Sovereign AI Race: Comparative Capstone (2026)

In this Report
This publication is part of the Sovereign AI Race series.
The Co-Intelligence-First (CI-First) approach is a genuine and unique University 365 concept: a proposal for imagining a better future where AI and Human Intelligence coexist productively, each amplifying the other rather than replacing it.

Sovereign AI Race: Comparative Capstone (2026)
The Context
The frame this report inherits, and does not change
The Sovereign AI Race series fixed its analytical frame before its first report was written. The frame has four parts: the five layers of sovereign AI capacity, the controlled metric set, the three races, and the terminology standard. Every country report applied all four identically, and each report recorded its own layer-by-layer verdicts at the moment of its publication. This capstone does not redefine the frame. It inherits it, uses it as given, and compares the twenty subjects through it. A reader who wants the frame in its canonical form will find it in any of the twenty country reports and in the series documentation; what follows restates the parts only as far as the comparison needs them.
The five layers separate "sovereign AI capacity" into questions that can be answered with evidence. Compute sovereignty is the physical layer: where the chips and data centres sit, and who may switch them off. Model sovereignty is who builds the models a country depends on, and in whose languages and domains those models are competent. Capital sovereignty is who funds the build-out and on what terms. Regulatory sovereignty is who writes the rules that govern AI use inside the jurisdiction, and whether they can be enforced. Talent and education sovereignty is who builds and runs the systems, and how the next generation is prepared. A state can hold any one of the layers without holding the others, and conflating them is the error the series was built to avoid. The capstone's first table sets out all twenty countries' verdicts on all five layers, exactly as the series recorded them.
The controlled metric set is the fixed list of quantities every country report carries with units and dates: flagship compute commitments, capital committed, flagship national models, anchor entities, chip dependency, the regulatory instrument and its status, talent anchors, independent index standing, a published adoption measure, and the country's distinguishing mechanism with its core tension. The capstone does not alter the metric set and does not introduce new metrics. It aggregates what the twenty reports established: the commitments are counted in the units the reports used, the models are named with their openness and their base, and the index figures are the verified set described in Data and Evidence.
The three races are the frame's temporal dimension, and they are the capstone's main instrument. The compute race is the contest over the physical layer: accelerator design and fabrication, memory supply, data centre capacity, energy, and the licensing regimes that decide who may import what. The model race is the contest over who builds the systems countries actually deploy, and in which languages they are competent. The rules race is the contest over who writes the enforceable rules, and who gets their rules adopted beyond their own jurisdiction. The three races run on different tempos, they are won by different kinds of state, and the series found that almost no country competes in all three at once. A country can lead the rules race from a small domestic market, as Singapore and Italy show in different ways. A country can lose the accelerator design race and still hold a supply chokepoint inside the compute race, as South Korea shows with memory. A country can be physically removed from the compute race by an act of war, as Bahrain was in 2026.
The terminology standard holds throughout. "Sovereign AI capacity" is the general concept; "frontier model" means a model at the current capability frontier and not any large model; "open weights" and "open source" are distinguished; "announced capacity" and "operational capacity" are never conflated; and the three races are named whenever the series' shorthand for competition, the "AI race", is used. The capstone keeps every one of these rules.
The five postures, and why grouping is the capstone's contribution

The five postures the series found across twenty countries. University 365 Research Center.

The twenty countries of this series span every inhabited continent. Image: NASA Blue Marble composite, public domain.
The twenty country reports produced twenty specific verdicts. The capstone's contribution is to show that the twenty fall into five postures, and that the posture a country chose explains more about its outcome than the size of its budget does. The postures were set out in the series plan and confirmed report by report; they are presented here with the evidence that placed each country in its group.
Owner of the full stack: China, the United States, South Korea. These are the three states that hold, in different proportions, all the layers that determine whether AI can be produced inside their jurisdiction. China and the United States own the frontier of the compute race, the model race and, in their different ways, the rules race. South Korea holds the full-stack label through a specific and unusual asset: it owns the memory supply that every accelerator needs, a chokepoint whose importance the series assessed as greater than the design of any single competing chip.
Owner of key layers: the United Arab Emirates, Saudi Arabia, France, India, Japan. These five states hold one or more layers outright, buy or rent the rest, and have each built a genuine specialism. Their strategies differ in which layer they chose to own: capital for the Gulf states, an open-weight national champion for France, a demand-side public platform with an open-weight private champion for India, and industrial depth in equipment, materials and robotics for Japan.
Regulator and host: Singapore, the United Kingdom, Germany, Spain, Italy, Portugal, Bahrain. These seven states govern AI with real instruments and host compute they do not own. Several of them write rules with more reach than their domestic market, and the series assessed their regulatory layer as genuinely held or actively enforced while the physical layer stays foreign-owned. This is the posture where the difference between holding a rule and holding a machine is clearest.
Sanctioned isolationist: Russia. One state in the series builds a genuinely integrated sovereign stack under sustained sanctions, at an efficiency cost that the reports quantified, with a fabrication ceiling that binds and a private cost of capital that throttles the build.
Ambition without compute: Morocco, Brazil, South Africa, Qatar. These four states have published strategies, trained people and, in some cases, built real model or hosting capacity, without securing the compute layer underneath it. Their reports treat the ambition as real and the compute gap as the binding constraint.
The vocabulary this report needs

Image: NASA Blue Marble composite, public domain.
Four terms recur, and they are defined here once.
The demonstration case. Bahrain's loss of its AWS region in 2026: damage in March and April 2026 spanning multiple availability zones, and AWS's statement on 15 September 2026 that it could not restore access to the region or to data hosted exclusively there. The series treats it as the controlled experiment it never expected to have, a direct test of what a host state owns when the hosted capacity is gone.
Posture. The strategic position a state occupies, defined by which layers it holds outright and which it buys, rents or hosts. Posture is the capstone's unit of comparison; a posture is not a rank.
Finished. Used in this report in the specific sense of the series' final assessment of a country's position in one race as of September 2026, not as a claim of permanence. Positions move, and The Road Ahead states what would move them.
The series record. The verdicts, figures and sources as published in the twenty country reports, used by the capstone without revision. Where the capstone adds a cross-series figure, it is labelled as such and sourced in Data and Evidence.

