World Model Readiness
Engraved technology instrument

For your company

Technology & Risk

Module · Whose cloud is your strategy on?

The Data Sovereignty & Cloud Check

Every AI stack rents its foundations from someone else; the question is how much you would lose if that landlord changed the terms. Where your data and models actually run, whose courts govern the contract, and what it would cost to leave are usually left unexamined until a price hike or a policy shift forces the issue. This module checks the five pieces of that dependence honestly, before it is decided for you.

Question 1 of 5 · You know where it runs

Do you know exactly where your data and models physically run?

A region setting in a console is not the whole answer: subprocessors, caching layers, inference locations and vendor support access all move data across borders. If you cannot name the countries and companies involved, you cannot reason about sovereignty at all.

Question 2 of 5 · You could leave

If your main AI vendor doubled prices or vanished tomorrow, could you leave?

Exit is a capability you build in advance, not a decision you make in a crisis. Exported data in a portable format, a tested alternative, no fine-tuning locked in a proprietary shape. Most teams discover the true lock-in only the day they try to move.

Question 3 of 5 · Jurisdiction understood

Do you know which country's laws and courts govern your AI contracts and data?

The governing-law clause decides who can compel access to your data and where you go when things break. A US-jurisdiction contract can expose EU data to foreign legal reach regardless of where the servers sit. Read the clause before you need it, not after.

Question 4 of 5 · Alternatives evaluated

Have you honestly assessed whether a sovereign or EU-based alternative could do the job?

The reflex is that only the hyperscalers can serve your needs. Sometimes true, often simply untested. European and self-hostable options have narrowed the gap for many workloads; not evaluating them is a choice you are making, not a fact you have checked.

Question 5 of 5 · Switching cost honest

Do you have an honest number for what leaving your current stack would cost?

Switching cost is the real measure of dependence, and it is usually understated on purpose. Retraining, re-integration, data migration, staff relearning, all add up. An unquantified switching cost is a lock-in you have chosen not to look at.

For the statistics · one click each

Three questions for the public picture

These do not affect your score. They feed the anonymised, aggregated statistics; groups under 8 respondents are never shown.

Where does the AI infrastructure you depend on primarily run?

US hyperscaler
EU region of a US provider
European provider
Self-hosted
We do not know

How prepared are you to switch away from your main AI vendor?

Fully locked in
Very hard
Possible with effort
Exit-ready
No single vendor

Under which jurisdiction does your primary AI contract sit?

United States
EU or EEA
Elsewhere
Mixed across vendors
We do not know

Your context

Used to calibrate the report. Company size and sector remain in the anonymized dataset; your email does not.

What the five levels look like

Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.

You know where it runs

  1. 1No idea
  2. 2Assume the vendor
  3. 3Region setting only
  4. 4Documented for main
  5. 5Full data-flow map

At the low end: You cannot govern a dependency you cannot locate. Ask each AI vendor for their subprocessor list and inference regions, and write down where your data actually travels. What good looks like: A full data-flow map is the foundation every other sovereignty decision rests on. Keep it current: vendors add subprocessors and regions without asking you.

You could leave

  1. 1Total lock-in
  2. 2Never considered
  3. 3Vaguely possible
  4. 4Plan on paper
  5. 5Tested exit path

At the low end: No exit means the vendor sets your price and your terms indefinitely. Start by exporting your data and prompts in a portable format, so leaving is at least mechanically possible. What good looks like: A tested exit path is the strongest negotiating position you can hold. Keep it warm; an exit route you have not exercised in a year is a plan, not a capability.

Jurisdiction understood

  1. 1Never read it
  2. 2Unsure
  3. 3Roughly aware
  4. 4Documented
  5. 5Documented and deliberate

At the low end: An unread governing-law clause is a risk you have signed without pricing. Pull the contracts for your main AI vendors and note the jurisdiction and data-access terms for each. What good looks like: Deliberately chosen jurisdiction means sovereignty is a decision you made, not one made for you. Revisit it whenever a vendor restructures or a new contract lands.

Alternatives evaluated

  1. 1Never looked
  2. 2Assumed impossible
  3. 3Glanced once
  4. 4Seriously evaluated
  5. 5Evaluated, viable path

At the low end: Never looking is how a default hardens into a dependency. Spend a day scoping whether one real workload could run on a European or self-hosted option; the map has changed. What good looks like: A viable alternative in hand converts dependence into a choice, even if you stay put. Keep the assessment fresh; the sovereign options improve quarter over quarter.

Switching cost honest

  1. 1Never quantified
  2. 2Assume it is huge
  3. 3Rough guess
  4. 4Estimated
  5. 5Estimated and reducing

At the low end: A switching cost you have never estimated is one the vendor gets to define for you. Put a rough figure on migration, re-integration and retraining; even a bad number beats none. What good looks like: A known switching cost you are actively reducing is what keeps a vendor honest. Track it over time; every proprietary feature you adopt quietly pushes it back up.