Why I am writing this
We build sovereign AI for a living, so it would be easy to read this as a vendor sharpening elbows. It is closer to self-defence. When the word means everything, it means nothing, and the buyers who most need it (banks, defence, government, space programmes) are the ones who lose when it is stretched.
I am not going to name anyone. The patterns are more useful than the names, and the checks work on us as well as on everyone else. Please use them on us.
The five fakes
1 · Residency without control
The claim: “Hosted in India.” The gap: the vendor holds the keys, pushes model and software updates at will, and ships logs and telemetry wherever it likes. The check: who can change the model running on your data tomorrow, without your approval?
2 · A borrowed brain with a flag on it
The claim: “Our own Indian model.” The gap: it is an adapted foundation model presented as built from scratch. Adapting an open model is legitimate engineering; hiding it is not. The check: from scratch, or adapted? And does the licence permit your use?
3 · The foreign side path
The claim: “A sovereign stack.” The gap: the model runs locally, but the guardrail, the embeddings, the speech recognition, the OCR or the monitoring call an overseas API. The check: show me every outbound network call, not just the model's.
4 · Air-gap on the brochure
The claim: “Air-gap ready.” The gap: it needs a licence server, a cloud console, a telemetry endpoint or an online update to keep working. The check: unplug the cable for a week. What stops?
5 · A sovereign box, ungoverned behaviour
The claim: “A sovereign platform.” The gap: the infrastructure is yours, but nobody can say which model made a decision, what it saw, or who approved it. The check: pick one decision from last week and show me the record.
The pattern behind all five
Each fake takes one property of sovereignty and presents it as the whole. Location stands in for control. A national flag stands in for lineage. A local model stands in for a local system. A deployment option stands in for independence. Infrastructure stands in for accountability.
Sovereignty is not one property. It is the set, and the weakest one decides.
That is why a single question exposes most of them: “Show me, from your own records, what happened on one real decision last week: where it ran, which model and version, what it saw, what it called, and who approved it.” A sovereign system answers with a record. A washed one answers with a slide.
What honest looks like
Honest vendors say
“This model is built from scratch; this one is adapted from an open foundation whose licence permits your use.” “These are the outbound calls, and here is how to switch each off.” “This works disconnected; this feature needs a connection.” “Here is the record for that decision.”
Honesty about the limits is the strongest signal you will get. Anyone who claims no limits has not been asked the right question yet.
Honest buyers ask
For records, not assurances. For a demonstration of a control blocking something, not a description of it. For the vendor's own list of what is not sovereign yet, and the plan for it.
And for an exit: if the vendor disappeared tomorrow, could you keep running what you rely on? If not, you are renting, whatever the contract calls it.
How we hold ourselves to it
We state the lineage of our model families plainly: Tatva Nano and Tatva Edge are trained from scratch in India, and our larger families are built on open foundation models, served and governed inside our own platform. We publish statuses as they are: preview means preview. Our platform runs in the customer's cloud or disconnected with Swaraj, masks data before any model sees it with Veil, and writes a signed Trust Receipt for every call. When something is a demonstration, our pages say so on screen.
If you want the five checks run on your AI programme, ours included, book a sovereignty review. For the full framework behind them, read the six-question sovereignty test.
Frequently asked questions
What is sovereign AI?
Sovereign AI is AI whose compute, models, data flows and decision records are under the control of the organisation or country that relies on it: where it runs, what it is built on, what it sends out, whether it works disconnected, and a verifiable record of what it did.
Is hosting an AI model in India enough to make it sovereign?
No. Data residency is necessary but not sufficient. If a vendor holds the keys, can update the model without approval, or sends logs and telemetry abroad, the system is hosted in India but not controlled by its user.
Is a model adapted from an open foundation model sovereign?
It can be, if the adaptation, the licence and the deployment are honest and under the user's control. The problem is not building on an open foundation; it is presenting an adapted model as built from scratch, or hiding a licence that restricts the user.
How can I check if an AI vendor's sovereignty claims are real?
Ask for records instead of assurances: who can update the model on your data; whether the model is from scratch or adapted, and under which licence; every outbound network call; what stops working when the system is disconnected; and the full record of one real decision from last week.
Written by
Siddhartha Chandurkar
Founder, ShepHertz Technologies
Siddhartha Chandurkar writes for AgentAnywhere, the sovereign AI platform built by ShepHertz Technologies, which has put AI into production since 2012.