Sovereign AI Race: Comparative Capstone (2026)
The Question
After twenty countries, what does the evidence say sovereign AI capacity actually is?

The layer that decides whether the other four can run. Photograph: Pexels License, via Pexels.
Each country report asked what its subject said it was doing, what it had built, where the money came from, what was genuinely domestic, what the rules were, what the talent position was, and where the country sat between capability and the appearance of it. The capstone asks the question those twenty answers make possible: taken together, what did the twenty states actually control?
The answer the evidence supports has three parts, and they are uncomfortable for almost everyone.
First, the layer that decides whether the other four can run is the layer almost nobody holds. The compute race has two owners at the frontier, China and the United States, and one supplier of a critical component, South Korea. Every other state in the series runs its sovereign capacity on imported accelerators, under licensing regimes written elsewhere, on terms that can change without its consent. The concentration is measured, and the series' reports cite the measurements: the United States hosts 5,427 data centres, more than ten times any other country, and China reports national intelligent computing capacity of 2,185 EFLOPS, more than any country except the United States. Counterpoint Research, whose sovereign AI model index assessed more than 80 countries, found that NVIDIA trains 92 per cent of sovereign models globally. Those are the three sources' own figures, labelled as such wherever the series used them, and they describe a concentration that every country report confirmed in its own way.
Second, the layers that survive are the ones that live in institutions, documents and people rather than in hardware. Regulation, data governance, language, curriculum and a trained workforce are not destroyed by a strike, an export control or a cancelled contract. The series' demonstration case makes the point sharper than any argument could: when Bahrain's cloud region was destroyed in 2026, the data protection regime, the AI policy, the procurement rules that function as operative regulation, the upskilling programme and the applied research base all survived intact. The compute did not. Every one of those surviving layers had been described in some earlier commentary as soft, slow or secondary to infrastructure. Bahrain's ledger reverses that order.
Third, the race that is actually being run is often not the race being described. The series found states competing in one race while their announcements described another: Gulf states running the capital race while their announcements described a compute race; European states running the rules race while their announcements described innovation races; states everywhere announcing compute at the frontier while operating an order of magnitude below it. The gap between the announced race and the run race is the series' central empirical finding, and the capstone's tables state it subject by subject.

Sovereign AI Race: Comparative Capstone (2026)
The Contradiction
The states that spent the most on sovereignty hold the least of it
The strongest contradiction the series produced is not that some states failed. It is that the pattern of failure is inverse to the pattern of spending. The states that committed the most capital to sovereign AI capacity, measured as a share of their own economies, are the states that hold the fewest of the five layers outright. The states that hold the most did not build their positions through sovereign AI programmes at all.
The United States and China own the frontier compute layer for reasons that run deeper than AI strategy. The American position rests on private industrial history: chip design leadership, fabrication located in Taiwan and South Korea, cloud capacity at a scale no other country approaches, and capital markets that absorbed between roughly 75 and 85 per cent of global AI venture funding in 2025 on the three independent measures the series verified, at 285.9 billion dollars of private AI investment in the single year. The Chinese position is state-directed and predates the sovereign AI wave: two decades of directed capital, guidance funds numbering over 2,100 with a target size of roughly 1.86 trillion dollars, and a state-backed venture machine that invested 184 billion dollars into more than 9,600 AI firms between 2000 and 2023, all recorded in the series' China report. Neither position is a sovereign AI programme in the sense the other eighteen countries use the term. The two full-stack owners arrived at the race and then wrote the rules of the race for everyone else: the licensing regime that decides which accelerators a country may import, and, newly, the sequencing of which frontier models its partners receive first.
South Korea, the third full-stack owner, sharpens the point. Its full-stack label rests on memory: it supplies the component every accelerator needs, and it is the only mid-sized economy in the series that owns a chokepoint in the compute race itself. Its report also records the condition attached to that label: the demand side of its own stack is one to two orders of magnitude below its supply side, its champion model is not yet chosen because the government's selection is an elimination contest, and its flagship stack is partly re-based on an American open foundation.
Against those three, the contradiction has a second half. The states that bought into the compute race at the largest scale, the Gulf states, did so as tenants and financiers. The United Arab Emirates assembled the most capitalised AI programme outside the United States and still holds compute conditionally: the Federal Register condition disclosed in the series' UAE report grants licence-free treatment to named entities and expires on 6 April 2027 unless two of them become United States companies. Saudi Arabia signed for hundreds of thousands of accelerators and a multi-gigawatt pipeline, and its compute layer is bought, at scale, on licence. Qatar and Bahrain built real hosting capacity and held the accelerator switch abroad. This is the contradiction in one sentence: the biggest spenders on the physical layer are its least protected holders, and the state that protected least of all, Bahrain, is the state whose surviving layers the series values most.
The contradiction has a third face, about time. The three races run on different clocks. The compute race is decided in years of construction, fabrication and licensing cycles. The model race moves in months and can be entered from a standing start, as Morocco and India show, because open weights let a state build a language layer on a foundation it did not create. The rules race is decided in legislative sessions, and its verdicts last decades, which is why states with almost no compute have written rules that the compute owners must now answer to. The series' evidence says the slowest race is not the least important one; it is the one the least-equipped states can actually win, and the one that survives the loss of everything physical underneath it. The contradiction is that so few states have noticed.

