Sovereignty & Data Residency
Sovereign AI Without Sovereign Compute?
· 10 minute read
You can run a sovereign agent on imported GPUs. You cannot pretend a foundry you do not own is a prerequisite for controlling a citizen file.
A finance-department review in a state capital stalled on a sentence someone had copied from a conference. Without sovereign compute there is no sovereign AI. The sentence sounded like strategy. It was being used as an excuse to keep using a foreign hosted model because the department did not own a wafer fab.
That is a category error. A foundry is an industrial policy object. A fiduciary duty is an institutional object. Confusing them lets the perfect chip become the enemy of a closed log store. It also lets vendors sell India-region GPUs as if the nationality of the silicon were the only question that mattered.
This is an opinion for CIOs who have to ship an agent this year, not for people writing a semiconductor mission document. You can do honest work on imported accelerators you operate. You cannot do honest work on a perfect slide about chips you will not receive.
Three layers of compute claim, only one of which you own this year
| Layer | Who usually owns it in 2026 | What a department can still control |
|---|---|---|
| Silicon and firmware | Foreign vendors; limited Indian assembly | Inventory, spare policy, accept/reject of management features that phone home |
| Facility and power | SDC, NIC, PSU DC, or a colo | Physical access, CCTV, visitor logs, power redundancy |
| Runtime and admin plane | Whoever holds kubeconfig, keys and the scheduler | This is the layer that decides whether the stack is yours |
IndiaAI and related programmes are trying to put more accelerators on Indian soil and to make them available to start-ups and institutions. That is useful national capacity. It does not automatically give your ministry a runtime it controls. A shared cluster can still ship your prompts to a vendor collector. A shared cluster can still train on your eval set. Ask the same questions you ask a hyperscaler.
What you can honestly call sovereign enough
For a departmental agent, sovereign enough is a practical bar. You decide the purpose. You hold the keys or hold the hardware security module that holds them. Inference, embeddings and traces stay on machines whose admin plane you can inspect. There is no silent hosted fallback. The operator, if there is one, is under a processor contract you would be willing to read aloud to a committee.
That bar can be met on NVIDIA, AMD or any other imported card in an SDC cage. It can be met on a rented Indian private cloud if the admin plane is not a foreign SaaS in disguise. It cannot be met by a slogan about Atmanirbhar silicon that leaves the prompt in a US abuse-review queue.
What a department should stop waiting for
Stop waiting for a domestic training cluster before you write the lawful-basis table. Stop waiting for a particular brand of accelerator before you close egress. Stop waiting for a national foundation model before you custody the adapter you already paid to label. Those waits are how hosted prompts become a habit.
You can wait, correctly, for capacity before you promise a 70B-class service to every officer in the state. That wait should appear in the file as a scoped refusal, not as a general paralysis. The 7B-class drafter on two imported cards is not a betrayal of industrial policy. It is the department doing its job with the silicon that exists.
Shared national capacity is a bridge when the contract is written like a processor contract. It is a trap when the access path is a hosted notebook with a foreign parent’s collector. Ask the notebook the same eight telemetry questions you ask a start-up. National in the brochure is not a free pass.
Export controls and other adult risks
Imported accelerators carry supply-chain and export-control risk. That risk is real. It is also regularly inflated in slides that want you to buy a particular cloud. Write it as a continuity problem. How many spare cards do you hold? Can the workload degrade to a smaller model on CPU? Can a second vendor's card run the same serving stack? Those are file questions. A paragraph about geopolitics without a spare-bin count is not.
Do not invent a classified circular that bans a brand. If your sector has an extra rule, counsel should put the citation in the file. This article does not have one to offer.
Objections
If the firmware is foreign, they can backdoor us. Firmware risk is a security problem. Mitigate with vendor choice, update control, network isolation of management ports, and monitoring. It is not solved by using a hosted model whose entire runtime you cannot see.
Shared national GPUs are automatically safe. They are automatically more available. Safe is a contract and an architecture.
