What sovereign capability actually looks like
Australia is having a debate about "sovereign AI capability". So far the debate is mostly about buildings: where the data centres go, whose power they use, how much water they drink, and how many billions of dollars of foreign investment they represent. Those are real questions. They are also questions about landlordship, not sovereignty. A foreign model, running in a foreign company's tenancy, in a data centre on Australian soil, is subcontracted capability paying local rent.
We use the phrase "sovereign AI capability" once, above, because that is what the public conversation calls it. From here on we will talk about what it actually is, layer by layer, because sovereignty is not one thing and the current policy settings cover about a layer and a half of it.
The withdrawal test
A capability is sovereign to the degree that it keeps working, and keeps being verifiable, if any foreign relationship is withdrawn. Not "is it hosted here" but: if the provider changed its terms, its prices, its politics or its export permissions tomorrow, what would still run on Monday, and what claims about it could you still check yourself? That is the whole test. Apply it rigorously and the layers separate immediately.
The test stopped being hypothetical some time ago. Three recent illustrations, each a different failure mode. When the United States sanctioned the International Criminal Court's chief prosecutor in 2025, his access to Microsoft services fell away and the Court began moving off Microsoft entirely - access lost over another government's politics, nothing the user did. (Microsoft disputes that it cut the service; either way, the Court no longer relies on it - which is the point.) In early 2026 Anthropic refused a Pentagon demand to drop its ban on fully autonomous weapons targeting and was designated a supply-chain risk for it: the mirror case, where the capability is withheld by the vendor's own policy and the decision is not yours. And the quietest failure needs no politics at all: a vendor advancing its product on its own release schedule can change, deprecate or remove a capability an Australian workflow was built on, with no obligation to keep the version you depend on running. Terms, prices, politics and export permissions are the dramatic cases; the roadmap is the routine one. Only the layers you can run and check yourself survive all four.
Seven layers
1. Compute. Hardware you own and can service. The current debate covers the gigawatt end - hyperscale centres - and ignores the other end entirely: the capability that runs on hardware a school, a council, a small business or a single practitioner owns outright. We do commercial design-review work for a paying client using a vision-enabled model running on one consumer-grade graphics card. Not a demonstration - the actual deliverable. The interesting sovereignty question is not "can Australia host a gigawatt" but "can ten thousand Australian organisations each own a kilowatt that does useful work". The second is achievable now and no one is planning for it.
2. Energy. Covered - and covered well - by the Data Centre Expectations and the announced standards. The one layer where policy is ahead of the commentary. Worth saying so.
3. Models. Weights you hold. A model reached only through an API is a service relationship, and service relationships fail the withdrawal test by definition. Open-weight models - many of them very capable, some of them trained overseas, all of them runnable, inspectable and adaptable on hardware from layer 1 - are the sovereignty option nobody's investment brochure mentions, because there is no tenancy to sell. Nobody has to train a frontier model from scratch for this. Sovereign model capability means Australian organisations holding, adapting and composing weights they can run without permission.
4. Orchestration and governance. The software layer where "computer suggests, human decides" either exists as record structures or does not exist at all - where determinations carry their author, model conclusions are marked as inferred, and consent travels with data. This layer is where governance is real. Conveniently, it is also where a small Australian software practice can be world-competitive, because it is made of design decisions, not gigawatts. This is the layer we build.
5. Data. Onshore storage settles where the data sleeps, nothing more. Sovereign data is data whose use is governed by the person or organisation it belongs to - granted, scoped, time-bound, revocable. The Consumer Data Right already runs this pattern for banking. Generalise the grant, bind it to the data itself, and the sovereignty is in the cryptography rather than the geography.
6. Verification. The ability to check claims without trusting the claimant: that this output came from that model, that this system runs within its licence, that this data was used inside its grant. Attestation and signed provenance. A nation that cannot verify its systems' claims has sovereign infrastructure and subcontracted truth.
Working reference code. A running reference implementation of the licensed-capability mechanism is published at git.meanwhile.computer/meanwhile/research - clone it and check the claims yourself.
7. People. The layer that makes the other six mean anything, and the one where concentration is the quiet risk: capability pooled in a handful of buildings owned by a handful of firms in two cities is fragile capability, whatever flag is on it. Distributed skill - practitioners across sectors and towns who can run, adapt and question these systems - is the sovereignty that cannot be acquired, only grown.
The library move
One program would do more for the seven layers than anything in the Standards: allocate compute to communities as public infrastructure. Every local government area receives a computing allocation - owned hardware, or capacity in a nearby facility - that belongs to the community and is usable by its people: residents, schools, clubs, community groups, the digital collectives a town already is, hosting and representing themselves. Not a grant they must win. Not credits they must spend with a vendor. Not something they are told to go and source. Available the way a library is available: maintained, staffed, free at the point of use, and nobody at the door asking for your business case.
Australia has made exactly this move twice before and both times it worked. Public libraries put the means of reading in every town before anyone could prove demand. Community broadcasting allocated spectrum - a scarce national resource - to communities, and built one of the strongest community media sectors in the world on it. Community computing is the third in the series, and the reasoning has not changed: a capability this basic either becomes shared infrastructure or becomes a divide.
The mechanics can be boring, which is a compliment for public infrastructure. Start with pilot councils. A meaningful community node is a rack in a council building, not a data centre, and it costs less than a suburban intersection upgrade. Uptake is the signal: fund what gets used, learn from what sits idle, expand on evidence. The National AI Plan already has a pillar called "spread the benefits" - this is what that pillar looks like when it is a thing you can walk into rather than a sentence.
Compute belongs in the same sentence as libraries, pools and playing fields. Any government that agrees can have this section.
What it should look like
The finished state is describable now, and reachable by the time the first Standards are reviewed: every agency and any business that wants it able to run capable models on hardware it owns; data moving under grants its owners control and can revoke; every consequential determination carrying a human author; provenance checkable end to end by parties who trust no one; conformity verified by machines rather than attested by paperwork; and the skills to operate all of it distributed across the country rather than concentrated where the investment announcements happen.
None of that requires a single additional gigawatt. Most of it is running, at small scale, today - some of it in our workshop, on hardware that cost less than a ute. The Standards can require the properties; the layers above show they are buildable. What the debate calls sovereignty is the easy layer. The other six are the country's actual choice.
Written with model assistance. Read and edited by a human - though I'm not an editor, so tell me what I've missed: drop me a line. Parts of this were generated; all of it was read, checked and meant. Feedback is welcome and gets used.