I was recently invited by another university in Singapore to talk about (their terminology, not mine) cross-cultural governance. This area is very en vogue at the moment, perhaps specifically in Southeast Asia, and though my talk covered three main areas—AI sovereignty, governance pluralism, and cultural alignment1—it especially got me thinking about AI sovereignty, and how this field has changed a lot in quite a short period of time. It’s quite recently become a hotbed of activity. So, I want to throw some of my thoughts on the topic out there.
This will not be an all-encompassing piece. Rather, it focuses more on my own thoughts and experiences. I expect AI sovereignty to be one of the next major focal points in AI governance; yet, let me be up-front, it can also develop in many different directions, and it’s too early to tell as yet. It might also mean that this post will be a bit more unstructured than my typical writing.
This brings me neatly to the next point: a while back, I wrote My Personal Primer on AI Governance, and while this here piece is not necessarily a companion piece as such, it will make much more sense when considered in the broader context of AI governance—so, if you’re new to the field, I’d recommend you go read that first and then return here!
In my original text, I foreground one of the core challenges to a global approach in AI governance: that the Global North and the Global South have fundamentally different priorities. Specifically,
The Global North is primarily concerned with misuses.
The Global South is primarily concerned with missed uses.
This remains largely constant, and it’s something many AI governance professionals have been aware of for a good while now. However, in most discussions, it has remained largely implied, and I suspect this core tension making itself explicitly known will be one key driver in the AI governance space moving forward. Indeed, it sits at the core of the debate around AI sovereignty, as it is beginning to gain more and more traction.
This notion of sovereignty is nothing new per se. Many countries and actors have been speaking about it—both explicitly and implicitly—for a very long time, and arguably AI sovereignty cannot be meaningfully decoupled from wider discussions around data sovereignty and, ultimately, tech sovereignty. Yet, now that AI has taken the limelight as a (the?) core public policy concern for many, this question of sovereignty has been rolled, kneaded, and baked into what is now discussed as AI sovereignty—yet, it remains largely unclear what this actually means.
A few weeks ago, I attended a round-table discussion where one of my co-panellists made the astute observation that, typically, when AI sovereignty is invoked, it has no stable definition, and posited that its meaning will only really become stable once we see action. Will sovereignty come to mean what it does in most legal settings—i.e. the capacity to set and enforce its own laws?—or will it take on a more state-driven kind of sovereignty? What about social and cultural aspects; might sovereignty turn inwards and become protectionist? Fact of the matter, we can’t yet say how this will play out.
In other words, AI sovereignty will be defined through practice—and I’m inclined to agree with my co-panellist. Even so, I think it’s worthwhile to initially consider this question conceptually. First and foremost, we can look at AI sovereignty as a sliding scale with Complete Sovereignty on one end, and Complete Openness on the other:
Complete Sovereignty means complete control over a full, end-to-end tech-stack. That is to say, you develop and deploy your own models; you build, run, and maintain your own data centres; generate and capture all data you need by yourself; running (and maintaining!) all cybersecurity requirements, and so on. In effect, you’re a closed system whilst only giving up minimal capabilities—or, ideally, none at all. Complete Openness is, effectively, the opposite: everything is supplied by external actors, through direct investments, service agreements, and so forth. In simplified terms, one is about having complete direct control, and the other is about having no direct control.
As in most cases with these kinds of sliding scales, most countries will fall somewhere in between these two extremes. In fact, there are only a handful of territories that even have the theoretical capacity to be completely sovereign—the big three, as always: the US, China and the EU. Even so, it is not clear that there is any real benefit to this, even if you technically could do it, given the amount of extra cost, resources, and just sheer effort that one would need to plough into such a megaproject.
Rather, most countries will aim for a middle ground that I like to think of as strategic autonomy:
Effectively, this means you retain direct control over critical systems—relating to matters of state and administration, defence, and healthcare, for example—through developing solutions yourself or with close allies, or tweaking open-source systems, so that you can’t be held hostage by external actors. At the same time, of course, you don’t need to do everything yourself. You might only store particularly sensitive data on your own servers, not all data, for example. For small(er) countries, this approach is likely to come with a slew of benefits, like creating closer friendships and allegiances, opening up diplomatic opportunities from bi- and/or multilateral initiatives, and, most importantly, actually being achievable.
However, it bears mentioning that whilst many countries will have the opportunity to operate in these middle-waters, there will still be countries effectively forced to abandon any such designs due to external pressures. These will primarily be poor nations in the Global South; techno-colonialism is a real threat, and a real problem (speaking of missed uses…).
