Sovereign AI Is Not One Decision. It's Five.
A Friday directive cut deployed model access mid-prompt and made me redraw 'sovereign AI' as five separable layers — chips, training, weights, inference, data-flow law — not one decision.
Last Friday around 5:30 PT, I was watching a Claude agent loop through a refactor: fourth tool call, halfway into rewriting the data layer of a small side-project, the kind of thing you fire off at the end of a workweek and check on between toddler dinner time and bedtime. My X tab was open in the next window because of course it was (little did I know that one line was about to land in it).
https://twitter.com/AnthropicAI/status/2065597531644743999
The US government had ordered Anthropic to suspend access to its Fable 5 and Mythos 5 models, the same family the agent in front of me belonged to (mine was a Claude release, not Mythos, but the family was the point). The directive specifically targeted access by
“any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.”
I read that line twice. Inside or outside. I’m on H1B. Andrej Karpathy joined Anthropic on May 19, less than a month before the order. The clause covers him. The clause covers me. What the order pulled was the same family I was holding — from people like me. By that exact sentence.
I closed the agent loop without finishing the refactor. Not because I had to. Because something in the way I was holding the tool changed.
Five layers of sovereign AI

Well, here’s where I’d been wrong (and where I think the threads were too). I had been thinking about “sovereign AI” as one decision (should we / can we / do we build our own?) and treating the whole thing as a single argument with a single answer.
The directive made me re-draw it. Sovereign AI is not one decision. It’s five.
Chips. Since October 2022, the US has been gating advanced chip exports. The first round, from BIS (the Commerce Department’s export-control arm), blocked 16/14nm logic chips to China. A 2023 expansion closed Nvidia’s workaround chips (the A800/H800 were sold specifically to skirt the first round; the second round caught up) and pulled in 43 more countries. CSIS (a DC think tank that watches this stuff) called it
“a far taller fence around a yard that is expanding.”
In plainer English: stricter rules, bigger fence, more countries. Chips sit upstream of every other layer. Nothing else happens without them.
Training. Once you have the chips, you have to actually train a model on them. That gets expensive fast. Epoch AI (an AI-research nonprofit that tracks compute and cost trends) broke down where the money goes for a frontier run: 47–67% to hardware, 29–49% to R&D staff, 2–6% to energy. Sam Altman said GPT-4 cost “more than $100 million.” Epoch projects the biggest runs will cross $1B by 2027. The bottleneck isn’t the dollar figure though. It’s that 29–49% staff share: the talent density to run a four-month dense-model job without the failed-runs budget eating you alive.
Weights. Once a model is trained, what you’re left with is a giant file of numbers, the network’s parameters (called the weights), that you can copy, ship, or self-host. The trained model is the weights. This layer is where China has been busy. DeepSeek-V3’s final pre-training run was $5.576M. The full DeepSeek operation, per SemiAnalysis (a chip-industry research outfit), sits north of $2.5B in capex and opex on roughly 50,000 Nvidia Hopper-class GPUs. Both numbers are true; they just live at different layers. Qwen3, Alibaba’s open-weight family, trained on 36 trillion tokens across 119 languages and shipped 100+ open-weight checkpoints into the world. This is the most contested layer right now, and also the one with the most good news.
Inference. This is the layer Friday’s directive landed at. Not the chips. Not the weights. It revoked deployed access to a running model, for a defined class of users, on a defined day, in an afternoon. The G42 case is the same shape with different actors. G42 is the UAE’s national-champion AI company, chaired by Sheikh Tahnoon bin Zayed; Microsoft committed $1.5B to it in April 2024, and by July 2025 US officials were already floating “cut off direct access of chips to G42.” Inference is where state action hits builders fastest.
Data-flow law. This is the rules layer: who’s allowed to send what data where. Schrems II, a 2020 ruling from the CJEU (the EU’s top court, Court of Justice of the European Union, named after the Austrian privacy activist who brought the case), invalidated the EU–US Privacy Shield because US surveillance law gave EU data subjects no real redress. China’s mirror image is the CAC, the Cyberspace Administration of China, China’s internet regulator, which requires companies to get sign-off before releasing a generative AI model. This makes AI sovereignty more of a Schrems II problem than an oil problem. Even when you self-host the weights, you inherit the laws and chip-supply chains that produced them. Self-hosting doesn’t reset the jurisdiction.
