9.7 Frontier

Sovereign AI model selection and disclosure

A provenance label for the AI model behind a government service: who built it, where it was trained, where it runs, whose law governs it. A person can see whether the model handling their case answers to their own country's law.

01

The impact of agents

As governments make explicit choices about which AI model powers a public service, that choice will keep happening with no visibility for the user relying on it. Which model a government deploys in a user-facing service, and who controls that model, is a sovereignty question. A service powered by a US-headquartered model provider is subject to different legal and political risks than one powered by a domestically developed or EU-sovereign model.

02

What must be verified

When a government chooses which AI model powers a service, it must make that sovereignty choice visible at the point of interaction. The disclosure names the model provider, the training jurisdiction, the inference-hosting jurisdiction, and the legal framework that governs the data. A choice held only at the policy level, unseen by the user the model decides about, does not meet that requirement.

03

Protecting access

A single form of disclosure reaches one kind of reader and excludes the rest. A dense page label loses users with low literacy. A glanceable badge gives an AI agent nothing to evaluate. Either way, someone ends up weighing the system handling them on a signal not built for them.

Keeping the path open

  • Offer the disclosure at graduated depth (a static page label, a contextual plain-language tooltip, machine-readable metadata), so users with different needs, and their agents, can each read it.
  • Present sovereignty as an informed choice across the range of provenance, rather than a single domestic-or-foreign verdict.
  • Make the label and tooltip operable by keyboard and read out by a screen reader, with the provenance facts announced as text rather than left to an icon or color.
04

Response surface

Model Provenance

A provenance label names who built the model, where it was trained and hosted, and whose law governs it.

Preview two systems in the same service
AI provenance
Kestrel-2 · benefits assessments
ProviderNational AI facility (public)
Trained inAustralia, on curated government corpora
Hosted inAustralia · government-assured data centers
Governing lawAustralian law only
Fully domestic: one legal system answers for every layer.

A contested decision eventually asks four things: which system decided, who built it, where it ran, and under whose law. The label answers them at the moment of use, not later in discovery.

05

Maturity

  1. Emerging

    For sovereign AI model selection as government policy, anchored to the French Ministry of Armed Forces' own communiqué notifying its Mistral AI framework agreement, not only trade-press coverage.

  2. Frontier Headline

    For user-facing AI model provenance labeling, and machine-readable model-provenance metadata for agent-to-agent queries.

06

Precedents

France's defence framework agreement with Mistral. The Ministry of Armed Forces notified a framework agreement to Mistral AI, managed by the Agency for Defense Artificial Intelligence and giving the armed forces, ministry directorates, and supervised bodies including the CEA, ONERA, and SHOM access to Mistral's models in secure environments. The ministry's notice states no fixed duration. Model selection is an explicit sovereignty decision at the level of a defence procurement.

The France-Germany sovereign AI partnership. France and Germany announced a partnership with Mistral AI and SAP to build a sovereign AI capability for public administration, with selected use cases to be deployed in administrations over several years. Two governments are jointly procuring a model layer for administration rather than each contracting separately.

Wider sovereign-AI investment. Other governments back sovereign AI capacity by different routes, the UK through equity stakes in domestic AI companies and the EU through public investment in compute infrastructure. A service's choice of model is becoming a deliberate sovereignty decision rather than a default.

The AI Agent Index on disclosure. Across the 30 agents indexed, half of developers publish a safety framework, 23 of 30 report no third-party testing, and 25 of 30 disclose no internal safety results; of the 13 agents at frontier levels of autonomy, 4 disclose any agentic safety evaluation. Basic transparency about the system is uneven, before sovereignty-relevant detail like model provenance and hosting jurisdiction is reached.

07

What carries over to agent use

The France/Mistral model demonstrates sovereign AI selection at policy level. The part still to be built is user-facing disclosure at the point of interaction.

The pattern is an "AI model provenance label" that discloses: (a) the model provider, (b) the model's training jurisdiction, (c) the inference-hosting jurisdiction, and (d) the legal framework governing data processed through it. None of the cited precedents test what depth of disclosure reaches a user or an agent; that design is still to be built.

The 2025 AI Agent Index disclosure gap suggests that market forces alone will not produce this transparency. Regulatory mandate, building on Article 50 of the EU AI Act, is likely necessary.

08

Where things go wrong

The failure mode is an opaque automated decision with no record of which model decided a case, or under whose law it ran. Labeling that provenance makes the deciding system contestable. The most direct risk to this exact label is a service that calls itself sovereign without the stack to back it: a model trained on a foreign hyperscaler's infrastructure, fine-tuned on a foreign platform, or served through an undisclosed sub-processor can still show a domestic-provider label on the front end. A label naming only the provider on the box, not the dependencies underneath, tells the user the opposite of what governs their data.

09

Sources

6 references France · Germany · UK · EU · International