Clancy and Naugle’s new model of AI sovereignty as an instrument of national power is one of the clearest pictures we have of the strategic-competition view of this field. It is worth taking seriously — which is why it is worth disagreeing with carefully. The model treats national power in agentic AI as a contest over five growth levers a country accumulates — accelerators, datasets, skilled workforce, electricity, and water — each with its own ceiling and each open to attack. As a description of how great powers are actually behaving, it is largely right. As a definition of what sovereignty is, it is incomplete in a way that matters enormously for everyone who is not a great power. This deck walks the argument: what the model gets right, where its definition stops, the test it fails, the trap it describes, and the layer the Village platform and Tractatus framework already run at.
The realist core is sound and the loop-by-loop construction is genuinely useful. The insight that adversary action shows up as degradation of availability across multiple levers — workforce, datasets, accelerators, and the physical substrate — unifies export controls, talent restrictions, and supply-chain attacks as one phenomenon rather than several. Pushing past the now-familiar water-and-electricity discussion to name all five levers, each with country-specific domestic limits and partner-nation backfill dynamics, is the right level of detail. The supplementary reference on how agentic compute is measured and what drives data-centre demand is a real contribution on its own. This critique is about the model’s definition of sovereignty, not its engineering.
The incompleteness is in the definition, not a missing variable. Because the definition is about control-as-capacity, not authority-as-right, there is no term for legitimacy, for the authority of the governed, or for whether the governed consent to how a model behaves on their behalf. The model defines sovereignty as capacity to independently control and out-compete. There is an older and arguably more durable definition: sovereignty as rightful authority over a domain — the recognised standing to make binding decisions within it. A nation with vast compute that exercises no legitimate authority over how that compute is used is powerful, but it is not obviously sovereign in the second sense.
The disagreement is old, and it predates AI by centuries. Political and legal theory has long separated two things the word "sovereignty" runs together: sovereignty as effective control — the de facto capacity to act without being overridden — and sovereignty as rightful authority — the de jure standing to make decisions that others are bound to recognise. A state can hold one without the other. A junta has effective control without rightful authority; a government-in-exile has rightful authority without effective control. The two usually travel together, which is why the distinction is easy to forget — but they are not the same property, and AI is prising them apart. Clancy and Naugle measure the first: their five levers are quantities of capacity. They are silent on the second — whether a system’s behaviour is authorised by the people it acts upon. The modern default — territorial, capacity-backed, non-interference sovereignty — is the Westphalian settlement, a poor fit for data and a poorer one for peoples whose authority was never territorial to begin with. Māori data sovereignty is not a bid to out-compute anyone; it is rangatiratanga — authority and control grounded in relationship and whakapapa, a de jure claim that holds whether or not it is matched by capacity. The governance form that fits is not a single sovereign but a polycentric one — many co-equal authorities with distinct jurisdictions over a shared resource, in Ostrom’s sense. Once the two concepts come apart, the move the rest of the argument makes is available: a community can hold rightful authority over its own data, and over how a model governs on its behalf, without holding the capacity to build the model. Authority is the layer that does not require winning the race.
A useful test: ask the model where the European Union’s domestic AI-sovereignty measures belong on its map, or where Māori data sovereignty belongs — rangatiratanga, authority and control over data, in Te Mana Raraunga’s sense — or where any indigenous governance claim belongs. There is no lever for any of them. They are neither adversary degradation nor capacity accumulation, so the model cannot represent them at all. The EU’s June 2026 technological-sovereignty package is a live assertion of AI sovereignty that a capacity model has no way to score. These are precisely the instruments by which smaller actors are asserting AI sovereignty right now: not by out-building Nvidia clusters, but by establishing rightful authority over data, provenance, and steering.
The model shows this better than its authors may intend. On its own axes the contest is unwinnable for anyone without national-scale capital. The authors say plainly that each lever’s limits are set by a country’s own capabilities and its ability to call on partner nations to backfill — and that is precisely the structural trap. A definition of sovereignty that permanently locks out most nations and communities is not a neutral measurement. As Yew and colleagues argue on the commodification of AI sovereignty: once “sovereign” AI factories, clouds, and models are things you can buy, the firms that sell them get to say what counts. When sovereignty is counted in accelerators and zettaFLOPS, the companies that sell accelerators and zettaFLOPS get to decide who is sovereign.
This is the pivot of the whole piece. Sovereignty-as-rightful-authority is separable from sovereignty-as-capacity, and the former can be held by actors who will never hold the latter. A community with modest compute that holds genuine, recognised authority over its own data and over how models steer on its behalf may be sovereign in a way no lever count captures. The Village platform and the Tractatus governance framework start from this second definition of sovereignty — the one the model has no lever for.
The claim is concrete and running in production. Every record carries per-record provenance and a tamper-evident, signed proof chain — a cryptographic origin hash and an append-only record of who did what to it, on every record the system holds. A community body — an iwi, a marae, a club, a whānau — holds and exercises real, co-equal authority over how the model behaves on its data. It is served by a model fine-tuned to its kaupapa. It writes and edits its own governance rules, layered over a platform safety floor it can raise but cannot be forced below. Through its own designated cultural authority it marks content as tapu or restricted, and the model must then refuse it or escalate to that authority rather than answer on its own. The authorities themselves — platform, iwi, community trust — are recognised as co-equal peers, each publishing the rules and steering that shape the model’s behaviour within its own jurisdiction, each able to withdraw them at any moment, at which point the platform must stop using them. This is deployed, composed at inference, and auditable end to end.
The incompleteness cuts both ways. The substrate beneath the Village — the frontier model weights, the accelerators, the compute itself — sits inside exactly the foreign-controlled levers Clancy and Naugle map: the models we run are open weights authored outside our jurisdiction, served locally on EU- and NZ-hosted GPUs. I do not pretend that dependency away. What I claim is that governance sovereignty and substrate sovereignty are separable, and that the former is built and running today for actors who will never hold the latter. The model itself shows why substrate sovereignty is out of reach for small actors: it sits downstream of national-scale resource loops they do not control. This fits Singh and Sengupta’s proposal to treat sovereignty as a continuum rather than a binary — autonomy at one layer, acknowledged dependence at another. That honest separation is the whole architecture.
The third option follows directly. The strategic-competition frame offers small nations a binary: align with American big-tech AI or Chinese big-tech AI, and accept the dependency either way. But if sovereignty is rightful authority rather than raw capacity, a third path opens that is independent of both — not by matching their levers, which is hopeless, but by refusing their definition of the contest. The actors the model’s loops exclude are not powerless. They are being measured on the wrong axis.
This is less a rebuttal than a request to widen the model. Add the nodes the realist frame leaves out: legitimacy, data-subject authority, the standing of the governed to steer. Once those are in, a second set of loops appears — ones where a community can gain sovereignty without gaining a single accelerator, and where an adversary’s compute advantage does not automatically erode another actor’s rightful authority over its own domain. Those loops are where much of the world will have to live, because the capacity loops were never open to it in the first place. The strategic-competition view is a true account of how the powerful are behaving. It is not a complete account of what sovereignty is. And in the gap between those two things — the scenarios the model cannot represent — is exactly where the rest of us are building.
The Village platform and the Tractatus framework are an attempt to make AI sovereignty achievable for actors who will never win the capacity race, by relocating sovereignty to the layer where rightful authority can actually be held. This work is licensed under CC BY 4.0 — you are free to share and adapt it, with attribution. Use Share to send the full paper, or Feedback to respond directly; feedback is routed through the Tractatus governed-feedback system.