FREQUENTLY ASKED QUESTIONS
Straight answers to the hard questions.
Straight answers about ownership, outside model routing, lawful access, hardware origin, jurisdictional change and continuity. Understand what runs locally, what may leave, who holds authority and what the evidence can actually prove.
What is true AI sovereignty—can any country supply it completely?CONTROL
True AI sovereignty is not complete isolation or national-origin purity. No jurisdiction supplies every layer of the AI stack. It is the practical ability to decide where work runs, what may leave, who holds the keys and whether essential operation can continue independently. Origin and dependencies remain documented, while provider, legal and jurisdictional developments are monitored so material changes can trigger review of the operating boundary.
Read the full article: True AI sovereignty—control, not country of origin.
If my data sits in a Canadian or EU region of a US cloud, can the US government still compel access?LAW
Region selection alone does not resolve provider-control exposure. The US CLOUD Act addresses data in a provider's possession, custody or control, while the exact legal result depends on the provider, facts, applicable agreement and challenge mechanisms. See the US Department of Justice's provider guidance, then have counsel assess your situation. This is why the Atlas separates geography from control.
What's the difference between data residency and sovereignty?LAW
Residency is where the bytes sit. Sovereignty is who can reach them, who holds the keys, and who can be ordered to hand them over. A workload can satisfy every residency rule and still be one subpoena away from disclosure. Residency is a fact about geography; sovereignty is a fact about control.
Does sovereign AI mean cutting ourselves off from the internet?ARCHITECTURE
No. Air-gap is a posture you can select, not a requirement. A governed boundary declares what runs locally and what may cross to an external model through a default-deny, permissioned route. Metering and receipts can prove what the route did; “attested” applies only after the deployed controls and evidence are verified against the selected Assurance Profile. You set the tolerance.
Does SovereigntyBox upload my data or sync anything automatically?PRIVACY
Nothing is copied automatically. You review and approve every piece of context that moves from the public Halo AI to your private system. In a fully offline deployment, the Halo AI works only with information stored on your machine.
Everyone builds through Taiwan. Isn't that your risk too?ARCHITECTURE
It is a material concentration risk. Many advanced accelerator and server supply chains route through Taiwan, but the exact exposure varies by configuration and must be documented unit by unit. The design goal above the hardware is local control of keys, support and update authority; the delivered unit's evidence must prove whether that goal was met.
Aren't open-weight models just worse?CAPABILITY
Capability changes quickly and depends on the task, model, quantization and evaluation method. The configurator treats open-weight capability as a planning input, not a universal benchmark claim. A proof-of-workload evaluation should decide whether local models clear your quality bar; governed external routing remains available where they do not.
What happens to us if a provider changes terms, deprecates a model, or is ordered to switch us off?LAW
Rented AI continuity depends on the provider, contract, policy and governing law. Owned infrastructure reduces that dependency only when the customer holds the weights, runtime, keys and update authority without a compulsory remote-control path. Those conditions must be verified for each deployment.
Who can push an update to the box?ARCHITECTURE
The design target is customer-controlled, severable update authority: signed packages, explicit acceptance and no compulsory remote push path. The final architecture and Sovereignty Report must verify who holds the acceptance key and whether any vendor route remains.
Can we keep using frontier APIs where they're genuinely better?CAPABILITY
Yes — by permission, not by dependency. Workloads route by policy: the owned floor covers the substitutable majority, and the frontier edge is reachable through the governed, metered boundary when a task justifies it. Rent the edge; own the floor. The cost chart on the homepage shows what each choice costs at volume.
Can we still use American AI providers?CONTROL
Yes. American frontier models may provide the best capability for particular tasks. We apply the same test to every provider: what can it access, change, revoke or be legally required to disclose? When the task, information and applicable legal or professional rules permit the route, the Halo AI limits what leaves and records what happened. Essential work retains a customer-controlled local option.
Why does AI sovereignty matter now?CONTINUITY
AI is becoming operating infrastructure. Trade measures, export controls, legal authority and provider-policy changes can affect supply, access, pricing, disclosure and continuity—even when data is stored locally. SovereigntyBox does not predict which dependency will change next; it helps the business understand those dependencies and retain a customer-controlled place for essential work to continue. Sovereignty News follows current developments, while the Sovereignty Atlas organises verified jurisdictional positions.
How does SovereigntyBox decide where work runs?ROUTING
The customer defines the operating boundary. The Halo AI evaluates each task against its data sensitivity, legal and professional limits, required capability, cost, available local capacity and approved providers. It can run locally, use an approved outside model, request human authorization or stop. Every permitted outside route limits what leaves and records the provider, reason and authorization.
Is this legal advice? Will this make us compliant with GDPR or the EU AI Act?LAW
No — and be suspicious of any vendor who says otherwise. We describe the law and document the system; we certify nothing. The Sovereignty Atlas maps what each jurisdiction requires, from primary sources, and the Sovereignty Report supplies the evidence about your deployment. The compliance determination belongs to your counsel, your assessor, or your regulator.
How do we prove any of this to a board, an auditor, or a regulator?EVIDENCE
With the receipt, not the pitch. A production deployment should regenerate a Sovereignty Report on material change: what's running, where each part came from, who can reach the runtime, which jurisdiction holds keys and update authority. The current public report is a specimen. Live rows must identify their evidence state, verifier, date, exceptions and residual risks so an assessor reads scoped facts, not marketing.
What does it cost compared to renting?ECONOMICS
It depends on workload, utilization, model choice, provider pricing, power, operations and amortization. The configurator produces a labelled planning comparison from editable assumptions; it is not a quote or a guarantee of savings. A buyer should replace every default with current provider prices and its own operating inputs.
Which countries' laws has this been checked against?LAW
The Sovereignty Atlas holds per-country dossiers: Canada, the UK, Ireland, Germany, France, Switzerland, Indonesia and Thailand at launch, each covering data residency, AI regulation, cloud procurement and export/access, every position labelled by confidence. More jurisdictions are added as they're verified — the atlas is the upstream half of the configurator's sovereignty stage.
Didn’t find your question here?
The concierge answers from the site's own material — nothing leaves the page. For everything else, contact us directly.