
Research
AI Agents
Sovereignty is about to commoditise. Control is not for sale

Article by
Dr. Anoj Winston Gladius
·
On 28 June 2026, Austria's State Secretary for Digitalisation wrote to the European Commission with an unusual request. Sixteen days earlier, a directive from the United States Department of Commerce had caused Anthropic to withdraw its two most capable models from every customer on the planet within hours — European customers included, European contractual guarantees notwithstanding. The Austrian letter did not ask for European data residency. It did not ask for EU-hosted inference, a stronger Data Boundary, or better contractual language about where prompts are processed. It asked the Commission to explore hosting Anthropic itself — the company — inside the Union. [¹] That is a remarkable thing for a government to commit to writing, and it contains the entire argument of this piece in a single sentence. The people responsible for European digital policy watched a model vanish and understood immediately that the problem had nothing to do with where the servers were. Meanwhile, the American labs are building. Aggregate hyperscaler infrastructure spending will pass six hundred billion dollars in 2026, and a meaningful share of it is landing in Europe. Within roughly three years, "your data stays in Europe" will be straightforwardly true of every major American AI provider. On that day, most of what the European AI industry currently sells as sovereignty will be worth close to nothing — and a number of European vendors whose entire differentiation is a map will discover they were selling a commodity all along. This piece is about what remains when that happens. The answer is not a smaller version of the same argument. It is a structurally different one.
This is the sixteenth piece in a series I have been writing for neuland.ai. [²] The thread running through all of them is that in enterprise AI the value, the risk and the moat sit in the layer above and around the model rather than in the model itself. Earlier pieces have worked through that claim from a dozen angles — control planes and execution surfaces, model drift, deployment topology, compliance as a system property, agent security, protocol governance, the workhorse economics of open weights, vendor data gateways, the consolidation of the ontology layer, the case against visual workflow builders, the services pivot, the open-weight frontier, distillation, and containment in both directions.
This piece is the one that asks what all of that is for, on a three-to-five year horizon, and it starts by taking seriously the objection that ought to keep every European AI vendor awake: what happens to the sovereignty argument when the Americans simply build here?
What is actually built today
It is worth being precise about the current state, because it is more partial than the marketing suggests and more advanced than the sceptics assume.
OpenAI has offered European data residency since early 2025 for enterprise and API customers. The important detail is what it covers: conversations, uploaded files and custom configurations are stored at rest in Europe, while inference processing — the part where the model actually reasons over the prompt — continues to run in the United States. [³] Microsoft operates an EU Data Boundary for tenants in the EU and EFTA, with two documented qualifications: a Flexible Routing mechanism that can process requests outside the boundary during periods of peak demand, and the exclusion of Anthropic models from the boundary entirely following their addition as a Copilot sub-processor in January 2026. [⁴] The sovereign public-sector offering announced for Germany runs on a partner's sovereign cloud, which in turn runs on Azure. [⁵] Anthropic, which has historically relied on cloud partnerships rather than direct capacity, began recruiting in April 2026 for a London-based principal whose sole remit is negotiating European data centre capacity deals. [⁶]
Read that list without prejudice in either direction. Today's sovereign offerings are genuinely partial, in ways that are documented rather than alleged. And the labs are unmistakably moving to close the gap.
So let us grant the objection its full strength. Assume they finish the job properly: European inference on European hardware, a European legal entity, European personnel, independent governance, the complete treatment. What changes?
What genuinely improves, and what dies with it
A great deal improves, and it would be dishonest to pretend otherwise. Data at rest and in flight stays in Europe. Latency improves. A long list of procurement checkboxes gets ticked. For a substantial part of the mid-market, an American frontier model running on European hardware under a competent data processing agreement will be entirely adequate, and those enterprises will be better served than they are today. This is a real improvement and European enterprises should welcome it.
It is also the end of a business model that a lot of European AI companies are currently running on.
Once "your data leaves Europe" stops being true, the pitch that consists of a map with a border drawn on it stops working. The DSGVO argument weakens sharply. The intuitive, emotionally available version of the sovereignty conversation — our data, our continent — collapses into something much narrower and much harder to sell: an argument about control, which remains hypothetical right up until the moment it isn't. Procurement committees are not good at pricing hypotheticals, which is precisely why 12 June 2026 was so instructive and precisely why its lesson will fade.
I think the European AI sector has perhaps three years before this bill arrives, and I do not think the sector is ready for it.
The four things that do not move
Here is the part that matters, and the reason I think the sovereignty argument survives — in a different and considerably sharper form.
