连续性、机密性或监管目标的依赖。",{},{"id":1237,"data":1238,"type":42,"tunes":1240},"h-decision",{"text":1239,"level":253},"何时需要更强的人工智能主权",{},{"id":1242,"data":1243,"type":397,"tunes":1272},"decision-table",{"content":1244,"stretched":43,"withHeadings":14},[1245,1248,1251,1254,1257,1260,1263,1266,1269],[1246,1247],"驱动因素","为什么可能需要更强的控制",[1249,1250],"关键公共基础设施","连续性和战略自主可能超过提供商便利性",[1252,1253],"国防\u002F安全敏感工作负载","外国控制\u002F管辖权和供应链风险可能不可接受",[1255,1256],"高度机密的企业数据","数据\u002F模型\u002F提供商控制可能需要更强的保证",[1258,1259],"长期工业平台","退出和硬件\u002F软件生命周期在多年内很重要",[1261,1262],"受监管的公共采购","可能需要正式的主权保证级别",[1264,1265],"国家语言\u002F文化模型","本地数据集\u002F模型控制可以保持战略能力",[1267,1268],"提供商集中风险","替代模型\u002F运行时路径提高韧性",[1270,1271],"正常低风险生产力使用","最大主权可能不必要且不经济",{},{"id":1274,"data":1275,"type":218,"tunes":1277},"p-decision-1",{"text":1276},"主权应当适度。目标不是在所有地方最大化本地所有权；而是保留足够的控制以应对后果和威胁模型。",{},{"id":1279,"data":1280,"type":42,"tunes":1282},"h-failures",{"text":1281,"level":253},"常见的主权人工智能失败模式",{},{"id":1284,"data":1285,"type":397,"tunes":1326},"failures-table",{"content":1286,"stretched":43,"withHeadings":14},[1287,1290,1293,1296,1299,1302,1305,1308,1311,1314,1317,1320,1323],[1288,1289],"失败模式","实际失败之处",[1291,1292],"“数据留在欧洲，因此主权”","位置与所有权、管辖权和供应链控制混淆",[1294,1295],"一个专有模型 API，没有经过测试的替代方案","关键推理依赖于一个外部行为者",[1297,1298],"开放权重模型，专有锁定运行时","模型开放性未提供完整的操作控制",[1300,1301],"自托管推理，仅云身份\u002FKMS","控制平面仍然依赖外部",[1303,1304],"本地数据但仅提供商向量\u002F索引格式","知识层无法干净迁移",[1306,1307],"多提供商抽象但没有评估","切换在技术上可行但在行为上不安全",[1309,1310],"有退出条款但没有迁移测试","合同可移植性不是操作可移植性",[1312,1313],"外国硬件被视为非主权的证明","主权被错误地定义为绝对自给自足",[1315,1316],"主权标签没有定义主体\u002F范围","没有人知道指的是谁的控制或哪些依赖",[1318,1319],"内部所有权但没有操作技能","系统无法独立维护",[1321,1322],"开源但没有维护能力","源代码可用性存在，但实际控制不存在",[1324,1325],"气隙被视为主权","连接隔离与依赖控制混淆",{},{"id":1328,"data":1329,"type":42,"tunes":1331},"h-misconceptions",{"text":1330,"level":253},"常见误解",{},{"id":1333,"data":1334,"type":397,"tunes":1369},"misconceptions-table",{"content":1335,"stretched":43,"withHeadings":14},[1336,1339,1342,1345,1348,1351,1354,1357,1360,1363,1366],[1337,1338],"误解","纠正",[1340,1341],"“主权人工智能意味着每个组件都必须国产。”","主权通常关乎有效控制、韧性和减少战略依赖，而不是完全自给自足。",[1343,1344],"“欧盟数据驻留等于欧盟主权。”","驻留是一个保证层；所有权、管辖权和供应链控制可以更进一步。",[1346,1347],"“开源等于主权。”","开源改善了控制和可移植性，但并未消除基础设施、硬件或操作依赖。",[1349,1350],"“自托管等于主权。”","自托管控制位置\u002F运行时，但不自动控制许可证、芯片、身份、供应链或更新路径。",[1352,1353],"“气隙等于主权。”","气隙控制连接性；主权控制更广泛的依赖链。",[1355,1356],"“私有 AI 等于主权 AI。”","隐私侧重于受保护的处理；主权侧重于战略\u002F操作控制。",[1358,1359],"“多云等于主权。”","两个云可能仍然共享相同的管辖权、技术依赖或专有控制平面。",[1361,1362],"“使用欧洲公司保证主权。”","公司位置有帮助，但技术、法律和供应链控制仍需审查。",[1364,1365],"“提供商抽象使每个模型都可替换。”","行为差异需要在路由或迁移之前进行评估。",[1367,1368],"“主权只适用于政府。”","该术语通常是国家\u002F地区的，但企业也对关键 AI 依赖有有意义的主权要求。",{},{"id":1371,"data":1372,"type":42,"tunes":1374},"h-design",{"text":1373,"level":253},"实用的主权人工智能设计序列",{},{"id":1376,"data":1377,"type":331,"tunes":1416},"design-flow",{"steps":1378,"title":1415,"orientation":330},[1379,1382,1385,1388,1391,1394,1397,1400,1403,1406,1409,1412],{"label":1380,"description":1381},"1. 定义主权主体","说明控制权是要求用于企业、公共机构、国家、欧盟领域还是其他权威机构。",{"label":1383,"description":1384},"2. 定义关键能力","确定哪些AI功能不能丢失或受外部控制。",{"label":1386,"description":1387},"3. 分类数据和司法管辖区","映射数据位置、法律控制、保留和允许的处理。",{"label":1389,"description":1390},"4. 映射模型依赖关系","记录权重\u002FAPI所有权、许可证、版本、微调和替换选项。",{"label":1392,"description":1393},"5. 映射基础设施和控制平面","记录计算、云、密钥、身份、网络和操作员访问。",{"label":1395,"description":1396},"6. 映射软件和供应链","识别专有运行时、开源、软件包、注册表、更新和关键供应商。",{"label":1398,"description":1399},"7. 选择控制机制","在合理的情况下应用本地推理、区域提供商、开放标准、开源或更强的所有权。",{"label":1401,"description":1402},"8. 构建提供商\u002F模型抽象","在可移植性重要的地方，避免业务应用程序硬编码单一供应商。",{"label":1404,"description":1405},"9. 独立保存权威数据","确保知识、来源和业务记录在模型替换后仍然存在。",{"label":1407,"description":1408},"10. 定义退出标准","为关键依赖设置最大可接受的迁移\u002F连续性时间。",{"label":1410,"description":1411},"11. 测试替换和恢复","运行现实的故障转移\u002F迁移演练，而不是信任架构图。",{"label":1413,"description":1414},"12. 定期重新评估","供应商所有权、政策、价格、法律、模型支持和技术生态系统会发生变化。","从战略依赖向外设计",{},{"id":1418,"data":1419,"type":42,"tunes":1421},"h-checklist",{"text":1420,"level":253},"主权AI架构检查清单",{},{"id":1423,"data":1424,"type":397,"tunes":1477},"checklist-table",{"content":1425,"stretched":43,"withHeadings":14},[1426,1429,1432,1435,1438,1441,1444,1447,1450,1453,1456,1459,1462,1465,1468,1471,1474],[1427,1428],"问题","预期证据",[1430,1431],"对谁而言是主权？","指定的权威机构\u002F司法管辖区\u002F组织",[1433,1434],"哪些能力是战略性的？","关键性分类",[1436,1437],"数据在哪里处理\u002F存储？","经验证的数据流图",[1439,1440],"谁可以在法律上\u002F技术上访问数据？","司法管辖区 + IAM + 操作员模型",[1442,1443],"谁控制模型访问\u002F权重？","许可证\u002F提供商\u002F模型所有权记录",[1445,1446],"模型可以替换吗？","评估的替代方案和迁移路径",[1448,1449],"谁控制推理计算？","基础设施\u002F控制平面所有权",[1451,1452],"谁控制身份和密钥？","IAM\u002FKMS 保管模型",[1454,1455],"哪些组件是专有的？","软件依赖清单",[1457,1458],"哪些依赖是开放\u002F可移植的？","标准\u002F源代码\u002F许可证据",[1460,1461],"还剩下哪些第三国依赖？","明确的依赖登记册",[1463,1464],"在提供商丢失期间关键操作能否继续？","连续性\u002F回退测试",[1466,1467],"数据和知识能否导出\u002F重建？","可移植性\u002F重建程序",[1469,1470],"员工能否在没有供应商干预的情况下操作平台？","运行手册\u002F技能\u002F操作证据",[1472,1473],"退出需要多长时间？","衡量的迁移目标",[1475,1476],"什么变化会触发重新评估？","所有权、法律、模型、提供商和供应链审查触发条件",{},{"id":1479,"data":1480,"type":42,"tunes":1482},"h-limitations",{"text":1481,"level":253},"限制和权衡",{},{"id":1484,"data":1485,"type":218,"tunes":1487},"p-limit-1",{"text":1486},"更强的主权可能会增加成本，因为必须直接或在受限的提供商生态系统内维护更多的基础设施、运营和专业知识。",{},{"id":1489,"data":1490,"type":218,"tunes":1492},"p-limit-2",{"text":1491},"对于某些工作负载，本地或区域替代方案可能落后于前沿模型能力。因此，主权政策应支持基于风险的路由，而不是强制将较弱的模型用于每项任务。",{},{"id":1494,"data":1495,"type":218,"tunes":1497},"p-limit-3",{"text":1496},"在现代半导体和软件供应链中，绝对独立很少现实。架构应识别并减少不可接受的依赖，而不是声称不可能的自给自足。",{},{"id":1499,"data":1500,"type":218,"tunes":1502},"p-limit-4",{"text":1501},"如果采购规则变得过于僵化，主权也可能减少生态系统选择。当前的欧盟政策明确试图在加强自主权的同时保留开放市场和伙伴关系。",{},{"id":1504,"data":1505,"type":218,"tunes":1507},"p-limit-5",{"text":1506},"如果没有团队能够修补、监控或迁移系统，那么系统在纸面上可能是“主权”的，但在操作上却很脆弱。",{},{"id":1509,"data":1510,"type":42,"tunes":1512},"h-change",{"text":1511,"level":253},"什么会改变这个答案？",{},{"id":1514,"data":1515,"type":218,"tunes":1517},"p-change-1",{"text":1516},"欧盟提出的CADA主权框架可能会在立法过程中演变，因此在采购或法律决策之前应重新检查确切的保证级别要求。",{},{"id":1519,"data":1520,"type":218,"tunes":1522},"p-change-2",{"text":1521},"提供商所有权、模型许可、地缘政治条件和半导体供应链可能会在没有任何应用程序代码更改的情况下实质性改变主权评估。",{},{"id":1524,"data":1525,"type":218,"tunes":1527},"p-change-3",{"text":1526},"稳定的架构原则是，主权取决于对关键依赖的有效控制和可信替代方案，而不是一个地理或品牌属性。",{},{"id":1529,"data":1530,"type":42,"tunes":1532},"h-related",{"text":1531,"level":253},"相关规范知识",{},{"id":1534,"data":1535,"type":218,"tunes":1537},"p-related-1",{"text":1536},"主权AI位于几个部署和控制概念之上：私有AI保护敏感处理，气隙AI隔离网络域，AI治理分配决策权，LLMOps操作模型\u002F提供商变更。",{},{"id":1539,"data":1540,"type":218,"tunes":1542},"p-related-2",{"text":1541},"提供商抽象和模型路由是减少依赖的实用机制，而真相源架构使组织证据独立于任何单一模型。",{},{"id":1544,"data":1545,"type":218,"tunes":1547},"p-related-3",{"text":1546},"企业AI架构决定了这些主权要求属于平台、应用程序、身份、基础设施和运营的哪个位置。",{},{"id":1549,"data":1550,"type":752,"tunes":1555},"ref-avb",{"url":1551,"title":1552,"excerpt":1553,"ctaLabel":1554},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","答案有效性边界：相关性与可靠AI答案之间缺失的层","对基础设施的主权并不能使答案成真。可靠的知识仍然需要证据、权威、范围和有效性控制。","阅读答案有效性边界",{},{"id":1557,"data":1558,"type":752,"tunes":1563},"ref-memory",{"url":1559,"title":1560,"excerpt":1561,"ctaLabel":1562},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI Agent 记忆不是 RAG：如何分离记忆、检索、状态和上下文","将状态、知识、检索和模型上下文分开可提高可移植性，并减少对单一 AI 提供商的耦合。","阅读架构文章",{},{"id":1565,"data":1566,"type":42,"tunes":1568},"h-faq",{"text":1567,"level":253},"常见问题",{},{"id":1570,"data":1571,"type":1570,"tunes":1614},"faq",{"items":1572,"title":1613},[1573,1577,1581,1585,1589,1593,1597,1601,1605,1609],{"id":1574,"answer":1575,"question":1576},"faq1","主权 AI 是指国家、公共机构或组织等特定权威实体对关键 AI 数据、模型、基础设施、软件、运营和依赖关系保持有效控制的能力。","什么是主权 AI？",{"id":1578,"answer":1579,"question":1580},"faq2","不。数据主权只是其中一个组成部分。AI 主权还包括模型控制、算力、软件供应链、身份、运营者、司法管辖以及替换关键提供商的能力。","主权 AI 等同于数据主权吗？",{"id":1582,"answer":1583,"question":1584},"faq3","不。如果所需控制水平、法律保障、可移植性和连续性得以保持，主权架构可以使用外部或云服务。","主权 AI 是否要求所有内容都在本地托管？",{"id":1586,"answer":1587,"question":1588},"faq4","不。开源或开放权重可以提高控制和可移植性，但在依赖关系和许可可接受的情况下，仍可使用专有组件。","主权 AI 是否要求开源模型？",{"id":1590,"answer":1591,"question":1592},"faq5","不。自托管控制推理位置，但仍可能依赖外部身份、专有运行时、外国硬件、许可证或更新基础设施。","自托管 AI 是否自动具备主权？",{"id":1594,"answer":1595,"question":1596},"faq6","气隙 AI 涉及物理\u002F网络隔离和受控传输。主权 AI 涉及对整个依赖链的有效控制。两者可以独立存在。","主权 AI 与气隙 AI 有何区别？",{"id":1598,"answer":1599,"question":1600},"faq7","有可能，取决于所需的主权级别以及谁控制位置、提供商所有权、管理访问、密钥、供应链、司法管辖和退出。","云 AI 服务能否具备主权？",{"id":1602,"answer":1603,"question":1604},"faq8","它减少了应用程序对单一模型提供商的耦合，并创建了技术迁移路径，尽管行为差异仍需评估。","为什么提供商抽象对主权很重要？",{"id":1606,"answer":1607,"question":1608},"faq9","映射关键依赖关系，并测试如果提供商、司法管辖区或供应链依赖变得不可接受，数据、模型、工作负载和运营能否在所需时间内继续或迁移。","如何衡量实际 AI 主权？",{"id":1610,"answer":1611,"question":1612},"faq10","认为主权是单一属性，例如欧盟托管、本地推理、开源或气隙。实际上，它是一个多层控制和依赖问题。","关于主权 AI 最大的误解是什么？","主权 AI 常见问题",{},{"id":1616,"data":1617,"type":42,"tunes":1619},"h-glossary",{"text":1618,"level":253},"术语表",{},{"id":1621,"data":1622,"type":1621,"tunes":1672},"glossary",{"title":1623,"entries":1624},"关键主权 AI 术语",[1625,1628,1632,1636,1640,1644,1648,1652,1656,1660,1664,1668],{"term":791,"anchor":1626,"definition":1627},"sovereign-ai","设计为使特定权威实体对关键数据、模型、基础设施、运营和依赖关系保持有效控制的 AI 能力。",{"term":1629,"anchor":1630,"definition":1631},"技术主权","tech-sovereignty","通过控制关键技术、数据和基础设施，同时减少战略性外部依赖，在数字领域独立行动的能力。",{"term":1633,"anchor":1634,"definition":1635},"战略依赖","strategic-dependency","其丧失、控制或变化可能实质性威胁连续性、安全性、自主权或政策目标的外部依赖。",{"term":1637,"anchor":1638,"definition":1639},"数据驻留","data-residency","描述数据物理或逻辑存储\u002F处理位置的要求；比主权范围更窄。",{"term":1641,"anchor":1642,"definition":1643},"数据主权","data-sovereignty","在适用法律、组织和司法管辖权威下对数据的控制。",{"term":1645,"anchor":1646,"definition":1647},"模型主权","model-sovereignty","对模型访问、权重、许可、修改、版本控制、部署和替换的控制程度。",{"term":1649,"anchor":1650,"definition":1651},"基础设施主权","infrastructure-sovereignty","对关键工作负载所需的算力、托管、控制平面、运营和基础设施司法管辖的控制。",{"term":1653,"anchor":1654,"definition":1655},"运营主权","operational-sovereignty","在不对外部运营者产生不可接受依赖的情况下部署、维护、观察、恢复和迁移系统的能力。",{"term":1657,"anchor":1658,"definition":1659},"提供商抽象","provider-abstraction","将业务逻辑与提供商特定 API 分离的应用程序架构，以便更安全地更改模型\u002F提供商依赖。",{"term":1661,"anchor":1662,"definition":1663},"退出策略","exit-strategy","将数据、工作负载和运营能力从外部依赖中移出的可测试计划。",{"term":1665,"anchor":1666,"definition":1667},"供应链主权","supply-chain-sovereignty","在关键软件、模型、硬件和更新依赖中的透明度、控制和可替代性程度。",{"term":1669,"anchor":1670,"definition":1671},"战略自主","strategic-autonomy","在没有不可接受的外部约束或依赖的情况下做出和执行关键决策的能力。",{},{"id":1674,"data":1675,"type":42,"tunes":1677},"h-conclusion",{"text":1676,"level":253},"结论",{},{"id":1679,"data":1680,"type":218,"tunes":1682},"p-conclusion-1",{"text":1681},"主权 AI 不是一个产品类别，也不是一个部署位置。它是一个架构和治理目标：对重要的 AI 能力保持有效控制。",{},{"id":1684,"data":1685,"type":218,"tunes":1687},"p-conclusion-2",{"text":1686},"最强的主权设计将数据与模型分离，将业务应用与提供商分离，将权威与模型能力分离，将关键运营与不可替代的外部依赖分离。",{},{"id":1689,"data":1690,"type":218,"tunes":1692},"p-conclusion-3",{"text":1691},"最简短的可靠规则是：主权不是由模型运行在哪里证明的；而是由谁控制关键堆栈、保留哪些依赖关系，以及当这些依赖变得不可接受时组织能否继续或改变方向来证明的。",{},{"id":1694,"data":1695,"type":42,"tunes":1697},"h-sources",{"text":1696,"level":253},"主要和当前来源",{},{"id":1699,"data":1700,"type":218,"tunes":1702},"p-sources-note",{"text":1701},"以下来源区分了欧盟官方技术主权政策、当前拟议的云\u002FAI 主权保证级别、欧洲算力倡议以及供应商技术框架。本文中的企业主权成熟度模型明确为原创综合，并非欧盟或行业标准。",{},{"id":1704,"data":1705,"type":1711,"tunes":1712},"src-eu-sovereignty",{"link":1706,"meta":1707},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Feu-tech-sovereignty",{"image":1708,"title":1709,"description":1710},{"url":767},"欧盟委员会 — 加强欧洲技术主权","欧盟当前对技术主权的定义：通过控制关键技术、数据和基础设施，同时减少对非欧盟提供商的依赖，实现独立行动。","linkTool",{},{"id":1714,"data":1715,"type":1711,"tunes":1721},"src-eu-package",{"link":1716,"meta":1717},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Flibrary\u002Fcommunication-european-tech-sovereignty-accompanied-eu-open-source-strategy",{"image":1718,"title":1719,"description":1720},{"url":767},"欧盟委员会 — 关于欧洲技术主权的通讯","2026 年政策方案，涵盖从芯片到基础设施、软件、云和 AI 的技术价值链。",{},{"id":1723,"data":1724,"type":1711,"tunes":1730},"src-cada",{"link":1725,"meta":1726},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcloud-and-ai-development-act",{"image":1727,"title":1728,"description":1729},{"url":767},"欧盟委员会 — 云和 AI 发展法案","当前拟议的欧盟框架，定义了位置、第三国独立性、所有权\u002F控制权和软件供应链控制四个云\u002FAI 主权保证级别。",{},{"id":1732,"data":1733,"type":1711,"tunes":1739},"src-open-source",{"link":1734,"meta":1735},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffactpages\u002Feu-open-source-strategy",{"image":1736,"title":1737,"description":1738},{"url":767},"欧盟委员会 — 欧盟开源战略","当前政策将开源与更大的控制、更低的锁定、安全性、复用和技术主权联系起来。",{},{"id":1741,"data":1742,"type":1711,"tunes":1748},"src-ai-factories",{"link":1743,"meta":1744},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fai-factories",{"image":1745,"title":1746,"description":1747},{"url":767},"欧盟委员会 — AI 工厂","当前欧盟 AI 算力基础设施倡议，将 AI 工厂和超级工厂与欧洲能力和技术主权联系起来。",{},{"id":1750,"data":1751,"type":1711,"tunes":1757},"src-gigafactories",{"link":1752,"meta":1753},"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fnews\u002Feu-launches-ai-gigafactories-call-boost-europes-computing-capacity-and-unlock-more-eu30-billion",{"image":1754,"title":1755,"description":1756},{"url":767},"欧盟委员会 — AI 超级工厂征集","2026 年倡议，旨在扩大欧洲 AI 算力、韧性和战略自主，基础设施在欧洲建设和运营。",{},{"id":1759,"data":1760,"type":1711,"tunes":1766},"src-eurohpc",{"link":1761,"meta":1762},"https:\u002F\u002Fwww.eurohpc-ju.europa.eu\u002Feurohpc-joint-undertaking-launches-ai-gigafactories-call-2026-07-30_en",{"image":1763,"title":1764,"description":1765},{"url":767},"EuroHPC JU — AI 超级工厂","EuroHPC 当前对大规模主权 AI 计算基础设施和技术独立的框架。",{},{"id":1768,"data":1769,"type":1711,"tunes":1775},"src-nvidia",{"link":1770,"meta":1771},"https:\u002F\u002Fwww.nvidia.com\u002Fen-us\u002Flp\u002Findustries\u002Fglobal-public-sector\u002Fsovereign-ai-technical-overview\u002F",{"image":1772,"title":1773,"description":1774},{"url":767},"NVIDIA — 构建主权AI模型","围绕数据\u002F基准、模型、硬件基础设施和框架组织的供应商技术框架；可作为行业视角参考，并非通用标准。",{},"2.31","主权人工智能关乎对模型、数据、基础设施、软件、运营和战略依赖的有效控制——而不仅仅是人工智能模型托管在哪里。","\u002Fuploads\u002F2026\u002F10\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies-1791488833132-niy85x.webp","sovereign-ai-control-of-models-data-infrastructure-and-dependencies-1791488833132-niy85x","PUBLISHED","2026-10-08T15:45:00.000Z","2026-10-08T19:45:54.313Z","2026-10-08T20:05:33.661Z",{"en":1785,"de":1786,"sr":1787,"es":1788,"fr":1789,"it":1790,"ru":1791,"zh":1792},"\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u002Fde\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u002Fsr\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u002Fes\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u002Ffr\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u002Fit\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u002Fru\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies","\u002Fzh\u002Fblog\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies",[1794,1798,1802,1806],{"id":1795,"name":1796,"slug":1797},84,"策略与数据边界","policy-and-data",{"id":1799,"name":1800,"slug":1801},57,"数据边界","data-boundaries",{"id":1803,"name":1804,"slug":1805},80,"访问与身份","access-and-identity",{"id":1807,"name":1808,"slug":1809},49,"控制与证据","controls",{"id":1811,"login":1812,"email":1813,"displayName":1814},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1816,3134],{"lang":1817,"title":1818,"content":1819,"contentJson":1820,"excerpt":3133},"en","Sovereign AI: Control of Models, Data, Infrastructure and Dependencies","{\"time\":1791488834259,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereign AI is the ability of a country, public institution, organization or other defined authority to retain effective control over the AI systems it depends on: their data, models, infrastructure, software stack, operators, legal exposure and strategic dependencies. Sovereignty is not the same as hosting data in one country, running an open model, using an EU cloud provider or disconnecting a server from the internet. Those can support sovereignty, but the defining question is whether the organization can make, enforce and preserve critical AI decisions without unacceptable dependence on an external actor.\"},\"tunes\":{}},{\"id\":\"direct\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"A practical sovereign-AI architecture controls more than model location. It asks:\u003Cbr>\u003Cbr>\u003Cstrong>Who controls the data? Who controls the model? Who controls the compute? Who controls the software stack? Who holds the keys? Which law and corporate control apply? Which supplier can disable, change or price the system? Can the workload be moved if that supplier becomes unacceptable?\u003C\u002Fstrong>\u003Cbr>\u003Cbr>Sovereignty therefore exists across a dependency chain, not as a single yes\u002Fno property.\"},\"tunes\":{}},{\"id\":\"not-standard\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"The term is not one universal technical standard\",\"body\":\"“Sovereign AI” is used by governments, vendors and industry with overlapping but non-identical meanings. The European Commission currently defines broader \u003Cstrong>tech sovereignty\u003C\u002Fstrong> as the ability to act independently by developing and controlling key technologies, data and infrastructure while reducing reliance on non-EU providers. NVIDIA's vendor framing emphasizes local data, models, infrastructure and frameworks. This article uses an explicit architectural synthesis of those control dimensions rather than presenting one vendor definition as a universal standard.\"},\"tunes\":{}},{\"id\":\"not-autarky\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Sovereignty does not require technological autarky\",\"body\":\"The objective is not necessarily to eliminate every foreign component. Current EU policy explicitly combines stronger autonomy with markets that remain open to partners. A sovereign architecture reduces \u003Cstrong>strategic dependency\u003C\u002Fstrong>: dependencies that can remove effective choice, expose critical data\u002Fcontrol to unwanted jurisdiction or make continuity impossible without one external supplier.\"},\"tunes\":{}},{\"id\":\"current\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"On 3 June 2026, the European Commission adopted its Tech Sovereignty package and proposed the Cloud and AI Development Act (CADA). The Commission's current CADA framework describes four cloud\u002FAI sovereignty assurance levels ranging from EU data location, through independence from third countries and software-supply-chain transparency, to EU ownership\u002Fcontrol and, at the highest level, full supply-chain control without third-country interference. This is strong evidence that sovereignty is broader than data residency.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What sovereign AI really means\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty is fundamentally about decision power under dependency. An organization may technically own its data yet still depend on a provider that controls model access, pricing, identity, encryption keys, software updates or the only available inference endpoint.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A sovereign architecture therefore asks which dependencies are acceptable, which must remain substitutable and which capabilities must be controlled directly.\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The European Commission's current tech-sovereignty definition is useful because it combines two ideas: develop\u002Fcontrol critical technology and reduce external reliance. That is closer to engineering reality than treating sovereignty as simple geographic hosting.\"},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Consider two companies that both store customer documents in Germany.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Company A sends every prompt and document to one proprietary cloud model. The model version can change, the provider controls the inference service and keys, and the application has no tested fallback.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Company B also uses a cloud model, but keeps its data and retrieval layer under its own control, can route to a locally hosted open-weight model, owns application keys and identity, records provider\u002Fmodel dependencies and has a tested migration path.\"},\"tunes\":{}},{\"id\":\"p-simple-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"Both may satisfy a data-location requirement. Company B has materially more operational sovereignty because it retains more meaningful choices if the external provider becomes unavailable or unacceptable.\"},\"tunes\":{}},{\"id\":\"simple-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"A practical sovereignty assessment\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Define the authority\",\"description\":\"Specify whose sovereignty matters: organization, public administration, country, EU, business unit or regulated environment.\"},{\"label\":\"2. Identify critical AI capabilities\",\"description\":\"List models, inference, retrieval, data, tools, identity, storage and operational services.\"},{\"label\":\"3. Map dependencies\",\"description\":\"For each capability, identify supplier, jurisdiction, ownership, licensing, update path and technical lock-in.\"},{\"label\":\"4. Classify control\",\"description\":\"Determine what is directly controlled, contractually controlled, substitutable or effectively external.\"},{\"label\":\"5. Identify unacceptable dependencies\",\"description\":\"Find dependencies that can block continuity, expose protected data or remove strategic choice.