For government, defence-adjacent and regulated buyers, the first question about AI infrastructure is never price. It is jurisdiction: where the data sits, which rules govern it, and who is permitted to touch it. We sequence those answers before hardware is discussed, because a procurement that discovers them late gets run twice.
The word sovereign gets used loosely enough to be useless. In a procurement it has to resolve into things you can verify: the named facility the workload runs in, the operator running it, the ownership chain above that operator, the jurisdiction that governs it, and the personnel permitted physical and logical access. Every one of those is checkable, and we only put forward options where all of them check out.
This is why we never propose a region. A region is a marketing unit. A sovereign workload lives in a building with an address, a power feed and a staff roster, and your compliance function is entitled to see all three before you commit to anything.
The same discipline extends to the supply chain behind the hardware. Export screening, end-user verification and the disclosure of every commercial relationship in the chain happen at the front of the process. In this segment the compliance file is not paperwork attached to the deal. It is the deal.

Almost no workload is uniformly sovereign. There is a regulated layer that genuinely cannot leave the jurisdiction, and an exportable layer that faces no such constraint. Treating the whole estate as sovereign is the most common and most expensive mistake in public-sector AI procurement, because it prices every GPU-hour at the scarcest local rate.
The design we run instead: the regulated data layer in a named in-country facility that satisfies the framework, the heavy training or exportable inference placed where capacity and power are genuinely available, and private connectivity between the two. Regulators get the residency they require. The budget gets world-market economics on everything the rules do not bind.
Getting that split right requires an honest data map before any hardware conversation, which is precisely the work most vendors skip because it does not sell servers.
Current verified lines with quantities, lead times and indicative pricing are public on the live inventory. The buying structures sit on the procurement desk and the leasing desk, and the decision frameworks are in buy versus lease and cloud versus bare metal.
By naming it and evidencing it: facility, operator, ownership chain, jurisdiction and access controls, in writing, before commercial terms. If a provider markets sovereign capacity but cannot produce that chain on request, the word on the brochure is doing work the paperwork will not.
No, and it rarely rules out foreign operators either. It governs where data resides and who may access it. Hardware provenance matters for export compliance rather than residency, and we run both files in parallel.
Directly. Advanced accelerators are controlled goods, so the end user, destination and re-export position are screened before anything is committed. In government-linked deals that screening is also what makes suppliers comfortable releasing allocation at all.
That is a facility and operator question, which is exactly why we name both up front. Where the requirement is cleared-staff-only or operator-of-choice, we filter the shortlist against it before anything is proposed rather than discovering the conflict at the final stage.
Yes. Deals are structured to pass review: disclosed relationships, auditable pricing on direct supplier terms, and documentation built for an auditor rather than for a sales meeting. Where a panel or framework arrangement applies, we work within it.
Twenty minutes with the desk, no pitch and no quote at the end of it. Tell us roughly what you need and we will come back within one business day.
Your enquiry has landed with the desk. Acknowledged within one hour.