FREQUENTLY ASKED QUESTIONS

Straight answers to the hard questions.

The questions buyers actually ask about sovereign AI — lawful access, Taiwan exposure, open-weight capability, update authority. Answered plainly, with the evidence linked.

If my data sits in a Canadian or EU region of a US cloud, can the US government still compel access?LAW

Yes. The US CLOUD Act follows provider control, not data location — a US-controlled provider can be compelled to produce data it holds regardless of which region stores it. "EU region" answers residency. It does not answer reach. This is why the atlas scores provider control separately from geography, and why the box puts both in your jurisdiction.

What's the difference between data residency and sovereignty?LAW

Residency is where the bytes sit. Sovereignty is who can reach them, who holds the keys, and who can be ordered to hand them over. A workload can satisfy every residency rule and still be one subpoena away from disclosure. Residency is a fact about geography; sovereignty is a fact about control.

Does sovereign AI mean cutting ourselves off from the internet?ARCHITECTURE

No. Air-gap is a posture you can select, not a requirement. The default is a governed boundary: the local floor runs everything it can, and anything that crosses to an external model does so through a default-deny, attested route — metered per run, with proof of what did and didn't leave. You set the tolerance.

Everyone builds through Taiwan. Isn't that your risk too?ARCHITECTURE

It is — and it's common-mode. Every serious AI box, from every vendor, is built through the same island; that risk cannot be bought away, only documented. What differs is the control layer above the hardware: keys, support and update authority sit in your jurisdiction, not a foreign one. The risk you can remove is the foreign kill switch, and that one is removed.

Aren't open-weight models just worse?CAPABILITY

The gap has collapsed. Inference cost at a fixed quality bar has fallen roughly an order of magnitude a year, and today's open weights reach last year's frontier on hardware you can own. For most document, knowledge-work and agentic workloads the difference no longer decides outcomes — and the frontier edge stays reachable through the governed boundary when it genuinely does.

What happens to us if a provider changes terms, deprecates a model, or is ordered to switch us off?LAW

On rented AI, nothing protects you — access ends when the provider's policy or government says so; it has already happened, worldwide, within hours. On owned infrastructure the question disappears: the weights are yours, the runtime is yours, and there is no external switch to flip. Continuity stops being a contract negotiation.

Who can push an update to the box?ARCHITECTURE

You, and only you. Update authority is severable: updates arrive as signed packages you accept offline, and the acceptance key lives in your jurisdiction. There is no compulsory control-plane link and no remote push channel that bypasses it. The Sovereignty Report records the signed manifest of what's running.

Can we keep using frontier APIs where they're genuinely better?CAPABILITY

Yes — by permission, not by dependency. Workloads route by policy: the owned floor covers the substitutable majority, and the frontier edge is reachable through the governed, metered boundary when a task justifies it. Rent the edge; own the floor. The cost chart on the homepage shows what each choice costs at volume.

Is this legal advice? Will this make us compliant with GDPR or the EU AI Act?LAW

No — and be suspicious of any vendor who says otherwise. We describe the law and document the system; we certify nothing. The Sovereignty Atlas maps what each jurisdiction requires, from primary sources, and the Sovereignty Report supplies the evidence about your deployment. The compliance determination belongs to your counsel, your assessor, or your regulator.

How do we prove any of this to a board, an auditor, or a regulator?EVIDENCE

With the receipt, not the pitch. Every deployment regenerates a Sovereignty Report on change: what's running, where each part came from, who can reach the runtime, which jurisdiction holds keys and update authority. Rows are labelled — attested, disclosed, zero-reach, severable — so an assessor reads facts, not marketing.

What does it cost compared to renting?ECONOMICS

At 50M tokens a day, every frontier tier runs more than the owned floor — the gap reaches an order of magnitude at the premium end, even after the July 2026 price cuts. The on-prem figure is a labelled planning estimate (hardware amortized five years, plus support, power and operations); the API figures are reported estimates. The configurator prices your actual workload in CAD before you commit to anything.

Which countries' laws has this been checked against?LAW

The Sovereignty Atlas holds per-country dossiers: Canada, the UK, Ireland, Germany, France, Switzerland, Indonesia and Thailand at launch, each covering data residency, AI regulation, cloud procurement and export/access, every position labelled by confidence. More jurisdictions are added as they're verified — the atlas is the upstream half of the configurator's sovereignty stage.

Something thornier?

The concierge answers from the site's own material — nothing leaves the page. For everything else, contact us directly.

SBX CONCIERGEnothing leaves this page