Analysis

Digital sovereignty: what a small business can really control

The subject is treated as a matter of state. Yet it is settled every week, in contracts signed by companies of twenty people.

A white keyboard on a dark desk, lit from the side
Sovereignty is decided at the moment of signing

When the head of a small business hears about digital sovereignty, they hear a debate that does not concern them: billions in investment, chip factories, international summits. They are right on one point — they will not influence any of those. They are wrong about the rest, because the decisions that really determine who sees their data are not taken at a summit. They are taken when signing a subscription.

The 2026 edition of Stanford’s AI Index devotes a whole chapter to the question and offers a grid we had not seen anywhere else: AI sovereignty is split into five layers (Stanford HAI, AI Index 2026). Of those five, a modest-sized business decides three, and often without realising it.

Global AI rests on very few players

The orders of magnitude are worth setting out once, to know what is being discussed. The United States hosts 5,427 data centres, far ahead of Germany (529), the United Kingdom (523) and China (449); France has 322, ninth worldwide (AI Index 2026, p. 33). The report itself states the limit of that count: it counts facilities, without measuring their size or their computing power.

Upstream, the concentration is stronger still. The report notes that a single foundry, TSMC in Taiwan, produces virtually every leading AI chip (AI Index 2026, p. 32). Downstream, model production remains shared between two countries: 1,618 models published since 2018 in the United States, 849 in China, 666 across Europe and Central Asia (AI Index 2026, p. 337). France accounts for 141, second in Europe behind the United Kingdom (AI Index 2026, p. 336).

No small business will redraw that map, and that is not where its room for manoeuvre lies — it is the thread followed by the article that opens this series. The useful question is therefore not whether one can escape it, but which of those dependencies are expensive, and which are chosen.

That concentration has a very concrete effect, and it is not a political one. When most of the computing capacity belongs to a handful of players, the price of an AI service, its terms of use and even its availability depend on decisions taken elsewhere. A business that has built a process on one interface can see, within a quarter, the price change, the model replaced by another, or the offer withdrawn. This is not a hypothesis: it is how a young, highly concentrated market ordinarily works.

Digital sovereignty has become public policy

The movement among states is clear. In Europe and Central Asia, the number of public supercomputing clusters went from 3 in 2018 to 44 in 2025 (AI Index 2026, p. 333). Rules follow: the report counts 66 data localisation measures adopted in Europe and Central Asia between 2000 and 2024, against only 3 in North America. Europe is not the strictest — East Asia and the Pacific count 77, Sub-Saharan Africa 71 (AI Index 2026, p. 334).

France holds a place that is both respectable and modest: $4.36 billion of private AI investment in 2025, fourth worldwide and first in the European Union (AI Index 2026, p. 182); around $320 million of public AI-related contracts between 2013 and 2024, third in Europe behind the United Kingdom and Germany (AI Index 2026, p. 357). These figures are American in method, global in scope: they describe momentum, not production capacity.

For a business, the practical consequence is immediate: the framework is tightening, and it tightens first on location. What used to be a preference becomes a contract clause, then a question in a tender.

The regulatory movement points the same way, without needing exegesis here: the European regulation on artificial intelligence adds obligations depending on the use, and the GDPR continues to apply to any personal data passing through. For a small business, the consequence fits in one line: what used to be an engineer’s preference becomes a document in a file, demanded by a client, an insurer or a public buyer.

Five layers, and you do not control five

This is the report’s main contribution, and the reason we cite it here. Sovereignty is defined as the capacity to act deliberately and to decide independently — then split into five distinct layers, which are not won at the same price or at the same level (AI Index 2026, p. 332 to 340). The table below sets them out, with what a small business can do about each.

LayerWhat it coversWhat a small business can do about it
InfrastructureChips, data centres, computing capacity.Nothing about manufacturing. But it chooses where its computation runs, and under which law the operator sits.
DataStorage location, applicable law, conditions of reuse.Almost everything. It is the most accessible layer, and the most often neglected.
ModelWho designs the model, with what data, and can it be inspected.A real choice: an open-weight model you can freeze, or a closed service you follow.
ApplicationThe business software the AI is embedded in.Room to negotiate: reversibility, data export, independence from a single vendor.
TalentThe skills available to design, run and check.The usual weak point. Some internal skill, even partial, beats none at all.

