If your organisation is about to connect an AI service to sensitive records, security operations or an essential workflow, the familiar checklist – encryption, passwords, access logs and patching – covers only the first layer. You also need to know who can alter the model, who can see what enters it, and whether the system will still work if an outside provider withdraws access.
That is the practical meaning of AI sovereignty. It is not an abstract demand to build everything within national borders. It is the ability to keep making consequential decisions under pressure. The framework below will help you test an AI system before dependence on it becomes a national vulnerability.
Sovereignty means control, not a domestic label
At the Kerala Cyber Suraksha Summit 2026, Gaganyaan astronaut and Indian Air Force pilot Prasanth Balakrishnan Nair put the central problem plainly: cybersecurity has limited value unless a country owns and controls the AI on which it depends.
A workable definition follows from that warning. AI sovereignty is a nation’s ability to govern, inspect, operate, secure and, when necessary, replace the AI systems used for critical functions. Ownership in this sense is broader than legal title. A government may buy a product and still lack meaningful control over its data, updates, computing infrastructure or continued availability.
You can examine that control through five layers:
- Data control. The operator knows what information leaves the organisation, where it is processed, who can access it, how long it is retained and whether it may be reused to train another model.
- Model control. Authorised domestic institutions can evaluate how the model behaves, inspect the relevant components where necessary, change its configuration and identify unacceptable limitations.
- Compute control. Critical services have enough assured computing capacity to continue if an external cloud, licence or application programming interface becomes unavailable.
- Operational control. A trusted local authority can approve updates, reject them, roll them back, isolate the system and shut it down without waiting for a foreign provider.
- Institutional control. Bharat’s laws, public authorities and accountable organisations determine acceptable use, auditing, incident response and liability.
No single layer proves sovereignty. A model hosted in Bharat may still depend on an opaque external service. A domestically branded system may still send sensitive prompts elsewhere. Conversely, an international partnership can support sovereignty when Bharat retains audit rights, operational control, continuity and a credible path to replacement.
The useful test is therefore not the flag attached to the vendor. It is whether Bharat retains freedom of action when commercial relations, technical conditions or geopolitical circumstances change.
AI can compromise judgement without breaching a network

Conventional controls remain necessary, but they do not settle every AI-era security problem. A firewall can block a malicious connection; it cannot decide whether a convincing voice recording contains a genuine instruction. An access-control system can protect a database; it cannot correct a decision-maker who has been persuaded by fabricated evidence.
The growing difficulty of distinguishing authentic content from synthetic content creates three distinct failure modes:
- Perception failure. A fabricated message, image, document or recording can induce an authorised person to act. The attacker may never need to enter the protected system.
- Dependency failure. A critical workflow can stop when a remote AI service, licence, update channel or computing platform is interrupted. The organisation may remain uncompromised yet become unable to function.
- Accountability failure. An opaque model can influence a consequential decision while leaving investigators unable to reconstruct what data, version, configuration or instruction produced the result.
Each failure requires a different response. High-consequence instructions delivered by voice, video, email or messaging applications should be confirmed through a second, pre-established channel. Two messages from the same potentially compromised account are not independent confirmation. Use a known telephone number, an authenticated internal system or an agreed escalation contact instead.
AI-assisted decisions should also preserve the original records, the model version, the instructions given to it and the identity of the human approver. If an organisation cannot reconstruct a serious decision after an incident, it does not have adequate operational control over that system.
Finally, continuity exercises should include the loss of the AI service itself. Disconnect the external endpoint in a controlled test. Reject an update. Restore an earlier approved version. Make the team perform the essential task manually or through an alternative system. A fallback that has never been exercised is an assumption, not a capability.
Use this seven-question AI sovereignty test