Sovereign AI Race: Comparative Capstone (2026)
The Current State
The compute race: two owners, one supplier, and nineteen tenants

The three races, and how the twenty subjects finished in each. University 365 Research Center.
The compute race is the contest over the physical layer: accelerators, fabrication, memory, data centres and energy, and the licensing regimes that govern who may import what. The series' finding is stark. Two states own the frontier of this race; one state owns an indispensable component of it; and the remaining seventeen subjects of the series, including several of the world's largest economies, run their sovereign capacity as tenants on terms written elsewhere.
The two owners are the United States and China, and the series' twenty reports show that their positions are mirror images. The American position is private and concentrated: frontier chip design, fabrication located abroad in Taiwan and South Korea, cloud capacity at a scale no other country approaches, and capital markets that absorbed between roughly 75 and 85 per cent of global AI venture funding in 2025 on the three independent measures the series verified, alongside 285.9 billion dollars of private AI investment in the single year. Its weakness is that the physical foundation runs through chokepoints it does not control, as the United States report states: fabrication for the leading accelerators sits in Taiwan and South Korea, and the American response to Chinese model progress changed direction mid-course, moving H200-class exports to China to case-by-case review effective 15 January 2026 after the earlier diffusion rule was rescinded.
The Chinese position is state-directed and constrained. The state plans and pays for a national compute fabric: national intelligent computing capacity reported at 2,185 EFLOPS by mid-2026, up 177 per cent year on year, with a fully domestic hundred-thousand-accelerator supercluster switched on at the Zhengzhou node of the national compute grid in July 2026, and Huawei's Ascend line the designated domestic accelerator family. The binding constraints are fabrication and memory: reported yields near 40 per cent against upward of 90 per cent for comparable Western parts, leading-edge wafer capacity an order of magnitude below global scale, and high-bandwidth memory sufficient for roughly a quarter of a million to three hundred thousand accelerator packages a year. The series' China report states the domestic accelerator industry became a real business inside the constraint, and that the export controls did not stop the model layer.
South Korea is the third full-stack owner by a different route. It does not design the leading accelerators and it does not host the largest AI data centres; it makes the high-bandwidth memory those accelerators cannot work without. The series assessed that position as in some ways stronger than designing a competing chip, because a country can lose an accelerator design race and still hold the supply of something every accelerator needs. Its weakness is symmetrical: the demand side of Korea's own compute is one to two orders of magnitude below its supply side, so its chokepoint is a seller's position, not a user's one.
Japan sits immediately outside the owner group with the deepest industrial substrate in the series. It hosts TSMC's second Kumamoto fab upgrading to 3 nanometres, it is rebuilding leading-edge logic through Rapidus on a 2027 schedule, it owns the equipment and materials layers every fab depends on, and its binding constraint is not money but grid access, quantified in its report. The series' Japan report states the position precisely: a state that owns the industrial substrate and rents the frontier.
Then there is everyone else, and this is where the series' central compute finding lives. The Gulf states bought into the race at the largest scale as tenants and financiers: the United Arab Emirates assembled a five-gigawatt campus programme with a one-gigawatt Stargate cluster inside it, and its compute layer still carries a written condition, the Federal Register's expiry of licence-free authorization for two named operators on 6 April 2027 unless they become United States companies. Saudi Arabia signed for hundreds of thousands of accelerators and a multi-gigawatt pipeline through its state champion, with its own data centre capacity growing from 68 megawatts in 2021 to 467 megawatts in the first quarter of 2026, and its compute layer is described in the series as bought, at scale, on licence. Qatar and Bahrain built real hosting capacity and held the accelerator switch abroad. European states present a third pattern: Germany operates Europe's first exascale public system and has no leading-edge private fabrication; the United Kingdom's public compute layer is real and small, and its flagship growth zone lost its anchor tenant; France rents its compute completely while holding the best energy position in the series; Spain's compute build-out is concentrated in Aragon and is not owned in Spain; Italy's public scientific base is genuine and its commercial build is foreign-owned, limited by the grid. India's sovereign stack is entirely imported silicon accessed through domestic operators, on a subsidy mechanism rather than a state fleet. Brazil built the series' most explicit hedge, one machine from each superpower, on a scientific base described as real and small. South Africa hosts roughly three quarters of Africa's data centre capacity and holds none of the switches that run it.
And Bahrain. The series' twentieth report is the only case in the twenty of a state physically removed from the compute race. The kingdom won the first AWS cloud region in the Gulf in 2019 and lost it in 2026: Iranian drone strikes in March damaged three AWS data centres including one in Bahrain, a second availability zone was disrupted in April, and on 15 September 2026 AWS stated that it could not restore access to the region or to data hosted exclusively there, with a further update promised for early 2027. The series' demonstration case is stated there and carried here: compute is the layer a host state does not own, and the first case of its loss was also the first proof of the observation.
The model race: open weights as the equaliser, and the base layer as the catch

