Compute & AI Infrastructure

How to Audit a Sovereign AI Program: Six Questions That Separate a Live Program from a Press Release

Updated September 23, 2026

Sovereign AI announcements are counted; operational capacity is not audited. Six questions, with the evidence to demand and the red flags, for builders, CVCs, and government buyers.

Audit framework visual with six question cards covering contracted versus announced compute, model layer dependency, data and governance, procurement terms and exit rights, security levels, and financing structure, each with evidence to demand, a red flag, and a named test case, plus a five-rung audit ladder from press release to metered operations and a what-would-change-this-view band.
Audit framework visual with six question cards covering contracted versus announced compute, model layer dependency, data and governance, procurement terms and exit rights, security levels, and financing structure, each with evidence to demand, a red flag, and a named test case, plus a five-rung audit ladder from press release to metered operations and a what-would-change-this-view band.

Atomic answer

Sovereign AI is now a counted sector. CNAS tracks 184 government-backed projects across 67 countries plus the European Union, and infrastructure rose to 80 percent of new activity in the first half of 2026. Counted is not audited. Operational capacity shows up in metered megawatts, controllable models, auditable data, exit rights, mapped security controls, and closed financing. This audit gives builders, CVCs, and government buyers the six questions that separate a live program from a press release, with the evidence to demand at each step, the red flags, and test cases from the UAE, Saudi Arabia, India, Japan, and the EU. (Primary for the counts; Analytical for the framework.)

Who is this for?

Three readers, one decision. The builder selling into a sovereign program needs to know whether the counterparty can pay and operate. The CVC or allocator needs to know whether contracted revenue survives the next refinancing. The government buyer needs to know whether public capital is buying capacity or a launch event. The questions are the same; the evidence differs by seat. (Analytical)

The count is not the audit

CNAS launched its Sovereign AI Index to track government-backed projects and published its second-wave data on 2026-08-20. The count is 184 projects across 67 countries plus the European Union, up from 16 governments in 2023. Infrastructure programs, meaning data centers, supercomputers, GPU clusters, and compute-access schemes, rose to 80 percent of projects in the first half of 2026 from 62 percent in the previous six months. Ten first-time entrants are lower- and middle-income economies, and India hosts 11 projects, more than any other country. (CNAS, 2026-08-20; Primary.)

Carnegie's 2026-09-03 essay supplies the vocabulary for the gap. Sovereignty is best read as agency under constraint: the capacity to switch providers, impose conditions, adapt models, and set rules, not the capacity to own every layer of the stack. Its audit test is blunt. An initiative that increases dependence on a single provider is sovereignty-washing, whatever the label says. (Carnegie Endowment, 2026-09-03; context, not authority.)

Bruegel supplies the scale check from the other direction. The EU operates about 2 gigawatts of AI compute, roughly 5 percent of global capacity, against about 35 gigawatts in the United States. Capital is not the binding constraint: 76 of 101 tracked EU projects are fully privately financed, and speed-to-operation and grid access decide which projects energize. (Bruegel, 2026-09-10; Primary, aggregating the Europe2031.ai dataset.) Funding a program is not the same as running one. The EU's own gigafactory call shows the timeline: awards are expected in early 2027, construction starts in 2027, and selected sites are expected to operate within 18 months of signature. (European Commission, 2026-07-30; Primary.)

The six questions below apply that standard to a specific program. Run them in order; any one can end the diligence.

Q1. Contracted versus announced compute

The first question is whether capacity exists in metal and power or only in slides. Announced capacity is a number in a release. Contracted capacity has a signed power or interconnection agreement, an allocated chip supply with any required export licenses, and a commissioning date held by a named operator. (Analytical)

Evidence to demand: metered megawatts today and over the last four quarters; interconnection and power purchase agreements; chip allocation and license documents; the commissioning schedule signed by the operator, not the sponsor.

Red flags: "up to" capacity with no power contract; a first phase that has slipped more than two quarters; a redesign that follows a threat event rather than a demand revision.