\"},{\"label\":\"6. Add alternatives or stronger ownership\",\"description\":\"Use open standards, local models, portable data, internal keys, multi-provider routing or sovereign infrastructure where justified.\"},{\"label\":\"7. Test exit and continuity\",\"description\":\"Prove that the organization can migrate, fail over or continue critical operation under the defined sovereignty requirement.\"},{\"label\":\"8. Reassess over time\",\"description\":\"Supplier ownership, law, model licenses, infrastructure and geopolitical conditions can change.\"}]},\"tunes\":{}},{\"id\":\"h-stops\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"At national or EU scale, sovereign AI includes far more than one enterprise deployment: semiconductor supply, high-performance computing, research capacity, talent, datasets, cloud infrastructure, model development and industrial ecosystems.\"},\"tunes\":{}},{\"id\":\"p-stops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"At enterprise scale, the same concept becomes narrower: which AI dependencies must the organization itself control or be able to replace?\"},\"tunes\":{}},{\"id\":\"p-stops-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture should always state the sovereignty subject and scope. “Sovereign AI” without saying sovereign for whom, over what and against which dependency is too vague for engineering.\"},\"tunes\":{}},{\"id\":\"h-eu\",\"type\":\"header\",\"data\":{\"text\":\"Current European tech-sovereignty framing\",\"level\":2},\"tunes\":{}},{\"id\":\"p-eu-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The European Commission currently defines tech sovereignty as Europe's ability to act independently in the digital world by developing and controlling key technologies, data and infrastructure while reducing reliance on non-EU providers.\"},\"tunes\":{}},{\"id\":\"p-eu-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The 2026 Tech Sovereignty package explicitly spans the value chain from chips to infrastructure, software, cloud and AI. This matters because an AI system can be dependent below the model layer: accelerators, hypervisors, container platforms, cloud control planes or proprietary libraries can all become strategic dependencies.\"},\"tunes\":{}},{\"id\":\"p-eu-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The Commission is also using AI Factories and AI Gigafactories to expand European compute capacity. Current AI Gigafactory policy describes infrastructure built and operated in Europe to strengthen resilience, strategic autonomy and the ability to develop advanced AI on European infrastructure.\"},\"tunes\":{}},{\"id\":\"h-cada\",\"type\":\"header\",\"data\":{\"text\":\"CADA makes sovereignty a graded assurance problem\",\"level\":2},\"tunes\":{}},{\"id\":\"cada-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Current proposed CADA level\",\"Control signal\"],[\"Level 1\",\"Data is processed and stored in infrastructure located in the EU\"],[\"Level 2\",\"Provider demonstrates independence from third countries and transparency over the software supply chain\"],[\"Level 3\",\"Provider is EU-owned and controlled, with additional sovereignty criteria; recognition paths can exist for third-country providers\"],[\"Level 4\",\"Full transparency and control over the software supply chain with no third-country interference\"]]},\"tunes\":{}},{\"id\":\"p-cada-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The proposed CADA framework is especially useful conceptually because it rejects a binary sovereignty label. It treats sovereignty as increasing assurance across location, legal\u002Fcorporate control and supply-chain control.\"},\"tunes\":{}},{\"id\":\"p-cada-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"It is also a proposed EU regulatory\u002Fprocurement framework, not a universal global technical standard. The four levels should not be copied mechanically into private architecture without understanding the actual risk model.\"},\"tunes\":{}},{\"id\":\"residency-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Data residency is only the first layer\",\"body\":\"A workload can process data entirely inside the EU and still depend on a third-country-controlled provider, proprietary software stack, foreign key-management plane or non-substitutable model API. Residency answers \u003Cstrong>where\u003C\u002Fstrong>; sovereignty also asks \u003Cstrong>who controls\u003C\u002Fstrong> and \u003Cstrong>what happens if dependency terms change\u003C\u002Fstrong>.\"},\"tunes\":{}},{\"id\":\"h-dimensions\",\"type\":\"header\",\"data\":{\"text\":\"The main control dimensions of sovereign AI\",\"level\":2},\"tunes\":{}},{\"id\":\"dimensions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Dimension\",\"Sovereignty question\"],[\"Data\",\"Who owns, stores, classifies, moves, deletes and authorizes use of the data?\"],[\"Models\",\"Who controls model weights\u002Faccess, versioning, licenses, fine-tuning and retirement?\"],[\"Compute\",\"Where does training\u002Finference run and who controls the capacity?\"],[\"Cloud\u002Finfrastructure\",\"Who owns and operates the control plane, hardware and hosting layer?\"],[\"Software stack\",\"Can core runtime\u002Forchestration components be inspected, replaced or self-operated?\"],[\"Identity &amp; keys\",\"Who controls identities, credentials, encryption keys and policy enforcement?\"],[\"Network\",\"Which external paths are required for normal operation?\"],[\"Operations\",\"Who can administer, patch, disable, observe and recover the system?\"],[\"Supply chain\",\"Which vendors, packages, chips, models and registries can interrupt or compromise the system?\"],[\"Jurisdiction\",\"Which legal authorities can compel access or affect service\u002Fcontrol?\"],[\"Skills &amp; know-how\",\"Can the organization operate or migrate the system without one supplier's personnel?\"],[\"Exit \u002F portability\",\"Can data, models and workloads move to an acceptable alternative in realistic time?\"]]},\"tunes\":{}},{\"id\":\"h-data\",\"type\":\"header\",\"data\":{\"text\":\"Data sovereignty is necessary but not sufficient\",\"level\":2},\"tunes\":{}},{\"id\":\"p-data-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Data sovereignty concerns control over data according to applicable law, organizational authority and policy. Location can be important, but control also includes encryption, access, retention, reuse, training rights and deletion.\"},\"tunes\":{}},{\"id\":\"p-data-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"If an external model provider is contractually allowed to retain prompts or train on them, the sovereignty risk differs from a provider that processes data transiently under stronger restrictions — even when both endpoints are in the same region.\"},\"tunes\":{}},{\"id\":\"p-data-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"RAG adds derived artifacts such as chunks, embeddings, indexes and cached answers. Sovereign data control should include those derivatives, not only original documents.\"},\"tunes\":{}},{\"id\":\"h-models\",\"type\":\"header\",\"data\":{\"text\":\"Model sovereignty is about control and substitutability\",\"level\":2},\"tunes\":{}},{\"id\":\"p-model-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A proprietary API model can be extremely capable while providing limited control over weights, training process, model retirement or future pricing.\"},\"tunes\":{}},{\"id\":\"p-model-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An open-weight model can provide more operational control because weights can be hosted independently, but the exact license, tokenizer, training provenance, architecture, fine-tuning rights and runtime requirements still matter.\"},\"tunes\":{}},{\"id\":\"p-model-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Model sovereignty is therefore not equivalent to “open model.” The relevant questions are which model artifacts can be possessed, modified, evaluated, deployed and replaced under the required legal and technical conditions.\"},\"tunes\":{}},{\"id\":\"h-open\",\"type\":\"header\",\"data\":{\"text\":\"Open source is a sovereignty tool, not sovereignty itself\",\"level\":2},\"tunes\":{}},{\"id\":\"p-open-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The EU Open Source Strategy explicitly connects open source with more control, less lock-in, stronger security and reusable digital building blocks.\"},\"tunes\":{}},{\"id\":\"p-open-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Open source can reduce dependency because source code can be inspected, modified and operated by alternative suppliers. Open standards can also reduce migration cost.\"},\"tunes\":{}},{\"id\":\"p-open-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"But open software running only on one non-substitutable cloud control plane can still leave major dependencies. Likewise, open model weights on hardware that cannot be sourced, supported or operated independently may provide only partial sovereignty.\"},\"tunes\":{}},{\"id\":\"h-infra\",\"type\":\"header\",\"data\":{\"text\":\"Infrastructure sovereignty goes below the cloud region\",\"level\":2},\"tunes\":{}},{\"id\":\"p-infra-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The phrase “hosted in Europe” does not fully describe infrastructure control. Relevant questions include corporate ownership, administrative access, key control, legal jurisdiction, support personnel, software supply chain and whether the service can continue if a foreign parent or supplier changes terms.\"},\"tunes\":{}},{\"id\":\"p-infra-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Current proposed CADA levels make exactly this distinction: EU data location is a lower assurance level than third-country independence, EU ownership\u002Fcontrol or full software-supply-chain control.\"},\"tunes\":{}},{\"id\":\"p-infra-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For some workloads, public cloud can still be consistent with the required sovereignty level; for others, self-operated infrastructure or specially governed cloud arrangements may be necessary.\"},\"tunes\":{}},{\"id\":\"h-compute\",\"type\":\"header\",\"data\":{\"text\":\"Compute sovereignty is capacity plus control\",\"level\":2},\"tunes\":{}},{\"id\":\"p-compute-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"AI systems depend heavily on accelerators and large-scale compute. If an organization has models and data but no acceptable compute path, practical sovereignty can still fail.\"},\"tunes\":{}},{\"id\":\"p-compute-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The EU's AI Factory\u002FGigafactory investments are explicitly intended to increase European AI compute capacity and strategic autonomy. This shows that compute itself is treated as a sovereignty layer, not merely a procurement detail.\"},\"tunes\":{}},{\"id\":\"p-compute-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"At enterprise scale, the equivalent question is whether critical inference workloads can continue under provider outage, quota restriction, price shock or policy change.\"},\"tunes\":{}},{\"id\":\"h-chips\",\"type\":\"header\",\"data\":{\"text\":\"Hardware and semiconductor dependencies remain\",\"level\":2},\"tunes\":{}},{\"id\":\"p-chips-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Even self-hosted AI commonly depends on globally sourced GPUs, CPUs, memory, networking equipment, drivers and firmware.\"},\"tunes\":{}},{\"id\":\"p-chips-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty therefore rarely means complete hardware independence. More realistic controls include supply-chain visibility, stock\u002Fmaintenance strategy, second-source options, interoperable runtimes and avoiding unnecessary coupling to one hardware-specific application contract.\"},\"tunes\":{}},{\"id\":\"p-chips-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The European Tech Sovereignty package explicitly includes semiconductor policy because lower-level hardware dependencies can constrain the entire AI stack.\"},\"tunes\":{}},{\"id\":\"h-stack\",\"type\":\"header\",\"data\":{\"text\":\"Software-stack sovereignty\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stack-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Between hardware and application sit drivers, operating systems, container runtimes, inference engines, databases, vector stores, orchestration frameworks and observability tools.\"},\"tunes\":{}},{\"id\":\"p-stack-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A sovereignty assessment should identify which of these components can be replaced without redesigning the business application.\"},\"tunes\":{}},{\"id\":\"p-stack-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Open interfaces are particularly valuable at these boundaries because they reduce the cost of changing one dependency without replacing the whole system.\"},\"tunes\":{}},{\"id\":\"h-provider\",\"type\":\"header\",\"data\":{\"text\":\"Provider abstraction is a sovereignty mechanism\",\"level\":2},\"tunes\":{}},{\"id\":\"p-provider-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Provider abstraction prevents application logic from becoming inseparable from one model vendor's API, authentication flow or message format.\"},\"tunes\":{}},{\"id\":\"p-provider-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Abstraction does not make models equivalent. Different models have different context windows, tool semantics, safety behavior, latency and quality. Sovereignty-oriented routing therefore needs explicit capability and regression testing.\"},\"tunes\":{}},{\"id\":\"p-provider-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The objective is credible exit, not pretending every provider is interchangeable.\"},\"tunes\":{}},{\"id\":\"h-routing\",\"type\":\"header\",\"data\":{\"text\":\"Multi-model routing can reduce strategic dependency\",\"level\":2},\"tunes\":{}},{\"id\":\"p-route-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A platform that can route suitable tasks between local models, regional providers and frontier cloud models has more options than one hard-coded to a single endpoint.\"},\"tunes\":{}},{\"id\":\"p-route-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Policy can decide that sensitive data stays on local or sovereign infrastructure while approved low-risk tasks may use external frontier models.\"},\"tunes\":{}},{\"id\":\"p-route-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This hybrid design can increase sovereignty without requiring every workload to use the same locally hosted model.\"},\"tunes\":{}},{\"id\":\"h-identity\",\"type\":\"header\",\"data\":{\"text\":\"Identity and encryption-key control are sovereignty layers\",\"level\":2},\"tunes\":{}},{\"id\":\"p-id-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An application can own its servers yet depend on an external identity provider that can suspend access or on a key-management service controlled under another jurisdiction.\"},\"tunes\":{}},{\"id\":\"p-id-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Critical sovereignty assessments should therefore include IAM, PKI, HSM\u002FKMS control, service credentials and administrative accounts.\"},\"tunes\":{}},{\"id\":\"p-id-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"“Customer-managed keys” can improve control, but the exact key custody and service architecture matter. A label is not enough to establish independence.\"},\"tunes\":{}},{\"id\":\"h-operations\",\"type\":\"header\",\"data\":{\"text\":\"Operational sovereignty means the ability to run the system\",\"level\":2},\"tunes\":{}},{\"id\":\"p-ops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Owning software artifacts is insufficient if only one vendor can deploy, patch, diagnose or restore them.\"},\"tunes\":{}},{\"id\":\"p-ops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Operational sovereignty requires documentation, internal knowledge, observable systems, backup\u002Frecovery processes and enough expertise to maintain or migrate the platform.\"},\"tunes\":{}},{\"id\":\"p-ops-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This is why sovereignty includes skills and ecosystem capability as well as servers. A dependency on irreplaceable external expertise can be as real as a dependency on an API.\"},\"tunes\":{}},{\"id\":\"h-jurisdiction\",\"type\":\"header\",\"data\":{\"text\":\"Jurisdiction is not the same as physical location\",\"level\":2},\"tunes\":{}},{\"id\":\"p-jur-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A server can be physically located in one country while the provider remains owned or controlled under another country's laws.\"},\"tunes\":{}},{\"id\":\"p-jur-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The exact legal consequence depends on contracts, corporate structure, data type and applicable law, so sovereignty architecture should involve legal expertise rather than infer legal immunity from a data-centre map.\"},\"tunes\":{}},{\"id\":\"p-jur-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"From an architecture perspective, jurisdiction is one dependency attribute alongside location, ownership, operator access and technical control.\"},\"tunes\":{}},{\"id\":\"h-supply\",\"type\":\"header\",\"data\":{\"text\":\"Sovereign AI is a supply-chain problem\",\"level\":2},\"tunes\":{}},{\"id\":\"p-supply-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Every imported model, container, package, driver and appliance adds an external dependency.\"},\"tunes\":{}},{\"id\":\"p-supply-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The strongest architectures know which dependencies are critical, which can be substituted, which require trusted update channels and which have no realistic replacement.\"},\"tunes\":{}},{\"id\":\"p-supply-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The proposed highest CADA assurance level's emphasis on software-supply-chain transparency and control reflects this reality: sovereignty can fail through the update path even when production data never leaves the region.\"},\"tunes\":{}},{\"id\":\"h-airgap\",\"type\":\"header\",\"data\":{\"text\":\"Sovereign AI does not require an air gap\",\"level\":2},\"tunes\":{}},{\"id\":\"p-airgap-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI solves a connectivity\u002Fisolation problem. Sovereign AI solves a control\u002Fdependency problem.\"},\"tunes\":{}},{\"id\":\"p-airgap-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A sovereign system may remain internet-connected and use carefully selected external providers while preserving effective control and exit options.\"},\"tunes\":{}},{\"id\":\"p-airgap-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Conversely, an air-gapped system can still be non-sovereign if it depends on proprietary foreign software, licenses, hardware or update processes it cannot replace.\"},\"tunes\":{}},{\"id\":\"ref-airgap\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access\",\"title\":\"Air-Gapped AI: How AI Systems Work Without Internet or Cloud Access\",\"excerpt\":\"Air gap describes the network and transfer boundary. Sovereignty describes control over the wider dependency chain.\",\"ctaLabel\":\"Read the Air-Gapped AI article\"},\"tunes\":{}},{\"id\":\"h-private\",\"type\":\"header\",\"data\":{\"text\":\"Sovereign AI vs private AI\",\"level\":2},\"tunes\":{}},{\"id\":\"private-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Different primary questions\",\"layout\":\"table\",\"columns\":[{\"id\":\"private\",\"label\":\"Private AI\"},{\"id\":\"sovereign\",\"label\":\"Sovereign AI\"}],\"rows\":[{\"id\":\"question\",\"label\":\"Primary question\",\"values\":[\"\",\"\"]},{\"id\":\"data\",\"label\":\"Data focus\",\"values\":[\"\",\"\"]},{\"id\":\"cloud\",\"label\":\"Can use cloud?\",\"values\":[\"\",\"\"]},{\"id\":\"open\",\"label\":\"Requires open source?\",\"values\":[\"\",\"\"]},{\"id\":\"airgap\",\"label\":\"Requires isolation?\",\"values\":[\"\",\"\"]}]},\"tunes\":{}},{\"id\":\"p-private-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Private AI can be fully adequate when the main requirement is confidentiality rather than strategic autonomy. Sovereignty becomes relevant when provider control, jurisdiction, continuity or dependency risk is itself part of the requirement.\"},\"tunes\":{}},{\"id\":\"h-local\",\"type\":\"header\",\"data\":{\"text\":\"Self-hosted AI is not automatically sovereign\",\"level\":2},\"tunes\":{}},{\"id\":\"p-local-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Self-hosting gives direct control over inference location and often over model files and logs.\"},\"tunes\":{}},{\"id\":\"p-local-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"But a self-hosted stack can still depend on one proprietary runtime, one GPU vendor, external license servers, foreign update infrastructure or a model license that prevents required modification or redistribution.\"},\"tunes\":{}},{\"id\":\"p-local-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Self-hosting is therefore one possible sovereignty control, not proof of sovereignty across the stack.