The Short Answer
Sovereign AI became buildable at both layers in early October 2026. Aleph Alpha's Kolibri gives you frontier-adjacent weights under Apache 2.0, and Palantir's Armada partnership gives you air-gapped compute you own. The remaining dependency is the orchestration layer between them. With ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and deploy anywhere.
For two years sovereign AI had a credibility problem: the open models were a step behind, and the hardware still lived in somebody else's building. Both of those changed inside the same week.
What is Kolibri, and why does an open-weight German model matter for enterprise AI?
Kolibri is an open-weight model Aleph Alpha released on 3 October 2026, the Day of German Reunification. It is licensed under Apache 2.0, which means you may run it, modify it, and ship it commercially without asking anyone.
The architecture is a Mixture-of-Experts: 78B total parameters with roughly 3B active per token, drawn from 384 smaller experts with 6 active at a time.
Native context is 262,144 tokens, which Aleph Alpha's blog reports extending to 1M by extrapolation. It is bilingual English and German, with 21.3% of pre-training tokens in German.
Aleph Alpha built it in Germany and trained it on infrastructure in Germany and Finland, under European and German law. That sentence is the product. Jurisdiction is not a feature you can add to a model later.
On published benchmarks it reports 96.9 on AIME 2025 and 92.7 on HumanEval+, and Aleph Alpha states it matches models with up to four times its active parameter count, naming Nemotron 3 Super.
It also reports a non-hallucination rate of 44.0 on AA-Omniscience against 14.8 for its predecessor.
| Kolibri property | Value | Why a buyer cares |
|---|---|---|
| License | Apache 2.0 | No seat count, no renewal, no revocation |
| Parameters | 78B total / ~3B active | Serving cost tracks the active count, not the total |
| Experts | 384, with 6 active per token | Fits far smaller hardware than 78B suggests |
| Context | 262K native, 1M by extrapolation | The model card recommends staying at or under 262K for serving |
| Jurisdiction | Trained in Germany and Finland | A residency answer that survives legal review |
What did Palantir and Armada announce about sovereign AI infrastructure?
On October 1, 2026, Palantir named Armada its inaugural certified modular data center partner, in a partnership aimed at sovereign AI infrastructure.
Palantir will validate and integrate its Sovereign AI Operating System, built on AIP, Ontology, Foundry and Apollo, on Armada's Galleon modular data centers. The work extends the Sovereign AI Operating System reference architecture Palantir developed with NVIDIA earlier in 2026.
Three claims in the announcement are the ones worth holding onto.
The modular data centers are manufactured in the U.S. and allied nations.
They can be deployed in months instead of years, on-grid, off-grid, or fully air-gapped. And the Armada Platform runs without reliance on any external cloud, including any operated by Armada.
That last clause is unusually precise, and precision is the point. "Air-gapped" is frequently sold as a posture. Naming the vendor's own cloud as something the deployment does not need is an architectural commitment instead.
Armada has been building toward this publicly, including Orion, a 10MW Galleon aimed at distributed deployments on what it calls the Sovereign AI Grid.
Why does sovereignty at the model and compute layers move the problem somewhere else?
Because sovereignty is a chain, and a chain is only as sovereign as the link you forgot to check.
Until this month, two links were genuinely weak. The weights were either proprietary and rented, or open and a visible step behind. The compute was either a hyperscaler region with a residency label, or a data center build measured in years.
Both links are now serviceable. You can hold Apache 2.0 weights that you are licensed to run forever, on hardware manufactured in allied nations, in a facility that does not phone home.
What remains is the layer in between, and it is the layer almost nobody audits: the orchestration that routes a request, the ontology that tells an agent what a "student" or a "claim" or a "case file" actually is, the role model that decides which agent may read which record, and the audit log that proves what happened.
Own the weights and own the rack, and a closed orchestration layer still ends the conversation. The data has to pass through it, which means the dependency you were trying to remove has simply moved up one floor.
What should an organization require from an AI vendor in October 2026?
Four requirements, each of which the two announcements above now make reasonable rather than aspirational.
Require the source code, under a perpetual license. Open weights underneath a closed platform is a half measure. If you cannot receive, read, and keep the orchestration code, you do not own the system, you own one component of it.
Require model-agnostic routing as configuration, not a project. Kolibri is the argument. A 78B Apache 2.0 model with a 262K-token native context appeared with no notice. The question is not whether you like it. It is how many weeks it takes you to try it, and whether trying it requires your vendor's cooperation.
Require that air-gapped means air-gapped. Ask the question Armada's announcement answers: does the deployment depend on any external cloud, including one the vendor operates? A yes is fine, as long as it is written down.
Require the ontology and the audit trail as exportable artifacts. The orchestration layer accumulates the thing you cannot regenerate: the typed relationships describing your institution, and the record of every decision an agent made. If those leave with the vendor, the switching cost was never really about the model.
On ibl.ai you deploy the whole agentic stack inside your own perimeter, which is the same claim Kolibri makes about weights and Armada makes about racks, applied to the software that connects them.
Our work with Syracuse University runs this way at ai.syracuse.edu, deployed on Syracuse's own cloud environment, with the university holding the complete source code under a perpetual license. The Syracuse case study has the detail.
For the longer argument about why open weights alone do not deliver sovereignty, see open-weight models and sovereign AI. For the government procurement version, see Palantir, Nebius and who actually owns a sovereign deployment.
For the hardware arithmetic of serving Kolibri next to Mistral's 1.05T-parameter model, see Mistral Large 4 (Le Chonk): The Infrastructure Math.
The Edge
Sovereign AI is now solved at the two layers that are easy to photograph, the model and the machine, and still unsolved at the layer in between that no one puts in a press release.
The orchestration layer is where the ontology, the permissions and the audit trail live, and it is the only layer whose contents you cannot re-download if the relationship ends.
ibl.ai is family-owned and operated from New York, NY β a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.