What Sovereign AI Budgets Actually Buy
Joel Christoph / Aug 6, 2026
Participants, including Nvidia Corp. CEO Jensen Huang (front, 2nd from R), Japanese Economy, Trade and Industry Minister Ryosei Akazawa (front, C) and Noetra Corp. President Hironobu Tamba (front, 2nd from L), pose for a photo during an event hosted by the Ministry of Economy, Trade and Industry in Tokyo on July 16, 2026. (Kyodo via AP Images)
Twenty-nine countries, most of them from the Global South, signed the founding accord of the World Artificial Intelligence Cooperation Organization in Shanghai on July 16, convened by China to draw in governments outside the small group that builds frontier AI systems. On June 3, the European Commission adopted its Cloud and AI Development Act proposal, aiming to triple EU data center capacity within five to seven years and to reorganize the EU's internal market. Both treat AI infrastructure as a strategic question. Governments from the Gulf to Southeast Asia are doing the same, buying compute and funding national foundation models under the banner of AI sovereignty. The budgets are substantial. What they are supposed to purchase is often left unstated.
Sovereignty can be used to justify almost any purchase
Much of the current argument about AI sovereignty concerns whether it is desirable or attainable. Analysts debate definitions while ministers announce multi-year packages. Very little of this gives a finance ministry anything usable when two proposals compete for the same money. Sovereignty also comes in distinct kinds, including control over infrastructure, jurisdiction over data and the freedom to change suppliers. They often trade against one another. A budget office needs to know which kind it is buying.
The word sovereignty does little to guide that decision. Invoked loosely, it justifies almost any purchase. The argument also has an interested advocate. Since February 2024, Nvidia's chief executive Jensen Huang has told governments that every country must own the production of its own intelligence. Nvidia sells most of the chips that such ownership needs. He may be right, but ministers should not take the vendor's word for it.
Full self-sufficiency across the AI stack — the set of infrastructure layers, platforms, tools and services that facilitate the use of AI — is out of reach, as the Tony Blair Institute argued in January. The Tech Policy Design Institute's June report, Expanding AI Sovereignty to AI Agency, counts 103 capabilities across six layers of the stack, from compute infrastructure to governance. No treasury can fund them all. Given a fixed sum, which capabilities should a government build at home, which should it pool with neighbors and which should it buy on terms that keep an exit open?
Governments should buy bargaining power rather than sovereignty
Henry Farrell and Abraham Newman supply the missing test. They showed that bargaining power in the global economy comes from occupying positions in networks that other actors cannot leave at an acceptable cost. That is what leverage means here: what a government can credibly demand because walking away would cost the other side more. Such positions also weaken with use, because the squeezed side starts building routes around them, so the strongest leverage tends to be the kind rarely exercised. Taiwan's position in advanced chipmaking is one. Control over access to the European market is another. A capability justifies its budget line when it changes what a government can demand from suppliers, partner states or international bodies. A capability that many others also possess may serve other ends, but it adds no bargaining power, however sovereign it feels.
Before approving an AI line item, a finance ministry should ask three questions. Which stated national objective does the capability serve, and through what chain of steps? Growth, security and influence over global rules reward different investments. How much bargaining power does the capability generate? Can the country use it? A data center that no laboratory draws on produces little beyond electricity bills. And what would the same money produce in its next-best use, inside or outside the AI sector?
What did Switzerland and Japan actually buy?
Switzerland's Apertus model is a subtler case. EPFL, ETH Zurich and the Swiss National Supercomputing Centre trained it on public machines and released it openly on September 2, 2025. Open release was the design goal, so Bern has nothing here to withhold or trade. That may be what its funders wanted. Publishing a model can also set standards that others adopt. That is a separate objective. It carries its own cost, which a budget should show. The model was trained on more than 10 million GPU hours of public supercomputing time. Run the test on that. Against commercial access to stronger models for a comparable outlay, Apertus buys less raw capability, more independence from closed providers and a model others can build on. A budget office should have to say which of those it is buying. Apertus belongs in the research budget or under standards-setting and not in the sovereignty column.
Japan shows the opposite case, along with its limits. Japan Investment Corporation, a state-backed fund overseen by the trade ministry, took the photoresist maker JSR private in a $6 billion deal in 2024. Every leading-edge fabrication plant depends on photoresists, the light-sensitive coatings that carry circuit patterns onto silicon wafers. Few firms make them. Tokyo had already tested that position in 2019, when export restrictions on photoresists and two other chemicals pushed South Korea to find suppliers in Belgium, the United States and Taiwan.
Set the two options against each other. The controls cost Tokyo no public money and produced the squeeze. They also taught the target to diversify. Ownership cost $6 billion and added little beyond what export laws already provided. The purchase secured equity in a position Japan already governed, regardless of the fund's stated rationale of industry consolidation. Then, in May 2026, Reuters reported that JIC was considering a sale, with Fujifilm and Mitsubishi Chemical interested, after AI spending lifted valuations across the chip supply chain. Both suitors are Japanese, so the position would stay inside Tokyo's jurisdiction either way. Even so, a state that treats a scarce asset as something to be sold at the right moment has priced the position as an investment. Leverage that is for sale is already half spent.
Ministries that test for leverage find it in cheaper places
A finance ministry applying this test will also find cheaper sources of leverage. Power supply, water and permitted land increasingly decide where data centers can be built. A country that can offer all three has something scarce to trade, though scarcity alone does not settle who captures its value. A government that offers discounted electricity and a tax holiday hands that value to the investor. Host countries compete for the same projects, so many end up conceding it.
Generic datasets age the same way, as models get better at learning from less. Data keeps its value when it is current, legally usable and hard for others to assemble. Some locally held collections qualify: court archives, health records or recordings of a language few others have gathered. New Zealand's Te Hiku Media shows how such data can be governed. The Māori organization built a speech dataset for its language and licensed it on terms that keep the benefits with the community. Governments can adopt the same principles of consent and benefit-sharing. Custody is not ownership, so they should not treat citizens' records as a sovereign asset to license at will.
Where one country's demand is too small to interest suppliers, pooled procurement or shared compute facilities can reach the scale at which suppliers negotiate. ASEAN, the African Union and the Gulf Cooperation Council could all do this, though today their members mostly negotiate with the same suppliers individually. The EU already pools for supercomputing through the EuroHPC Joint Undertaking.
Where a capability remains outsourced, the terms of purchase determine how much bargaining power a government retains. Multi-vendor contracts preserve an exit option at a fraction of the cost of building it at home, though only where migration has been tested. A buyer can also negotiate training quotas for its own engineers, the portability of models and data or the placement of source code in escrow with a third party. Governments often become dependent after the sale, once the only people who can run the system work for the supplier. The proposed Cloud and AI Development Act itself encourages public bodies to avoid relying on a single vendor.
Sovereignty is only one line in the cost-benefit table
Ministers will say, fairly, that capabilities get used in ways nobody forecast. A strict test would have rejected some investments that later paid off. Some spending is best understood as a financial option: a small payment now for the right to act later. But options have prices and expiry dates. Ministries can fund small, staged bets with capped downside, each with a date for renewal or closure. A government that cannot say what its options cost or what they might open up has not made an investment case.
Fund a capability at home when the leverage it generates toward a defined national objective exceeds the return on the next-best use of the same public money. Otherwise, pool it regionally, or buy it from the market while keeping an exit option. A sovereignty claim then becomes one line in a cost-benefit table, set against outcomes governments already pursue, such as jobs and a seat at the standard-setting table. The next sovereign AI budget that reaches a cabinet should arrive with an answer to one question: how much leverage does this money buy, and over whom?
Authors