\"},\"tunes\":{}},{\"id\":\"h-nvidia\",\"type\":\"header\",\"data\":{\"text\":\"Vendor framing: NVIDIA's four technical pillars\",\"level\":2},\"tunes\":{}},{\"id\":\"p-nvidia-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"NVIDIA's current sovereign-AI technical guidance organizes the topic around four pillars: data\u002Fbenchmarks, models, hardware infrastructure and frameworks.\"},\"tunes\":{}},{\"id\":\"p-nvidia-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"That is a useful technical decomposition, especially for national model-building programs. NVIDIA also frames sovereign AI around local datasets, country-specific language\u002Fculture and infrastructure located within national borders.\"},\"tunes\":{}},{\"id\":\"p-nvidia-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Because NVIDIA is a major infrastructure vendor, this should be read as a vendor perspective rather than a neutral global standard. The broader dependency\u002Fcontrol model in this article additionally includes ownership, jurisdiction, identity, supply chain and exit rights.\"},\"tunes\":{}},{\"id\":\"h-levels\",\"type\":\"header\",\"data\":{\"text\":\"A practical enterprise sovereignty maturity model\",\"level\":2},\"tunes\":{}},{\"id\":\"levels-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Original architecture synthesis\",\"body\":\"The following five levels are a practical engineering model proposed for this article. They are \u003Cstrong>not\u003C\u002Fstrong> the European Commission's CADA levels and are not an industry standard.\"},\"tunes\":{}},{\"id\":\"levels-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Level\",\"Architecture state\"],[\"S0 — External dependency\",\"AI capability depends on one external provider with little portability or control\"],[\"S1 — Data-controlled\",\"Organization controls source data, access and retention but relies heavily on external model\u002Fplatform services\"],[\"S2 — Portable application\",\"Data and application remain controlled; model\u002Fprovider boundary is abstracted and migration is technically realistic\"],[\"S3 — Controlled runtime\",\"Critical inference, identity, keys, retrieval and operations can run on organization-controlled or approved sovereign infrastructure\"],[\"S4 — Strategic resilience\",\"Critical stack has tested alternatives, supply-chain visibility, internal operational capability and defined continuity\u002Fexit plans\"]]},\"tunes\":{}},{\"id\":\"p-levels-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A workload does not need the maximum level by default. The required control should follow consequence, regulation, confidentiality, continuity needs and strategic importance.\"},\"tunes\":{}},{\"id\":\"p-levels-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The point of a maturity model is to expose where dependency remains — not to turn sovereignty into a marketing badge.\"},\"tunes\":{}},{\"id\":\"h-lockin\",\"type\":\"header\",\"data\":{\"text\":\"Vendor lock-in becomes sovereignty risk when exit is no longer credible\",\"level\":2},\"tunes\":{}},{\"id\":\"p-lockin-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Lock-in is not always bad. Teams accept proprietary dependencies because they provide speed, quality, support or economics.\"},\"tunes\":{}},{\"id\":\"p-lockin-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"It becomes a sovereignty problem when the dependency is strategically critical and the organization cannot realistically migrate within its required continuity window.\"},\"tunes\":{}},{\"id\":\"p-lockin-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Exit therefore needs to be designed and tested, not described in a contract alone.\"},\"tunes\":{}},{\"id\":\"h-exit\",\"type\":\"header\",\"data\":{\"text\":\"What a credible exit plan contains\",\"level\":2},\"tunes\":{}},{\"id\":\"exit-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Area\",\"Exit evidence\"],[\"Data\",\"Export in usable, documented formats\"],[\"Prompts\u002Fconfiguration\",\"Stored in application-controlled source\u002Fconfig\"],[\"Models\",\"Alternative model identified and evaluated where required\"],[\"Provider API\",\"Adapter boundary limits provider-specific code\"],[\"RAG\",\"Corpus, metadata and indexes can be rebuilt outside provider\"],[\"Identity\",\"Application is not permanently coupled to one external identity control plane\"],[\"Keys\",\"Key ownership\u002Fexport\u002Frotation model is understood\"],[\"Infrastructure\",\"Deployment can move to approved alternative environment\"],[\"Observability\",\"Logs\u002Fmetrics\u002Ftraces are exportable and not provider-only\"],[\"Operational knowledge\",\"Runbooks and staff capability exist outside supplier\"],[\"Licensing\",\"Migration is legally permitted\"],[\"Recovery\",\"Fallback\u002Fcontinuity path has been tested\"]]},\"tunes\":{}},{\"id\":\"h-portability\",\"type\":\"header\",\"data\":{\"text\":\"Portability is not identical to sovereignty — but it is one of its strongest mechanisms\",\"level\":2},\"tunes\":{}},{\"id\":\"p-port-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A system that can move data but not reproduce model behavior may still be locked in.\"},\"tunes\":{}},{\"id\":\"p-port-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A system that can switch model endpoints but cannot migrate identity, retrieval data or audit records may still have a critical dependency.\"},\"tunes\":{}},{\"id\":\"p-port-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty requires portability of the critical capability, not merely export of one database.\"},\"tunes\":{}},{\"id\":\"h-standards\",\"type\":\"header\",\"data\":{\"text\":\"Open standards and protocol boundaries reduce replacement cost\",\"level\":2},\"tunes\":{}},{\"id\":\"p-standards-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Standards such as ordinary HTTP APIs, OAuth\u002FOIDC, OpenTelemetry and interoperable data formats can reduce dependency even when implementations remain proprietary.\"},\"tunes\":{}},{\"id\":\"p-standards-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"AI-specific protocols can also help at selected boundaries, but no protocol removes provider-specific behavior or legal dependency.\"},\"tunes\":{}},{\"id\":\"p-standards-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The sovereignty value of a standard is practical: does it let the organization replace a component without rewriting the whole platform?\"},\"tunes\":{}},{\"id\":\"h-governance\",\"type\":\"header\",\"data\":{\"text\":\"Sovereignty is a governance decision, not only a technical design\",\"level\":2},\"tunes\":{}},{\"id\":\"p-gov-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Organizations must decide which dependencies are acceptable and who can approve them.\"},\"tunes\":{}},{\"id\":\"p-gov-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"AI governance can classify models\u002Fproviders, define sovereignty requirements by risk tier, require exit evidence and set conditions for third-country or cloud usage.\"},\"tunes\":{}},{\"id\":\"p-gov-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"A sovereignty requirement should therefore appear in architecture decisions, procurement, risk management and operational testing rather than only in a policy statement.\"},\"tunes\":{}},{\"id\":\"h-procurement\",\"type\":\"header\",\"data\":{\"text\":\"Procurement determines much of practical sovereignty\",\"level\":2},\"tunes\":{}},{\"id\":\"p-proc-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Contracts can define data use, retention, support, portability, model deprecation notice, sub-processors, access jurisdiction and termination assistance.\"},\"tunes\":{}},{\"id\":\"p-proc-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"But contractual promises cannot replace technical portability. If no alternative implementation exists, an exit clause may still be operationally weak.\"},\"tunes\":{}},{\"id\":\"p-proc-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty-oriented procurement should evaluate both legal control and technical substitutability.\"},\"tunes\":{}},{\"id\":\"h-hybrid\",\"type\":\"header\",\"data\":{\"text\":\"Hybrid AI can be more sovereign than an all-local design\",\"level\":2},\"tunes\":{}},{\"id\":\"p-hybrid-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty is sometimes incorrectly equated with “everything runs locally.”\"},\"tunes\":{}},{\"id\":\"p-hybrid-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A hybrid architecture can keep sensitive data and authoritative knowledge on controlled infrastructure while using external frontier models for approved tasks, with policy-based routing and tested fallbacks.\"},\"tunes\":{}},{\"id\":\"p-hybrid-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"If the external model can be removed without losing critical organizational capability, the hybrid platform may have stronger practical sovereignty than a nominally local stack that is locked to one proprietary runtime.\"},\"tunes\":{}},{\"id\":\"h-security\",\"type\":\"header\",\"data\":{\"text\":\"Sovereignty does not replace security\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sec-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Controlling infrastructure does not automatically make it secure. Sovereign environments still need vulnerability management, least privilege, incident response, backups, secure supply chains and auditability.\"},\"tunes\":{}},{\"id\":\"p-sec-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A locally controlled model can still leak one tenant's data to another if retrieval or authorization is incorrect.\"},\"tunes\":{}},{\"id\":\"p-sec-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty answers who controls the system; security answers whether that control is exercised safely.\"},\"tunes\":{}},{\"id\":\"h-regulation\",\"type\":\"header\",\"data\":{\"text\":\"Sovereignty and regulatory compliance are different\",\"level\":2},\"tunes\":{}},{\"id\":\"p-reg-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An EU-hosted, EU-controlled AI stack can still violate the AI Act, GDPR or sector-specific requirements.\"},\"tunes\":{}},{\"id\":\"p-reg-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Likewise, a compliant system can use external providers and still have limited technological sovereignty.\"},\"tunes\":{}},{\"id\":\"p-reg-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Regulation and sovereignty can reinforce each other, but they are separate architecture\u002Fgovernance dimensions.\"},\"tunes\":{}},{\"id\":\"h-implementation\",\"type\":\"header\",\"data\":{\"text\":\"Original implementation evidence: sovereignty-oriented building blocks\",\"level\":2},\"tunes\":{}},{\"id\":\"impl-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Evidence boundary\",\"body\":\"The projects below demonstrate control-oriented architecture patterns such as provider abstraction, local inference, local evidence stores and explicit permission boundaries. They are \u003Cstrong>not\u003C\u002Fstrong> presented as a nationally sovereign AI stack, certified sovereign cloud or proof of full supply-chain independence.\"},\"tunes\":{}},{\"id\":\"h-client\",\"type\":\"header\",\"data\":{\"text\":\"Aaasaasa AI Client: provider, model, runtime and permissions are separable\",\"level\":3},\"tunes\":{}},{\"id\":\"p-client-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Aaasaasa AI Client separates the agent\u002Fclient, provider, provider-specific model, connection location and permission policy. Providers can include Ollama, LM Studio\u002FOpenAI-compatible services and dedicated cloud paths.\"},\"tunes\":{}},{\"id\":\"p-client-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The architecture explicitly distinguishes local runtime from local inference: a local agent runtime can use a cloud model, while Direct Ollama chat can perform local inference.\"},\"tunes\":{}},{\"id\":\"p-client-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This separation is sovereignty-relevant because provider dependence becomes an explicit configuration layer rather than being hard-coded into the business application.\"},\"tunes\":{}},{\"id\":\"p-client-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"Central permissions are also application\u002Fsession policy rather than a property of the model. That keeps operational authority under the application's control even when model\u002Fprovider choice changes.\"},\"tunes\":{}},{\"id\":\"h-sot\",\"type\":\"header\",\"data\":{\"text\":\"Source of Truth Research Engine: local evidence authority\",\"level\":3},\"tunes\":{}},{\"id\":\"p-sot-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The Source of Truth Research Engine is designed around persistent sources, snapshots, hashes, claims and provenance rather than letting model output become the authority.\"},\"tunes\":{}},{\"id\":\"p-sot-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"That pattern is sovereignty-relevant at the knowledge layer: organizational evidence remains an independent controlled artifact even when the reasoning model can be replaced.\"},\"tunes\":{}},{\"id\":\"p-sot-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The project therefore demonstrates a useful dependency principle: keep authoritative data\u002Fevidence separable from the model that interprets it.\"},\"tunes\":{}},{\"id\":\"impl-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Verified pattern\",\"Sovereignty relevance\"],[\"Multiple model\u002Fprovider paths\",\"Reduces hard-coded dependence on one inference provider\"],[\"Local Ollama inference\",\"Creates an organization-controlled inference option\"],[\"Runtime location separate from provider\",\"Makes real dependency visible\"],[\"Central application permission profiles\",\"Authority remains outside model\u002Fvendor\"],[\"Persistent source\u002Fevidence identity\",\"Knowledge survives model substitution\"],[\"Cloud paths remain available\",\"Shows hybrid architecture rather than false “local-only” positioning\"],[\"No verified sovereign infrastructure certification\",\"Prevents overclaiming full-stack sovereignty\"]]},\"tunes\":{}},{\"id\":\"h-map\",\"type\":\"header\",\"data\":{\"text\":\"Build a sovereignty dependency map\",\"level\":2},\"tunes\":{}},{\"id\":\"map-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Layer\",\"Primary provider\u002Fdependency\",\"Control state\",\"Alternative\",\"Exit time\"],[\"Model\",\"e.g. provider\u002Fmodel snapshot\",\"Owned \u002F licensed \u002F API-only\",\"Named replacement\",\"Measured\"],[\"Inference\",\"Cloud\u002Flocal runtime\",\"Direct \u002F contractual\",\"Second runtime\",\"Measured\"],[\"Embeddings\u002Freranking\",\"Model\u002Fruntime\",\"Direct \u002F external\",\"Alternative model\",\"Measured\"],[\"Data\",\"Database\u002Fobject store\",\"Direct \u002F provider\",\"Portable export\",\"Measured\"],[\"Identity\",\"IdP\u002FKMS\",\"Direct \u002F external\",\"Fallback\u002Fmigration path\",\"Measured\"],[\"Infrastructure\",\"Cloud\u002FHW\u002Fcluster\",\"Owned \u002F leased\",\"Alternate environment\",\"Measured\"],[\"Tool integrations\",\"SaaS\u002Finternal services\",\"External\u002Finternal\",\"Fallback\u002Fmanual process\",\"Measured\"],[\"Observability\",\"Logs\u002Ftraces\",\"Portable\u002Fprovider-only\",\"Alternate stack\",\"Measured\"]]},\"tunes\":{}},{\"id\":\"p-map-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The table's value is not the exact columns; it forces strategic dependency to become visible and testable.\"},\"tunes\":{}},{\"id\":\"p-map-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An architecture review can then distinguish convenient dependencies from dependencies that threaten continuity, confidentiality or regulatory objectives.\"},\"tunes\":{}},{\"id\":\"h-decision\",\"type\":\"header\",\"data\":{\"text\":\"When stronger AI sovereignty is justified\",\"level\":2},\"tunes\":{}},{\"id\":\"decision-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Driver\",\"Why stronger control may be justified\"],[\"Critical public infrastructure\",\"Continuity and strategic autonomy may outweigh provider convenience\"],[\"Defence\u002Fsecurity-sensitive workloads\",\"Foreign control\u002Fjurisdiction and supply-chain risk may be unacceptable\"],[\"Highly confidential enterprise data\",\"Data\u002Fmodel\u002Fprovider control may need stronger guarantees\"],[\"Long-lived industrial platforms\",\"Exit and hardware\u002Fsoftware lifecycle matter over many years\"],[\"Regulated public procurement\",\"Formal sovereignty assurance levels may be required\"],[\"National language\u002Fcultural models\",\"Local datasets\u002Fmodel control can preserve strategic capability\"],[\"Provider concentration risk\",\"Alternative model\u002Fruntime paths improve resilience\"],[\"Normal low-risk productivity use\",\"Maximum sovereignty may be unnecessary and uneconomic\"]]},\"tunes\":{}},{\"id\":\"p-decision-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty should be proportionate. The objective is not to maximize local ownership everywhere; it is to retain enough control for the consequence and threat model.\"},\"tunes\":{}},{\"id\":\"h-failures\",\"type\":\"header\",\"data\":{\"text\":\"Common sovereign-AI failure modes\",\"level\":2},\"tunes\":{}},{\"id\":\"failures-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Failure mode\",\"What actually failed\"],[\"“Data stays in Europe, therefore sovereign”\",\"Location was confused with ownership, jurisdiction and supply-chain control\"],[\"One proprietary model API with no tested alternative\",\"Critical inference depends on one external actor\"],[\"Open-weight model, proprietary locked runtime\",\"Model openness did not provide full operational control\"],[\"Self-hosted inference, cloud-only identity\u002FKMS\",\"Control plane remains externally dependent\"],[\"Local data but provider-only vector\u002Findex format\",\"Knowledge layer cannot migrate cleanly\"],[\"Multi-provider abstraction without evals\",\"Switching is technically possible but behaviorally unsafe\"],[\"Exit clause with no migration test\",\"Contractual portability is not operational portability\"],[\"Foreign hardware treated as proof of non-sovereignty\",\"Sovereignty was incorrectly defined as absolute autarky\"],[\"Sovereign label with no defined subject\u002Fscope\",\"Nobody knows whose control or which dependencies are meant\"],[\"Internal ownership but no operational skills\",\"System cannot be maintained independently\"],[\"Open source with no maintenance capacity\",\"Source availability exists, practical control does not\"],[\"Air gap treated as sovereignty\",\"Connectivity isolation was confused with dependency control\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Correction\"],[\"“Sovereign AI means every component must be domestic.”\",\"Sovereignty is usually about effective control, resilience and reduction of strategic dependencies, not total autarky.\"],[\"“EU data residency equals EU sovereignty.”\",\"Residency is one assurance layer; ownership, jurisdiction and supply-chain control can go further.\"],[\"“Open source equals sovereign.”\",\"Open source improves control and portability but does not eliminate infrastructure, hardware or operational dependencies.\"],[\"“Self-hosted equals sovereign.”\",\"Self-hosting controls location\u002Fruntime, not automatically licenses, chips, identity, supply chain or update paths.\"],[\"“Air-gapped equals sovereign.”\",\"Air gap controls connectivity; sovereignty controls the wider dependency chain.\"],[\"“Private AI equals sovereign AI.”\",\"Privacy focuses on protected processing; sovereignty focuses on strategic\u002Foperational control.\"],[\"“Multi-cloud equals sovereignty.”\",\"Two clouds can still share the same jurisdiction, technology dependency or proprietary control plane.\"],[\"“Using a European company guarantees sovereignty.”\",\"Corporate location helps but technical, legal and supply-chain controls still need examination.\"],[\"“Provider abstraction makes every model replaceable.”\",\"Behavioral differences require evaluation before routing or migration.\"],[\"“Sovereignty is only for governments.”\",\"The term is often national\u002Fregional, but enterprises also have meaningful sovereignty requirements over critical AI dependencies.\"]]},\"tunes\":{}},{\"id\":\"h-design\",\"type\":\"header\",\"data\":{\"text\":\"A practical sovereign-AI design sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"design-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Design from strategic dependency outward\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Define the sovereignty subject\",\"description\":\"State whether control is required for an enterprise, public body, country, EU domain or another authority.\"},{\"label\":\"2. Define critical capabilities\",\"description\":\"Identify which AI functions cannot be lost or externally controlled.\"},{\"label\":\"3. Classify data and jurisdiction\",\"description\":\"Map data location, legal control, retention and permitted processing.\"},{\"label\":\"4. Map model dependencies\",\"description\":\"Record weights\u002FAPI ownership, license, version, fine-tuning and substitution options.