These five aren’t independent. The chips constrain the training; the data-flow law sits over the whole thing. A serious sovereign-AI defender would say that’s exactly the point: the layers are entangled enough that decomposing them is how you concede the strategy. Fair. They’re entangled. They’re also separable, and the directive separated them in public.
What the X threads got right and wrong
I want to do justice to the threads because they’re written by people I respect, and because they’re mostly correct on the inputs and wrong on the shape.
Sridhar Vembu (founder of Zoho, India’s bootstrapped software giant) and Hemant Mohapatra (partner at Lightspeed India, with a deep technical background) are right about the cost numbers. Mohapatra’s ~$250M for compute and ~$500–600M all-in for a GPT-class run sit coherently between the public anchors. That’s roughly one mid-sized Indian VC fund. The math is doable. What’s missing is the rest of the stack: chip access, the talent share Epoch flagged, and an investor or sovereign willing to write a check that produces a depreciating asset rather than a SaaS multiple. The cost number is the easy part of the cost answer.
Pratyush Kumar’s “we are building” frame is right at the weights layer (Pratyush is one of Sarvam’s co-founders, and his team is the one actually shipping Indian foundation models). Sarvam-30B and Sarvam-105B did ship in February 2026, Apache 2.0 (a permissive open-source license), on IndiaAI Mission compute via Yotta and Nvidia. That’s a real artifact. It’s also silent on the inference layer (where Friday happened) and the chip layer (where India is structurally downstream).
Deedy Das (a Menlo Ventures VC who’s been vocal on Indian foundation-model launches) made waves with his “23 downloads” tweet, and Prabhat Tiwari’s LinkedIn teardown of Sarvam-M is the longer version of the same point: shipped artifacts aren’t adopted artifacts. Param 1’s 12 downloads, despite training on 5 trillion words, make the point a pattern, not a Sarvam-only complaint. (I’d add that a weights-layer critique using inference-layer evidence is itself a layer-collapse, a small one, but worth seeing.)
The unifying mistake on Friday was the same across all five voices: treat “sovereign AI” as one decision. Once you separate the layers, the threads stop disagreeing with each other and start disagreeing about which layer they’re standing on.
What’s doable vs. what’s not
Here is the per-layer triage as honestly as I can do it from where I sit. Pretending every layer is equally addressable is how you get Project Independence: a heroic plan with the wrong shape.
Chips: not doable for India in 2026. The US CHIPS Act put $52.7B of public money into the layer and has unlocked ~$630B in announced private investment across 28 states. Even with all that, TSMC’s Arizona fab (TSMC is Taiwan Semiconductor, the world’s biggest contract chip manufacturer) runs 4-5x the cost of its Taiwan equivalent. The US is barely doable. India isn’t the next entrant.
Training compute: partially doable. IndiaAI Compute (the government-funded GPU pool) is at 18,693 GPUs: 12,896 H100s, 1,480 H200s, 7,200 AMD MI200/MI300. That’s enough for the next Sarvam-class run. It’s not enough for a 2027 frontier run, which Epoch puts at $1B+.
Weights: doable today. Sarvam-30B/105B exists. Qwen3 and DeepSeek-R1 have shown that open-weight families are a viable hedge under chip pressure. This is the layer where India can and should be loud.
Inference: doable but contested. Self-hosting open weights is a real option for builders right now. You pay in ops effort, not in capital. The Friday directive is what makes thinking about this layer non-optional, and the G42 chip-cutoff signal is the same risk for state-partner deployments.
Data-flow law: doable for governments, not for individual builders. The EU has the legal muscle (Schrems II is the receipts!). India’s DPDP Act (the Digital Personal Data Protection Act, passed 2023) is mostly placeholder so far. The CAC regime is a different bargain entirely. As a builder you don’t write this layer; you read it.