The physical layer the series assessed for every subject: capacity that is owned by three states, supplied in its critical component by one, and rented by the rest. Photograph: Pexels License, via Pexels.
The model race is the contest over who builds the systems countries actually deploy, in whose languages, and with whose permission. The series' finding here is more hopeful and more nuanced than in compute. The model race has become genuinely contestable in a way the compute race has not, because open weights let a state build a language layer on a foundation it did not create; and the same fact means much of what presents as sovereign model capability is an adaptation of somebody else's base.
The measured scale of that adaptation is the series' most useful single statistic, and it comes from the analyst house whose index the series cites throughout. Counterpoint Research, whose Sovereign AI LLM Index assessed more than 80 countries and more than 170 models, found that 56 per cent of sovereign AI models were adapted models rather than from-scratch foundation models, and that Meta's Llama was the dominant foreign base at 38 per cent of adapted sovereign models, followed by Alibaba's Qwen and France's Mistral. The same analysis found that NVIDIA supplied 92 per cent of the chips used to train the sovereign models in the index. Those are analyst estimates, labelled as such in every report that used them, and they map exactly onto what the twenty country reports found case by case.
The from-scratch cases are the minority and they carry the strongest model sovereignty claims. China's open-weight frontier layer is the largest in the series: DeepSeek's V4 generation under an MIT licence with downloadable weights, an Alibaba Qwen family that took more than half of global open-source model downloads by March 2026, and Kimi, MiniMax and GLM operating comparable families, with the distribution itself now state policy. The United States holds the proprietary frontier and has demonstrated that access to its frontier models can be sequenced as a national security asset rather than a shared allied resource; it conceded the open base layer by default, which is why American foundations sit under so many of the world's adapted sovereign models. South Korea's open-weight output at the 250 to 750 billion parameter scale is the strongest outside China and the United States, with one model holding a real independent index position, and the series' Korea report notes its flagship stack is partly re-based on an American open foundation. Italy holds the series' strongest from-scratch national model case, trained on Italian public hardware. France's Mistral ships open weights on licence terms reported as Apache 2.0, trained on NVIDIA processors it cannot make, license or replace, and exports its base outward; Japan's domestic layer is real, Japanese-first and mixed on weights, with the government's own switch to domestic models scheduled for fiscal 2027.
The adapted cases are the majority, and the series treats them as real capability with an honest boundary. Saudi Arabia's flagship is built on a Chinese open base, post-trained with Saudi alignment; the United Arab Emirates' K2 Think likewise runs on a Chinese open base while Falcon ranks first on the sovereign model index; Qatar's Fanar 2.0 is a continual pre-training of Google's Gemma on about 120 billion curated Arabic tokens, published open with a technical report that names sovereignty as a design principle; Singapore's SEA-LION covers Southeast Asian languages on foreign bases, since October 2025 on Chinese ones; India's Sarvam models are trained from scratch in India but at 30 and 105 billion parameters, mid-weight rather than frontier; Morocco's Darija-first work is research-grade; Portugal's Amália is the smallest defensible version of model sovereignty, executed and released openly; Brazil's Portuguese-language depth sits on foreign foundations; South Africa is capable at the language tier and absent at the frontier; Bahrain does not build models at all, and its report treats the procurement layer as a coherent choice rather than a gap. Russia is the special case: one genuinely integrated sovereign line, a second substantial line, and a third built on a foreign base, with no independent evaluation regime for its model claims.
The model race's verdict for the series is therefore twofold. The race is genuinely entered by states at every income level, because the entry ticket is language and curation rather than capital, and the series' evidence says the states that entered it built something real: language coverage, domain competence, and a national capability that did not exist before. But the frontier of the race is owned by two countries, and the base layer underneath most sovereign models belongs to a handful of foreign laboratories. A state that adapts a foreign base has moved its dependency from the compute layer to the base model layer; it has not removed it. The states that understand this are the ones whose reports say so in their own documents, and the series was written so that each one's boundary is visible.
The rules race: the race the least-equipped states can win
The rules race is the contest over who writes the enforceable rules that govern AI use, and whose rules get adopted beyond their own jurisdiction. The series' finding is that this is the one race a state can win without owning compute or models, that several small states have noticed, and that the rules race is where the series' five postures divide most cleanly.
The European Union's member states run the race inside a bloc framework that no national report needed to duplicate: the European enforcement phase of the AI Act runs from 2 August 2026 with the Article 50 transparency duties, and the Digital Omnibus on AI deferred the most demanding high-risk obligations to December 2027 and August 2028. Within that frame, the series' European reports found a striking inversion between legal ambition and physical capacity. Italy is the first EU member state with a comprehensive national AI law, in force and implemented to the level of the Official Gazette, attached to the series' most constrained physical layer. Spain built the Union's first AI supervisory agency, its first AI sandbox and one of its first AI factories, and its national AI law is still a bill; its most consequential AI enforcement has come from its data protection authority. Germany is the strongest national enforcement layer in Europe, the first large member state to translate the AI Act into machinery, with courts producing the continent's reference rulings, attached to a compute layer with no leading-edge private fabrication. France supplies the bloc's champion and moved later on its own enforcement, with its penalty provisions still pending, and the state's own audit office as a strength the series named. Portugal applied the European framework cleanly and late, without a national statute, and its report notes the application was without a national layer of its own.
Outside Europe, the rules race belongs to four distinctive models. Singapore runs the most adopted voluntary governance stack in the field, with the widest adoption and no enforcement power at all, which its report calls coherent: it competes where smallness is an advantage, in convening and standard-setting, and it rations megawatts as policy, the only compute allocation regime of its kind in the series. The United Kingdom's most consequential AI rules come from its competition authority rather than its legislature, and they are world-firsts; its AI Security Institute is the best in its class and cannot compel access to what it tests; and its copyright position was resolved by refusal. South Korea wrote the first comprehensive AI statute outside Europe and deferred enforcement by design, creating the institutions and the vocabulary while its privacy statute carries the penalties that change corporate behaviour. The United States holds the rules layer and contests it at home, with export control as the instrument that reaches furthest and a domestic framework unresolved in both directions.
The remaining cases show the race's floor and its variety. China's regulatory instrument is administrative, which its report calls a capability and a risk, with instruments in force from PIPL to the content labelling provisions and a draft AI law on the legislative agenda with no published draft. Russia's first AI law is a development and localisation statute, not a safety law, which its report states plainly, and its programme is the fastest in the series and the most clearly developmental in purpose. India built the most complete AI policy stack in the developing world in two years with governance guidelines that are voluntary by design and carry no enforcement by MeitY's own repeated statement, while its data protection rules phase in over eighteen months. Brazil's AI law is nearly four years old and still not in force, and four instruments govern AI in its absence, one of which enforces. Morocco's regulatory model is the series' cleanest extension model, in the words of its report, and the most transferable instrument in the series. South Africa enforces seriously under laws written before AI existed and has no statutory AI framework at all. Saudi Arabia scores well on governance readiness and has no comprehensive AI statute; its data protection law is in force and its enforcement has developed more slowly than the strategy around it. The United Arab Emirates consolidated its regulatory machinery into a federal authority and left the statute underneath it unenforced in the specific sense that its data protection law has been in force since 2022 without implementing regulations. Qatar's governing strategy dates from 2019 and its AI-specific layer is voluntary, with sectoral regulators carrying the real enforcement capacity. Bahrain's operative regulation is procurement: a general policy, guidelines that function as enforceable rules by contract, a data protection regime in force since 2019, and the series' first case of an AI law approved by a chamber of parliament and never enacted. South Africa adds the series' hardest regulatory failure: a national AI policy withdrawn after fabricated citations, which its report records as a warning about the sourcing standard a strategy document itself must meet.
The five postures, measured against each other
The postures are the capstone's organising device, and this section states the evidence that placed each country and compares within the groups.
Owner of the full stack: China, the United States, South Korea. The group is defined by holding all the layers that determine whether AI can be produced in the jurisdiction, in different proportions. China holds four of the five layers outright, in the words of its report, with compute at an efficiency cost: the only country in the series attempting all five, with the fabrication and memory ceilings as the remaining condition. The United States holds all five with its sovereignty question inverted: the state's instruments are aimed outward while the capability is owned inward by private firms, its physical foundation runs through chokepoints it does not control, and its talent lead reversed in the 2026 index. South Korea owns exactly one layer completely, memory, and its full-stack label carries the condition that its demand side is one to two orders smaller than its supply side and its model stack is partly re-based. Within the group, the three finished the compute race as owners at different depths, the model race as the frontier plus its most important supplier, and the rules race as the authors of the constraints everyone else manages: American export control, Chinese state direction, Korean legislation.
Owner of key layers: the United Arab Emirates, Saudi Arabia, France, India, Japan. This is the series' most diverse group. The UAE runs state-as-equity-investor: sovereign capital at 49 billion dollars in a single fund, open-weight state models, and hosted foreign frontier compute, with four of five layers held and compute rented conditionally. Saudi Arabia runs a state-owned national champion funded by the sovereign wealth fund, with a conditionality rule requiring partners to use Saudi data centres or build local workforce, holding capital more strongly than any middle power in the series and buying compute at scale on licence. France holds depth: an open-weight champion exporting its base, the best energy position in the series, and a talent system that is broad, deep and leaking, with compute rented completely and capital led from abroad. India holds the most complete policy stack in the developing world, a demand-side compute platform that has been flat for nine months, real mid-weight models, and the world's largest talent outflow sitting under its second-largest talent pool. Japan holds the industrial substrate and rents the frontier: the most precise sovereignty definition in the series, a definition of managed dependence, top-two sovereign AI investment with a measurement caveat, and a demographic constraint the policy treats as an emergency. The group's shared characteristic is that each chose one or two layers to own outright, built a genuine specialism, and stated its boundaries more honestly than the full-stack owners or the ambition group.
Regulator and host: Singapore, the United Kingdom, Germany, Spain, Italy, Portugal, Bahrain. The seven states that govern AI with real instruments and host compute they do not own. Singapore is the purest case and its own prime minister has stated the ceiling; the country owns the rules, the assurance infrastructure and a financial stake in the frontier, and rents the compute and builds on others' models. The United Kingdom is a maker of research, talent, applications, capital and rules, and a taker at the two layers that decide the frontier; its private capital scale advantage is largely foreign and the grid queue, not money, is the binding constraint. Germany has built the governing, funding and research layers of an AI sovereign and must rent the layers where the frontier is decided; its model champion left, absorbed by a Canadian company. Spain is the series' most developed supervisory architecture attached to its least developed enforcement statute, with the public compute core European and the private perimeter American. Italy is the series' legal first mover with its most constrained physical layer; its from-scratch model is the strongest such case in the series and commercially thin. Portugal owns its language and rents everything else, and its firms have not yet adopted what it built. Bahrain completes the group as the series' first case of compute loss, and its report's finding is the group's thesis: the four layers that survived its loss are the ones the rest of the group holds, and the one it lost is the one none of the group owns.
Sanctioned isolationist: Russia. One state, one posture. Russia holds genuine capability at the layers a determined state can build without the frontier: one integrated sovereign model line, a real installed compute base, the fastest regulatory programme in the series, and a school-level talent build-out that is real and recent. Its constraints are the country's own published fabrication ceiling, an unaudited flagship supercomputer claim, a civil AI budget outranked by the military line in its own budget, a thinning financial cushion, a private cost of capital that throttles the build, and a measured talent outflow its state has quantified without solving. Its report's honest verdict is the harshest in the series because the state's numbers cannot be checked: the sovereignty claim rests on figures no independent body verifies.
Ambition without compute: Morocco, Brazil, South Africa, Qatar. The four states with published strategies, trained people and, in some cases, real model or hosting capacity, without the compute layer underneath. Morocco has the most complete strategy in Africa, the largest announced-to-operating compute gap in the series, and binding constraints of electricity and water that the strategy's own design choices admit. Brazil chose the series' most transparent strategy, a hedge of one machine from each superpower, funded through development banks rather than a sovereign fund, with a development-bank state rather than an owner state and an AI law not yet in force. South Africa hosts roughly three quarters of Africa's data centre capacity without holding any of the switches, enforces seriously under older instruments, and is assessed by its report as being in a stronger position than its posture label implies, precisely because hosting-without-control is the condition most of the world actually occupies. Qatar is the series' most clearly theorised sovereignty position, honest about its own boundaries: an Arabic-first model line on a Google backbone, every accelerator imported, two capital channels with opposite sovereignty properties, and a demography that cannot staff the industry.
The demonstration case: what Bahrain settled