\"},{\"label\":\"5. Map infrastructure and control plane\",\"description\":\"Record compute, cloud, keys, identity, networks and operator access.\"},{\"label\":\"6. Map software and supply chain\",\"description\":\"Identify proprietary runtime, open source, packages, registries, updates and critical suppliers.\"},{\"label\":\"7. Choose control mechanisms\",\"description\":\"Apply local inference, regional providers, open standards, open source or stronger ownership where justified.\"},{\"label\":\"8. Build provider\u002Fmodel abstraction\",\"description\":\"Keep business applications from hard-coding one supplier where portability matters.\"},{\"label\":\"9. Preserve authoritative data independently\",\"description\":\"Ensure knowledge, provenance and business records survive model replacement.\"},{\"label\":\"10. Define exit criteria\",\"description\":\"Set maximum acceptable migration\u002Fcontinuity time for critical dependencies.\"},{\"label\":\"11. Test replacement and recovery\",\"description\":\"Run realistic failover\u002Fmigration exercises rather than trust architecture diagrams.\"},{\"label\":\"12. Reassess periodically\",\"description\":\"Supplier ownership, policy, prices, law, model support and technology ecosystems change.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"Sovereign AI architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected evidence\"],[\"Sovereign for whom?\",\"Named authority\u002Fjurisdiction\u002Forganization\"],[\"Which capabilities are strategic?\",\"Criticality classification\"],[\"Where is data processed\u002Fstored?\",\"Verified data-flow map\"],[\"Who can legally\u002Ftechnically access data?\",\"Jurisdiction + IAM + operator model\"],[\"Who controls model access\u002Fweights?\",\"License\u002Fprovider\u002Fmodel ownership record\"],[\"Can the model be replaced?\",\"Evaluated alternative and migration path\"],[\"Who controls inference compute?\",\"Infrastructure\u002Fcontrol-plane ownership\"],[\"Who controls identity and keys?\",\"IAM\u002FKMS custody model\"],[\"Which components are proprietary?\",\"Software dependency inventory\"],[\"Which dependencies are open\u002Fportable?\",\"Standards\u002Fsource\u002Flicensing evidence\"],[\"Which third-country dependencies remain?\",\"Explicit dependency register\"],[\"Can critical operation continue during provider loss?\",\"Continuity\u002Ffallback test\"],[\"Can data and knowledge be exported\u002Frebuilt?\",\"Portability\u002Frebuild procedure\"],[\"Can staff operate the platform without supplier intervention?\",\"Runbooks\u002Fskills\u002Foperational evidence\"],[\"How long would exit take?\",\"Measured migration objective\"],[\"What changes would trigger reassessment?\",\"Ownership, legal, model, provider and supply-chain review triggers\"]]},\"tunes\":{}},{\"id\":\"h-limitations\",\"type\":\"header\",\"data\":{\"text\":\"Limits and trade-offs\",\"level\":2},\"tunes\":{}},{\"id\":\"p-limit-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Stronger sovereignty can increase cost because more infrastructure, operations and expertise must be maintained directly or within a constrained provider ecosystem.\"},\"tunes\":{}},{\"id\":\"p-limit-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Local or regional alternatives may lag frontier-model capability for some workloads. Sovereignty policy should therefore support risk-based routing rather than force weaker models into every task.\"},\"tunes\":{}},{\"id\":\"p-limit-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Absolute independence is rarely realistic in modern semiconductor and software supply chains. Architecture should identify and reduce unacceptable dependencies instead of claiming impossible self-sufficiency.\"},\"tunes\":{}},{\"id\":\"p-limit-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereignty can also reduce ecosystem choice if procurement rules become too rigid. Current EU policy explicitly tries to strengthen autonomy while retaining open markets and partnerships.\"},\"tunes\":{}},{\"id\":\"p-limit-5\",\"type\":\"paragraph\",\"data\":{\"text\":\"A system can become “sovereign” on paper while operationally fragile if no team can patch, monitor or migrate it.\"},\"tunes\":{}},{\"id\":\"h-change\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The EU's proposed CADA sovereignty framework may evolve through the legislative process, so exact assurance-level requirements should be rechecked before procurement or legal decisions.\"},\"tunes\":{}},{\"id\":\"p-change-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Provider ownership, model licensing, geopolitical conditions and semiconductor supply chains can materially change the sovereignty assessment without any application-code change.\"},\"tunes\":{}},{\"id\":\"p-change-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The stable architectural principle is that sovereignty depends on effective control and credible alternatives across critical dependencies, not on one geographic or branding attribute.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereign AI sits above several deployment and control concepts: Private AI protects sensitive processing, Air-Gapped AI isolates network domains, AI Governance assigns decision rights, and LLMOps operates model\u002Fprovider changes.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Provider abstraction and model routing are practical mechanisms for reducing dependency, while Source of Truth architecture keeps organizational evidence independent of any one model.\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Enterprise AI Architecture determines where these sovereignty requirements belong across platforms, applications, identity, infrastructure and operations.\"},\"tunes\":{}},{\"id\":\"ref-avb\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers\",\"title\":\"The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers\",\"excerpt\":\"Sovereignty over infrastructure does not make an answer true. Reliable knowledge still requires evidence, authority, scope and validity controls.\",\"ctaLabel\":\"Read the Answer Validity Boundary\"},\"tunes\":{}},{\"id\":\"ref-memory\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context\",\"title\":\"AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context\",\"excerpt\":\"Keeping state, knowledge, retrieval and model context separate improves portability and reduces coupling to one AI provider.\",\"ctaLabel\":\"Read the architecture article\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Sovereign AI FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is sovereign AI?\",\"answer\":\"Sovereign AI is the ability of a defined authority such as a country, public institution or organization to retain effective control over critical AI data, models, infrastructure, software, operations and dependencies.\"},{\"id\":\"faq2\",\"question\":\"Is sovereign AI the same as data sovereignty?\",\"answer\":\"No. Data sovereignty is one component. AI sovereignty also includes model control, compute, software supply chain, identity, operators, jurisdiction and the ability to replace critical providers.\"},{\"id\":\"faq3\",\"question\":\"Does sovereign AI require everything to be hosted locally?\",\"answer\":\"No. A sovereign architecture can use external or cloud services if the required level of control, legal assurance, portability and continuity is preserved.\"},{\"id\":\"faq4\",\"question\":\"Does sovereign AI require open-source models?\",\"answer\":\"No. Open source or open weights can improve control and portability, but proprietary components can still be used where dependency and licensing are acceptable.\"},{\"id\":\"faq5\",\"question\":\"Is self-hosted AI automatically sovereign?\",\"answer\":\"No. Self-hosting controls inference location but can still depend on external identity, proprietary runtimes, foreign hardware, licenses or update infrastructure.\"},{\"id\":\"faq6\",\"question\":\"What is the difference between sovereign AI and air-gapped AI?\",\"answer\":\"Air-gapped AI is about physical\u002Fnetwork isolation and controlled transfer. Sovereign AI is about effective control over the entire dependency chain. Either can exist without the other.\"},{\"id\":\"faq7\",\"question\":\"Can a cloud AI service be sovereign?\",\"answer\":\"Potentially, depending on the required sovereignty level and who controls location, provider ownership, administrative access, keys, supply chain, jurisdiction and exit.\"},{\"id\":\"faq8\",\"question\":\"Why does provider abstraction matter for sovereignty?\",\"answer\":\"It reduces application coupling to one model provider and creates a technical migration path, although behavioral differences still require evaluation.\"},{\"id\":\"faq9\",\"question\":\"How do you measure practical AI sovereignty?\",\"answer\":\"Map critical dependencies and test whether data, models, workloads and operations can continue or migrate within the required time if a provider, jurisdiction or supply-chain dependency becomes unacceptable.\"},{\"id\":\"faq10\",\"question\":\"What is the biggest misconception about sovereign AI?\",\"answer\":\"That sovereignty is one property such as EU hosting, local inference, open source or an air gap. In reality it is a multi-layer control and dependency problem.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key sovereign-AI terms\",\"entries\":[{\"term\":\"Sovereign AI\",\"definition\":\"AI capability designed so a defined authority retains effective control over critical data, models, infrastructure, operations and dependencies.\",\"anchor\":\"sovereign-ai\"},{\"term\":\"Tech sovereignty\",\"definition\":\"Ability to act independently in the digital domain by controlling key technologies, data and infrastructure while reducing strategic external dependencies.\",\"anchor\":\"tech-sovereignty\"},{\"term\":\"Strategic dependency\",\"definition\":\"External dependency whose loss, control or change can materially threaten continuity, security, autonomy or policy objectives.\",\"anchor\":\"strategic-dependency\"},{\"term\":\"Data residency\",\"definition\":\"Requirement describing where data is physically or logically stored\u002Fprocessed; narrower than sovereignty.\",\"anchor\":\"data-residency\"},{\"term\":\"Data sovereignty\",\"definition\":\"Control of data under applicable legal, organizational and jurisdictional authority.\",\"anchor\":\"data-sovereignty\"},{\"term\":\"Model sovereignty\",\"definition\":\"Degree of control over model access, weights, licensing, modification, versioning, deployment and replacement.\",\"anchor\":\"model-sovereignty\"},{\"term\":\"Infrastructure sovereignty\",\"definition\":\"Control over compute, hosting, control plane, operations and infrastructure jurisdiction needed for critical workloads.\",\"anchor\":\"infrastructure-sovereignty\"},{\"term\":\"Operational sovereignty\",\"definition\":\"Ability to deploy, maintain, observe, recover and migrate a system without unacceptable dependence on one external operator.\",\"anchor\":\"operational-sovereignty\"},{\"term\":\"Provider abstraction\",\"definition\":\"Application architecture separating business logic from provider-specific APIs so model\u002Fprovider dependencies can be changed more safely.\",\"anchor\":\"provider-abstraction\"},{\"term\":\"Exit strategy\",\"definition\":\"Testable plan for moving data, workloads and operational capability away from an external dependency.\",\"anchor\":\"exit-strategy\"},{\"term\":\"Supply-chain sovereignty\",\"definition\":\"Degree of transparency, control and substitutability across critical software, model, hardware and update dependencies.\",\"anchor\":\"supply-chain-sovereignty\"},{\"term\":\"Strategic autonomy\",\"definition\":\"Capacity to make and execute critical decisions without unacceptable external constraint or dependency.\",\"anchor\":\"strategic-autonomy\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereign AI is not one product category and not one deployment location. It is an architecture and governance objective: retain effective control over the AI capabilities that matter.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The strongest sovereignty designs separate data from models, business applications from providers, authority from model capability and critical operations from non-substitutable external dependencies.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The shortest reliable rule is: sovereignty is not proven by where the model runs; it is proven by who controls the critical stack, which dependencies remain, and whether the organization can continue or change direction when those dependencies become unacceptable.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary and current sources\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"The sources below separate official EU tech-sovereignty policy, current proposed cloud\u002FAI sovereignty assurance levels, European compute initiatives and a vendor technical framing. The enterprise sovereignty maturity model in this article is explicitly original synthesis, not an EU or industry standard.\"},\"tunes\":{}},{\"id\":\"src-eu-sovereignty\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Feu-tech-sovereignty\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — Strengthening Europe's Tech Sovereignty\",\"description\":\"Current EU definition of tech sovereignty as independent action through control of key technologies, data and infrastructure while reducing reliance on non-EU providers.\"}},\"tunes\":{}},{\"id\":\"src-eu-package\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Flibrary\u002Fcommunication-european-tech-sovereignty-accompanied-eu-open-source-strategy\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — Communication on European Tech Sovereignty\",\"description\":\"2026 policy package covering the technology value chain from chips through infrastructure, software, cloud and AI.\"}},\"tunes\":{}},{\"id\":\"src-cada\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fcloud-and-ai-development-act\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — Cloud and AI Development Act\",\"description\":\"Current proposed EU framework defining four cloud\u002FAI sovereignty assurance levels across location, third-country independence, ownership\u002Fcontrol and software-supply-chain control.\"}},\"tunes\":{}},{\"id\":\"src-open-source\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Ffactpages\u002Feu-open-source-strategy\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — EU Open Source Strategy\",\"description\":\"Current policy connecting open source with greater control, lower lock-in, security, reuse and technological sovereignty.\"}},\"tunes\":{}},{\"id\":\"src-ai-factories\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fai-factories\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — AI Factories\",\"description\":\"Current EU AI compute infrastructure initiative linking AI factories and gigafactories with European capacity and technological sovereignty.\"}},\"tunes\":{}},{\"id\":\"src-gigafactories\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fnews\u002Feu-launches-ai-gigafactories-call-boost-europes-computing-capacity-and-unlock-more-eu30-billion\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"European Commission — AI Gigafactories call\",\"description\":\"2026 initiative to expand European AI compute, resilience and strategic autonomy on infrastructure built and operated in Europe.\"}},\"tunes\":{}},{\"id\":\"src-eurohpc\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.eurohpc-ju.europa.eu\u002Feurohpc-joint-undertaking-launches-ai-gigafactories-call-2026-07-30_en\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"EuroHPC JU — AI Gigafactories\",\"description\":\"Current EuroHPC framing of large-scale sovereign AI computing infrastructure and technological independence.\"}},\"tunes\":{}},{\"id\":\"src-nvidia\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nvidia.com\u002Fen-us\u002Flp\u002Findustries\u002Fglobal-public-sector\u002Fsovereign-ai-technical-overview\u002F\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NVIDIA — Building Sovereign AI Models\",\"description\":\"Vendor technical framing organized around data\u002Fbenchmarks, models, hardware infrastructure and frameworks; useful as industry perspective, not a universal standard.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":1821,"blocks":1822,"version":3132},1791488834259,[1823,1827,1832,1837,1842,1847,1851,1855,1859,1863,1867,1871,1875,1879,1883,1887,1916,1920,1924,1928,1932,1936,1940,1944,1948,1952,1971,1975,1979,1984,1988,2031,2035,2039,2043,2047,2051,2055,2059,2063,2067,2071,2075,2079,2083,2087,2091,2095,2099,2103,2107,2111,2115,2119,2123,2127,2131,2135,2139,2143,2147,2151,2155,2159,2163,2167,2171,2175,2179,2183,2187,2191,2195,2199,2203,2207,2211,2215,2219,2223,2227,2231,2235,2239,2243,2247,2251,2255,2262,2266,2291,2295,2299,2303,2307,2311,2315,2319,2323,2327,2331,2336,2358,2362,2366,2370,2374,2378,2382,2386,2426,2430,2434,2438,2442,2446,2450,2454,2458,2462,2466,2470,2474,2478,2482,2486,2490,2494,2498,2502,2506,2510,2514,2518,2522,2526,2530,2534,2538,2542,2547,2551,2555,2559,2563,2567,2571,2575,2579,2583,2611,2615,2660,2664,2668,2672,2703,2707,2711,2754,2758,2795,2799,2840,2844,2899,2903,2907,2911,2915,2919,2923,2927,2931,2935,2939,2943,2947,2951,2955,2962,2969,2973,3008,3012,3052,3056,3060,3064,3068,3072,3076,3083,3090,3097,3104,3111,3118,3125],{"id":215,"data":1824,"type":218,"tunes":1826},{"text":1825},"Sovereign AI is the ability of a country, public institution, organization or other defined authority to retain effective control over the AI systems it depends on: their data, models, infrastructure, software stack, operators, legal exposure and strategic dependencies. Sovereignty is not the same as hosting data in one country, running an open model, using an EU cloud provider or disconnecting a server from the internet. Those can support sovereignty, but the defining question is whether the organization can make, enforce and preserve critical AI decisions without unacceptable dependence on an external actor.",{},{"id":221,"data":1828,"type":226,"tunes":1831},{"body":1829,"title":1830,"variant":225},"A practical sovereign-AI architecture controls more than model location. It asks:\u003Cbr>\u003Cbr>\u003Cstrong>Who controls the data? Who controls the model? Who controls the compute? Who controls the software stack? Who holds the keys? Which law and corporate control apply? Which supplier can disable, change or price the system? Can the workload be moved if that supplier becomes unacceptable?