Test case: Stargate UAE. The Emirates News Agency reported construction underway on a 1 GW cluster inside the 5 GW UAE-US campus, with the first 200 MW targeted for 2026 delivery. G42's chief executive said in January 2026 that chip deliveries were months away. By September 2026, a Reuters exclusive reported a redesign into a network of sites after attacks on regional data centers, citing six people familiar with the matter. Announced, allocated, and reconfigured are three different states. (WAM, 2025-10-16; Data Center Dynamics, 2026-01-21; Reuters, 2026-09-11; Primary for WAM, Mixed for the anonymously sourced redesign reporting.)

Q2. The model layer

Compute without model control is a rental business. The question is who can run, fine-tune, audit, and keep the model, and what happens when the provider exits or the export license changes. (Analytical)

Evidence to demand: the weights license and fine-tuning rights; IP ownership and evaluation data; the named model owner and a successor or escrow plan; the share of the model stack built domestically versus accessed by API.

Red flags: a sovereign label on a foreign-hosted API; no fine-tune or audit rights; model access that a foreign regulator can revoke. Bruegel cites the June 2026 US order that forced a frontier lab to disable its top-tier models as the demonstration that access can be cut. (Bruegel, 2026-09-10, citing Reuters; Primary research, secondary incident reporting.)

Test case: India supports 20 indigenous foundation model proposals with intellectual property retained by the applicants, and Sarvam's 30 billion and 105 billion parameter models are among the launched outputs. That is a model-layer position, not only a data center position. Japan's second AI Basic Plan states the goal as "open AI Sovereignty," an explicit choice of interoperability over autarky. (PIB, 2026-08-06; Cabinet Office of Japan, 2026-07-14; Primary.)

Q3. Data and governance

Data sovereignty is the layer buyers claim first and audit last. The evidence is provenance and control: where training data comes from, who can access it, and what happens to it at exit. (Analytical)

Evidence to demand: dataset provenance and consent basis; residency and access-control architecture; deletion and portability terms; an oversight body with audit rights and a published reporting cadence.

Red flags: localized cloud infrastructure that depends on a foreign provider, Carnegie's definitional case of sovereignty-washing; open-data repositories counted by volume rather than usability; no audit trail for training data.

Test case: India's AIKosh repository reports 367 datasets uploaded for reuse, and the EU's proposed Cloud and AI Development Act would require public buyers to assess sovereignty risk in cloud procurement. Volume and process are inputs. Neither is a governance finding on its own. (PIB, 2026-08-06; DD News, July 2026; Bruegel, 2026-09-10; Primary for the program disclosures, Mixed for the dataset count.)

Q4. Procurement terms and exit rights

A contract without an exit is a dependency with a purchase order. The audit question is what the buyer can do at renewal: move workloads, keep data, keep models, and buy from a second provider. (Analytical)

Evidence to demand: term and termination for convenience; data egress and portability terms; published scoring; a multi-vendor award structure; the switching cost in money and months.

Red flags: single-provider awards; no exit clause; opaque sovereignty scoring; lock-in marketed as sovereignty.

Test case: The European Commission's April 2026 sovereign cloud award is the current benchmark. It commits up to EUR 180 million over six years across four providers running in parallel, selected on a Cloud Sovereignty Framework with eight objectives and Sovereignty Effectiveness Assurance Levels from SEAL-0 to SEAL-4. Eligibility required SEAL-2, data sovereignty; most winners reached SEAL-3, digital resilience; one partnership reached SEAL-2. Secondary reporting describes 48 underlying scoring criteria in eight categories. Four parallel contracts are the structural answer to lock-in, not a slogan. (European Commission, 2026-04-17; European Commission, 2026-04-17; The Brussels Times, 2026-06-01; Primary for the award and framework, Mixed for the 48-criteria detail.)