What survived the loss of the Bahrain region, against what was removed. University 365 Research Center.

The Bahrain region served government and enterprise workloads across three availability zones until 2026, the first hyperscaler region in the Gulf and the first in this series to be lost. Photograph: Pexels License, via Pexels.
On 15 September 2026, Amazon Web Services reported that it could not restore access to its Bahrain cloud region, or to data hosted exclusively there, after damage during the Iran war that spanned multiple availability zones. The series' Bahrain report, published two weeks later, treated the event as what it was: a controlled experiment in compute sovereignty that no one designed and that the series could not have commissioned.
Read against the other nineteen reports, Bahrain settles four questions the series had been answering from inference.
First, it confirms the ownership boundary. Nineteen reports said, in nineteen different ways, that hosting is not ownership and that the layer a host state appears to hold is a foreign asset on its soil. Bahrain demonstrates the difference as an event: the kingdom built its cloud-first government policy on the region for seven years, and when the region went, the capacity did not revert to the state, because it was never the state's. The switch was never in Manama, and neither, it turns out, was the backup.
Second, it confirms the survivability order. The ledger the Bahrain report drew, what survived against what was lost, is the capstone's clearest evidence for the series' central claim. Surviving: the data protection regime in force since 2019 with its resolutions, the AI policy approved in May 2025, the procurement guidelines that function as the country's operative AI regulation, the Tamkeen programme to train fifty thousand Bahrainis by 2030, the applied research base, and a sovereign fund whose AI capital had been spent on an application rather than on infrastructure a strike could reach. Lost or unrecoverable: the hyperscale region, the data held exclusively in it, the unenacted 38-article AI law's momentum, and any remaining claim to host the physical layer at hyperscale. The strike sorted the layers exactly as the frame predicted: it removed hardware, it could not touch the rules and the people.
Third, it confirms what "announced capacity" is worth when the test comes. The series recorded the announced-versus-operating gap in every country. Bahrain is the one case where the question was settled by force rather than by audit, and the answer was that the operating capacity was the number that mattered and the announcement was the thing that vanished.
Fourth, it gives the series its hardest finding, which the Bahrain report states and this capstone carries: the distinction between capacity and capability. Capacity is what a state can rent, host or buy; capability is what it can write, teach and enforce. The first survives only as long as the arrangement does. The second survived the strike. Every report in this series can be read as a variation on that distinction, and the twentieth country lived it.