Capital can buy anything that can be specified in advance. Data centres, accelerators, power contracts, engineers, acquisitions, certifications. Six hundred billion dollars is currently demonstrating exactly how much can be specified in advance. What capital cannot buy is anything whose value derives from a property it structurally does not possess. There are four of those in enterprise AI, and none of them is a matter of geography.
First: jurisdiction attaches to the entity, not to the concrete. A company incorporated in the United States remains subject to United States legal process regardless of where its hardware sits. This is the CLOUD Act point, which is well understood in principle and consistently underweighted in practice — the compact formulation now circulating among European compliance practitioners is that data residency is not data sovereignty. [⁷] But 12 June 2026 demonstrated something considerably stronger than a disclosure risk. A model was not subpoenaed; it was withdrawn, globally, within hours, by an export-control directive addressed to an American company. No European data centre would have altered that outcome by a minute, because the entity receiving the order was American. That is not a data protection problem. It is a continuity-of-service problem with a geopolitical trigger, and the only architecture that survives it is one where the loss of any single provider is a routing change rather than an outage. The Austrian letter is a European government reaching this conclusion in public, and asking for the only remedy that actually addresses it.
Second: a model vendor cannot sell model neutrality. This one is arithmetic rather than ethics, and I think it is the most underappreciated structural fact in the enterprise AI market. A company whose revenue is inference cannot build an orchestration layer that routes away from its own inference. Not because anyone is acting in bad faith, but because the routing logic and the margin are the same object. Ask what happens when the honest answer for a given workload is a small self-hosted open-weight model that generates no vendor revenue at all — a category of workload that, on current evidence, covers the clear majority of enterprise AI traffic. A model vendor's orchestrator will not choose it. It cannot be built to choose it.
This means neutrality at the model layer is available only to a company that has nothing to sell at that layer. It is an advantage that consists entirely of an absence, which is an unusual kind of asset and a genuinely durable one, because it cannot be acquired — only structurally possessed. It also applies with equal force to European model vendors. Jurisdiction does not exempt anyone from their own incentives; a European lab's orchestration layer routes to that European lab for the same reason. There is exactly one shape of company that can credibly offer to route to the best available model for a given workload under a given policy, and it is one that does not make models.
Third: the weights cannot ship. Genuinely air-gapped operation — no outbound call, no external runtime dependency, the model executing entirely inside the customer's perimeter — requires the weights to sit inside that perimeter. For a frontier lab the weights are the entire business. This is not a policy position that could be revisited under commercial pressure; it is an architectural boundary that holds in every jurisdiction, permanently. Any enterprise whose regulator, works council or threat model requires true isolation is choosing between open weights and nothing. That constituency is small today and, on the evidence of the conversations we have with regulated institutions, growing.
Fourth: semantic ownership is orthogonal to location. If the model of your business — your entities, relationships, decision rules, the specific meaning your organisation attaches to words that mean something else elsewhere — lives inside a vendor's product, it makes no difference which data centre that product runs in. You still cannot port it, and you still pay per action to query a description of your own company. The four-way race to own the enterprise ontology layer is being run by vendors who understand this perfectly well; the entire point of the race is to be the place where the customer's semantic layer ends up.
And this one has a property the other three lack, which I have come to think is the most important idea in the whole argument. An ontology decays. A model of a living business that is not continuously maintained is wrong within months — stale entities, retired products, reorganised units, changed thresholds. That maintenance burden is normally read as a cost, and it is one. It is also the reason the asset cannot be copied. Everything that can be duplicated in an afternoon is a static artefact: code, schemas, prompts, weights, architecture diagrams. A thing that must be kept true is not an artefact but a standing relationship with the business it describes. A competitor can take the file. They cannot take the relationship, and the file is already wrong by the time they have it.
That inverts the usual logic of moats. Here, the maintenance burden is the moat — the property that makes the asset expensive is precisely the property that makes it uncopyable.
Where this goes, 2026 to 2030
Six things I would defend, with the caveat that anyone offering a confident five-year view of this industry is selling something.
The model finishes becoming a component. This is most of the way done already. Open weights reached the frontier on multiple benchmarks in mid-2026, and the gap now moves in both directions release by release. By 2028 the choice of model is a routing decision revisited monthly, not a vendor relationship revisited every three years. The labs know this, which is why five of them turned into services businesses within sixty days in the summer of 2026. When the product commoditises, the margin has to move.