Q5. Security levels

Sovereign programs hold model weights, citizen data, and sometimes classified workloads. The audit question is whether security is a mapped, independently tested control set or a certification claim. (Analytical)

Evidence to demand: control mapping to a published framework; independent audit reports; model-weight protection, insider-threat controls, and incident reporting; cleared personnel for the most sensitive tiers; supply-chain assurance for hardware and the update path.

Red flags: classified-grade claims without a third-party audit; weights stored on shared infrastructure; no insider or exfiltration controls; a security posture that depends on the vendor's good behavior.

Test case: RAND's Security Level 3 framework, published 2026-08-25, adapts 262 controls from NIST SP 800-53 Rev 5 to 31 high-feasibility attack vectors and targets implementation in six to twelve months. A program that cannot produce an SL3-equivalent mapping and an audit date is asking the buyer to accept the vendor's word. (RAND, 2026-08-25; Primary.)

Q6. Financing structure

The last question is who pays, who guarantees, and who absorbs the first loss. Sovereign programs increasingly run through joint ventures and special purpose vehicles, which move debt off a government balance sheet without removing the obligation. (Analytical)

Evidence to demand: SPV ownership and governance; the offtake counterparty and its credit; guarantees, equity cure rights, and cost-overrun allocation; refinancing dates and rate sensitivity.

Red flags: announced capex with no closed financing; an unsigned MoU marketed as a joint venture; capacity subject to customer commitments; off-balance-sheet leases marketed as sovereign assets; a single offtaker rated weaker than the program.

Test case: In December 2025, Saudi Arabia's Humain and stc subsidiary center3 announced a proposed joint venture, 51 percent Humain and 49 percent center3, targeting up to 1 GW of AI data centers, with an initial 250 MW "subject to contractual commitments with customers." The instrument remains an unsigned memorandum of understanding, not a signed joint venture; stc disclosed a six-month extension on 2026-06-18 with the parties still completing regulatory and commercial requirements. Humain's stated ambition is 6.6 GW over a decade, while the kingdom's operational data center capacity reached more than 467 MW in the first quarter of 2026, up from 68 MW in 2021. The distance between ambition and meter is the audit. (Saudi Press Agency, 2025-12-18; Data Center Dynamics, 2025-12-18; Arab News, 2026-06-18; The National, 2026-09-01; Primary for the MoU announcement and extension, Mixed for the capacity figures.) The mechanics behind these structures are mapped in The AI Infrastructure Credit Stack.

How to run the audit

Five moves, in order. Get the meter: request current metered load, not nameplate. Match the money: trace every announced dollar to a closed financing document or a balance sheet line. Read the contract: find the exit, the egress, and the scoring. Test the switch: ask what the buyer does in month 13 if the provider changes terms. Verify the controls: request the control mapping and the audit date. A program that answers all five has passed a serious first diligence. A program that answers none has produced a press release. (Analytical)

What would change this view

This framework weakens as an indictment if programs start publishing operational audits. The falsifiers are specific: CNAS-type inventories adding metered capacity and control mappings as tracked fields; government buyers publishing sovereignty scoring with the awards, as the EU did; JV capacity milestones converting to energized megawatts on schedule; and independent counts converging with sponsor self-reports. It also weakens if the sovereign premium disappears, meaning compliant capacity prices at parity with the general market. If compliance instead raises prices and slows energization, as Bruegel warns the EU's local-content criteria could, the audit becomes more important, not less. (Bruegel, 2026-09-10; Analytical.)