\u003C\u002Fstrong>\u003Cbr>\u003Cbr>Sovereignty therefore exists across a dependency chain, not as a single yes\u002Fno property.","Direct answer",{},{"id":229,"data":1833,"type":226,"tunes":1836},{"body":1834,"title":1835,"variant":233},"“Sovereign AI” is used by governments, vendors and industry with overlapping but non-identical meanings. The European Commission currently defines broader \u003Cstrong>tech sovereignty\u003C\u002Fstrong> as the ability to act independently by developing and controlling key technologies, data and infrastructure while reducing reliance on non-EU providers. NVIDIA's vendor framing emphasizes local data, models, infrastructure and frameworks. This article uses an explicit architectural synthesis of those control dimensions rather than presenting one vendor definition as a universal standard.","The term is not one universal technical standard",{},{"id":236,"data":1838,"type":226,"tunes":1841},{"body":1839,"title":1840,"variant":240},"The objective is not necessarily to eliminate every foreign component. Current EU policy explicitly combines stronger autonomy with markets that remain open to partners. A sovereign architecture reduces \u003Cstrong>strategic dependency\u003C\u002Fstrong>: dependencies that can remove effective choice, expose critical data\u002Fcontrol to unwanted jurisdiction or make continuity impossible without one external supplier.","Sovereignty does not require technological autarky",{},{"id":243,"data":1843,"type":226,"tunes":1846},{"body":1844,"title":1845,"variant":233},"On 3 June 2026, the European Commission adopted its Tech Sovereignty package and proposed the Cloud and AI Development Act (CADA). The Commission's current CADA framework describes four cloud\u002FAI sovereignty assurance levels ranging from EU data location, through independence from third countries and software-supply-chain transparency, to EU ownership\u002Fcontrol and, at the highest level, full supply-chain control without third-country interference. This is strong evidence that sovereignty is broader than data residency.","Current-source note — 8 October 2026",{},{"id":249,"data":1848,"type":254,"tunes":1850},{"title":1849,"maxLevel":252,"minLevel":253},"Contents",{},{"id":257,"data":1852,"type":42,"tunes":1854},{"text":1853,"level":253},"What sovereign AI really means",{},{"id":262,"data":1856,"type":218,"tunes":1858},{"text":1857},"Sovereignty is fundamentally about decision power under dependency. An organization may technically own its data yet still depend on a provider that controls model access, pricing, identity, encryption keys, software updates or the only available inference endpoint.",{},{"id":267,"data":1860,"type":218,"tunes":1862},{"text":1861},"A sovereign architecture therefore asks which dependencies are acceptable, which must remain substitutable and which capabilities must be controlled directly.",{},{"id":272,"data":1864,"type":218,"tunes":1866},{"text":1865},"The European Commission's current tech-sovereignty definition is useful because it combines two ideas: develop\u002Fcontrol critical technology and reduce external reliance. That is closer to engineering reality than treating sovereignty as simple geographic hosting.",{},{"id":277,"data":1868,"type":42,"tunes":1870},{"text":1869,"level":253},"The simplest example",{},{"id":282,"data":1872,"type":218,"tunes":1874},{"text":1873},"Consider two companies that both store customer documents in Germany.",{},{"id":287,"data":1876,"type":218,"tunes":1878},{"text":1877},"Company A sends every prompt and document to one proprietary cloud model. The model version can change, the provider controls the inference service and keys, and the application has no tested fallback.",{},{"id":292,"data":1880,"type":218,"tunes":1882},{"text":1881},"Company B also uses a cloud model, but keeps its data and retrieval layer under its own control, can route to a locally hosted open-weight model, owns application keys and identity, records provider\u002Fmodel dependencies and has a tested migration path.",{},{"id":297,"data":1884,"type":218,"tunes":1886},{"text":1885},"Both may satisfy a data-location requirement. Company B has materially more operational sovereignty because it retains more meaningful choices if the external provider becomes unavailable or unacceptable.",{},{"id":302,"data":1888,"type":331,"tunes":1915},{"steps":1889,"title":1914,"orientation":330},[1890,1893,1896,1899,1902,1905,1908,1911],{"label":1891,"description":1892},"1. Define the authority","Specify whose sovereignty matters: organization, public administration, country, EU, business unit or regulated environment.",{"label":1894,"description":1895},"2. Identify critical AI capabilities","List models, inference, retrieval, data, tools, identity, storage and operational services.",{"label":1897,"description":1898},"3. Map dependencies","For each capability, identify supplier, jurisdiction, ownership, licensing, update path and technical lock-in.",{"label":1900,"description":1901},"4. Classify control","Determine what is directly controlled, contractually controlled, substitutable or effectively external.",{"label":1903,"description":1904},"5. Identify unacceptable dependencies","Find dependencies that can block continuity, expose protected data or remove strategic choice.",{"label":1906,"description":1907},"6. Add alternatives or stronger ownership","Use open standards, local models, portable data, internal keys, multi-provider routing or sovereign infrastructure where justified.",{"label":1909,"description":1910},"7. Test exit and continuity","Prove that the organization can migrate, fail over or continue critical operation under the defined sovereignty requirement.",{"label":1912,"description":1913},"8. Reassess over time","Supplier ownership, law, model licenses, infrastructure and geopolitical conditions can change.","A practical sovereignty assessment",{},{"id":334,"data":1917,"type":42,"tunes":1919},{"text":1918,"level":253},"Where the simple example stops",{},{"id":339,"data":1921,"type":218,"tunes":1923},{"text":1922},"At national or EU scale, sovereign AI includes far more than one enterprise deployment: semiconductor supply, high-performance computing, research capacity, talent, datasets, cloud infrastructure, model development and industrial ecosystems.",{},{"id":344,"data":1925,"type":218,"tunes":1927},{"text":1926},"At enterprise scale, the same concept becomes narrower: which AI dependencies must the organization itself control or be able to replace?",{},{"id":349,"data":1929,"type":218,"tunes":1931},{"text":1930},"The architecture should always state the sovereignty subject and scope. “Sovereign AI” without saying sovereign for whom, over what and against which dependency is too vague for engineering.",{},{"id":354,"data":1933,"type":42,"tunes":1935},{"text":1934,"level":253},"Current European tech-sovereignty framing",{},{"id":359,"data":1937,"type":218,"tunes":1939},{"text":1938},"The European Commission currently defines tech sovereignty as Europe's ability to act independently in the digital world by developing and controlling key technologies, data and infrastructure while reducing reliance on non-EU providers.",{},{"id":364,"data":1941,"type":218,"tunes":1943},{"text":1942},"The 2026 Tech Sovereignty package explicitly spans the value chain from chips to infrastructure, software, cloud and AI. This matters because an AI system can be dependent below the model layer: accelerators, hypervisors, container platforms, cloud control planes or proprietary libraries can all become strategic dependencies.",{},{"id":369,"data":1945,"type":218,"tunes":1947},{"text":1946},"The Commission is also using AI Factories and AI Gigafactories to expand European compute capacity. Current AI Gigafactory policy describes infrastructure built and operated in Europe to strengthen resilience, strategic autonomy and the ability to develop advanced AI on European infrastructure.",{},{"id":374,"data":1949,"type":42,"tunes":1951},{"text":1950,"level":253},"CADA makes sovereignty a graded assurance problem",{},{"id":379,"data":1953,"type":397,"tunes":1970},{"content":1954,"stretched":43,"withHeadings":14},[1955,1958,1961,1964,1967],[1956,1957],"Current proposed CADA level","Control signal",[1959,1960],"Level 1","Data is processed and stored in infrastructure located in the EU",[1962,1963],"Level 2","Provider demonstrates independence from third countries and transparency over the software supply chain",[1965,1966],"Level 3","Provider is EU-owned and controlled, with additional sovereignty criteria; recognition paths can exist for third-country providers",[1968,1969],"Level 4","Full transparency and control over the software supply chain with no third-country interference",{},{"id":400,"data":1972,"type":218,"tunes":1974},{"text":1973},"The proposed CADA framework is especially useful conceptually because it rejects a binary sovereignty label. It treats sovereignty as increasing assurance across location, legal\u002Fcorporate control and supply-chain control.",{},{"id":405,"data":1976,"type":218,"tunes":1978},{"text":1977},"It is also a proposed EU regulatory\u002Fprocurement framework, not a universal global technical standard. The four levels should not be copied mechanically into private architecture without understanding the actual risk model.",{},{"id":410,"data":1980,"type":226,"tunes":1983},{"body":1981,"title":1982,"variant":414},"A workload can process data entirely inside the EU and still depend on a third-country-controlled provider, proprietary software stack, foreign key-management plane or non-substitutable model API. Residency answers \u003Cstrong>where\u003C\u002Fstrong>; sovereignty also asks \u003Cstrong>who controls\u003C\u002Fstrong> and \u003Cstrong>what happens if dependency terms change\u003C\u002Fstrong>.","Data residency is only the first layer",{},{"id":417,"data":1985,"type":42,"tunes":1987},{"text":1986,"level":253},"The main control dimensions of sovereign AI",{},{"id":422,"data":1989,"type":397,"tunes":2030},{"content":1990,"stretched":43,"withHeadings":14},[1991,1994,1997,2000,2003,2006,2009,2012,2015,2018,2021,2024,2027],[1992,1993],"Dimension","Sovereignty question",[1995,1996],"Data","Who owns, stores, classifies, moves, deletes and authorizes use of the data?",[1998,1999],"Models","Who controls model weights\u002Faccess, versioning, licenses, fine-tuning and retirement?",[2001,2002],"Compute","Where does training\u002Finference run and who controls the capacity?",[2004,2005],"Cloud\u002Finfrastructure","Who owns and operates the control plane, hardware and hosting layer?",[2007,2008],"Software stack","Can core runtime\u002Forchestration components be inspected, replaced or self-operated?",[2010,2011],"Identity &amp; keys","Who controls identities, credentials, encryption keys and policy enforcement?",[2013,2014],"Network","Which external paths are required for normal operation?",[2016,2017],"Operations","Who can administer, patch, disable, observe and recover the system?",[2019,2020],"Supply chain","Which vendors, packages, chips, models and registries can interrupt or compromise the system?",[2022,2023],"Jurisdiction","Which legal authorities can compel access or affect service\u002Fcontrol?",[2025,2026],"Skills &amp; know-how","Can the organization operate or migrate the system without one supplier's personnel?",[2028,2029],"Exit \u002F portability","Can data, models and workloads move to an acceptable alternative in realistic time?",{},{"id":466,"data":2032,"type":42,"tunes":2034},{"text":2033,"level":253},"Data sovereignty is necessary but not sufficient",{},{"id":471,"data":2036,"type":218,"tunes":2038},{"text":2037},"Data sovereignty concerns control over data according to applicable law, organizational authority and policy. Location can be important, but control also includes encryption, access, retention, reuse, training rights and deletion.",{},{"id":476,"data":2040,"type":218,"tunes":2042},{"text":2041},"If an external model provider is contractually allowed to retain prompts or train on them, the sovereignty risk differs from a provider that processes data transiently under stronger restrictions — even when both endpoints are in the same region.",{},{"id":481,"data":2044,"type":218,"tunes":2046},{"text":2045},"RAG adds derived artifacts such as chunks, embeddings, indexes and cached answers. Sovereign data control should include those derivatives, not only original documents.",{},{"id":486,"data":2048,"type":42,"tunes":2050},{"text":2049,"level":253},"Model sovereignty is about control and substitutability",{},{"id":491,"data":2052,"type":218,"tunes":2054},{"text":2053},"A proprietary API model can be extremely capable while providing limited control over weights, training process, model retirement or future pricing.",{},{"id":496,"data":2056,"type":218,"tunes":2058},{"text":2057},"An open-weight model can provide more operational control because weights can be hosted independently, but the exact license, tokenizer, training provenance, architecture, fine-tuning rights and runtime requirements still matter.",{},{"id":501,"data":2060,"type":218,"tunes":2062},{"text":2061},"Model sovereignty is therefore not equivalent to “open model.” The relevant questions are which model artifacts can be possessed, modified, evaluated, deployed and replaced under the required legal and technical conditions.",{},{"id":506,"data":2064,"type":42,"tunes":2066},{"text":2065,"level":253},"Open source is a sovereignty tool, not sovereignty itself",{},{"id":511,"data":2068,"type":218,"tunes":2070},{"text":2069},"The EU Open Source Strategy explicitly connects open source with more control, less lock-in, stronger security and reusable digital building blocks.",{},{"id":516,"data":2072,"type":218,"tunes":2074},{"text":2073},"Open source can reduce dependency because source code can be inspected, modified and operated by alternative suppliers. Open standards can also reduce migration cost.",{},{"id":521,"data":2076,"type":218,"tunes":2078},{"text":2077},"But open software running only on one non-substitutable cloud control plane can still leave major dependencies. Likewise, open model weights on hardware that cannot be sourced, supported or operated independently may provide only partial sovereignty.",{},{"id":526,"data":2080,"type":42,"tunes":2082},{"text":2081,"level":253},"Infrastructure sovereignty goes below the cloud region",{},{"id":531,"data":2084,"type":218,"tunes":2086},{"text":2085},"The phrase “hosted in Europe” does not fully describe infrastructure control. Relevant questions include corporate ownership, administrative access, key control, legal jurisdiction, support personnel, software supply chain and whether the service can continue if a foreign parent or supplier changes terms.",{},{"id":536,"data":2088,"type":218,"tunes":2090},{"text":2089},"Current proposed CADA levels make exactly this distinction: EU data location is a lower assurance level than third-country independence, EU ownership\u002Fcontrol or full software-supply-chain control.",{},{"id":541,"data":2092,"type":218,"tunes":2094},{"text":2093},"For some workloads, public cloud can still be consistent with the required sovereignty level; for others, self-operated infrastructure or specially governed cloud arrangements may be necessary.",{},{"id":546,"data":2096,"type":42,"tunes":2098},{"text":2097,"level":253},"Compute sovereignty is capacity plus control",{},{"id":551,"data":2100,"type":218,"tunes":2102},{"text":2101},"AI systems depend heavily on accelerators and large-scale compute. If an organization has models and data but no acceptable compute path, practical sovereignty can still fail.",{},{"id":556,"data":2104,"type":218,"tunes":2106},{"text":2105},"The EU's AI Factory\u002FGigafactory investments are explicitly intended to increase European AI compute capacity and strategic autonomy. This shows that compute itself is treated as a sovereignty layer, not merely a procurement detail.",{},{"id":561,"data":2108,"type":218,"tunes":2110},{"text":2109},"At enterprise scale, the equivalent question is whether critical inference workloads can continue under provider outage, quota restriction, price shock or policy change.",{},{"id":566,"data":2112,"type":42,"tunes":2114},{"text":2113,"level":253},"Hardware and semiconductor dependencies remain",{},{"id":571,"data":2116,"type":218,"tunes":2118},{"text":2117},"Even self-hosted AI commonly depends on globally sourced GPUs, CPUs, memory, networking equipment, drivers and firmware.",{},{"id":576,"data":2120,"type":218,"tunes":2122},{"text":2121},"Sovereignty therefore rarely means complete hardware independence. More realistic controls include supply-chain visibility, stock\u002Fmaintenance strategy, second-source options, interoperable runtimes and avoiding unnecessary coupling to one hardware-specific application contract.",{},{"id":581,"data":2124,"type":218,"tunes":2126},{"text":2125},"The European Tech Sovereignty package explicitly includes semiconductor policy because lower-level hardware dependencies can constrain the entire AI stack.",{},{"id":586,"data":2128,"type":42,"tunes":2130},{"text":2129,"level":253},"Software-stack sovereignty",{},{"id":591,"data":2132,"type":218,"tunes":2134},{"text":2133},"Between hardware and application sit drivers, operating systems, container runtimes, inference engines, databases, vector stores, orchestration frameworks and observability tools.",{},{"id":596,"data":2136,"type":218,"tunes":2138},{"text":2137},"A sovereignty assessment should identify which of these components can be replaced without redesigning the business application.",{},{"id":601,"data":2140,"type":218,"tunes":2142},{"text":2141},"Open interfaces are particularly valuable at these boundaries because they reduce the cost of changing one dependency without replacing the whole system.",{},{"id":606,"data":2144,"type":42,"tunes":2146},{"text":2145,"level":253},"Provider abstraction is a sovereignty mechanism",{},{"id":611,"data":2148,"type":218,"tunes":2150},{"text":2149},"Provider abstraction prevents application logic from becoming inseparable from one model vendor's API, authentication flow or message format.",{},{"id":616,"data":2152,"type":218,"tunes":2154},{"text":2153},"Abstraction does not make models equivalent. Different models have different context windows, tool semantics, safety behavior, latency and quality. Sovereignty-oriented routing therefore needs explicit capability and regression testing.",{},{"id":621,"data":2156,"type":218,"tunes":2158},{"text":2157},"The objective is credible exit, not pretending every provider is interchangeable.",{},{"id":626,"data":2160,"type":42,"tunes":2162},{"text":2161,"level":253},"Multi-model routing can reduce strategic dependency",{},{"id":631,"data":2164,"type":218,"tunes":2166},{"text":2165},"A platform that can route suitable tasks between local models, regional providers and frontier cloud models has more options than one hard-coded to a single endpoint.",{},{"id":636,"data":2168,"type":218,"tunes":2170},{"text":2169},"Policy can decide that sensitive data stays on local or sovereign infrastructure while approved low-risk tasks may use external frontier models.",{},{"id":641,"data":2172,"type":218,"tunes":2174},{"text":2173},"This hybrid design can increase sovereignty without requiring every workload to use the same locally hosted model.",{},{"id":646,"data":2176,"type":42,"tunes":2178},{"text":2177,"level":253},"Identity and encryption-key control are sovereignty layers",{},{"id":651,"data":2180,"type":218,"tunes":2182},{"text":2181},"An application can own its servers yet depend on an external identity provider that can suspend access or on a key-management service controlled under another jurisdiction.",{},{"id":656,"data":2184,"type":218,"tunes":2186},{"text":2185},"Critical sovereignty assessments should therefore include IAM, PKI, HSM\u002FKMS control, service credentials and administrative accounts.",{},{"id":661,"data":2188,"type":218,"tunes":2190},{"text":2189},"“Customer-managed keys” can improve control, but the exact key custody and service architecture matter. A label is not enough to establish independence.",{},{"id":666,"data":2192,"type":42,"tunes":2194},{"text":2193,"level":253},"Operational sovereignty means the ability to run the system",{},{"id":671,"data":2196,"type":218,"tunes":2198},{"text":2197},"Owning software artifacts is insufficient if only one vendor can deploy, patch, diagnose or restore them.",{},{"id":676,"data":2200,"type":218,"tunes":2202},{"text":2201},"Operational sovereignty requires documentation, internal knowledge, observable systems, backup\u002Frecovery processes and enough expertise to maintain or migrate the platform.",{},{"id":681,"data":2204,"type":218,"tunes":2206},{"text":2205},"This is why sovereignty includes skills and ecosystem capability as well as servers. A dependency on irreplaceable external expertise can be as real as a dependency on an API.",{},{"id":686,"data":2208,"type":42,"tunes":2210},{"text":2209,"level":253},"Jurisdiction is not the same as physical location",{},{"id":691,"data":2212,"type":218,"tunes":2214},{"text":2213},"A server can be physically located in one country while the provider remains owned or controlled under another country's laws.",{},{"id":696,"data":2216,"type":218,"tunes":2218},{"text":2217},"The exact legal consequence depends on contracts, corporate structure, data type and applicable law, so sovereignty architecture should involve legal expertise rather than infer legal immunity from a data-centre map.",{},{"id":701,"data":2220,"type":218,"tunes":2222},{"text":2221},"From an architecture perspective, jurisdiction is one dependency attribute alongside location, ownership, operator access and technical control.",{},{"id":706,"data":2224,"type":42,"tunes":2226},{"text":2225,"level":253},"Sovereign AI is a supply-chain problem",{},{"id":711,"data":2228,"type":218,"tunes":2230},{"text":2229},"Every imported model, container, package, driver and appliance adds an external dependency.",{},{"id":716,"data":2232,"type":218,"tunes":2234},{"text":2233},"The strongest architectures know which dependencies are critical, which can be substituted, which require trusted update channels and which have no realistic replacement.",{},{"id":721,"data":2236,"type":218,"tunes":2238},{"text":2237},"The proposed highest CADA assurance level's emphasis on software-supply-chain transparency and control reflects this reality: sovereignty can fail through the update path even when production data never leaves the region.",{},{"id":726,"data":2240,"type":42,"tunes":2242},{"text":2241,"level":253},"Sovereign AI does not require an air gap",{},{"id":731,"data":2244,"type":218,"tunes":2246},{"text":2245},"Air-gapped AI solves a connectivity\u002Fisolation problem. Sovereign AI solves a control\u002Fdependency problem.",{},{"id":736,"data":2248,"type":218,"tunes":2250},{"text":2249},"A sovereign system may remain internet-connected and use carefully selected external providers while preserving effective control and exit options.",{},{"id":741,"data":2252,"type":218,"tunes":2254},{"text":2253},"Conversely, an air-gapped system can still be non-sovereign if it depends on proprietary foreign software, licenses, hardware or update processes it cannot replace.",{},{"id":746,"data":2256,"type":752,"tunes":2261},{"url":2257,"title":2258,"excerpt":2259,"ctaLabel":2260},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","Air-Gapped AI: How AI Systems Work Without Internet or Cloud Access","Air gap describes the network and transfer boundary. Sovereignty describes control over the wider dependency chain.","Read the Air-Gapped AI article",{},{"id":755,"data":2263,"type":42,"tunes":2265},{"text":2264,"level":253},"Sovereign AI vs private AI",{},{"id":760,"data":2267,"type":792,"tunes":2290},{"rows":2268,"title":2284,"layout":397,"columns":2285},[2269,2272,2275,2278,2281],{"id":764,"label":2270,"values":2271},"Primary question",[767,767],{"id":769,"label":2273,"values":2274},"Data