Learn

    Point of view

    Sovereignty washing: when "sovereign AI" isn't

    Why a local region isn't sovereignty, the red flags to watch for, and what real control actually requires.

    By James Drayson

    In short

    Sovereignty washing is marketing a service as "sovereign" because it runs in a local data centre, while control still sits with a foreign provider, for example a UK region operated by a US company that can be compelled to hand over data under the CLOUD Act. Real sovereignty requires control of the model and data path, not just the location.

    Locai One with the side panel open

    The trick: location without control

    The sovereignty-washing playbook is simple: point to a local region or "UK data residency" and imply your data is therefore sovereign. But residency is about where data sits, not who controls it. If the operator is subject to foreign law, a local region doesn't stop foreign-government access, and if the model is rented, you don't control the capability either.

    Red flags to watch for

    • "UK region" as the whole pitch: Location is highlighted while ownership and jurisdiction are left vague.
    • Foreign-owned operator: The provider is subject to laws like the US CLOUD Act regardless of where servers sit.
    • Rented model: You can't export the weights or run the model independently.
    • No air-gap option: If it can't run isolated, your data path still depends on someone else.

    What real sovereignty requires

    • Model ownership: You hold the weights and IP, not just an API key.
    • Controlled data path: Inference runs inside your perimeter with no external dependency.
    • True jurisdiction: The provider and deployment are genuinely under your country's law.

    What this looks like with Locai

    Compliance is far easier to evidence when the machine, the model and the logs are all things you own, not things a vendor describes in a whitepaper.

    Locai Labs builds Locai One, an on-prem AI appliance. It is one machine that arrives with everything already in it: the hardware, our open-weight Locai Juno models, and Locai OS, the operating system that serves the models and handles users, access and monitoring. You plug it into a mains socket and your network, and your team is working in about 15 minutes. No cloud account, no per-token bill, and nothing leaving the building.

    The reason a data-centre-class model fits in a box on your floor is SPACE, our compression algorithm. Instead of asking how much of a model can be cut while keeping it broadly similar, SPACE asks what the model needs to be good at, preserves the subnetworks behind those capabilities and strips back the rest. The result is a smaller specialist rather than a shrunken generalist, tuned to the exact hardware it ships on.

    Locai One starts at £29,950 for a team, and Locai One Pro at £49,950 for an organisation, bought once and owned outright. Both run air-cooled on standard mains power and work fully air-gapped. Any compatible open-weight model runs alongside Juno, and if you need a model trained on your own proprietary data we can post-train one and deploy it on the same machine.

    Frequently asked questions

    What is sovereignty washing?

    Marketing a service as sovereign based on local data residency while control remains with a foreign provider, so the "sovereignty" is superficial.

    Is a UK data centre enough for sovereignty?

    No. If the operator is subject to foreign law (e.g. the US CLOUD Act), a UK location doesn't prevent foreign access. Sovereignty needs control, not just location.

    How do I spot sovereignty washing?

    Look past "UK region" claims: ask who owns the operator, whether you own the model weights, whether it can run air-gapped, and which jurisdiction truly applies.

    What is real sovereign AI?

    A model you own, running inside your perimeter under your jurisdiction, with a controlled data path, so no third party or foreign government has an access route.

    Book a sovereign AI briefing

    A 30-minute session on owning your model: deployment options, the data path, and a clear cost range for your use case.