FAQ

Q: Is this an argument against sovereign AI? A: No. It is an argument against counting announcements as capacity. Sovereignty is a real objective; the audit asks which programs are actually building it. (Analytical)

Q: What is the fastest single check? A: Metered megawatts today and who can switch off the model. Those two answers predict most of the rest. (Analytical)

Q: Does this overlap with vendor security reviews? A: It sits above them. A vendor review tests the product; this audit tests the program, meaning the contract, the exit rights, the financing, and the operational status. (Analytical)

Q: What if the program is classified? A: Unclassified evidence still exists: contract structure, metered power, funding documents, and audit scope. If none of it can be shown to the buyer's own diligence team, that is the finding. (Analytical)

Q: Does the audit apply outside government programs? A: Yes. The same six questions apply to hyperscaler sovereign-cloud offerings and to private ventures carrying sovereign branding. The meter does not care who owns the logo. (Analytical)

Sources

  • CNAS Insights, "Sovereign AI's Second Wave Is Coming Into View": cnas.org (2026-08-20, accessed 2026-09-18). Primary.
  • CNAS Sovereign AI Index, interactive project inventory: interactives.cnas.org (accessed 2026-09-18). Primary.
  • Carnegie Endowment for International Peace, Luca Belli, "Operationalizing AI Sovereignty Through Agency, Interoperability, and Openness": carnegieendowment.org (2026-09-03, accessed 2026-09-18). Context, not authority.
  • RAND Corporation, "Achieving AI Model Weight Security Level 3 (SL3)": rand.org (2026-08-25, accessed 2026-09-18). Primary.
  • RAND Corporation, SL3 full report PDF: rand.org PDF (2026-08-25, accessed 2026-09-18). Primary.
  • Bruegel, Bertin Martens and Tillman Schenk, "How can Europe address its pressing AI compute infrastructure shortfall?": bruegel.org (2026-09-10, accessed 2026-09-18). Primary research, aggregating the Europe2031.ai dataset.
  • European Commission, "EU launches AI Gigafactories call to boost Europe's computing capacity and unlock more than EUR 30 billion in investment": ec.europa.eu (2026-07-30, accessed 2026-09-18). Primary.
  • European Commission, "Commission awards EUR 180 million tender for sovereign cloud to four European providers": ec.europa.eu (2026-04-17, accessed 2026-09-18). Primary.
  • European Commission, "Commission advances cloud sovereignty through strategic procurement": commission.europa.eu (2026-04-17, accessed 2026-09-18). Primary; carries the SEAL definitions and framework detail.
  • The Brussels Times, "EU's EUR 180m cloud contract sparks scrutiny over sovereignty scoring system": brusselstimes.com (2026-06-01, accessed 2026-09-18). Mixed; carrier for the 48-criteria detail.
  • PIB, "Government Expands Sovereign AI Infrastructure Through IndiaAI Mission and Semiconductor Initiatives": pib.gov.in (2026-08-06, accessed 2026-09-18). Primary.
  • PIB, "IndiaAI Mission Expands AI Ecosystem with Affordable Compute and Startup Support": pib.gov.in (2026-03-25, accessed 2026-09-18). Primary.
  • DD News, "IndiaAI mission gets boost as compute capacity tops 34,000 GPUs": ddnews.gov.in (2026, accessed 2026-09-18). Mixed; carrier for the AIKosh 367-dataset count.
  • METI, GENIAC program page: meti.go.jp (accessed 2026-09-18). Primary.
  • METI and NEDO, "Selection of 16 New Projects ... under the GENIAC Computing Resource Provision Support Project (Cycle 4)": meti.go.jp (2026-06-04, accessed 2026-09-18). Primary.
  • Cabinet Office of Japan, "Japan's Second Artificial Intelligence Basic Plan": cao.go.jp PDF (2026-07-14, accessed 2026-09-18). Primary.
  • WAM (Emirates News Agency), "G42 advances construction of Stargate UAE AI Infrastructure Cluster": wam.ae (2025-10-16, accessed 2026-09-18). Primary state news agency; confirms the 1 GW cluster, 200 MW first phase, and 5 GW campus.
  • Data Center Dynamics, "G42 CEO says company will receive first AI chip shipments within months": datacenterdynamics.com (2026-01-21, accessed 2026-09-18). Mixed.
  • Reuters, "Exclusive: UAE revises AI data center plan after Iranian attacks, sources say": reuters.com (2026-09-11, accessed 2026-09-18). Mixed; original wire exclusive resting on six anonymous sources.
  • Saudi Press Agency, "HRH the Crown Prince Launches HUMAIN as Global AI Powerhouse": spa.gov.sa (2025-05-12, accessed 2026-09-18). Primary.
  • Saudi Press Agency, "stc and HUMAIN Announce JV Partnership to Develop Data Centers Supporting up to 1 GW of AI Workloads": spa.gov.sa (2025-12-18, accessed 2026-09-18). Primary.
  • Data Center Dynamics, "Saudi Telecom Company signs MoU with Humain to develop 1GW of data center capacity": datacenterdynamics.com (2025-12-18, accessed 2026-09-18). Mixed; carries the 51/49 split, the 250 MW initial phase subject to customer commitments, and the 6.6 GW ambition.
  • Arab News, "PIF-backed Humain, stc extend MoU for Saudi AI data center venture": arabnews.com (2026-06-18, accessed 2026-09-18). Mixed; reports the Tadawul filing on the unsigned MoU extension.
  • The National, "Accenture and AWS step up Middle East push into cloud and AI": thenationalnews.com (2026-09-01, accessed 2026-09-18). Mixed; Saudi government figures for operational capacity.
  • Companion visual, "How to Audit a Sovereign AI Program": how-to-audit-sovereign-ai-program.svg (accessed 2026-09-18). Site asset.
  • Related Stack & State analysis, "The AI Infrastructure Credit Stack": stackandstate.com (updated 2026-09-18, accessed 2026-09-18). Site analysis.
  • Related Stack & State analysis, "The Inference-Era Industrial Base": stackandstate.com (updated 2026-09-18, accessed 2026-09-18). Site analysis.
  • Bottleneck Map pillar: Bottleneck Map (accessed 2026-09-18). Site pillar.

