Book a free AI Reality Check
How it works Industries Case studies Resources What you could ask Where to start Book a free AI Reality Check

Sovereign AI

Whose rules does your AI actually answer to?

Sovereign AI means the organisation using it determines who may read its data, which jurisdiction governs that data, and whether the capability can be withdrawn. For Australian organisations holding regulated, privileged or commercially sensitive information, those three questions increasingly determine which AI is available to them at all.

Definition

Three questions you should be able to answer about any AI you use

These apply to whatever your organisation already uses, not only to what a vendor proposes. An inability to answer all three is itself a material finding - and a common one.

Who can read what you put in?

Not just the model. The vendor, the vendor's own suppliers, and anyone who can lawfully compel them. “We do not train on your data” answers a different question - it says nothing about who processed it.

Whose law applies to it?

Where the work is done, and which country's authorities can reach it. Storing data in an Australian region does not by itself decide either - they are separate questions, and they have separate answers.

Can you switch it off and keep working?

If the price trebles, the terms change or the service is withdrawn, do you still have the models, the data and the workflows - or were you renting access to all three?

The Australian position

What the Australian record already establishes

Four public developments, each dated: three from regulators and Parliament, one from the infrastructure market. Read together, they establish where Australian regulatory attention is directed, which questions boards are increasingly expected to have answered, and why hosting in Australia does not answer them on its own. Positions of this kind develop over time, so every item below carries its date and a link to the source - check the current position before relying on any of it for procurement.

30 April 2026

The prudential regulator wrote to every entity it regulates to say that AI governance was not keeping pace with AI adoption, and that the largest single gap it found was third-party and supply-chain risk - AI arriving inside vendor platforms, with contracts that often said nothing about audit rights, notice of model changes, incident reporting, or changes to how data is handled.

Significance beyond regulated finance: this is a regulator describing, in writing, the ordinary position of any organisation whose AI arrived as a feature of software it already licensed.

The letter, on APRA's site →

20 August 2026

Both houses of Parliament appointed a Joint Select Committee on Artificial Intelligence. Its terms of reference name sovereign AI capability and data sovereignty directly, alongside national security, consumer protection and the adequacy of existing law.

Significance: sovereign AI capability has moved from vendor positioning onto the parliamentary record, with terms of reference attached to it.

The committee, at aph.gov.au →

31 August 2026

The Attorney-General released an exposure draft of the next tranche of Privacy Act reform. Among its proposals: a test of whether collecting and using personal information is fair and reasonable, a formal split between the organisation that decides what happens to data and the one that processes it, stronger consent standards, and notification of eligible breaches within 72 hours. Consultation closed on 18 September 2026.

Significance: a statutory controller-and-processor split is the distinction that determines who remains answerable when an AI vendor processes information about your clients.

The exposure draft and consultation →

9 September 2026

NVIDIA announced partnerships with eight companies across Australia's data-centre ecosystem, targeting up to two gigawatts of AI infrastructure by 2027. One partner describes its customers as enterprises, government and research organisations that require Australian data residency.

Significance: onshore capacity answers where the work is done. It does not by itself answer who operates the model or whose law can reach that operator - the distinction the European precedent below turns on.

The announcement, on NVIDIA's newsroom →

The European precedent

Where the same questions have already been tested

European jurisdictions reached these questions earlier. The relevance to an Australian organisation is not the European rules themselves, which do not apply here, but the evidence of what emerges once the questions are put formally - to vendors and to regulators alike.

10 June 2025

Appearing before a French Senate commission of inquiry, the director of public and legal affairs of Microsoft France was asked whether he could guarantee that data entrusted to Microsoft by French citizens would never be transmitted to United States authorities without the explicit authorisation of the French government. He answered that he could not. The constraint is jurisdictional rather than technical: United States law reaches United States companies irrespective of where the data physically resides.

Significance: in-country data storage does not by itself constitute sovereignty. It answers the storage question and leaves jurisdiction and continuity open.

Official record of the hearing, Sénat →

2 August 2026

The European Union's AI Act reached the date on which its transparency duties, and oversight of the companies supplying general-purpose AI models, began to apply. Suppliers now have to be able to say what their systems are and what goes into them.

Significance: the questions a European buyer can now put to a vendor in writing are the same ones an Australian buyer has always been entitled to ask, and rarely does.

The amending regulation on EUR-Lex →

24 July 2026

A further regulation, published in the Official Journal that day, pushed the AI Act's obligations for higher-risk systems back to December 2027 and August 2028. The timetable moved; the direction did not.

Significance: implementation timetables move. Planning on the assumption that scrutiny recedes is a materially different position from planning on the assumption that it arrives later than announced.

Regulation (EU) 2026/1744 →

The point

None of this is a prediction. It is what regulators and parliaments have already written down.

No Australian law currently compels most organisations to adopt sovereign AI, and this page does not argue that one is imminent. The case is narrower and more durable: these questions are now being put by parties with the standing to put them, and an organisation that can already answer them carries no remediation risk when they are asked formally.

Assessment framework

Sovereignty is a ladder, not a switch

The term is applied loosely across the market. In practice sovereignty is graduated: each rung answers more of the three questions than the one below it, and each costs more to operate. Most organisations should not sit on the top rung for everything they do.

Sovereignty by tier

The page's three questions, put as what you control. Does each one hold for that tier?

Deployment tier
Only you can read it
Your law applies
You can switch it off
Public AI
AI inside software you already licence
Semi-private - your own cloud tenant
Private - your own cloud or your own building
Yes - you decide
Partly - shared with the provider
No - the vendor decides

Public AI

Sovereign: no

Fast, capable and genuinely useful for work that is already public - market research, general drafting, anything you would be content to see published. Your prompts may be retained and may be used to improve the model, and the processing happens on the vendor's terms. Right tool, narrow remit.

AI inside software you already buy

Sovereign: no

The assistant that appeared in the office suite, the CRM, the service desk. Convenient, and frequently enabled by default. The vendor processes your content in order to provide the feature, on the terms of an agreement that is rarely examined in detail. Selecting a large, reputable platform does not by itself determine where processing occurs or who may lawfully compel access to it.

Semi-private - your own cloud tenant

Sovereign over storage, not over processing

Your data resides in your own tenant, in a region you nominate, and is not used to train public models. The model itself still runs as a service operated by the cloud provider, under that provider's contract and home jurisdiction. This is a substantial improvement and, for most organisations, the appropriate first rung - no hardware to procure, no ceiling on model capability. It is not the top rung and should not be described as one.

Private - your own cloud, or your own building

All three questions answered

The models run inside infrastructure you control. Who can read it: you. Whose law applies: yours. Can you switch it off and keep working: yes - the models, the data and the workflows are all in your hands. This is what TonsleyAI deploys, and it is the rung the other three are measured against.

Most organisations end up using more than one rung at once, deliberately - open research on a public model, day-to-day work in their own tenant, anything confidential kept private. The skill is not picking one. It is matching each job to the lowest rung its data actually allows, and knowing why.

Sovereign AI, in practice

From requirement to implementation

Sovereignty is a requirement, not a product. What you actually buy is a job being done - documents answered, enquiries turned into orders, materials checked against a standard, work found, history made searchable, questions answered across systems. Six builds cover most of it, and every one of them runs inside your own environment.

Which rung does your data actually need?

Five questions, about a minute, and you will have a first answer - plus a plain-English note on what it would cost you in effort. It runs entirely in your browser. There is no form and nothing to submit.