Sovereign AI Race: Comparative Capstone (2026)
Key Findings
1. Twenty countries produced five postures, and the posture explains more than the budget. The series' twenty subjects finished in five groups: owner of the full stack (China, the United States, South Korea), owner of key layers (the United Arab Emirates, Saudi Arabia, France, India, Japan), regulator and host (Singapore, the United Kingdom, Germany, Spain, Italy, Portugal, Bahrain), sanctioned isolationist (Russia), and ambition without compute (Morocco, Brazil, South Africa, Qatar). The groups do not track spending. The two largest per-capita spenders on sovereign AI capacity, the United Arab Emirates and Saudi Arabia, sit in the middle group with their compute rented or bought on licence, and the state that spent least on compute, Bahrain, holds the layers that survived its loss.
2. The compute race has two owners, one component supplier, and seventeen tenants. The United States and China own the frontier of the physical layer. South Korea owns the memory every accelerator needs. Every other state in the series runs its sovereign capacity on imported accelerators under foreign licensing regimes. The series' reports measured the concentration from three directions: 5,427 data centres in the United States, more than ten times any other country; Chinese national compute capacity of 2,185 EFLOPS; and NVIDIA training 92 per cent of sovereign models globally, in Counterpoint Research's index.
3. The model race is the one non-compute race a state can actually enter, and most entries are adaptations. Open weights turned the model layer into the contestable layer: a state can build a language capability on a base it did not train. Counterpoint found 56 per cent of sovereign models are adaptations of foreign bases, with Meta's Llama the dominant source at 38 per cent. The states that entered built real capability, and their reports state the boundary: the dependency moved from the compute layer to the base model layer, and it did not disappear.
4. The rules race is the one a small state can win outright. Singapore's governance stack is the most adopted voluntary system in the field. Italy wrote the first comprehensive national AI law in the European Union and implemented it to the level of the Official Gazette. South Korea wrote the first comprehensive AI statute outside Europe. The United Kingdom's most consequential AI rules come from a competition authority rather than a legislature. None of the four owns significant compute, which is the point: rules are the layer that drafting capacity can hold without a defence budget.
5. The states that hold compute built it under sanctions or bought it on licence, and the series can now state the pattern as a rule. Five countries in, the France report hardened this finding; twenty countries later it holds without exception. Every compute layer genuinely owned was built under exclusion (China, Russia) or inherited from industrial history (the United States, South Korea, Japan's materials base), and every compute layer acquired quickly was bought on licensable terms (the Gulf, India, Europe's national champions). There is no observed case of a state buying its way into owned compute.
6. Bahrain is the series' demonstration case, and its ledger reverses the standard order of priorities. When the AWS Bahrain region was destroyed in 2026, the data protection regime, the AI policy, the procurement rules that functioned as operative regulation, the upskilling programme and the research base survived intact. The cloud region, the data held exclusively in it, the unenacted 38-article AI law's momentum, and the claim to host the physical layer did not. Compute is the layer a small state cannot protect; rules, data governance, language and people are the layers that survive.
7. Announced capacity outran operating capacity in every single case where both numbers could be measured. Saudi Arabia's data centre capacity grew sevenfold to 467 megawatts while announcements described a multi-gigawatt pipeline. The United Arab Emirates operates roughly three hundred megawatts against a five-gigawatt campus plan. India's subsidised fleet stood flat at about 38,000 GPUs for nine months against a 100,000 target. Morocco announced half a gigawatt twice and operates scientific infrastructure measured in a fraction of it. The gap is structural, not fraudulent: construction takes years and announcements take minutes, and the series treats both numbers as real with different meanings.
8. The talent layer is the deepest constraint across the series, and it cuts two ways. The states with compute cannot staff it (South Korea's demand side one to two orders below its supply side; Germany's shortage and allocation problem; Japan's demographic emergency) and the states with talent cannot keep it (India's outflow the largest in the world; Morocco producing and exporting; Italy losing people; Russia's measured outflow). The states that resolved it, Bahrain among them, treated training as the layer a strike cannot reach.
9. The series found as many kinds of incompleteness as completeness, and it treats them as distinct positions. Italy's law is in force with implementation complete and its physical layer constrained; Spain's supervisory architecture is the most developed in Europe and its statute is still a bill; Bahrain's AI law has sat unenacted since April 2024 and its operative regulation is procurement; Brazil's AI law is nearly four years old and not in force; South Africa enforces seriously under laws written before AI existed and has no statutory framework at all. The series treats enforcement without statute and statute without enforcement as two distinct capabilities, and it found both in abundance.
10. The series' own verification changed published positions, and the capstone carries the corrected set. The Oxford Insights January 2026 full-rankings table prints rank and six pillar scores and no overall column; a pillar-as-overall error was found on two live reports (Italy and Russia) and corrected on 29 September 2026; and in the capstone's own re-derivation of the full set, one further recorded figure was corrected, Morocco's overall at 43.06. Bahrain and Russia both compute to 59.57 and are ranked 48th and 49th; the publisher's rank is the tiebreak and the capstone uses it.