The Sarvam question, reframed
I want to come back to Sarvam, because every Indian timeline I read over the weekend landed there eventually.
The selection is real. On April 26, 2025, the Government of India under the IndiaAI Mission picked Sarvam by name from 506 proposals to build “India’s sovereign LLM,” with bespoke compute access via Jio, Yotta, CtrlS, Tata Communications, and NxtGen (the major Indian cloud and data-center operators that joined the IndiaAI compute pool). That’s a national-champion designation, not a neutral grants program. Calling it that isn’t a hit-piece, it’s a description.
Here’s what the IndiaAI Mission has actually put behind each layer so far. The Mission was approved in March 2024 with ₹10,371.92 crore (about $1.1B) over 2024-2029. ₹4,563.36 crore (~$480M) of that is earmarked specifically for compute, which built the national GPU pool. The Sarvam selection is the foundation-model partner pillar, sitting at the weights layer. AIKosha (the government-run platform with 80+ models and 300+ datasets available to Indian researchers and startups) is the research-side inference platform. Chips and data-flow law aren’t IndiaAI’s beat: chips need a fab and a decade, not a model lab; data-flow law is the DPDP Act’s job. So in five-layer terms, IndiaAI has funded compute, weights, and a research-side slice of inference. Chips and data-flow law remain untouched, and commercial inference is what the next argument is about.
Even before Friday’s directive, that argument was already gaining ground locally. 3one4 Capital made the case in early June for a “National Inference Mission”: global AI revenue jumped from $90B in Q1 2024 to $435B in Q1 2026 (5x in two years, with the apps-and-models slice growing 12x), and without indigenous inference at production scale, India risks paying a growing share of its $418.3B services-export earnings back out to foreign model providers in dollars. Their proposal: a $5B AI Fund with $1B co-investments each from TCS, Infosys, Wipro, and HCL, plus inference-localisation commitments as a condition of market access for global providers. Friday’s directive is the strongest argument the inference-mission framing has gotten yet.
The “this is UPI” framing is wrong on the structure even where it’s right on the intent. UPI is India’s instant-payments rail; NPCI (the National Payments Corporation of India) runs it as a not-for-profit utility. Sarvam is a VC-backed for-profit (~$41M Series A from Lightspeed, Peak XV, and Khosla). Different vehicle.
And the cautionary tales are loud. Project Independence (Nixon’s November 1973 plan to make America energy-independent by 1980) didn’t work. US oil-import dependence actually rose from 36% in 1973 to nearly 50% by 1979. GAIA-X, the EU’s seven-year-old sovereign-cloud project with ~180 announced data spaces, still hasn’t displaced AWS, Azure, or GCP inside European public institutions. Aleph Alpha, Germany’s crowned foundation-model champion, was acquired by Cohere (a Canadian AI company) in April 2026. Three countries, three decades, three failure modes (a government plan, a multi-stakeholder cloud, an crowned champion). All three started with the press release.

The reframe I keep landing on: don’t crown, layer. National infrastructure isn’t one company’s logo. If you do it well, it’s five layers of backup, where you concede the layers you can’t win and hold the layers you can.
What I’m doing Monday
Monday morning I’ll open the agent loop again. The refactor will still be where I left it. I’m going to do three small things differently.
I’ll start lining up a backup model. I don’t have one today, and Friday taught me that “deployed model access” is a revocable input. Anyone building on a single hosted model needs a backup ready, and the right time to plan one is before you need it, not the afternoon after you do. Not because I think Claude is going anywhere (I love Claude, and this post wouldn’t exist without it), but because the directive proved how quickly that input can be revoked.
I’ll keep my eyes off “who is India’s frontier lab?” and on the three layers a builder actually decides: which model my code calls (inference), what weights I’m willing to host (weights), what data leaves the country (data-flow law). Chips and training compute are real fights, just not ones I can fight from a laptop. The other three are.
And I’ll stop arguing on the timeline as if “sovereign AI” is one question. It isn’t. It’s five (how cool is that, in a deeply unfun way!).
Friday’s prompt didn’t finish. Monday’s might. Claude is the same tool it was on Thursday. What changed is how I think about depending on it.