Agent economics become the binding constraint. Once task-specific agents are ordinary rather than novel, nobody asks whether they work. They ask what it costs to run several million long-lived sessions continuously — scheduling, isolation, memory, inference efficiency, the cost of a session that stays alive for six hours and touches nine systems. This is a distributed systems problem, not a machine learning problem, and it is why the most consequential infrastructure engineers of the previous era are currently leaving large platform companies to build substrate rather than joining model labs. The constraint moved, and the people best positioned to see it are voting with their careers.
Cross-boundary authorisation becomes the crisis. The industry is standardising agent-to-agent protocols at speed and has not solved delegation at all. When an agent on one company's platform invokes an agent on another's, the question of whose rights govern the second agent's data access has no widely implemented answer. I expect a serious, well-publicised incident traceable to a delegation chain within two years, and I expect it to reshape enterprise procurement the way the early cloud breaches did.
The ontology layer consolidates, and then produces a backlash. The four vendors racing for it will succeed. Somewhere around 2028 a meaningful number of enterprises will discover that their institutional knowledge is encoded in a product they do not control and that leaving costs more than staying. The market for owned, portable semantic layers opens after that realisation, not before — which is an uncomfortable piece of timing for anyone building one now.
Regulatory divergence becomes structural rather than transitional. The AI Act became broadly applicable on 2 August 2026. By the end of the decade Europe has a mature regime and much of the rest of the world has something looser. This is not friction to be smoothed away; it is a permanent bifurcation that creates a durable market for systems designed natively for the stricter regime rather than retrofitted to it.
The floor of what is trivially buildable keeps rising, and the value of services rises with it. Every year more can be assembled by fewer people with less expertise. This does not reduce the value of knowing what to build; it concentrates it. The consulting that dies is the kind that sold implementation labour. The kind that grows is rooted in domain knowledge and the right to operate in production — which is precisely why the frontier labs spent roughly eight billion dollars in a single quarter hiring engineers to embed inside their customers' buildings.
Where neuland.ai stands
We have said for some time that we do not compete at the model layer. The discipline this argument demands is to say the second half out loud as well: we do not compete at the compute infrastructure layer either. That layer is currently absorbing the largest capital deployment in the history of the technology industry, and a company of our size in Cologne has no business pretending otherwise. Custom silicon and data-centre-scale co-design are somebody else's problem, and they will be solved well.
What we build is the layer where sovereignty, context and authorisation intersect — and every one of the four properties above is a design constraint in it rather than a marketing claim on top of it.
The neuland.ai HUB is an enterprise AI management and orchestration platform. Its model layer is agnostic by construction, because we have nothing to sell there: frontier proprietary models where the workload justifies them and the jurisdictional posture permits, self-hosted open-weight models tuned per domain for everything else, with the routing decision made per workload against capability, cost, residency and policy. Its authorisation model reduces the search space to the requesting user's rights before the model reasons, rather than filtering afterwards, so that material a user may not see does not exist for that query and therefore cannot be retrieved or cited — a guarantee that holds identically for a user, a session, an agent, and an agent arriving from another platform under a delegated identity. That requires keeping the record of permissions in a deliberately boring, auditable transactional store, entirely separate from the layer that holds meaning, and paying the real engineering cost of keeping the two consistent. Its orchestrator records procedures as ordered, replayable structures rather than drawings on a canvas, so that a workflow is data — inspectable, forkable, resumable, with human approval available at any point in the graph, and identical machinery underneath both a declared deterministic process and a recursive agentic decomposition. Its knowledge layer builds the customer's own model of their own world, inside the customer's own substrate. And it deploys wherever the customer's constraints require: sovereign cloud, private cloud, on-premises, or genuinely air-gapped — which is possible only because we can run entirely on weights the customer holds. [⁸]
The research effort behind this is deliberately bounded. We do not do foundation-model research and we say so, because naming the boundary of your field is what makes claims inside it credible. The work is systems and infrastructure research: the runtime that makes smaller, self-hosted models enterprise-grade — reproducible in process, auditable by construction, economical at scale. The most defensible layer, the knowledge layer, is also the one still under construction. I would rather write that sentence myself than have someone else discover it.
Personal take
The bet, stated plainly enough to be wrong: by 2029, enterprises that own their semantic layer and their authorisation model will have optionality that enterprises who rented both will not. They will change models without renegotiating. They will survive a provider disappearing on a Friday evening. They will answer a regulator's question about a specific automated decision without opening a support ticket. And they will do all of it at a marginal cost that does not scale linearly with usage.