focus",[767,767],{"id":773,"label":2276,"values":2277},"Can use cloud?",[767,767],{"id":777,"label":2279,"values":2280},"Requires open source?",[767,767],{"id":781,"label":2282,"values":2283},"Requires isolation?",[767,767],"Different primary questions",[2286,2288],{"id":787,"label":2287},"Private AI",{"id":790,"label":2289},"Sovereign AI",{},{"id":795,"data":2292,"type":218,"tunes":2294},{"text":2293},"Private AI can be fully adequate when the main requirement is confidentiality rather than strategic autonomy. Sovereignty becomes relevant when provider control, jurisdiction, continuity or dependency risk is itself part of the requirement.",{},{"id":800,"data":2296,"type":42,"tunes":2298},{"text":2297,"level":253},"Self-hosted AI is not automatically sovereign",{},{"id":805,"data":2300,"type":218,"tunes":2302},{"text":2301},"Self-hosting gives direct control over inference location and often over model files and logs.",{},{"id":810,"data":2304,"type":218,"tunes":2306},{"text":2305},"But a self-hosted stack can still depend on one proprietary runtime, one GPU vendor, external license servers, foreign update infrastructure or a model license that prevents required modification or redistribution.",{},{"id":815,"data":2308,"type":218,"tunes":2310},{"text":2309},"Self-hosting is therefore one possible sovereignty control, not proof of sovereignty across the stack.",{},{"id":820,"data":2312,"type":42,"tunes":2314},{"text":2313,"level":253},"Vendor framing: NVIDIA's four technical pillars",{},{"id":825,"data":2316,"type":218,"tunes":2318},{"text":2317},"NVIDIA's current sovereign-AI technical guidance organizes the topic around four pillars: data\u002Fbenchmarks, models, hardware infrastructure and frameworks.",{},{"id":830,"data":2320,"type":218,"tunes":2322},{"text":2321},"That is a useful technical decomposition, especially for national model-building programs. NVIDIA also frames sovereign AI around local datasets, country-specific language\u002Fculture and infrastructure located within national borders.",{},{"id":835,"data":2324,"type":218,"tunes":2326},{"text":2325},"Because NVIDIA is a major infrastructure vendor, this should be read as a vendor perspective rather than a neutral global standard. The broader dependency\u002Fcontrol model in this article additionally includes ownership, jurisdiction, identity, supply chain and exit rights.",{},{"id":840,"data":2328,"type":42,"tunes":2330},{"text":2329,"level":253},"A practical enterprise sovereignty maturity model",{},{"id":845,"data":2332,"type":226,"tunes":2335},{"body":2333,"title":2334,"variant":233},"The following five levels are a practical engineering model proposed for this article. They are \u003Cstrong>not\u003C\u002Fstrong> the European Commission's CADA levels and are not an industry standard.","Original architecture synthesis",{},{"id":851,"data":2337,"type":397,"tunes":2357},{"content":2338,"stretched":43,"withHeadings":14},[2339,2342,2345,2348,2351,2354],[2340,2341],"Level","Architecture state",[2343,2344],"S0 — External dependency","AI capability depends on one external provider with little portability or control",[2346,2347],"S1 — Data-controlled","Organization controls source data, access and retention but relies heavily on external model\u002Fplatform services",[2349,2350],"S2 — Portable application","Data and application remain controlled; model\u002Fprovider boundary is abstracted and migration is technically realistic",[2352,2353],"S3 — Controlled runtime","Critical inference, identity, keys, retrieval and operations can run on organization-controlled or approved sovereign infrastructure",[2355,2356],"S4 — Strategic resilience","Critical stack has tested alternatives, supply-chain visibility, internal operational capability and defined continuity\u002Fexit plans",{},{"id":874,"data":2359,"type":218,"tunes":2361},{"text":2360},"A workload does not need the maximum level by default. The required control should follow consequence, regulation, confidentiality, continuity needs and strategic importance.",{},{"id":879,"data":2363,"type":218,"tunes":2365},{"text":2364},"The point of a maturity model is to expose where dependency remains — not to turn sovereignty into a marketing badge.",{},{"id":884,"data":2367,"type":42,"tunes":2369},{"text":2368,"level":253},"Vendor lock-in becomes sovereignty risk when exit is no longer credible",{},{"id":889,"data":2371,"type":218,"tunes":2373},{"text":2372},"Lock-in is not always bad. Teams accept proprietary dependencies because they provide speed, quality, support or economics.",{},{"id":894,"data":2375,"type":218,"tunes":2377},{"text":2376},"It becomes a sovereignty problem when the dependency is strategically critical and the organization cannot realistically migrate within its required continuity window.",{},{"id":899,"data":2379,"type":218,"tunes":2381},{"text":2380},"Exit therefore needs to be designed and tested, not described in a contract alone.",{},{"id":904,"data":2383,"type":42,"tunes":2385},{"text":2384,"level":253},"What a credible exit plan contains",{},{"id":909,"data":2387,"type":397,"tunes":2425},{"content":2388,"stretched":43,"withHeadings":14},[2389,2392,2394,2397,2399,2402,2404,2407,2410,2413,2416,2419,2422],[2390,2391],"Area","Exit evidence",[1995,2393],"Export in usable, documented formats",[2395,2396],"Prompts\u002Fconfiguration","Stored in application-controlled source\u002Fconfig",[1998,2398],"Alternative model identified and evaluated where required",[2400,2401],"Provider API","Adapter boundary limits provider-specific code",[926,2403],"Corpus, metadata and indexes can be rebuilt outside provider",[2405,2406],"Identity","Application is not permanently coupled to one external identity control plane",[2408,2409],"Keys","Key ownership\u002Fexport\u002Frotation model is understood",[2411,2412],"Infrastructure","Deployment can move to approved alternative environment",[2414,2415],"Observability","Logs\u002Fmetrics\u002Ftraces are exportable and not provider-only",[2417,2418],"Operational knowledge","Runbooks and staff capability exist outside supplier",[2420,2421],"Licensing","Migration is legally permitted",[2423,2424],"Recovery","Fallback\u002Fcontinuity path has been tested",{},{"id":951,"data":2427,"type":42,"tunes":2429},{"text":2428,"level":253},"Portability is not identical to sovereignty — but it is one of its strongest mechanisms",{},{"id":956,"data":2431,"type":218,"tunes":2433},{"text":2432},"A system that can move data but not reproduce model behavior may still be locked in.",{},{"id":961,"data":2435,"type":218,"tunes":2437},{"text":2436},"A system that can switch model endpoints but cannot migrate identity, retrieval data or audit records may still have a critical dependency.",{},{"id":966,"data":2439,"type":218,"tunes":2441},{"text":2440},"Sovereignty requires portability of the critical capability, not merely export of one database.",{},{"id":971,"data":2443,"type":42,"tunes":2445},{"text":2444,"level":253},"Open standards and protocol boundaries reduce replacement cost",{},{"id":976,"data":2447,"type":218,"tunes":2449},{"text":2448},"Standards such as ordinary HTTP APIs, OAuth\u002FOIDC, OpenTelemetry and interoperable data formats can reduce dependency even when implementations remain proprietary.",{},{"id":981,"data":2451,"type":218,"tunes":2453},{"text":2452},"AI-specific protocols can also help at selected boundaries, but no protocol removes provider-specific behavior or legal dependency.",{},{"id":986,"data":2455,"type":218,"tunes":2457},{"text":2456},"The sovereignty value of a standard is practical: does it let the organization replace a component without rewriting the whole platform?",{},{"id":991,"data":2459,"type":42,"tunes":2461},{"text":2460,"level":253},"Sovereignty is a governance decision, not only a technical design",{},{"id":996,"data":2463,"type":218,"tunes":2465},{"text":2464},"Organizations must decide which dependencies are acceptable and who can approve them.",{},{"id":1001,"data":2467,"type":218,"tunes":2469},{"text":2468},"AI governance can classify models\u002Fproviders, define sovereignty requirements by risk tier, require exit evidence and set conditions for third-country or cloud usage.",{},{"id":1006,"data":2471,"type":218,"tunes":2473},{"text":2472},"A sovereignty requirement should therefore appear in architecture decisions, procurement, risk management and operational testing rather than only in a policy statement.",{},{"id":1011,"data":2475,"type":42,"tunes":2477},{"text":2476,"level":253},"Procurement determines much of practical sovereignty",{},{"id":1016,"data":2479,"type":218,"tunes":2481},{"text":2480},"Contracts can define data use, retention, support, portability, model deprecation notice, sub-processors, access jurisdiction and termination assistance.",{},{"id":1021,"data":2483,"type":218,"tunes":2485},{"text":2484},"But contractual promises cannot replace technical portability. If no alternative implementation exists, an exit clause may still be operationally weak.",{},{"id":1026,"data":2487,"type":218,"tunes":2489},{"text":2488},"Sovereignty-oriented procurement should evaluate both legal control and technical substitutability.",{},{"id":1031,"data":2491,"type":42,"tunes":2493},{"text":2492,"level":253},"Hybrid AI can be more sovereign than an all-local design",{},{"id":1036,"data":2495,"type":218,"tunes":2497},{"text":2496},"Sovereignty is sometimes incorrectly equated with “everything runs locally.”",{},{"id":1041,"data":2499,"type":218,"tunes":2501},{"text":2500},"A hybrid architecture can keep sensitive data and authoritative knowledge on controlled infrastructure while using external frontier models for approved tasks, with policy-based routing and tested fallbacks.",{},{"id":1046,"data":2503,"type":218,"tunes":2505},{"text":2504},"If the external model can be removed without losing critical organizational capability, the hybrid platform may have stronger practical sovereignty than a nominally local stack that is locked to one proprietary runtime.",{},{"id":1051,"data":2507,"type":42,"tunes":2509},{"text":2508,"level":253},"Sovereignty does not replace security",{},{"id":1056,"data":2511,"type":218,"tunes":2513},{"text":2512},"Controlling infrastructure does not automatically make it secure. Sovereign environments still need vulnerability management, least privilege, incident response, backups, secure supply chains and auditability.",{},{"id":1061,"data":2515,"type":218,"tunes":2517},{"text":2516},"A locally controlled model can still leak one tenant's data to another if retrieval or authorization is incorrect.",{},{"id":1066,"data":2519,"type":218,"tunes":2521},{"text":2520},"Sovereignty answers who controls the system; security answers whether that control is exercised safely.",{},{"id":1071,"data":2523,"type":42,"tunes":2525},{"text":2524,"level":253},"Sovereignty and regulatory compliance are different",{},{"id":1076,"data":2527,"type":218,"tunes":2529},{"text":2528},"An EU-hosted, EU-controlled AI stack can still violate the AI Act, GDPR or sector-specific requirements.",{},{"id":1081,"data":2531,"type":218,"tunes":2533},{"text":2532},"Likewise, a compliant system can use external providers and still have limited technological sovereignty.",{},{"id":1086,"data":2535,"type":218,"tunes":2537},{"text":2536},"Regulation and sovereignty can reinforce each other, but they are separate architecture\u002Fgovernance dimensions.",{},{"id":1091,"data":2539,"type":42,"tunes":2541},{"text":2540,"level":253},"Original implementation evidence: sovereignty-oriented building blocks",{},{"id":1096,"data":2543,"type":226,"tunes":2546},{"body":2544,"title":2545,"variant":233},"The projects below demonstrate control-oriented architecture patterns such as provider abstraction, local inference, local evidence stores and explicit permission boundaries. They are \u003Cstrong>not\u003C\u002Fstrong> presented as a nationally sovereign AI stack, certified sovereign cloud or proof of full supply-chain independence.","Evidence boundary",{},{"id":1102,"data":2548,"type":42,"tunes":2550},{"text":2549,"level":252},"Aaasaasa AI Client: provider, model, runtime and permissions are separable",{},{"id":1107,"data":2552,"type":218,"tunes":2554},{"text":2553},"Aaasaasa AI Client separates the agent\u002Fclient, provider, provider-specific model, connection location and permission policy. Providers can include Ollama, LM Studio\u002FOpenAI-compatible services and dedicated cloud paths.",{},{"id":1112,"data":2556,"type":218,"tunes":2558},{"text":2557},"The architecture explicitly distinguishes local runtime from local inference: a local agent runtime can use a cloud model, while Direct Ollama chat can perform local inference.",{},{"id":1117,"data":2560,"type":218,"tunes":2562},{"text":2561},"This separation is sovereignty-relevant because provider dependence becomes an explicit configuration layer rather than being hard-coded into the business application.",{},{"id":1122,"data":2564,"type":218,"tunes":2566},{"text":2565},"Central permissions are also application\u002Fsession policy rather than a property of the model. That keeps operational authority under the application's control even when model\u002Fprovider choice changes.",{},{"id":1127,"data":2568,"type":42,"tunes":2570},{"text":2569,"level":252},"Source of Truth Research Engine: local evidence authority",{},{"id":1132,"data":2572,"type":218,"tunes":2574},{"text":2573},"The Source of Truth Research Engine is designed around persistent sources, snapshots, hashes, claims and provenance rather than letting model output become the authority.",{},{"id":1137,"data":2576,"type":218,"tunes":2578},{"text":2577},"That pattern is sovereignty-relevant at the knowledge layer: organizational evidence remains an independent controlled artifact even when the reasoning model can be replaced.",{},{"id":1142,"data":2580,"type":218,"tunes":2582},{"text":2581},"The project therefore demonstrates a useful dependency principle: keep authoritative data\u002Fevidence separable from the model that interprets it.",{},{"id":1147,"data":2584,"type":397,"tunes":2610},{"content":2585,"stretched":43,"withHeadings":14},[2586,2589,2592,2595,2598,2601,2604,2607],[2587,2588],"Verified pattern","Sovereignty relevance",[2590,2591],"Multiple model\u002Fprovider paths","Reduces hard-coded dependence on one inference provider",[2593,2594],"Local Ollama inference","Creates an organization-controlled inference option",[2596,2597],"Runtime location separate from provider","Makes real dependency visible",[2599,2600],"Central application permission profiles","Authority remains outside model\u002Fvendor",[2602,2603],"Persistent source\u002Fevidence identity","Knowledge survives model substitution",[2605,2606],"Cloud paths remain available","Shows hybrid architecture rather than false “local-only” positioning",[2608,2609],"No verified sovereign infrastructure certification","Prevents overclaiming full-stack sovereignty",{},{"id":1176,"data":2612,"type":42,"tunes":2614},{"text":2613,"level":253},"Build a sovereignty dependency map",{},{"id":1181,"data":2616,"type":397,"tunes":2659},{"content":2617,"stretched":43,"withHeadings":14},[2618,2624,2630,2635,2640,2644,2646,2650,2655],[2619,2620,2621,2622,2623],"Layer","Primary provider\u002Fdependency","Control state","Alternative","Exit time",[2625,2626,2627,2628,2629],"Model","e.g. provider\u002Fmodel snapshot","Owned \u002F licensed \u002F API-only","Named replacement","Measured",[2631,2632,2633,2634,2629],"Inference","Cloud\u002Flocal runtime","Direct \u002F contractual","Second runtime",[2636,2637,2638,2639,2629],"Embeddings\u002Freranking","Model\u002Fruntime","Direct \u002F external","Alternative model",[1995,2641,2642,2643,2629],"Database\u002Fobject store","Direct \u002F provider","Portable export",[2405,1210,2638,2645,2629],"Fallback\u002Fmigration path",[2411,2647,2648,2649,2629],"Cloud\u002FHW\u002Fcluster","Owned \u002F leased","Alternate environment",[2651,2652,2653,2654,2629],"Tool integrations","SaaS\u002Finternal services","External\u002Finternal","Fallback\u002Fmanual process",[2414,2656,2657,2658,2629],"Logs\u002Ftraces","Portable\u002Fprovider-only","Alternate stack",{},{"id":1227,"data":2661,"type":218,"tunes":2663},{"text":2662},"The table's value is not the exact columns; it forces strategic dependency to become visible and testable.",{},{"id":1232,"data":2665,"type":218,"tunes":2667},{"text":2666},"An architecture review can then distinguish convenient dependencies from dependencies that threaten continuity, confidentiality or regulatory objectives.",{},{"id":1237,"data":2669,"type":42,"tunes":2671},{"text":2670,"level":253},"When stronger AI sovereignty is justified",{},{"id":1242,"data":2673,"type":397,"tunes":2702},{"content":2674,"stretched":43,"withHeadings":14},[2675,2678,2681,2684,2687,2690,2693,2696,2699],[2676,2677],"Driver","Why stronger control may be justified",[2679,2680],"Critical public infrastructure","Continuity and strategic autonomy may outweigh provider convenience",[2682,2683],"Defence\u002Fsecurity-sensitive workloads","Foreign control\u002Fjurisdiction and supply-chain risk may be unacceptable",[2685,2686],"Highly confidential enterprise data","Data\u002Fmodel\u002Fprovider control may need stronger guarantees",[2688,2689],"Long-lived industrial platforms","Exit and hardware\u002Fsoftware lifecycle matter over many years",[2691,2692],"Regulated public procurement","Formal sovereignty assurance levels may be required",[2694,2695],"National language\u002Fcultural models","Local datasets\u002Fmodel control can preserve strategic capability",[2697,2698],"Provider concentration risk","Alternative model\u002Fruntime paths improve resilience",[2700,2701],"Normal low-risk productivity use","Maximum sovereignty may be unnecessary and uneconomic",{},{"id":1274,"data":2704,"type":218,"tunes":2706},{"text":2705},"Sovereignty should be proportionate. The objective is not to maximize local ownership everywhere; it is to retain enough control for the consequence and threat model.",{},{"id":1279,"data":2708,"type":42,"tunes":2710},{"text":2709,"level":253},"Common sovereign-AI failure modes",{},{"id":1284,"data":2712,"type":397,"tunes":2753},{"content":2713,"stretched":43,"withHeadings":14},[2714,2717,2720,2723,2726,2729,2732,2735,2738,2741,2744,2747,2750],[2715,2716],"Failure mode","What actually failed",[2718,2719],"“Data stays in Europe, therefore sovereign”","Location was confused with ownership, jurisdiction and supply-chain control",[2721,2722],"One proprietary model API with no tested alternative","Critical inference depends on one external actor",[2724,2725],"Open-weight model, proprietary locked runtime","Model openness did not provide full operational control",[2727,2728],"Self-hosted inference, cloud-only identity\u002FKMS","Control plane remains externally dependent",[2730,2731],"Local data but provider-only vector\u002Findex format","Knowledge layer cannot migrate cleanly",[2733,2734],"Multi-provider abstraction without evals","Switching is technically possible but behaviorally unsafe",[2736,2737],"Exit clause with no migration test","Contractual portability is not operational portability",[2739,2740],"Foreign hardware treated as proof of non-sovereignty","Sovereignty was incorrectly defined as absolute autarky",[2742,2743],"Sovereign label with no defined subject\u002Fscope","Nobody knows whose control or which dependencies are meant",[2745,2746],"Internal ownership but no operational skills","System cannot be maintained independently",[2748,2749],"Open source with no maintenance capacity","Source availability exists, practical control does not",[2751,2752],"Air gap treated as sovereignty","Connectivity isolation was confused with dependency control",{},{"id":1328,"data":2755,"type":42,"tunes":2757},{"text":2756,"level":253},"Common misconceptions",{},{"id":1333,"data":2759,"type":397,"tunes":2794},{"content":2760,"stretched":43,"withHeadings":14},[2761,2764,2767,2770,2773,2776,2779,2782,2785,2788,2791],[2762,2763],"Misconception","Correction",[2765,2766],"“Sovereign AI means every component must be domestic.”","Sovereignty is usually about effective control, resilience and reduction of strategic dependencies, not total autarky.",[2768,2769],"“EU data residency equals EU sovereignty.”","Residency is one assurance layer; ownership, jurisdiction and supply-chain control can go further.",[2771,2772],"“Open source equals sovereign.”","Open source improves control and portability but does not eliminate infrastructure, hardware or operational dependencies.",[2774,2775],"“Self-hosted equals sovereign.”","Self-hosting controls location\u002Fruntime, not automatically licenses, chips, identity, supply chain or update paths.",[2777,2778],"“Air-gapped equals sovereign.”","Air gap controls connectivity; sovereignty controls the wider dependency chain.",[2780,2781],"“Private AI equals sovereign AI.”","Privacy focuses on protected processing; sovereignty focuses on strategic\u002Foperational control.",[2783,2784],"“Multi-cloud equals sovereignty.”","Two clouds can still share the same jurisdiction, technology dependency or proprietary control plane.",[2786,2787],"“Using a European company guarantees sovereignty.”","Corporate location helps but technical, legal and supply-chain controls still need