Sovereign AI Race: Comparative Capstone (2026)
Deep Analysis
Why the posture explains more than the money

Six cases where both the announced and the operating figures could be measured. University 365 Research Center.
The series' most durable finding is a negative one: money did not buy compute sovereignty anywhere it was tried at speed.
Consider the two clearest cases. The United Arab Emirates deployed more capital per head of population into AI than any state in the series and holds four of the five layers. The fifth, compute, is rented, and its rental carries a written national-security condition: the Federal Register's licence-free authorization for two named operators expires in April 2027 unless they become United States companies. Saudi Arabia, the region's other large spender, buys its compute on licence at the largest announced volume in the series. Between them, the two states committed sums that would fund a domestic accelerator programme several times over, and neither built one, because neither could: the accelerator layer is not for sale at any price a single state can pay, because the sellers' export regimes price it as an instrument of alliance rather than a product.
Now consider the states that hold compute outright and the route each took. The United States inherited design leadership from five decades of semiconductor industry. China reached its position through a state-directed substitution programme that began before the AI wave and is still paying an efficiency cost reported at roughly 40 per cent yields against upward of 90 per cent for Western parts. South Korea built its memory position through the same industrial policy era, decade by decade. Japan owns materials and equipment because it rebuilt its industrial base around them. Russia, the series' sanctioned case, is building under exclusion and publishes its own ceiling. Every owned compute layer in the series was either inherited or built under conditions of exclusion or long-horizon industrial policy. None was bought.
The posture framework's value is that it predicts a state's remaining options. A state that cannot own compute can still choose between the four alternatives the series documented: own a language layer (Portugal, Qatar, Morocco, the UAE), write rules with more reach than its market (Singapore, Italy, South Korea), buy equity in the frontier (the UAE, Saudi Arabia, Singapore), or train people and hold the institutions that survive everything else (Bahrain, Germany, India). What it cannot do is convert spending into the physical layer, and the series' twenty reports document twenty separate confirmations.
The concentration numbers, and what they actually mean
Three numbers anchor the series' structural finding, and they need stating precisely because each measures a different thing.
The first is physical: the United States hosts 5,427 data centres, more than ten times any other country. That is the Stanford AI Index 2026's count, and it is a count of facilities, not of capacity, which means the true concentration in installed accelerator capacity is higher than ten times, because American facilities are also larger and more densely accelerated. The second is reported: China's Ministry of Industry and Information Technology put national intelligent computing capacity at 2,185 EFLOPS as of the end of June 2026, up 177 per cent year on year, on a measurement basis that independent firms counting differently record at 725 EFLOPS for a prior period. The two bases are not comparable and the series never compared them; what the Chinese figure establishes is direction and scale, that China built the second-largest compute base on earth with a growing domestic accelerator share. The third is about dependency: Counterpoint Research found NVIDIA trains 92 per cent of sovereign models globally across the more than 80 countries it assessed, which is the number that matters most for the nineteen non-owning states, because a sovereign model trained on one vendor's chips inherits that vendor's licensing regime no matter whose flag flies over the model card.
Read together, the three numbers describe a hierarchy with very few exits. The chips are designed in one country. They are fabricated in two. The memory they need comes mostly from one other. The models trained on them overwhelmingly use one vendor's silicon, and the bases most sovereign models adapt come from an even shorter list of laboratories. A state's sovereign AI programme, in nineteen of twenty cases, is a way of arranging dependencies rather than removing them, and the series' contribution is to name which dependencies each arrangement leaves standing.
Two consequences follow, and the series documented both. First, the dependency that matters most is the one held by the fewest actors: not the model, where alternatives exist, but the accelerator and its memory, where they do not. That is why South Korea's position, supplying memory rather than competing in design, was assessed as one of the strongest in the series. Second, dependencies are stable until a geopolitically motivated actor changes the terms, and the series observed the terms changing repeatedly during its own publication window: the diffusion rule rescinded, H200-class exports moved to case-by-case review, a 25 per cent tariff imposed, the UAE's authorization granted and given an expiry date, and Gulf cloud infrastructure struck by drones. A state planning on rented capacity should plan for the terms to change on the supplier's schedule, because in the series' evidence they did.
The three races, and how each of the twenty finished

The vault door, the lit row, and the queue at the kiosk. University 365 Research Center.
The capstone's central table, reproduced as Table 2 in Data and Evidence, records each country's position in each of the three races as the series assessed them. The narrative that follows states the pattern each race produced.
The compute race finished with three owners (China, the United States, South Korea), one near-owner that owns the industrial substrate and rents the frontier (Japan), four states whose capacity is bought or licensed rather than owned (the United Arab Emirates, Saudi Arabia, France, India), the seven regulator-and-host states, whose compute is foreign-owned (Singapore, the United Kingdom, Germany, Spain, Italy, Portugal, Bahrain), one sanctioned builder (Russia), and the four ambition-without-compute states (Morocco, Brazil, South Africa, Qatar), whose positions range from real hosting at regional scale to announcements. The race's verdict is the series' hardest: compute is the only layer that cannot be acquired at speed, bought at any scale, or protected by any means available to a small state.
The model race finished differently. Two owners of the frontier (the United States, China), one strong second tier that is partly re-based (South Korea), five serious national capabilities with honest boundaries (France, Japan, the United Arab Emirates, India, Italy), and a long tail of language and domain specialists whose work is real and whose bases are foreign (Saudi Arabia, Qatar, Singapore, Portugal, Brazil, South Africa, Morocco, and Bahrain's procurement layer, with Russia the partial exception holding one genuinely integrated sovereign line alongside a tier built on foreign bases). No state that entered this race with a serious language programme finished with nothing; several finished with less than their announcements implied; and the common finding across the tail is that the model layer is where sovereignty is genuinely purchasable at a small state's budget, up to the line where the base model begins.
The rules race finished with the widest spread and the least correlation to wealth. The rule-makers with global reach are the European Union's framework and its member states' implementations (Italy, Germany, Spain, Portugal, France, in that order of legal completeness), Singapore's voluntary stack with the widest adoption, the United Kingdom's regulator-led world-firsts, South Korea's early statute, China's administrative machinery, and the United States' export regime. The rule-takers and rule-adapters are everyone else, including states that wrote national frameworks with no enforcement (India's voluntary guidelines, Brazil's unenforced statute, Qatar's 2019 strategy, Bahrain's unenacted law) and states that enforce under older instruments (South Africa). The race's verdict is the series' most hopeful: drafting capacity is cheap, the payoff compounds, and the states that wrote early are the states whose frameworks other states copy.
The races converge on one observation. A state that wins the rules race or the model race holds something durable because both live in documents, institutions and people, and both survived every physical setback the series observed. A state that holds the compute layer holds something durable only as long as it also holds the means to defend it, which is what the United States, China and South Korea do and what the other seventeen do not.