Methodology

This article follows the Bottleneck Map method. The constraint is assigned to Layer 3, Compute & AI Infrastructure, because the audit question is what a sovereign program can actually run, with Layer 6 (Non-Dilutive Capital and Procurement) connected through the financing and procurement terms and Layer 9 (Sovereign Capital) connected through the state balance sheets and guarantees behind the programs.

Claims are labeled Primary where a named institution, government release, rating action, or company disclosure is cited inline; Mixed where trade press, secondary reporting, or aggregated datasets carry the figure; Analytical where the claim is Stack & State judgment across sources. The following claims are held rather than asserted: Humain's state-media claim of a data center "with a capacity of up to 6 gigawatts" (the draft uses the 6.6 GW decade ambition and the 467 MW operational figure instead, both with named sources); the Humain-center3 joint venture itself (the draft states that the instrument is an unsigned MoU extended 2026-06-18, not a signed JV); the September 2026 Stargate UAE redesign (sourced to the Reuters exclusive, which rests on six anonymous sources and is labeled Mixed); India's GPU counts, which diverge across dated releases (more than 38,000 GPUs onboarded as of 2026-03-25); and the EU framework's 48-criteria detail (secondary reporting; the Commission's primary materials describe eight objectives and the SEAL levels). Carnegie and CNAS counts are used as evidence of the inventory and framing, not as authority over any specific program. No bracketed placeholders remain in this draft.

Research cutoff and access date for all sources: 2026-09-18. Corrections: /connect/.

Stack & State is an editorial and ecosystem-intelligence publication. Nothing here is legal, investment, procurement, or compliance advice. Program details change; verify requirements with primary sources and qualified advisors.

Editor

Walter Guevara, INSEAD MBA

Walter Guevara, INSEAD MBA, is the founder of Stack & State. He writes on the DMV gov-tech and capital ecosystem, operating as a bilingual architect between Silicon Valley and Washington DC.

Built the Bottleneck Map methodology, tracking 25 constraints across 10 layers of the sovereign technology ecosystem.

Operates at the SV-DC nexus: translates between technology roadmaps, institutional architecture, and the capital stacks that connect them.

Verified sources

Last verified