examination.",[2789,2790],"“Provider abstraction makes every model replaceable.”","Behavioral differences require evaluation before routing or migration.",[2792,2793],"“Sovereignty is only for governments.”","The term is often national\u002Fregional, but enterprises also have meaningful sovereignty requirements over critical AI dependencies.",{},{"id":1371,"data":2796,"type":42,"tunes":2798},{"text":2797,"level":253},"A practical sovereign-AI design sequence",{},{"id":1376,"data":2800,"type":331,"tunes":2839},{"steps":2801,"title":2838,"orientation":330},[2802,2805,2808,2811,2814,2817,2820,2823,2826,2829,2832,2835],{"label":2803,"description":2804},"1. Define the sovereignty subject","State whether control is required for an enterprise, public body, country, EU domain or another authority.",{"label":2806,"description":2807},"2. Define critical capabilities","Identify which AI functions cannot be lost or externally controlled.",{"label":2809,"description":2810},"3. Classify data and jurisdiction","Map data location, legal control, retention and permitted processing.",{"label":2812,"description":2813},"4. Map model dependencies","Record weights\u002FAPI ownership, license, version, fine-tuning and substitution options.",{"label":2815,"description":2816},"5. Map infrastructure and control plane","Record compute, cloud, keys, identity, networks and operator access.",{"label":2818,"description":2819},"6. Map software and supply chain","Identify proprietary runtime, open source, packages, registries, updates and critical suppliers.",{"label":2821,"description":2822},"7. Choose control mechanisms","Apply local inference, regional providers, open standards, open source or stronger ownership where justified.",{"label":2824,"description":2825},"8. Build provider\u002Fmodel abstraction","Keep business applications from hard-coding one supplier where portability matters.",{"label":2827,"description":2828},"9. Preserve authoritative data independently","Ensure knowledge, provenance and business records survive model replacement.",{"label":2830,"description":2831},"10. Define exit criteria","Set maximum acceptable migration\u002Fcontinuity time for critical dependencies.",{"label":2833,"description":2834},"11. Test replacement and recovery","Run realistic failover\u002Fmigration exercises rather than trust architecture diagrams.",{"label":2836,"description":2837},"12. Reassess periodically","Supplier ownership, policy, prices, law, model support and technology ecosystems change.","Design from strategic dependency outward",{},{"id":1418,"data":2841,"type":42,"tunes":2843},{"text":2842,"level":253},"Sovereign AI architecture checklist",{},{"id":1423,"data":2845,"type":397,"tunes":2898},{"content":2846,"stretched":43,"withHeadings":14},[2847,2850,2853,2856,2859,2862,2865,2868,2871,2874,2877,2880,2883,2886,2889,2892,2895],[2848,2849],"Question","Expected evidence",[2851,2852],"Sovereign for whom?","Named authority\u002Fjurisdiction\u002Forganization",[2854,2855],"Which capabilities are strategic?","Criticality classification",[2857,2858],"Where is data processed\u002Fstored?","Verified data-flow map",[2860,2861],"Who can legally\u002Ftechnically access data?","Jurisdiction + IAM + operator model",[2863,2864],"Who controls model access\u002Fweights?","License\u002Fprovider\u002Fmodel ownership record",[2866,2867],"Can the model be replaced?","Evaluated alternative and migration path",[2869,2870],"Who controls inference compute?","Infrastructure\u002Fcontrol-plane ownership",[2872,2873],"Who controls identity and keys?","IAM\u002FKMS custody model",[2875,2876],"Which components are proprietary?","Software dependency inventory",[2878,2879],"Which dependencies are open\u002Fportable?","Standards\u002Fsource\u002Flicensing evidence",[2881,2882],"Which third-country dependencies remain?","Explicit dependency register",[2884,2885],"Can critical operation continue during provider loss?","Continuity\u002Ffallback test",[2887,2888],"Can data and knowledge be exported\u002Frebuilt?","Portability\u002Frebuild procedure",[2890,2891],"Can staff operate the platform without supplier intervention?","Runbooks\u002Fskills\u002Foperational evidence",[2893,2894],"How long would exit take?","Measured migration objective",[2896,2897],"What changes would trigger reassessment?","Ownership, legal, model, provider and supply-chain review triggers",{},{"id":1479,"data":2900,"type":42,"tunes":2902},{"text":2901,"level":253},"Limits and trade-offs",{},{"id":1484,"data":2904,"type":218,"tunes":2906},{"text":2905},"Stronger sovereignty can increase cost because more infrastructure, operations and expertise must be maintained directly or within a constrained provider ecosystem.",{},{"id":1489,"data":2908,"type":218,"tunes":2910},{"text":2909},"Local or regional alternatives may lag frontier-model capability for some workloads. Sovereignty policy should therefore support risk-based routing rather than force weaker models into every task.",{},{"id":1494,"data":2912,"type":218,"tunes":2914},{"text":2913},"Absolute independence is rarely realistic in modern semiconductor and software supply chains. Architecture should identify and reduce unacceptable dependencies instead of claiming impossible self-sufficiency.",{},{"id":1499,"data":2916,"type":218,"tunes":2918},{"text":2917},"Sovereignty can also reduce ecosystem choice if procurement rules become too rigid. Current EU policy explicitly tries to strengthen autonomy while retaining open markets and partnerships.",{},{"id":1504,"data":2920,"type":218,"tunes":2922},{"text":2921},"A system can become “sovereign” on paper while operationally fragile if no team can patch, monitor or migrate it.",{},{"id":1509,"data":2924,"type":42,"tunes":2926},{"text":2925,"level":253},"What would change this answer?",{},{"id":1514,"data":2928,"type":218,"tunes":2930},{"text":2929},"The EU's proposed CADA sovereignty framework may evolve through the legislative process, so exact assurance-level requirements should be rechecked before procurement or legal decisions.",{},{"id":1519,"data":2932,"type":218,"tunes":2934},{"text":2933},"Provider ownership, model licensing, geopolitical conditions and semiconductor supply chains can materially change the sovereignty assessment without any application-code change.",{},{"id":1524,"data":2936,"type":218,"tunes":2938},{"text":2937},"The stable architectural principle is that sovereignty depends on effective control and credible alternatives across critical dependencies, not on one geographic or branding attribute.",{},{"id":1529,"data":2940,"type":42,"tunes":2942},{"text":2941,"level":253},"Related canonical knowledge",{},{"id":1534,"data":2944,"type":218,"tunes":2946},{"text":2945},"Sovereign AI sits above several deployment and control concepts: Private AI protects sensitive processing, Air-Gapped AI isolates network domains, AI Governance assigns decision rights, and LLMOps operates model\u002Fprovider changes.",{},{"id":1539,"data":2948,"type":218,"tunes":2950},{"text":2949},"Provider abstraction and model routing are practical mechanisms for reducing dependency, while Source of Truth architecture keeps organizational evidence independent of any one model.",{},{"id":1544,"data":2952,"type":218,"tunes":2954},{"text":2953},"Enterprise AI Architecture determines where these sovereignty requirements belong across platforms, applications, identity, infrastructure and operations.",{},{"id":1549,"data":2956,"type":752,"tunes":2961},{"url":2957,"title":2958,"excerpt":2959,"ctaLabel":2960},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","The Answer Validity Boundary: The Missing Layer Between Relevance and Reliable AI Answers","Sovereignty over infrastructure does not make an answer true. Reliable knowledge still requires evidence, authority, scope and validity controls.","Read the Answer Validity Boundary",{},{"id":1557,"data":2963,"type":752,"tunes":2968},{"url":2964,"title":2965,"excerpt":2966,"ctaLabel":2967},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context","Keeping state, knowledge, retrieval and model context separate improves portability and reduces coupling to one AI provider.","Read the architecture article",{},{"id":1565,"data":2970,"type":42,"tunes":2972},{"text":2971,"level":253},"Frequently asked questions",{},{"id":1570,"data":2974,"type":1570,"tunes":3007},{"items":2975,"title":3006},[2976,2979,2982,2985,2988,2991,2994,2997,3000,3003],{"id":1574,"answer":2977,"question":2978},"Sovereign AI is the ability of a defined authority such as a country, public institution or organization to retain effective control over critical AI data, models, infrastructure, software, operations and dependencies.","What is sovereign AI?",{"id":1578,"answer":2980,"question":2981},"No. Data sovereignty is one component. AI sovereignty also includes model control, compute, software supply chain, identity, operators, jurisdiction and the ability to replace critical providers.","Is sovereign AI the same as data sovereignty?",{"id":1582,"answer":2983,"question":2984},"No. A sovereign architecture can use external or cloud services if the required level of control, legal assurance, portability and continuity is preserved.","Does sovereign AI require everything to be hosted locally?",{"id":1586,"answer":2986,"question":2987},"No. Open source or open weights can improve control and portability, but proprietary components can still be used where dependency and licensing are acceptable.","Does sovereign AI require open-source models?",{"id":1590,"answer":2989,"question":2990},"No. Self-hosting controls inference location but can still depend on external identity, proprietary runtimes, foreign hardware, licenses or update infrastructure.","Is self-hosted AI automatically sovereign?",{"id":1594,"answer":2992,"question":2993},"Air-gapped AI is about physical\u002Fnetwork isolation and controlled transfer. Sovereign AI is about effective control over the entire dependency chain. Either can exist without the other.","What is the difference between sovereign AI and air-gapped AI?",{"id":1598,"answer":2995,"question":2996},"Potentially, depending on the required sovereignty level and who controls location, provider ownership, administrative access, keys, supply chain, jurisdiction and exit.","Can a cloud AI service be sovereign?",{"id":1602,"answer":2998,"question":2999},"It reduces application coupling to one model provider and creates a technical migration path, although behavioral differences still require evaluation.","Why does provider abstraction matter for sovereignty?",{"id":1606,"answer":3001,"question":3002},"Map critical dependencies and test whether data, models, workloads and operations can continue or migrate within the required time if a provider, jurisdiction or supply-chain dependency becomes unacceptable.","How do you measure practical AI sovereignty?",{"id":1610,"answer":3004,"question":3005},"That sovereignty is one property such as EU hosting, local inference, open source or an air gap. In reality it is a multi-layer control and dependency problem.","What is the biggest misconception about sovereign AI?","Sovereign AI FAQ",{},{"id":1616,"data":3009,"type":42,"tunes":3011},{"text":3010,"level":253},"Glossary",{},{"id":1621,"data":3013,"type":1621,"tunes":3051},{"title":3014,"entries":3015},"Key sovereign-AI terms",[3016,3018,3021,3024,3027,3030,3033,3036,3039,3042,3045,3048],{"term":2289,"anchor":1626,"definition":3017},"AI capability designed so a defined authority retains effective control over critical data, models, infrastructure, operations and dependencies.",{"term":3019,"anchor":1630,"definition":3020},"Tech sovereignty","Ability to act independently in the digital domain by controlling key technologies, data and infrastructure while reducing strategic external dependencies.",{"term":3022,"anchor":1634,"definition":3023},"Strategic dependency","External dependency whose loss, control or change can materially threaten continuity, security, autonomy or policy objectives.",{"term":3025,"anchor":1638,"definition":3026},"Data residency","Requirement describing where data is physically or logically stored\u002Fprocessed; narrower than sovereignty.",{"term":3028,"anchor":1642,"definition":3029},"Data sovereignty","Control of data under applicable legal, organizational and jurisdictional authority.",{"term":3031,"anchor":1646,"definition":3032},"Model sovereignty","Degree of control over model access, weights, licensing, modification, versioning, deployment and replacement.",{"term":3034,"anchor":1650,"definition":3035},"Infrastructure sovereignty","Control over compute, hosting, control plane, operations and infrastructure jurisdiction needed for critical workloads.",{"term":3037,"anchor":1654,"definition":3038},"Operational sovereignty","Ability to deploy, maintain, observe, recover and migrate a system without unacceptable dependence on one external operator.",{"term":3040,"anchor":1658,"definition":3041},"Provider abstraction","Application architecture separating business logic from provider-specific APIs so model\u002Fprovider dependencies can be changed more safely.",{"term":3043,"anchor":1662,"definition":3044},"Exit strategy","Testable plan for moving data, workloads and operational capability away from an external dependency.",{"term":3046,"anchor":1666,"definition":3047},"Supply-chain sovereignty","Degree of transparency, control and substitutability across critical software, model, hardware and update dependencies.",{"term":3049,"anchor":1670,"definition":3050},"Strategic autonomy","Capacity to make and execute critical decisions without unacceptable external constraint or dependency.",{},{"id":1674,"data":3053,"type":42,"tunes":3055},{"text":3054,"level":253},"Conclusion",{},{"id":1679,"data":3057,"type":218,"tunes":3059},{"text":3058},"Sovereign AI is not one product category and not one deployment location. It is an architecture and governance objective: retain effective control over the AI capabilities that matter.",{},{"id":1684,"data":3061,"type":218,"tunes":3063},{"text":3062},"The strongest sovereignty designs separate data from models, business applications from providers, authority from model capability and critical operations from non-substitutable external dependencies.",{},{"id":1689,"data":3065,"type":218,"tunes":3067},{"text":3066},"The shortest reliable rule is: sovereignty is not proven by where the model runs; it is proven by who controls the critical stack, which dependencies remain, and whether the organization can continue or change direction when those dependencies become unacceptable.",{},{"id":1694,"data":3069,"type":42,"tunes":3071},{"text":3070,"level":253},"Primary and current sources",{},{"id":1699,"data":3073,"type":218,"tunes":3075},{"text":3074},"The sources below separate official EU tech-sovereignty policy, current proposed cloud\u002FAI sovereignty assurance levels, European compute initiatives and a vendor technical framing. The enterprise sovereignty maturity model in this article is explicitly original synthesis, not an EU or industry standard.",{},{"id":1704,"data":3077,"type":1711,"tunes":3082},{"link":1706,"meta":3078},{"image":3079,"title":3080,"description":3081},{"url":767},"European Commission — Strengthening Europe's Tech Sovereignty","Current EU definition of tech sovereignty as independent action through control of key technologies, data and infrastructure while reducing reliance on non-EU providers.",{},{"id":1714,"data":3084,"type":1711,"tunes":3089},{"link":1716,"meta":3085},{"image":3086,"title":3087,"description":3088},{"url":767},"European Commission — Communication on European Tech Sovereignty","2026 policy package covering the technology value chain from chips through infrastructure, software, cloud and AI.",{},{"id":1723,"data":3091,"type":1711,"tunes":3096},{"link":1725,"meta":3092},{"image":3093,"title":3094,"description":3095},{"url":767},"European Commission — Cloud and AI Development Act","Current proposed EU framework defining four cloud\u002FAI sovereignty assurance levels across location, third-country independence, ownership\u002Fcontrol and software-supply-chain control.",{},{"id":1732,"data":3098,"type":1711,"tunes":3103},{"link":1734,"meta":3099},{"image":3100,"title":3101,"description":3102},{"url":767},"European Commission — EU Open Source Strategy","Current policy connecting open source with greater control, lower lock-in, security, reuse and technological sovereignty.",{},{"id":1741,"data":3105,"type":1711,"tunes":3110},{"link":1743,"meta":3106},{"image":3107,"title":3108,"description":3109},{"url":767},"European Commission — AI Factories","Current EU AI compute infrastructure initiative linking AI factories and gigafactories with European capacity and technological sovereignty.",{},{"id":1750,"data":3112,"type":1711,"tunes":3117},{"link":1752,"meta":3113},{"image":3114,"title":3115,"description":3116},{"url":767},"European Commission — AI Gigafactories call","2026 initiative to expand European AI compute, resilience and strategic autonomy on infrastructure built and operated in Europe.",{},{"id":1759,"data":3119,"type":1711,"tunes":3124},{"link":1761,"meta":3120},{"image":3121,"title":3122,"description":3123},{"url":767},"EuroHPC JU — AI Gigafactories","Current EuroHPC framing of large-scale sovereign AI computing infrastructure and technological independence.",{},{"id":1768,"data":3126,"type":1711,"tunes":3131},{"link":1770,"meta":3127},{"image":3128,"title":3129,"description":3130},{"url":767},"NVIDIA — Building Sovereign AI Models","Vendor technical framing organized around data\u002Fbenchmarks, models, hardware infrastructure and frameworks; useful as industry perspective, not a universal standard.",{},"2.31.6","Sovereign AI is about effective control over models, data, infrastructure, software, operations and strategic dependencies — not simply where an AI model is hosted.",{"lang":7,"title":208,"content":210,"contentJson":3135,"excerpt":1777},{"time":212,"blocks":3136,"version":1776},[3137,3140,3143,3146,3149,3152,3155,3158,3161,3164,3167,3170,3173,3176,3179,3182,3194,3197,3200,3203,3206,3209,3212,3215,3218,3221,3230,3233,3236,3239,3242,3259,3262,3265,3268,3271,3274,3277,3280,3283,3286,3289,3292,3295,3298,3301,3304,3307,3310,3313,3316,3319,3322,3325,3328,3331,3334,3337,3340,3343,3346,3349,3352,3355,3358,3361,3364,3367,3370,3373,3376,3379,3382,3385,3388,3391,3394,3397,3400,3403,3406,3409,3412,3415,3418,3421,3424,3427,3430,3433,3450,3453,3456,3459,3462,3465,3468,3471,3474,3477,3480,3483,3493,3496,3499,3502,3505,3508,3511,3514,3531,3534,3537,3540,3543,3546,3549,3552,3555,3558,3561,3564,3567,3570,3573,3576,3579,3582,3585,3588,3591,3594,3597,3600,3603,3606,3609,3612,3615,3618,3621,3624,3627,3630,3633,3636,3639,3642,3645,3648,3660,3663,3676,3679,3682,3685,3698,3701,3704,3721,3724,3739,3742,3758,3761,3782,3785,3788,3791,3794,3797,3800,3803,3806,3809,3812,3815,3818,3821,3824,3827,3830,3833,3847,3850,3866,3869,3872,3875,3878,3881,3884,3889,3894,3899,3904,3909,3914,3919],{"id":215,"data":3138,"type":218,"tunes":3139},{"text":217},{},{"id":221,"data":3141,"type":226,"tunes":3142},{"body":223,"title":224,"variant":225},{},{"id":229,"data":3144,"type":226,"tunes":3145},{"body":231,"title":232,"variant":233},{},{"id":236,"data":3147,"type":226,"tunes":3148},{"body":238,"title":239,"variant":240},{},{"id":243,"data":3150,"type":226,"tunes":3151},{"body":245,"title":246,"variant":233},{},{"id":249,"data":3153,"type":254,"tunes":3154},{"title":251,"maxLevel":252,"minLevel":253},{},{"id":257,"data":3156,"type":42,"tunes":3157},{"text":259,"level":253},{},{"id":262,"data":3159,"type":218,"tunes":3160},{"text":264},{},{"id":267,"data":3162,"type":218,"tunes":3163},{"text":269},{},{"id":272,"data":3165,"type":218,"tunes":3166},{"text":274},{},{"id":277,"data":3168,"type":42,"tunes":3169},{"text":279,"level":253},{},{"id":282,"data":3171,"type":218,"tunes":3172},{"text":284},{},{"id":287,"data":3174,"type":218,"tunes":3175},{"text":289},{},{"id":292,"data":3177,"type":218,"tunes":3178},{"text":294},{},{"id":297,"data":3180,"type":218,"tunes":3181},{"text":299},{},{"id":302,"data":3183,"type":331,"tunes":3193},{"steps":3184,"title":329,"orientation":330},[3185,3186,3187,3188,3189,3190,3191,3192],{"label":306,"description":307},{"label":309,"description":310},{"label":312,"description":313},{"label":315,"description":316},{"label":318,"description":319},{"label":321,"description":322},{"label":324,"description":325},{"label":327,"description":328},{},{"id":334,"data":3195,"type":42,"tunes":3196},{"text":336,"level":253},{},{"id":339,"data":3198,"type":218,"tunes":3199},{"text":341},{},{"id":344,"data":3201,"type":218,"tunes":3202},{"text":346},{},{"id":349,"data":3204,"type":218,"tunes":3205},{"text":351},{},{"id":354,"data":3207,"type":42,"tunes":3208},{"text":356,"level":253},{},{"id":359,"data":3210,"type":218,"tunes":3211},{"text":361},{},{"id":364,"data":3213,"type":218,"tunes":3214},{"text":366},{},{"id":369,"data":3216,"type":218,"tunes":3217},{"text":371},{},{"id":374,"data":3219,"type":42,"tunes":3220},{"text":376,"level":253},{},{"id":379,"data":3222,"type":397,"tunes":3229},{"content":3223,"stretched":43,"withHeadings":14},[3224,3225,3226,3227,3228],[383,384],[386,387],[389,390],[392,393],[395,396],{},{"id":400,"data":3231,"type":218,"tunes":3232},{"text":402},{},{"id":