Small models on old cards are not real AI. They are real enough for a large class of retrieval and drafting jobs. The adult move is to match model size to the job, not to the keynote.
Rental cages and notebooks
Renting a cage in an Indian data centre can be honest sovereign-enough compute if you badge in, you hold the keys, and the operator cannot read your disks or your prompts as a convenience. Ask those three in writing. A cage whose lights-out support includes an undefined break-glass is a hosted platform with a better story about geography.
Hosted notebooks are the opposite default. They exist to make a scientist productive. They log. They snapshot. They often sit under a foreign parent even when the GPU is in Mumbai. Use them for public, non-personal experiments. Do not use them for a survey file, a citizen letter, or a shop-floor photo.
If IndiaAI or a state cluster is the only way you will get a large model this year, write a project that uses it for non-personal fine-tunes or for public-language work, and keep the citizen agent on the small cards you control. Mixing those jobs because the big cluster is empty on weekends is how a national programme becomes your undeclared processor.
A 90-day honesty pass on compute
- Days 1–15: list every GPU and CPU path you actually use, including hosted notebooks.
- Days 16–40: write admin-plane ownership against each path. Kill any path whose admin plane you cannot name.
- Days 41–70: for the surviving path, write a degrade plan (smaller model, fewer users, CPU fallback) and a spare policy.
- Days 71–90: put the degrade plan in the file the secretary sees, not only in the SRE wiki.
What goes in the file
A one-page compute honesty note: whose silicon, whose facility, whose admin plane, whose logs, what degrades if the cards die, and why this is good enough for this data class. Leave the foundry speech to the industrial-policy file.
Attach the spare-bin count and the last restore of a smaller model onto CPU or a weaker card. Attach the notebook ban if you use shared national capacity for anything else. A compute file that only lists SKUs is a shopping list. A compute file that lists admin planes is a sovereignty file.
Prcept AI runs on hardware you operate. We do not pretend imported GPUs are indigenous silicon, and we do not need that pretence to keep your prompts inside your perimeter.
How to defend this in the file
A P1 CIO/CTO will be asked to explain “Sovereign AI Without Sovereign Compute?” to a secretary who has ten minutes. Do not start with the model. Start with the store, the hop, the clause, or the residual risk. “sovereign compute India” is a search phrase. The file needs a decision.
You can run a sovereign agent on imported GPUs. You cannot pretend a foundry you do not own is a prerequisite for controlling a citizen file. DPDP does not define sovereign AI. Transfers can be lawful and still be a bad idea. Sector circulars can be stricter than DPDP. Write which instrument you are using.
If you cannot name the Data Fiduciary, the processor, the location of traces, and the erasure method, you are not ready for production personal data — whatever the architecture PDF says.
- One sentence on lawful basis or the procurement rule you are invoking.
- One sentence on where prompts, embeddings and logs live.
- One sentence on who can compel the operator.
- One artefact: packet capture, DPA schedule, or deletion certificate template.
Close this loop before the next CAB
Put “Sovereign AI Without Sovereign Compute?” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “sovereign compute India” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- Does sovereign AI require Indian-made chips?
- Not as a matter of DPDP or current general procurement law. Indian-made accelerators are a national industrial goal. A department can still control purpose, logs, keys and weights on imported hardware it operates.
- Is a GPU in an India region of a foreign cloud sovereign compute?
- It is local compute under a foreign operator. That can be the right residual risk for some workloads. It is not the same as a rack whose admin plane you hold.
- Should we wait for IndiaAI capacity before we start?
- Do not wait to map workflows, write-set lists and lawful bases. Do wait to buy a 70B serving cluster you cannot staff. Shared or rented Indian capacity can be a bridge if the contract gives you the controls this series describes.
- What if export controls cut off our spare parts?
- That is a continuity risk, not a privacy statute. Mitigate with spare inventory, dual vendors where you can, and workloads that can degrade to smaller models. Write the degrade plan before the spare bin is empty.
- Does CPU-only inference count?
- For small models and low concurrency, yes. It is slower and still honest. A CPU box you control beats a GPU you cannot inspect.