---
title: "Sovereign AI · sovereign clouds, air-gapped agents, national AI factories · Agent Fieldbook"
url: https://agentfieldbook.org/security/sovereignty/
description: "Where an AI agent physically runs and whose law governs it. Sovereign AI offerings catalogued by operator, jurisdiction, isolation mechanism and status: sovereign public clouds, air-gapped deployments and nation-scale AI factories. A source-graded field book for regulated, defence and public-sector agent deployment."
section: "Security · Sovereign AI"
source: Agent Fieldbook — generated from the published page
---

# Whose jurisdiction is your agent running in

**Sovereign public cloud · Sovereign public + private cloud · Sovereign / air-gapped cloud · Sovereign AI infrastructure · Sovereign AI zone**

Sovereign AI is the move to keep AI infrastructure, data and inference inside a national or regional boundary: sovereign clouds, air-gapped deployments, and nation-scale AI factories. The lens for regulated, defence and public-sector partners: where the compute physically sits and which law governs it.

| Offering | Type | Jurisdiction | Mechanism | Status | src |
| --- | --- | --- | --- | --- | --- |
| **AWS European Sovereign Cloud** Amazon Web Services | Sovereign public cloud | EU (Brandenburg, Germany) | A structurally isolated AWS partition operated by an EU legal entity under German law: EU-resident-only operations, independent IAM, billing, DNS and certificate authority. Separate from global AWS. | Live (Jan 2026) | [↗ T1](https://aws.amazon.com/compliance/digital-sovereignty/) |
| **Microsoft Sovereign Cloud** Microsoft | Sovereign public + private cloud | Per-country (public + private options) | Sovereign Public Cloud and Sovereign Private Cloud tiers. M365 Copilot AI data can be processed in-country; Foundry Local runs LLM inference on NVIDIA hardware in fully disconnected environments: sovereign AI without a network connection. | GA / expanding (2025+) | [↗ T1](https://www.microsoft.com/en-us/sovereignty) |
| **Google Distributed Cloud (air-gapped)** Google Cloud | Sovereign / air-gapped cloud | On-prem / regional | Runs Google Cloud + Gemini models on customer-owned or in-country infrastructure, including fully air-gapped deployments with no connection to Google. Data and control plane stay inside the jurisdiction. | GA (air-gapped + connected) | [↗ T1](https://cloud.google.com/distributed-cloud) |
| **Oracle EU Sovereign Cloud** Oracle | Sovereign public cloud | EU (operated by EU entities) | Physically and logically separate EU realm operated by EU-based Oracle entities with EU-resident support, isolated from Oracle's commercial regions. Same OCI services incl. AI/GenAI. | GA | [↗ T1](https://www.oracle.com/uk/cloud/eu-sovereign-cloud/) |
| **NVIDIA Sovereign AI** NVIDIA | Sovereign AI infrastructure | National (multiple states) | The thesis that every nation should own AI infrastructure trained on its own data, language and culture. NVIDIA supplies the accelerators + software stack to national AI-factory buildouts. | Active (nation-scale buildouts) | [↗ T1](https://www.nvidia.com/en-us/data-center/sovereign-ai/) |
| **HUMAIN AI Zone (Saudi Arabia)** HUMAIN + AWS | Sovereign AI zone | Saudi Arabia | Purpose-built in-country AI zone deploying up to 150,000 AI accelerators including NVIDIA GB300 GPUs: one of the largest sovereign AI infrastructure projects globally. | Announced / building | [↗ T2](https://press.aboutamazon.com/aws/2025/5/humain-and-aws-announce-5-billion-ai-zone-in-saudi-arabia) |

## Field notes

Where an agent's data sits, and which legal regime governs it

Every entry here is a commercial offering, not a state programme. The operators are AWS, Microsoft, Google, Oracle, NVIDIA and, in Saudi Arabia, HUMAIN with AWS. What they sell a business is a clean answer to where its data sits and which legal regime governs it, delivered through in-region operation, structural isolation, or a fully air-gapped deployment.

The trade is coverage against control. A sovereign partition launches with a fraction of the services of the commercial region, fills in over time, and carries a price premium for the isolation. For an agent the practical consequence is jurisdictional routing: the deployment has to prove not only what it did but where it happened.

- [Brandon Chaplin](https://www.linkedin.com/in/brandon-chaplin-digital-marketing-strategist)

## Common questions

### What is sovereign AI?

Keeping AI infrastructure, data and inference inside a national or regional boundary, under that jurisdiction's law. In practice that means sovereign cloud regions run by a local legal entity, air-gapped deployments, and state-backed national compute. The driver is regulation, not performance.

### What is a sovereign cloud?

A partition of a cloud provider structurally separated so that only in-region staff operate it and only in-region law applies. The AWS European Sovereign Cloud, for example, runs as an EU legal entity with its own identity, billing, DNS and certificate authority. The trade-off is fewer services and a price premium.

### Does it matter where an AI model runs?

For regulated work, yes. Where inference happens decides which government can compel access to the data and which rules apply to it. A healthcare, defence or public-sector deployment running on infrastructure in another jurisdiction can breach data-residency rules outright.

### What is an AI factory?

State-backed compute built so a country has its own training and inference capacity rather than renting it from a foreign provider. It usually pairs domestic data centres and accelerators with a sovereign cloud, so model development and serving can happen entirely inside the border.

### Is a sovereign cloud worth the cost?

It depends whether data residency is a legal requirement or a preference. Sovereign regions launch with a fraction of the services, GPU and managed-model coverage arrives later, and the isolation carries a price premium. For regulated sectors the requirement decides it. For everyone else it rarely pays.

## Next in the learning path

- [Standards The regulation that makes sovereignty a requirement](https://agentfieldbook.org/security/standards/)

- [Governance The runtime controls that sit inside the boundary](https://agentfieldbook.org/security/governance/)

- [Incident log The exposure sovereign deployment contains](https://agentfieldbook.org/security/incidents/)

- [Human oversight The control regime layered on top](https://agentfieldbook.org/security/oversight/)