That is a bet rather than a certainty, and it fails in two identifiable ways. It fails if vendor-maintained ontologies turn out to be good enough that no serious enterprise minds renting one — plausible, if the vendors do the maintenance well and price it honestly. And it fails if sovereignty turns out to be a stated purchasing criterion rather than a real one, so that when American infrastructure arrives in Europe the control argument simply never gets made in a procurement meeting. Both are testable within three years. If either proves out, we will have been wrong in an interesting way rather than a vague one.
What I am reasonably confident of is the shape of the thing. Sovereignty of location is being purchased right now, at enormous scale, by companies with far more capital than any European vendor will ever assemble, and it will be a commodity before the decade is halfway through. Sovereignty of control is not on the market, because the four things it consists of cannot be bought: a legal domicile, a structural absence at the model layer, permission to hold the weights, and a maintained description of a specific company's world that is worthless the moment nobody maintains it.
Europe's opportunity in enterprise AI was never the first kind. It was always the second. The uncomfortable part is that we have about three years to make that argument before the easy version of it stops being available.
A brief note on the regulatory backdrop, since it continues to develop. The EU AI Act became broadly applicable on 2 August 2026, with GPAI enforcement powers under Chapter V binding from that date. The Digital Omnibus agreement of 7 May 2026 postponed the high-risk Annex III obligations to 2 December 2027 and Annex I obligations to 2 August 2028. [⁹] The strategic implication is unchanged from the previous pieces in this series, and now has a deadline attached: the architecture decisions taken between now and the end of 2027 determine what an enterprise can still choose in 2029.
Sovereignty is about to commoditise. Control is not for sale. That is the work in front of us, and it is the work we have been doing.
¹ Letter from Austria's State Secretary for Digitalisation to the European Commission, 28 June 2026, urging member states to explore hosting Anthropic within the European Union, citing the global suspension of Claude Fable 5 and Claude Mythos 5. The suspension followed a United States Department of Commerce export-control directive issued on 12 June 2026; access was restored at the end of June 2026. See the earlier piece in this series on flexibility as an architectural property for the full sequence.
² Series articles at neuland.ai: Zentrale Plattform für Enterprise-KI .
³ OpenAI European data residency, available to Enterprise, Edu and API customers since early 2025. Covers storage at rest of conversations, uploaded files and custom configurations within Europe; inference processing continues to occur in the United States. Reported in comparative enterprise AI guidance published in 2026.
⁴ Microsoft EU Data Boundary for EU and EFTA tenants. Flexible Routing permits temporary processing of AI requests outside the boundary during peak demand, configurable in the administration centre. Anthropic became a Copilot sub-processor in January 2026; Anthropic models are excluded from the EU Data Boundary, disabled by default for EU tenants.
⁵ Sovereign public-sector AI offering announced for Germany, delivered through a partner sovereign cloud platform which itself operates on Microsoft Azure infrastructure, with announced expansion to 4,000 GPUs.
⁶ Anthropic recruitment for a London-based principal to drive commercial sourcing and transaction execution for European data centre capacity, advertised April 2026. The company had previously relied primarily on cloud partnerships rather than direct capacity agreements in the region. Aggregate hyperscaler AI infrastructure expenditure for 2026 is projected above 600 billion US dollars.
⁷ On the distinction between data residency and data sovereignty under the US CLOUD Act: a United States-headquartered provider may be compelled to disclose data within its possession, custody or control irrespective of storage location. Formulation widely used in European compliance practice through 2026.
⁸ neuland.ai HUB platform architecture: model-agnostic routing per workload across frontier proprietary and self-hosted open-weight models; permission-aware retrieval enforced at query time ahead of reasoning, with the authoritative permission record held in a transactional store separate from the retrieval layer; relationship-based access control extended to delegated identities arriving across platform boundaries; orchestration recording procedures as ordered, replayable, forkable structures with human approval available at any point, supporting both declared deterministic processes and recursive agentic decomposition; customer-owned ontology and knowledge layer generated from customer data; governance, observability, audit and explainability applied uniformly across the platform; deployment options spanning sovereign cloud, private cloud, on-premises and air-gapped operation. neuland.ai AG retains responsibility for content quality and clean delivery of results across all customer engagements.
⁹ EU AI Act broadly applicable from 2 August 2026, with GPAI enforcement powers under Chapter V binding from that date. Council and European Parliament provisional political agreement on the Digital Omnibus on AI, 7 May 2026: Annex III high-risk obligations postponed to 2 December 2027; Annex I obligations postponed to 2 August 2028; Article 50(2) watermarking obligations moved to 2 December 2026.
Image generated using the neuland.ai HUB.