Reading those five lines in order has a useful effect: you stop treating sovereignty as a box to tick. A business can be perfectly sovereign over its data and completely captive on its line-of-business application, and it is the second that will trap it the day it wants to change.

The talent layer deserves an extra word, because it is where small businesses assume they have already lost. It is not about hiring a researcher. It is about one person in the business being able to say what the system does, where the data goes, and who to turn to when an answer looks doubtful. That skill is acquired in a few weeks on a real case. Without it, the other four layers are decided by the supplier, for want of anyone to answer back.

What a small business actually decides

Three decisions, and all of them are taken before signing. Where the data the service will process is stored. Where the computation runs, and under which law the operator running it sits — a data centre located in France but operated by a company subject to US law does not put the data beyond the reach of a legal demand: we set this out in what a sovereign cloud really protects.

The third decision is the least often asked: can you change model without rebuilding everything? An open-weight model can be frozen on a version, replayed identically and replaced. A closed service changes when its vendor decides, and a use that worked may stop working without warning. What this implies for the most sensitive flows is developed in what sovereign AI changes in practice and, on the execution side, in running an LLM inside the business.

Those three decisions translate into four clauses, and they fit on one page. How long the data sent is kept, and whether it is actually deleted. A ban on using it to train or improve a model. The list of sub-processors involved, with their countries. And the ability to freeze a model version, or at least to be warned before it changes. A serious supplier answers all four; one who does not has already answered.

That leaves the case where the supplier refuses, or stays vague. It calls for sorting, not for a crusade. Not every flow deserves the same care: a press release and a patient file do not carry the same weight. So uses are sorted into two piles — what may leave, what must not — and the effort is reserved for the second. That sorting, done once, avoids both paranoia and carelessness.

Open source redeals part of the hand

The report notes a movement that favours smaller organisations: on GitHub, contributions from the rest of the world now outpace Europe’s and approach those of the United States (AI Index 2026, p. 12). In practice: the models you can run in-house are no longer degraded versions of what the market sells. The French vendor Mistral AI publishes several of its models under an open licence, and they are enough for most of a small business’s uses.

It is also what makes size less decisive than people think: on specific tasks a compact model often beats a generalist giant, and it fits on a machine you own. We devote the next article in this series to it.

Two caveats, to stay honest. An open-weight model is not a transparent model: the parameters are published, the training data almost never. And running a model in-house shifts the burden rather than removing it — updates, backups, access management, and someone to answer for it. Sovereignty is paid for in operations. That is a modest price for what it guarantees, provided it was planned for.

One last remark, which holds for the whole series. Sovereignty is not a moral position, and it says nothing about a supplier’s quality. It says only who can legally demand access to your data, and who decides when your tool changes. Framed that way, the question stops being ideological: it becomes a clause, a price, and a risk you accept or refuse knowingly.

Digital sovereignty is not won in one move, and nobody in a small business has time to make a project of it. It is won at the moment of signing, by asking four questions instead of none. It is a small thing, and it is exactly what separates a chosen dependency from one you simply inherit.

Common questions

What is sovereign AI?

An AI system whose chain you control: where the computation runs, the law applying to the operator, and the model itself, preferably open-weight so it can be frozen and inspected. Hosting in Europe is only one condition among several.

Can a small business run AI locally?

Yes, for most everyday uses: summarising, classifying, extracting, searching your own documents. A compact open model fits on a high-end desktop machine. The cost is not the hardware but the running: updates, security, access.

What is the difference between sovereign cloud and sovereign AI?

Sovereign cloud is about hosting: where the servers are, who runs them. Sovereign AI adds the model question: who designed it, can it be frozen, can a decision be explained afterwards. You can be hosted in France and still depend entirely on a closed model.

Source: Stanford HAI, Artificial Intelligence Index Report 2026, published on 29 June 2026 under a CC BY-ND 4.0 licence. Page numbers refer to the PDF file; the five-layer breakdown appears on pages 332 to 340. The data centre count comes from Cloudscene and measures neither the size nor the capacity of the facilities. This article is an analysis by Maeliom; it is neither a translation nor an adaptation of the report, and is neither affiliated with nor endorsed by Stanford University.


Next article

AI workflow: not every decision deserves an LLM

Read

A transformation to support?