Crucially to aiming for this kind of strategic autonomy is that it necessitates different countries emphasising different needs, approaches and strategies. Now, all of this sounds grand on paper. We’ll have a few big dogs who make a load of stuff, and many smaller guys who are just kinda hanging out. As we all know, the real world loves to be messy and complicated—and though this discussion around AI sovereignty and what it means (and should mean) remains contested, we can already begin to see lines being drawn, and I want to briefly highlight four of them here:
🇺🇸 🤼♂️ 🇪🇺: What some may have missed is that two of the world’s biggest players are already locking horns. The European Union, long a champion of consumer protection, has steadily extended its regulatory reach from data privacy—via the landmark General Data Protection Regulation (GDPR)—to the realm of artificial intelligence through its AI Act. The United States, meanwhile, continues to resist such state-driven oversight, favouring market-led innovation and corporate self-regulation, to the point of . The friction has sharpened in recent months, with Washington reportedly pressuring Brussels to ease enforcement of its digital regulations, arguing they unfairly disadvantage American firms. At stake is not just commerce, but the EU’s capacity to uphold its own regulatory sovereignty—the ability to define and enforce its digital rules independent of US influence. While not a fight over AI sovereignty in name, it’s a struggle over who sets the terms of the digital order—the market or the state, Silicon Valley or Brussels.
🇸🇬: Singapore is a small country. This presents a number of challenges; there are just some things that Singapore cannot do because of lack of scale. Singapore could have the most AI-capable population, the best digital-public infrastructure, and the first out of the gate, but being the Little Red Dot, running up against some physical limitations is inevitable. That being said, Singapore has long been able to use its strategic position at the Strait of Malacca to its advantage. Having, over time, become a ‘bridge’ between ‘East and West’, first through its port, and later as a financial centre, Singapore is self-aware of its strengths as well as its weaknesses. This means that whilst Singapore cannot be the biggest, boldest, baddest actor, it can be the most trusted, and through carving out a space for its own strategic autonomy. In practice, this kind of strategic autonomy will be set its own high-trust standard for other players to store particularly sensitive data in Singapore, and not compete by developing the leanest, meanest new models.
🇻🇳: Vietnam might not be at the forefront of people’s minds as far as AI is concerned, but they’re making moves. Vietnam’s approach to AI sovereignty centres on self-reliance and state-led development. Rather than releasing a national model, the government has focused on building domestic infrastructure, securing data control, and nurturing local talent under its updated National AI Strategy and forthcoming AI law. Central to this vision is the creation of a “third stack”—home-grown systems and partnerships that reduce reliance on foreign technologies. Vietnam’s narrative frames AI as a matter of national infrastructure and independence. Yet, as the state deepens its control over data and digital systems, sovereignty might take a turn to be all too similar to centralisation.
🇲🇾: Malaysia recently released its own national AI model, ILMU. Touted during its release at the ASEAN AI Summit in Kuala Lumpur in August as being made by Malaysians for Malaysians, significant emphasis was placed upon its capacity to speak Malay; being a “culturally intelligent AI”. This is not surprising at all, as Malaysia has long emphasised a sense of AI sovereignty. The announcement nonetheless places significant focus on Malay-ness, and not Malaysian-ness. For those unaware, Malaysia is around 69% Malay/Bumiputera, 23% Chinese, and 6.7% Indian. In short, Malaysia is a multi-ethnic, multicultural state. Furthermore, Malaysia has historically struggled to manage inter-ethnic tensions; a challenge that has never fully been settled. Though we will have to wait and see exactly how this will turn out remains to be seen. However, the case of Malaysia begs the question: when does AI sovereignty turn into AI nationalism?
As this all shows, AI sovereignty, whilst likely the next hot-button topic in governance and policy circles is not a new topic per se, but rather one that has already been molded and shaped by various decisions, actions, and intentions. In other words, what makes it an exciting area of debate and discussion is not that it is a blank canvas. Rather, there are a lot of forces pushing the discussion in different directions, many of which we can already see—likely to be based on various forms of strategic autonomy. I also expect that we will see it being interpreted and integrated in very different ways depending on country, context, and overall strategic vision. In other words, I expect it will be an exciting space to keep an eye on, as it’ll bring some tensions to the fore, whilst also opening up new opportunities for cooperation and, perhaps, even the formation of larger AI governance/regulatory/policy ‘blocs’.
For now, only time will tell.
It’s very likely I’ll do one post on each of these topics, but you’ll have to bear with me!
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.