The Short Answer
Sovereign AI stopped being rhetoric in 2026 and became procurement. France's Ministry of the Armed Forces signed a framework agreement with Mistral in January; Nigeria's National Digital Cloud Policy scopes sovereignty to government and regulated data. Both are contracts, not speeches. On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, with no per-seat pricing, so you can deploy anywhere.
One correction before the argument, because the circulating summary overstates one half of it.
Nigeria did not impose blanket data localisation. Its policy deliberately scopes sovereignty requirements to defined categories of government and regulated data, and leaves general commercial data alone. That restraint is the sophisticated part, not a weakness.
What did France actually buy when it chose Mistral over OpenAI?
A framework agreement, and the distinction from a policy statement matters.
In January 2026 the French Ministry of the Armed Forces awarded Mistral a framework agreement giving defence agencies and related institutions access to its models and services, running on sovereign French infrastructure.
In June, France launched Notre IA ("Our AI"), a plan to distribute sovereign tools across public services. Its centrepiece is an assistant called L'Assistant, built on a Mistral model and hosted in SecNumCloud-certified datacentres.
France is backing the strategy with over β¬109 billion in AI investment, and Mistral's valuation passed $14 billion in early 2026.
Note what this is and is not. It is a procurement channel that routes public-sector work toward domestic providers on domestically-controlled infrastructure. It is not a law banning American models from France.
The mechanism is the interesting part: sovereignty enforced through the contract, not through legislation. That is faster to implement and easier to reverse.
What does Nigeria's National Digital Cloud Policy actually require?
Less than the headlines suggest, and more precisely than most policies of its kind.
The Federal Ministry of Communications, Innovation and Digital Economy inaugurated the policy as a national framework for the country's cloud and data-infrastructure ecosystem.
It sets four priorities: investment and market development, regional digital-services exports, government cloud transformation, and digital sovereignty and security.
Crucially, it does not impose general data-localisation requirements on commercial data. Sovereignty requirements apply narrowly, to defined categories of government and regulated data where national control is genuinely necessary.
Sector regulators go further where the risk justifies it. The Central Bank of Nigeria has mandated that payment transaction data generated in the country be stored and managed locally from January 2027.
This is a better template than blanket localisation, which raises costs across an entire economy to protect a subset of data. Scope the requirement to the data that actually needs it.
Does choosing a domestic AI vendor make a government sovereign?
No, and this is the failure mode both programmes still have to navigate.
A domestic supplier can lock you in exactly as thoroughly as a foreign one. Nationality of the vendor is a political property. Ownership of the artifacts is an architectural one, and only the second survives a change of supplier.
The clearest evidence is British. The UK's Β£500m Sovereign AI Unit is the most concrete sovereign-AI programme any major government has run β and its own contract terms let suppliers keep all the IP while government retains usage rights only.
You can fund a national programme properly, buy from a local champion, and still own nothing at the end of it. We worked through that case in UK Sovereign AI: Real Procurement, But the IP Still Leaves.
Three questions decide the outcome, and none of them is about the vendor's passport:
- Who holds the source code, under what licence, and for how long?
- Where does inference physically run, and can it run with no outbound connectivity?
- What do you still possess if the commercial relationship ends tomorrow?
What does sovereign AI procurement cost against per-seat licensing?
Per-seat pricing is the wrong shape for a government, more so than for a company, because agency headcount is set by statute and budget rather than by how much anyone uses a tool.
An agency pays for every badge whether that person opens the assistant daily or never. Self-hosted inference does not work that way: the same infrastructure serves 500 staff or 15,000.
Every figure below is arithmetic on a vendor's published per-user price.
| Agency size | ChatGPT Enterprise ~$60/user/mo |
Microsoft 365 Copilot $30/user/mo |
Glean ~$40/user/mo |
Self-hosted, owned stack |
|---|---|---|---|---|
| 500 staff | $360,000/yr | $180,000/yr | $240,000/yr | Infrastructure |
| 5,000 staff | $3,600,000/yr | $1,800,000/yr | $2,400,000/yr | Unchanged |
| 15,000 staff | $10,800,000/yr | $5,400,000/yr | $7,200,000/yr | Unchanged |
| Cost driver | Headcount on the payroll | Actual usage | ||
The right-hand column is deliberately not a dollar figure. Infrastructure costs vary too much between agencies to quote honestly, and a fabricated number would undercut the argument.
The shape is what matters. Three columns multiply by headcount and one does not. At 15,000 staff the per-seat lines have grown thirtyfold against the 500-staff row while the infrastructure has not changed.
There is a second, slower cost that procurement rarely scores. A per-seat contract buys access for a budget cycle; an owned deployment is an asset that persists across administrations.
What should a public-sector buyer put in the contract?
Four clauses, and they are cheap to insist on before signing and nearly impossible to retrofit.
Source-code escrow or a perpetual licence. Usage rights expire with the relationship. A perpetual licence to the code you are running does not, and it is the difference between a supplier change and a rebuild.
A named deployment boundary. Specify where inference runs and whether the system must function with no outbound connectivity. "Cloud" is not an answer; a jurisdiction, a certification tier, and an air-gap requirement are.
Model portability. Require that the platform run any model, including one you have not chosen yet. A domestic model is a good default, not a permanent architecture β and today's national champion is tomorrow's legacy dependency.
Exit terms with the data schema attached. The right to export your data is worthless without the schema and the embeddings to make it usable. Write down what leaves with you.
ibl.ai is family-owned and operated from New York, NY β a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.
What do these sovereign AI programmes still get wrong?
Three things worth naming, because the enthusiasm is running ahead of the evidence.
Sovereignty is being measured by supplier nationality. It is easy to audit and nearly meaningless. A French agency running a French model on French infrastructure under a licence it does not hold is one contract renewal from losing all three.
Capability is being confused with control. Both France and Nigeria are, correctly, building domestic capability. That is an industrial-policy goal. Control is an architectural one, and a government can have either without the other.
Almost nobody is publishing the contract terms. The UK case only became legible because its terms were examined. Until sovereign-AI procurement is scored on ownership rather than announced on origin, most of these programmes will not know which kind they bought.
For a worked example of an institution that got the architecture right rather than the press release, see DRONA 2.0: A Military College Replaced Its Custom GPT, and for the wider policy picture, Why Government AI Must Be Sovereign: EU, Kenya, Taiwan.