Digital Sovereignty: Understanding the Whole Chain, From Chips to AI Models

2026-09-24
Digital Sovereignty: Understanding the Whole Chain, From Chips to AI Models

In just a few years, digital sovereignty has moved from the vocabulary of specialists to that of governments. Generative artificial intelligence has pushed the question to the forefront: before handing documents to a model, many public organizations first want to know where it comes from and where it runs. Without clear answers, that uncertainty often slows AI adoption rather than speeding it up.

But what exactly are we talking about? Sovereignty is not a switch you turn on or off. It is a chain, and every link raises its own questions.

A priority for governments

In Canada

In 2024, the federal government launched the Canadian Sovereign AI Compute Strategy, with 2 billion dollars over five years. It provides up to 700 million dollars for private AI data centres in Canada, up to 1 billion dollars for public supercomputing infrastructure, and 300 million dollars to help businesses access compute capacity. In September 2026, Ottawa presented new investments in sovereign and affordable compute capacity.

In the provinces

Provinces are moving too. In Quebec, the Ministry of Cybersecurity and Digital Technology defines digital sovereignty as a government's ability to control and protect its infrastructure, technologies and data against foreign influence. In February 2026, it published a policy statement on digital sovereignty and IT procurement that relies on sovereign hosting in the government cloud, data control mechanisms, open source software and local expertise.

Abroad

France has long relied on the SecNumCloud qualification from its national cybersecurity agency to identify trusted cloud services, and a bill would require it for local governments of more than 30,000 residents for their sensitive data. On the model side, Mistral AI announced in September 2026 a 3 billion euro raise to build a European "sovereign AI layer", from open models to compute capacity.

Sovereignty plays out along a whole chain

1. Chips

It all starts with hardware. In 2025, Taiwanese manufacturer TSMC held 69.9% of the global semiconductor foundry market, according to TrendForce. No public organization controls this link, but it is a reminder that total sovereignty does not exist: the goal is to reduce dependencies where it is possible.

2. Data centres

Where is the data stored, and under which jurisdiction does the company running the data centre operate? A server located in Canada but operated by a company subject to foreign laws does not offer the same guarantees as a local host. This is at the heart of sovereign hosting policies.

3. AI models

Large models are mostly developed in the United States and China. According to Stanford's 2026 AI Index, US organizations released 50 notable models in 2025, and China is closing the gap quickly. Europe is betting on players such as Mistral AI. Using a model means sending it data: knowing where it runs and what it keeps becomes essential.

4. Open models and local deployment

Alongside closed models, more and more open weight models can be installed on infrastructure the organization controls. They are often combined with a RAG approach (retrieval-augmented generation): the model answers based on the organization's own documents, indexed locally, without those documents leaving the chosen environment.

5. Software and its subprocessors

Finally, every cloud application relies on other providers: hosting, email, support, analytics, and now AI model providers. The real question becomes: which data is shared with which third parties, and why?

Large models or local models: a trade-off

There is no single right answer. Large cloud models are usually more capable and easier to use, but data leaves the organization's environment. Open models deployed locally offer more control, but they require infrastructure and expertise, and they often perform less well on complex tasks.

The right choice depends on the sensitivity of the data and the use case. Translating a progress note does not carry the same requirements as analyzing confidential documents. This is the kind of more local deployment we explored for Planivore's compliance module, developed through a Scale AI-funded initiative: a RAG hosted in Canada that draws on an organization's documentation to validate strategic content. It is a good example of what a more local deployment makes possible, and of the trade-offs it involves.

Six questions to find your way

  • Where is our data hosted, and under which jurisdiction?
  • Which third parties receive our data, and which data?
  • Which AI model is used, who develops it and where does it run?
  • Is our data used to train a model?
  • Can AI features be turned on or off depending on data sensitivity?
  • Can we get our data back in a usable format if we change providers?

In short

Digital sovereignty is not a state you reach once and for all. It is a series of informed choices, link by link, between control, performance and cost. For a public organization, the starting point is simple: know where your data goes, who sees it, and be able to decide.

Call to action

To structure the governance of your strategic plan, explore our guides.

Sources

More on this topic
Municipal elections are coming this fall. How to realign your strategic plan with a new council's priorities without starting over.
Learn why Excel falls short for managing strategic plans and how a collaborative dashboard can improve execution, accountability, and results.
Find out why an NPO should have a strategic plan monitoring tool. This article highlights benefits such as efficient resource management, performance monitoring and simplified grant applications.

See Planivore at work in your organization

Book a demo: we'll show you, based on your own challenges, how Planivore structures your plans, tracks your KPIs and simplifies your reporting.