Run this test before a pilot receives sensitive data and again before the system becomes part of an essential workflow. The system owner should answer every question in writing and support the answer with architecture records, contracts, logs or a completed test. We don’t know is not a low-risk answer.
- What crosses the boundary? List every category of data sent outside the organisation or country, including prompts, uploaded files, outputs, logs, error reports, identifiers and feedback.
- Who can use that information? Identify every provider and subcontractor that may access, retain or reuse it. Record whether the data can be used for model training or service improvement.
- Who controls the model in operation? Name the authority that can change its configuration, restrict a capability, approve a version, isolate it or stop it locally.
- What happens when the external service disappears? Test whether the essential function continues if the remote endpoint, cloud region, licence, payment channel or support relationship becomes unavailable.
- How are updates governed? Establish who verifies the origin of an update, tests it, approves deployment, monitors the result and restores the previous version if behaviour changes.
- Can an incident be reconstructed? Confirm that investigators can recover the relevant inputs, outputs, model version, configuration, access records and human decisions without depending entirely on the provider.
- Can the organisation leave? Document how it will export necessary data, preserve records, replace the model and continue the function without losing access to its own operational history.
A simple red-amber-green triage makes the answers usable. Green means the control is documented and has been tested. Amber means the control exists mainly as a contractual promise or has not been exercised. Red means no accountable person can demonstrate it.
This triage is not a formal certification. It is a decision tool. For a low-consequence drafting assistant, some amber answers may be manageable if sensitive data is excluded. For defence, public safety, identity systems, essential infrastructure or core government continuity, the absence of tested continuity, local shutdown authority, incident records or an exit path should block deployment until the gap is closed.
Bharat should secure critical functions before chasing scale

National AI policy can become preoccupied with headline models and computing capacity. Those investments matter, but sovereignty begins with the functions whose disruption or manipulation would impose the greatest consequence. Bharat can turn that principle into a practical sequence.
- Map existing dependence. For each AI-enabled workflow, record the owner, provider, model, data involved, external connections, human approver and fallback. An institution cannot reduce a dependency it has not identified.
- Classify by consequence. Give the highest scrutiny to systems connected to defence, public safety, essential infrastructure, identity, core administration and decisions that are difficult to reverse. Do not apply the same controls to a public writing assistant and a system that can affect an essential service.
- Procure enforceable rights. Contracts for critical systems should address data use, subcontractors, audit access, operational logs, update approval, vulnerability handling, rollback, continuity, data export and termination. A general promise of security does not answer these separate questions.
- Build a usable fallback. Depending on the function, this may be an approved domestic model, a portable open system, a second provider or a well-rehearsed manual procedure. The fallback must use compatible data and must be tested before an emergency.
- Invest across the stack. Sovereign capability requires trusted computing infrastructure, governed datasets, model evaluation, Bharatiya-language capability, cybersecurity engineering, skilled operators and independent testing. Buying or training a model without the surrounding operational capacity creates another fragile dependency.
- Exercise the whole system. Rehearse synthetic-media incidents, loss of a provider, a disputed update and a model producing unreliable output during an urgent event. Include technical teams, leadership, communications staff and the people responsible for the affected public function.
The whole-of-nation character of future digital conflict means government cannot close every gap by itself. Operators of essential services, startups, universities, media organisations and civil society all influence whether false information spreads, whether incidents are preserved for investigation and whether essential functions can continue. Shared procedures for authenticating emergency communications and reporting suspected manipulation are as important as another security appliance.
Sovereignty should not become a pretext for isolation or automatic distrust of foreign technology. International collaboration can broaden capability and reduce cost. The condition is that no single outside party gains an unreviewable veto over a critical national function. Domestic origin is not a substitute for security, either: an opaque, unauditable domestic system can still be dangerous.
If you are an employee or citizen rather than a policymaker, the same discipline applies at a smaller scale. Do not enter confidential, security-sensitive or identity data into a public AI service unless your institution has approved the service and its data handling. Treat an urgent instruction carried only by synthetic-capable media as unverified. Confirm it through a known channel, and preserve the original message or file when reporting suspected manipulation.
Key takeaways for your next AI decision
- Treat AI as a dependency layer, not merely as a software feature protected by ordinary network controls.
- Demand evidence of control over data, models, computing, operations and institutional accountability.
- Use an independent confirmation channel for high-consequence instructions conveyed through audio, video, email or messaging applications.
- Test service loss, rollback and replacement before a critical AI system enters routine use.
- Judge domestic and international providers by auditability, continuity and replaceability rather than branding alone.
Put the seven questions into your next procurement, risk or governance review before approving another AI pilot. Digital swaraj begins with that disciplined refusal to depend on a system no accountable person can inspect, stop or replace.
References


Leave a Reply
You must be logged in to post a comment.