405,"data":3234,"type":218,"tunes":3235},{"text":407},{},{"id":410,"data":3237,"type":226,"tunes":3238},{"body":412,"title":413,"variant":414},{},{"id":417,"data":3240,"type":42,"tunes":3241},{"text":419,"level":253},{},{"id":422,"data":3243,"type":397,"tunes":3258},{"content":3244,"stretched":43,"withHeadings":14},[3245,3246,3247,3248,3249,3250,3251,3252,3253,3254,3255,3256,3257],[426,427],[429,430],[432,433],[435,436],[438,439],[441,442],[444,445],[447,448],[450,451],[453,454],[456,457],[459,460],[462,463],{},{"id":466,"data":3260,"type":42,"tunes":3261},{"text":468,"level":253},{},{"id":471,"data":3263,"type":218,"tunes":3264},{"text":473},{},{"id":476,"data":3266,"type":218,"tunes":3267},{"text":478},{},{"id":481,"data":3269,"type":218,"tunes":3270},{"text":483},{},{"id":486,"data":3272,"type":42,"tunes":3273},{"text":488,"level":253},{},{"id":491,"data":3275,"type":218,"tunes":3276},{"text":493},{},{"id":496,"data":3278,"type":218,"tunes":3279},{"text":498},{},{"id":501,"data":3281,"type":218,"tunes":3282},{"text":503},{},{"id":506,"data":3284,"type":42,"tunes":3285},{"text":508,"level":253},{},{"id":511,"data":3287,"type":218,"tunes":3288},{"text":513},{},{"id":516,"data":3290,"type":218,"tunes":3291},{"text":518},{},{"id":521,"data":3293,"type":218,"tunes":3294},{"text":523},{},{"id":526,"data":3296,"type":42,"tunes":3297},{"text":528,"level":253},{},{"id":531,"data":3299,"type":218,"tunes":3300},{"text":533},{},{"id":536,"data":3302,"type":218,"tunes":3303},{"text":538},{},{"id":541,"data":3305,"type":218,"tunes":3306},{"text":543},{},{"id":546,"data":3308,"type":42,"tunes":3309},{"text":548,"level":253},{},{"id":551,"data":3311,"type":218,"tunes":3312},{"text":553},{},{"id":556,"data":3314,"type":218,"tunes":3315},{"text":558},{},{"id":561,"data":3317,"type":218,"tunes":3318},{"text":563},{},{"id":566,"data":3320,"type":42,"tunes":3321},{"text":568,"level":253},{},{"id":571,"data":3323,"type":218,"tunes":3324},{"text":573},{},{"id":576,"data":3326,"type":218,"tunes":3327},{"text":578},{},{"id":581,"data":3329,"type":218,"tunes":3330},{"text":583},{},{"id":586,"data":3332,"type":42,"tunes":3333},{"text":588,"level":253},{},{"id":591,"data":3335,"type":218,"tunes":3336},{"text":593},{},{"id":596,"data":3338,"type":218,"tunes":3339},{"text":598},{},{"id":601,"data":3341,"type":218,"tunes":3342},{"text":603},{},{"id":606,"data":3344,"type":42,"tunes":3345},{"text":608,"level":253},{},{"id":611,"data":3347,"type":218,"tunes":3348},{"text":613},{},{"id":616,"data":3350,"type":218,"tunes":3351},{"text":618},{},{"id":621,"data":3353,"type":218,"tunes":3354},{"text":623},{},{"id":626,"data":3356,"type":42,"tunes":3357},{"text":628,"level":253},{},{"id":631,"data":3359,"type":218,"tunes":3360},{"text":633},{},{"id":636,"data":3362,"type":218,"tunes":3363},{"text":638},{},{"id":641,"data":3365,"type":218,"tunes":3366},{"text":643},{},{"id":646,"data":3368,"type":42,"tunes":3369},{"text":648,"level":253},{},{"id":651,"data":3371,"type":218,"tunes":3372},{"text":653},{},{"id":656,"data":3374,"type":218,"tunes":3375},{"text":658},{},{"id":661,"data":3377,"type":218,"tunes":3378},{"text":663},{},{"id":666,"data":3380,"type":42,"tunes":3381},{"text":668,"level":253},{},{"id":671,"data":3383,"type":218,"tunes":3384},{"text":673},{},{"id":676,"data":3386,"type":218,"tunes":3387},{"text":678},{},{"id":681,"data":3389,"type":218,"tunes":3390},{"text":683},{},{"id":686,"data":3392,"type":42,"tunes":3393},{"text":688,"level":253},{},{"id":691,"data":3395,"type":218,"tunes":3396},{"text":693},{},{"id":696,"data":3398,"type":218,"tunes":3399},{"text":698},{},{"id":701,"data":3401,"type":218,"tunes":3402},{"text":703},{},{"id":706,"data":3404,"type":42,"tunes":3405},{"text":708,"level":253},{},{"id":711,"data":3407,"type":218,"tunes":3408},{"text":713},{},{"id":716,"data":3410,"type":218,"tunes":3411},{"text":718},{},{"id":721,"data":3413,"type":218,"tunes":3414},{"text":723},{},{"id":726,"data":3416,"type":42,"tunes":3417},{"text":728,"level":253},{},{"id":731,"data":3419,"type":218,"tunes":3420},{"text":733},{},{"id":736,"data":3422,"type":218,"tunes":3423},{"text":738},{},{"id":741,"data":3425,"type":218,"tunes":3426},{"text":743},{},{"id":746,"data":3428,"type":752,"tunes":3429},{"url":748,"title":749,"excerpt":750,"ctaLabel":751},{},{"id":755,"data":3431,"type":42,"tunes":3432},{"text":757,"level":253},{},{"id":760,"data":3434,"type":792,"tunes":3449},{"rows":3435,"title":784,"layout":397,"columns":3446},[3436,3438,3440,3442,3444],{"id":764,"label":765,"values":3437},[767,767],{"id":769,"label":770,"values":3439},[767,767],{"id":773,"label":774,"values":3441},[767,767],{"id":777,"label":778,"values":3443},[767,767],{"id":781,"label":782,"values":3445},[767,767],[3447,3448],{"id":787,"label":788},{"id":790,"label":791},{},{"id":795,"data":3451,"type":218,"tunes":3452},{"text":797},{},{"id":800,"data":3454,"type":42,"tunes":3455},{"text":802,"level":253},{},{"id":805,"data":3457,"type":218,"tunes":3458},{"text":807},{},{"id":810,"data":3460,"type":218,"tunes":3461},{"text":812},{},{"id":815,"data":3463,"type":218,"tunes":3464},{"text":817},{},{"id":820,"data":3466,"type":42,"tunes":3467},{"text":822,"level":253},{},{"id":825,"data":3469,"type":218,"tunes":3470},{"text":827},{},{"id":830,"data":3472,"type":218,"tunes":3473},{"text":832},{},{"id":835,"data":3475,"type":218,"tunes":3476},{"text":837},{},{"id":840,"data":3478,"type":42,"tunes":3479},{"text":842,"level":253},{},{"id":845,"data":3481,"type":226,"tunes":3482},{"body":847,"title":848,"variant":233},{},{"id":851,"data":3484,"type":397,"tunes":3492},{"content":3485,"stretched":43,"withHeadings":14},[3486,3487,3488,3489,3490,3491],[855,856],[858,859],[861,862],[864,865],[867,868],[870,871],{},{"id":874,"data":3494,"type":218,"tunes":3495},{"text":876},{},{"id":879,"data":3497,"type":218,"tunes":3498},{"text":881},{},{"id":884,"data":3500,"type":42,"tunes":3501},{"text":886,"level":253},{},{"id":889,"data":3503,"type":218,"tunes":3504},{"text":891},{},{"id":894,"data":3506,"type":218,"tunes":3507},{"text":896},{},{"id":899,"data":3509,"type":218,"tunes":3510},{"text":901},{},{"id":904,"data":3512,"type":42,"tunes":3513},{"text":906,"level":253},{},{"id":909,"data":3515,"type":397,"tunes":3530},{"content":3516,"stretched":43,"withHeadings":14},[3517,3518,3519,3520,3521,3522,3523,3524,3525,3526,3527,3528,3529],[913,914],[429,916],[918,919],[432,921],[923,924],[926,927],[929,930],[932,933],[935,936],[938,939],[941,942],[944,945],[947,948],{},{"id":951,"data":3532,"type":42,"tunes":3533},{"text":953,"level":253},{},{"id":956,"data":3535,"type":218,"tunes":3536},{"text":958},{},{"id":961,"data":3538,"type":218,"tunes":3539},{"text":963},{},{"id":966,"data":3541,"type":218,"tunes":3542},{"text":968},{},{"id":971,"data":3544,"type":42,"tunes":3545},{"text":973,"level":253},{},{"id":976,"data":3547,"type":218,"tunes":3548},{"text":978},{},{"id":981,"data":3550,"type":218,"tunes":3551},{"text":983},{},{"id":986,"data":3553,"type":218,"tunes":3554},{"text":988},{},{"id":991,"data":3556,"type":42,"tunes":3557},{"text":993,"level":253},{},{"id":996,"data":3559,"type":218,"tunes":3560},{"text":998},{},{"id":1001,"data":3562,"type":218,"tunes":3563},{"text":1003},{},{"id":1006,"data":3565,"type":218,"tunes":3566},{"text":1008},{},{"id":1011,"data":3568,"type":42,"tunes":3569},{"text":1013,"level":253},{},{"id":1016,"data":3571,"type":218,"tunes":3572},{"text":1018},{},{"id":1021,"data":3574,"type":218,"tunes":3575},{"text":1023},{},{"id":1026,"data":3577,"type":218,"tunes":3578},{"text":1028},{},{"id":1031,"data":3580,"type":42,"tunes":3581},{"text":1033,"level":253},{},{"id":1036,"data":3583,"type":218,"tunes":3584},{"text":1038},{},{"id":1041,"data":3586,"type":218,"tunes":3587},{"text":1043},{},{"id":1046,"data":3589,"type":218,"tunes":3590},{"text":1048},{},{"id":1051,"data":3592,"type":42,"tunes":3593},{"text":1053,"level":253},{},{"id":1056,"data":3595,"type":218,"tunes":3596},{"text":1058},{},{"id":1061,"data":3598,"type":218,"tunes":3599},{"text":1063},{},{"id":1066,"data":3601,"type":218,"tunes":3602},{"text":1068},{},{"id":1071,"data":3604,"type":42,"tunes":3605},{"text":1073,"level":253},{},{"id":1076,"data":3607,"type":218,"tunes":3608},{"text":1078},{},{"id":1081,"data":3610,"type":218,"tunes":3611},{"text":1083},{},{"id":1086,"data":3613,"type":218,"tunes":3614},{"text":1088},{},{"id":1091,"data":3616,"type":42,"tunes":3617},{"text":1093,"level":253},{},{"id":1096,"data":3619,"type":226,"tunes":3620},{"body":1098,"title":1099,"variant":233},{},{"id":1102,"data":3622,"type":42,"tunes":3623},{"text":1104,"level":252},{},{"id":1107,"data":3625,"type":218,"tunes":3626},{"text":1109},{},{"id":1112,"data":3628,"type":218,"tunes":3629},{"text":1114},{},{"id":1117,"data":3631,"type":218,"tunes":3632},{"text":1119},{},{"id":1122,"data":3634,"type":218,"tunes":3635},{"text":1124},{},{"id":1127,"data":3637,"type":42,"tunes":3638},{"text":1129,"level":252},{},{"id":1132,"data":3640,"type":218,"tunes":3641},{"text":1134},{},{"id":1137,"data":3643,"type":218,"tunes":3644},{"text":1139},{},{"id":1142,"data":3646,"type":218,"tunes":3647},{"text":1144},{},{"id":1147,"data":3649,"type":397,"tunes":3659},{"content":3650,"stretched":43,"withHeadings":14},[3651,3652,3653,3654,3655,3656,3657,3658],[1151,1152],[1154,1155],[1157,1158],[1160,1161],[1163,1164],[1166,1167],[1169,1170],[1172,1173],{},{"id":1176,"data":3661,"type":42,"tunes":3662},{"text":1178,"level":253},{},{"id":1181,"data":3664,"type":397,"tunes":3675},{"content":3665,"stretched":43,"withHeadings":14},[3666,3667,3668,3669,3670,3671,3672,3673,3674],[1185,1186,1187,1188,1189],[432,1191,1192,1193,1194],[1196,1197,1198,1199,1194],[1201,1202,1203,1204,1194],[429,1206,1207,1208,1194],[929,1210,1203,1211,1194],[935,1213,1214,1215,1194],[1217,1218,1219,1220,1194],[938,1222,1223,1224,1194],{},{"id":1227,"data":3677,"type":218,"tunes":3678},{"text":1229},{},{"id":1232,"data":3680,"type":218,"tunes":3681},{"text":1234},{},{"id":1237,"data":3683,"type":42,"tunes":3684},{"text":1239,"level":253},{},{"id":1242,"data":3686,"type":397,"tunes":3697},{"content":3687,"stretched":43,"withHeadings":14},[3688,3689,3690,3691,3692,3693,3694,3695,3696],[1246,1247],[1249,1250],[1252,1253],[1255,1256],[1258,1259],[1261,1262],[1264,1265],[1267,1268],[1270,1271],{},{"id":1274,"data":3699,"type":218,"tunes":3700},{"text":1276},{},{"id":1279,"data":3702,"type":42,"tunes":3703},{"text":1281,"level":253},{},{"id":1284,"data":3705,"type":397,"tunes":3720},{"content":3706,"stretched":43,"withHeadings":14},[3707,3708,3709,3710,3711,3712,3713,3714,3715,3716,3717,3718,3719],[1288,1289],[1291,1292],[1294,1295],[1297,1298],[1300,1301],[1303,1304],[1306,1307],[1309,1310],[1312,1313],[1315,1316],[1318,1319],[1321,1322],[1324,1325],{},{"id":1328,"data":3722,"type":42,"tunes":3723},{"text":1330,"level":253},{},{"id":1333,"data":3725,"type":397,"tunes":3738},{"content":3726,"stretched":43,"withHeadings":14},[3727,3728,3729,3730,3731,3732,3733,3734,3735,3736,3737],[1337,1338],[1340,1341],[1343,1344],[1346,1347],[1349,1350],[1352,1353],[1355,1356],[1358,1359],[1361,1362],[1364,1365],[1367,1368],{},{"id":1371,"data":3740,"type":42,"tunes":3741},{"text":1373,"level":253},{},{"id":1376,"data":3743,"type":331,"tunes":3757},{"steps":3744,"title":1415,"orientation":330},[3745,3746,3747,3748,3749,3750,3751,3752,3753,3754,3755,3756],{"label":1380,"description":1381},{"label":1383,"description":1384},{"label":1386,"description":1387},{"label":1389,"description":1390},{"label":1392,"description":1393},{"label":1395,"description":1396},{"label":1398,"description":1399},{"label":1401,"description":1402},{"label":1404,"description":1405},{"label":1407,"description":1408},{"label":1410,"description":1411},{"label":1413,"description":1414},{},{"id":1418,"data":3759,"type":42,"tunes":3760},{"text":1420,"level":253},{},{"id":1423,"data":3762,"type":397,"tunes":3781},{"content":3763,"stretched":43,"withHeadings":14},[3764,3765,3766,3767,3768,3769,3770,3771,3772,3773,3774,3775,3776,3777,3778,3779,3780],[1427,1428],[1430,1431],[1433,1434],[1436,1437],[1439,1440],[1442,1443],[1445,1446],[1448,1449],[1451,1452],[1454,1455],[1457,1458],[1460,1461],[1463,1464],[1466,1467],[1469,1470],[1472,1473],[1475,1476],{},{"id":1479,"data":3783,"type":42,"tunes":3784},{"text":1481,"level":253},{},{"id":1484,"data":3786,"type":218,"tunes":3787},{"text":1486},{},{"id":1489,"data":3789,"type":218,"tunes":3790},{"text":1491},{},{"id":1494,"data":3792,"type":218,"tunes":3793},{"text":1496},{},{"id":1499,"data":3795,"type":218,"tunes":3796},{"text":1501},{},{"id":1504,"data":3798,"type":218,"tunes":3799},{"text":1506},{},{"id":1509,"data":3801,"type":42,"tunes":3802},{"text":1511,"level":253},{},{"id":1514,"data":3804,"type":218,"tunes":3805},{"text":1516},{},{"id":1519,"data":3807,"type":218,"tunes":3808},{"text":1521},{},{"id":1524,"data":3810,"type":218,"tunes":3811},{"text":1526},{},{"id":1529,"data":3813,"type":42,"tunes":3814},{"text":1531,"level":253},{},{"id":1534,"data":3816,"type":218,"tunes":3817},{"text":1536},{},{"id":1539,"data":3819,"type":218,"tunes":3820},{"text":1541},{},{"id":1544,"data":3822,"type":218,"tunes":3823},{"text":1546},{},{"id":1549,"data":3825,"type":752,"tunes":3826},{"url":1551,"title":1552,"excerpt":1553,"ctaLabel":1554},{},{"id":1557,"data":3828,"type":752,"tunes":3829},{"url":1559,"title":1560,"excerpt":1561,"ctaLabel":1562},{},{"id":1565,"data":3831,"type":42,"tunes":3832},{"text":1567,"level":253},{},{"id":1570,"data":3834,"type":1570,"tunes":3846},{"items":3835,"title":1613},[3836,3837,3838,3839,3840,3841,3842,3843,3844,3845],{"id":1574,"answer":1575,"question":1576},{"id":1578,"answer":1579,"question":1580},{"id":1582,"answer":1583,"question":1584},{"id":1586,"answer":1587,"question":1588},{"id":1590,"answer":1591,"question":1592},{"id":1594,"answer":1595,"question":1596},{"id":1598,"answer":1599,"question":1600},{"id":1602,"answer":1603,"question":1604},{"id":1606,"answer":1607,"question":1608},{"id":1610,"answer":1611,"question":1612},{},{"id":1616,"data":3848,"type":42,"tunes":3849},{"text":1618,"level":253},{},{"id":1621,"data":3851,"type":1621,"tunes":3865},{"title":1623,"entries":3852},[3853,3854,3855,3856,3857,3858,3859,3860,3861,3862,3863,3864],{"term":791,"anchor":1626,"definition":1627},{"term":1629,"anchor":1630,"definition":1631},{"term":1633,"anchor":1634,"definition":1635},{"term":1637,"anchor":1638,"definition":1639},{"term":1641,"anchor":1642,"definition":1643},{"term":1645,"anchor":1646,"definition":1647},{"term":1649,"anchor":1650,"definition":1651},{"term":1653,"anchor":1654,"definition":1655},{"term":1657,"anchor":1658,"definition":1659},{"term":1661,"anchor":1662,"definition":1663},{"term":1665,"anchor":1666,"definition":1667},{"term":1669,"anchor":1670,"definition":1671},{},{"id":1674,"data":3867,"type":42,"tunes":3868},{"text":1676,"level":253},{},{"id":1679,"data":3870,"type":218,"tunes":3871},{"text":1681},{},{"id":1684,"data":3873,"type":218,"tunes":3874},{"text":1686},{},{"id":1689,"data":3876,"type":218,"tunes":3877},{"text":1691},{},{"id":1694,"data":3879,"type":42,"tunes":3880},{"text":1696,"level":253},{},{"id":1699,"data":3882,"type":218,"tunes":3883},{"text":1701},{},{"id":1704,"data":3885,"type":1711,"tunes":3888},{"link":1706,"meta":3886},{"image":3887,"title":1709,"description":1710},{"url":767},{},{"id":1714,"data":3890,"type":1711,"tunes":3893},{"link":1716,"meta":3891},{"image":3892,"title":1719,"description":1720},{"url":767},{},{"id":1723,"data":3895,"type":1711,"tunes":3898},{"link":1725,"meta":3896},{"image":3897,"title":1728,"description":1729},{"url":767},{},{"id":1732,"data":3900,"type":1711,"tunes":3903},{"link":1734,"meta":3901},{"image":3902,"title":1737,"description":1738},{"url":767},{},{"id":1741,"data":3905,"type":1711,"tunes":3908},{"link":1743,"meta":3906},{"image":3907,"title":1746,"description":1747},{"url":767},{},{"id":1750,"data":3910,"type":1711,"tunes":3913},{"link":1752,"meta":3911},{"image":3912,"title":1755,"description":1756},{"url":767},{},{"id":1759,"data":3915,"type":1711,"tunes":3918},{"link":1761,"meta":3916},{"image":3917,"title":1764,"description":1765},{"url":767},{},{"id":1768,"data":3920,"type":1711,"tunes":3923},{"link":1770,"meta":3921},{"image":3922,"title":1773,"description":1774},{"url":767},{},"Post erfolgreich abgerufen",{"items":3926,"source":4011,"manualIds":4012,"manualMatchedIds":4013},[3927,3934,3941,3948,3955,3962,3969,3976,3983,3990,3997,4004],{"id":3928,"slug":3929,"title":3930,"excerpt":3931,"featuredImage":3932,"publishedAt":3933},"471","how-to-know-whether-an-ai-agent-actually-used-the-right-evidence","如何判断一个AI智能体是否真正使用了正确的证据","AI代理可以引用来源，却仍然使用错误的证据。本文介绍一种实用方法，用于核查主张支持、来源权威性、适用性、出处，以及证据是否实际影响了答案。","\u002Fuploads\u002F2026\u002F09\u002Fhow-to-know-whether-an-ai-agent-actually-used-the-right-evidence-1790351317188-o5z9ve.webp","2026-09-25T11:47:00.000Z",{"id":3935,"slug":3936,"title":3937,"excerpt":3938,"featuredImage":3939,"publishedAt":3940},"468","ai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI代理记忆不是RAG：如何区分记忆、检索、状态和上下文","代理记忆、RAG、状态和上下文经常被当作可以互换的概念来使用。它们并不是。这个实用的架构模型将这四个层次区分开来，展示了每一层各自应处的位置，并解释了当系统将它们合并为一层时会出现什么问题。","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context-1790350560308-np0xy6.webp","2026-09-25T11:34:00.000Z",{"id":3942,"slug":3943,"title":3944,"excerpt":3945,"featuredImage":3946,"publishedAt":3947},"470","what-should-an-ai-agent-remember-forget-recompute-or-retrieve-again","AI代理应该记住、遗忘、重新计算还是再次检索什么？","长时间运行的代理不应记住所有内容。本文提供了一个实用的生命周期模型，用于决定哪些内容应属于持久记忆、哪些内容应重新检索、哪些内容重新计算更安全，以及哪些内容应过期或被取代。","\u002Fuploads\u002F2026\u002F09\u002Fwhat-should-an-ai-agent-remember-forget-recompute-or-retrieve-again-1790351131087-iehz28.webp","2026-09-25T09:43:00.000Z",{"id":3949,"slug":3950,"title":3951,"excerpt":3952,"featuredImage":3953,"publishedAt":3954},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","什么是AI平台架构师？模型、数据、运行时、安全与运维","AI平台架构师负责跨模型、提供商、检索、智能体、身份、安全、评估、可观测性和运营设计可复用的AI基础。","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z",{"id":3956,"slug":3957,"title":3958,"excerpt":3959,"featuredImage":3960,"publishedAt":3961},"492","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","MCP 解析：它连接什么、不做什么以及它适用于何处","模型上下文协议通过标准的客户端-服务器边界，将AI应用程序连接到外部工具、资源和提示。了解MCP能做什么、不能做什么，以及它在智能体架构中的定位。","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","2026-10-08T15:09:00.000Z",{"id":3963,"slug":3964,"title":3965,"excerpt":3966,"featuredImage":3967,"publishedAt":3968},"489","agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","智能体AI解析：当AI系统能够规划、使用工具并采取行动","代理式AI在多步执行循环中使用模型，这些模型可以在明确的运行时和权限边界内选择工具、观察结果、更新状态并调整其下一步行动。","\u002Fuploads\u002F2026\u002F10\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act-1791481499084-wnji2a.webp","2026-10-08T11:43:00.000Z",{"id":3970,"slug":3971,"title":3972,"excerpt":3973,"featuredImage":3974,"publishedAt":3975},"487","vector-databases-embeddings-and-reranking-three-different-parts-of-retrieval","向量数据库、嵌入和重排序：检索的三个不同部分","嵌入表示含义，向量数据库检索候选结果，重排序器则精炼结果。了解这三个检索层在RAG中如何不同并协同工作。","\u002Fuploads\u002F2026\u002F10\u002Fvector-databases-embeddings-and-reranking-three-different-parts-of-retrieval-1791480129884-9dtasz.webp","2026-10-08T11:21:00.000Z",{"id":3977,"slug":3978,"title":3979,"excerpt":3980,"featuredImage":3981,"publishedAt":3982},"494","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","气隙AI：AI系统如何在没有互联网或云访问的情况下工作","气隙AI在隔离的安全域内运行模型、RAG和AI应用，无需互联网或云依赖。了解模型、数据、更新和工具如何离线运行。","\u002Fuploads\u002F2026\u002F10\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0.webp","2026-10-08T11:32:00.000Z",{"id":3984,"slug":3985,"title":3986,"excerpt":3987,"featuredImage":3988,"publishedAt":3989},"481","generative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing","生成式人工智能解析：模型、检索、工具与应用并非同一回事","生成式AI不仅仅是一个模型。了解模型、检索、工具、上下文、运行时和应用程序如何在生产AI系统中协同工作。","\u002Fuploads\u002F2026\u002F10\u002Fgenerative-ai-explained-models-retrieval-tools-and-applications-are-not-the-same-thing-1791475411822-pp0dvz.webp","2026-10-08T12:00:00.000Z",{"id":3991,"slug":3992,"title":3993,"excerpt":3994,"featuredImage":3995,"publishedAt":3996},"467","the-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers","答案有效性边界：相关性到可靠AI答案之间缺失的层级","一个来源可能相关、权威，但对于所提出的问题仍然是错误的。缺失的层次是适用性：答案成立的条件，以及迫使其被重新考虑的变化。本文介绍了“答案有效性边界”这一面向人类、AI搜索和RAG系统的来源设计模式。","\u002Fuploads\u002F2026\u002F09\u002Fthe-answer-validity-boundary-the-missing-layer-between-relevance-and-reliable-ai-answers-1790272901306-1g5jly.webp","2026-09-24T11:59:00.000Z",{"id":3998,"slug":3999,"title":4000,"excerpt":4001,"featuredImage":4002,"publishedAt":4003},"479","where-does-an-llm-get-its-data-rag-data-sources-in-python","LLM从哪里获取数据？Python中的RAG数据源","LLM 并不会神奇地知道你的文件、数据库或 API。这个 RAG 系列的实用续篇用简单的 Python 展示了外部数据如何变成可检索的证据：从文本文件和 SQL 到全文搜索、嵌入、上下文组装以及最终的 LLM 调用。","\u002Fuploads\u002F2026\u002F09\u002Fwhere-does-an-llm-get-its-data-rag-data-sources-in-python-1790517200521-nfsi5i.webp","2026-09-27T05:51:00.000Z",{"id":4005,"slug":4006,"title":4007,"excerpt":4008,"featuredImage":4009,"publishedAt":4010},"480","when-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger","人工智能何时应停止信任自身知识？——检索触发机制","AI 模型并非每个问题都需要检索。重要的问题在于知道何时其内部知识已不再足够。检索触发器是一个实用的决策边界，它决定 AI 系统何时应停止仅依赖模型知识，并在回答前获取外部证据。","\u002Fuploads\u002F2026\u002F09\u002Fwhen-should-an-ai-stop-trusting-its-own-knowledge-the-retrieval-trigger-1790574991244-f4rpyg.webp","2026-09-28T01:49:00.000Z","fallback",[],[]]