Sovereign AI: Who Holds the Keys?

Sovereign AI is control over where your AI runs, which model it uses and who can switch it off. For industries that cannot go dark, that control is the strategy.

Imagine: 2:14 a.m., a refinery control room. A pressure anomaly is spreading across three units. The shift lead turns to the AI assistant that has read every maintenance log and incident report from the last decade. It replies with a polite message: service unavailable for your organization.

Fiction? Only just.

In July 2025, after a new round of EU sanctions, Microsoft suspended Outlook, Teams and other core tools at Nayara Energy, operator of one of India's largest refineries, even though the company held fully paid licenses. Employees moved to a domestic email provider. Access returned days later, just before a Delhi High Court hearing.

That was email. Now picture the AI that reads your contracts, prices your bids and watches your plant.

That is the question Sovereign AI answers: who holds the switch?

What is Sovereign AI?

Sovereign AI is an organization’s ability to decide where its AI runs, what it learns from, what data it can access, which model it uses, who can see it, and who can turn it off.

In other words, sovereignty is about control across the AI stack.

It isn’t a flag on a data centre, and it isn’t simply a "made in India" label. It also isn’t the open-versus-closed debate. It is control across four layers.

Sovereignty is control across four layers
  1. Layer 4OperationsWho can audit, override or stop it?If you don't control itAccountability without authority
  2. Layer 3InfrastructureWhere does inference physically run?If you don't control itA cable cut or policy change takes you offline
  3. Layer 2ModelCan you choose, swap, fine-tune or freeze it?If you don't control itYour roadmap is set by a vendor's release notes
  4. Layer 1DataWhere do prompts, documents and outputs live?If you don't control itYour IP sharpens someone else's advantage
Built from the bottom up: the data, the model that reads it, where it runs, and the people who can stop it.

Sovereignty isn’t owning everything. It’s never being forced to accept a decision you didn’t make.

Why does sovereignty matter for mission-critical industries?

In most businesses, an AI outage is an inconvenience. In mission-critical industries it is a safety incident, a compliance breach or a lost contract.

Where AI is moving in, and what is at stake
IndustryWhere AI is moving inWhat's at stake
Defence & aerospaceDesign data, maintenance, supply chainNational security, export-controlled data
Energy & utilitiesGrid operations, predictive maintenancePhysical safety, continuity of supply
Elevators, escalators & HVACFleet monitoring, service, bidsPassenger safety, uptime SLAs
EPC & infrastructureTenders, contracts, project riskCrore-scale margins, liability
Government & PSUsProcurement, citizen servicesPublic trust, DPDP compliance

These industrial organizations possess something increasingly valuable: proprietary data and institutional knowledge. Engineering drawings. Source code. Product architectures. Manufacturing recipes. Maintenance history. Operational telemetry. Safety cases. Customer information. Supply-chain intelligence.

This information is often the competitive advantage itself.

Putting that data into an AI system therefore isn’t simply a technology decision. It is a decision about IP, security, regulatory exposure, business continuity and competitive advantage.

Nations already get it. The IndiaAI Mission has backed 20 indigenous model proposals: 12 large and 8 small language models. Enterprises running critical operations need the same instinct.

When does an AI system need to be air-gapped?

"Cloud-first" is a sound default, until your data is a blueprint, a grid topology or a defence tender. For that class of data, the safest network connection is none.

An air-gapped deployment removes three risks at once: data leaving the perimeter, dependence on outside connectivity, and silent changes pushed from outside.

NIST defines an air gap as an interface where systems are not physically connected and logical connections are not automated, with data transfer occurring manually under human control.

The deployment spectrum
  1. Public APIFastest start
  2. Private cloud / VPCYour tenant
  3. On-premiseYour hardware
  4. Air-gappedNo network at all
ConvenienceControl and responsibility
More control means more responsibility. Not every workload belongs at the right-hand end, but the ones that do should never be forced left.

Our rule: match the gap to the classification. Not every workload needs isolation. The ones that do should never be forced online.

Open weights vs frontier models: the wrong debate?

Frontier models vs open weights
Frontier models (API) Open weights (self-hosted)
Peak reasoningBest in classClosing the gap fast
Data stays with youDepends on the contractAlways
Runs offlineNoYes
CustomisationPrompting, limited tuningFull fine-tuning
Cost profilePay per tokenUpfront infra, predictable
Who can change itThe providerYou

Security teams learn this the hard way: a rented model may refuse to analyse real attack logs because they look like an attack. A self-hosted model works under your policies, not someone else’s.

The winning pattern isn’t picking a side. Frontier models for complex reasoning on non-sensitive work. Open weights for sensitive, regulated or offline workloads. Routed by policy, not by habit.

Bring your own LLM: don’t let your AI strategy expire

If replacing your model means rebuilding your platform, you don’t have an AI strategy. You have a dependency.

One of the biggest architectural mistakes an enterprise can make is allowing its AI platform to become permanently coupled to one model provider. Models will change. Prices will change. Capabilities will change. Regulations will change. Your business requirements will change.

Your AI strategy should not expire with your LLM contract.

Bring Your Own LLM (BYO-LLM) means the application layer is model-agnostic. You plug in the model you trust, whether frontier, open-weight or one of India’s emerging sovereign models, and swap it when a better, cheaper or safer option appears.

  • Negotiating power stays with you.
  • Data agreements stay with you.
  • Model upgrades become a configuration change, not a project.

Choosing the right model: five questions before you sign

Five questions before you sign
  1. 1How sensitive is the data?BecauseIt sets your deployment floor: API, private or air-gapped.
  2. 2How hard is the task?BecauseExtraction isn't contract reasoning. Don't pay frontier prices for simple work.
  3. 3Does it perform on your documents?BecauseBenchmarks don't read your RFPs. Test on real data.
  4. 4What do the licence terms allow?BecauseCommercial use, fine-tuning rights, data retention.
  5. 5Can it run where you need it?BecauseHardware, latency, Indian languages, offline operation.
The best model on the leaderboard is rarely the best model for the job.

The most overlooked Sovereign AI feature: the kill switch

Here’s a simple test I believe every enterprise AI architecture should pass: can you stop it?

If an AI agent is connected to enterprise systems, it may eventually have the ability to:

  • Read sensitive information
  • Generate engineering artifacts
  • Modify software
  • Trigger workflows
  • Invoke APIs
  • Make recommendations
  • Potentially execute actions

At that point, the AI is no longer merely answering questions. It is operating inside your enterprise. A sovereign architecture therefore needs controlled mechanisms to stop, isolate, revoke, roll back and recover.

Two hands, one switch
The switch they hold
  • API deprecations
  • Usage-policy changes
  • Sanctions and export controls
  • Price changes
  • Regional outages
Shrink this
The switch you must hold
  • Halt any agent instantly
  • Roll back to a previous model version
  • Revoke tool and data access
  • Fail over to human decision-makers
  • A full audit trail of what the AI did
Own this
  1. Stop
  2. Isolate
  3. Revoke
  4. Rollback
  5. Recover
Every AI system has a kill switch. The only question is whose hand is on it.

The kill switch should not be an emergency button invented after deployment. It should be an architectural capability.

Sovereignty means shrinking the left column and owning the right one. Design so that when the AI goes off, the business doesn’t. Human-in-the-loop isn’t the brake. It’s the steering wheel.

The sovereignty test

Five statements. Be honest about how things run today.

The sovereignty test

Tick every statement that is true for your organization today.

0/5Fewer than four? Your AI is rented, not owned.
Your answers stay in your browser.

The last word

The next decade of AI in critical industries won’t be won by whoever has the smartest model. Models will keep getting smarter, cheaper and more interchangeable. It will be won by the organizations that control the stack those models run on.

Intelligence is becoming a commodity. Control is not.

So before your next AI decision, ask the only question that matters at 2:14 a.m.: who holds the switch?

At tiramai, we build AI-native platforms for industries that can’t go dark: sovereign by design, model-agnostic by default. Let’s talk.

Sources

  • #sovereign AI
  • #air-gapped AI
  • #BYO LLM
  • #open weights
  • #kill switch
  • #mission-critical industries
Share
Written byVijay Venkatesh SrinivasanCo-Founder and CPTO, tiramai
Connect on LinkedIn
Talk to us

Working through this for your organisation? Our team can walk you through it on your own use case.

See the platform

How tiramai runs governed AI in the cloud, your private cloud or fully on-premises.

Explore ProductSphere
FAQ

Questions About This Topic

Sovereign AI is an organization’s ability to decide where its AI runs, what it learns from, what data it can access, which model it uses, who can see it, and who can turn it off. It is control across four layers: data, model, infrastructure and operations.