Sovereign AI Race: Comparative Capstone (2026)
Data and Evidence
Table 1: The five layers, the verdicts for all twenty countries
Country | Compute | Models | Capital | Regulation | Talent and education |
United Arab Emirates | Rented, conditionally | Held, at sub-frontier scale | Owned | Held in form, not in force | Imported, building |
Saudi Arabia | Bought, at scale, on licence | Held, on a borrowed foundation | Owned | Mandated, not yet comprehensive | Volume without depth |
China | Owned, at an efficiency cost | Owned, and distributed as policy | Owned | Held, and rapidly changeable | Held, and strengthening |
United States | Owned, on chokepoints it does not control | Held, at a narrowing frontier | Owned, and concentrated | Held, and contested at home | Held, and eroding at the intake |
France | Rented, on the best energy position in the series | Held, and exported as a base | Mixed, and audited by the state's own court | Held, and moving later | Broad, deep, and leaking |
India | Functioning, flat, and rented | Real Indic capability, honestly not frontier | Ambitious on paper, thin in the account | Deliberately voluntary, and untested | Vast at the base, leaking at the top |
Morocco | Announced far beyond operating | Language-layer contribution, honestly scoped | Private and foreign capital carry the compute layer | The cleanest extension model in the series | Produces, then exports |
Japan | Industrial depth, frontier bought, geography being relocated | Real, Japanese-first, honestly positioned | Top-two state funder, outward private champion | Promotion by design, soft law operative | The demographic constraint is structural |
South Korea | A supply chokepoint with a demand side one to two orders smaller | Strongest outside China and the US, chosen by contest, partly re-based | State directs corporate capital; the capital faces two directions | Early comprehensive law, restrained enforcement | The condition attached to the full-stack label |
Singapore | Scarcity as policy; capacity as a selected franchise | Regional specialist on foreign bases, honestly framed | Financial exposure to the frontier, deliberate and disclosed | Exported voluntarily, binds no one, adopted widely | Strongest demand side in the series, constructed supply side |
Germany | Strong operator, no producer, and the fab that did not arrive | Research grade and honest about it | Funded and fragmented, by design and by federalism | The strongest national enforcement layer in Europe | Deep institutions, acute allocation problem |
United Kingdom | Genuine public asset, private build, paused flagship | Research sovereignty without ownership | The deepest private capital market in Europe, the thinnest state balance sheet in the series | Real rules from a market regulator, none from a legislature | A strong pipeline feeding a narrowing entrance |
Brazil | Announced capability with a real scientific base and a bicontinental buying strategy | Portuguese-language depth on foreign foundations | A development-bank state, not an owner state | Enforcement without the statute; the statute without a vote | Training at scale, returns under-built |
Spain | A public European core and a private American perimeter | Europe's strongest public model infrastructure, with an honest boundary | Direct state equity and a large private market, with the state as the smaller counterparty | The Union's most granular supervisory architecture, with almost none of it in force | Strong supply, weak matching, exceptional inflow |
Italy | A genuine public scientific base and a foreign-owned commercial build, limited by the grid | The strongest from-scratch national model layer in the series, commercially thin | A co-investor state in a market owned by foreign balance sheets | The strongest regulatory position in the series, applied to a small domestic market | A strong academic supply chain in a country that loses people |
Russia | A real installed base and an unaudited claim above it, with the fabrication ceiling binding | One genuinely integrated sovereign line, a second substantial line, and a third built on a foreign base | A state that funds AI from a subordinate budget line and a thinning reserve, with the private cost of capital throttling the build | The fastest regulatory programme in the series and the most clearly developmental in purpose | A deep tradition, a real and recent school-level build-out, and an outflow the state has measured without solving |
Portugal | Real hosting infrastructure on a decommissioned industrial site, with the ownership of the layer entirely foreign | The smallest defensible version of model sovereignty, executed and released openly | An externally financed strategy and a state that buys compute rather than owning it | The European framework implemented without a national layer, applied cleanly and late | A real university base and a language advantage, constrained by pay and retention |
South Africa | Real hosting capacity at continental scale, with the switch held abroad | Capable at the language and research tier, absent at the frontier | Platform-financed capacity with no state instrument of size | Serious enforcement under older instruments and no statutory AI framework at all | A genuine language research base inside a labour market with the region's highest measured exposure |
Qatar | Real hosting capacity and a national champion, with the accelerator switch abroad | The series' clearest stated sovereignty doctrine, delivered on a borrowed backbone | Two capital channels with opposite sovereignty properties, and a large passive position | A strategy, voluntary guidance and sectoral rules, with no statute of its own | A deep, concentrated research core on a demography that cannot supply the workforce |
Bahrain | The series' first case of compute loss, with the surviving capacity private and unquantified | A procurement layer rather than a technical layer, which the report treats as a coherent choice | A small fund spent on an application where the country has genuine assets, not on infrastructure | No act and real operative regulation, delivered through procurement and data protection | The layer that survived the compute loss intact, and the country's most durable investment |
Table 2: The three races, how each of the twenty finished
Country | Compute race | Model race | Rules race |
United States | Owner: design, cloud and capital; chokepoints in fabrication abroad | Owner: the proprietary frontier, margin narrowed to 2.7 per cent | Rule-maker: export control as the instrument with the widest reach |
China | Owner at an efficiency cost: 2,185 EFLOPS reported, domestic accelerator line shipping | Owner: the open-weight frontier and more than half of global open-model downloads | Rule-maker by administrative measure: fast, single-purpose, changeable without a vote |
South Korea | Chokepoint supplier: the memory every accelerator needs | Strong second tier: 250 to 750 billion parameter open models, champion not yet chosen | Early mover: the first comprehensive AI statute outside Europe, enforcement deferred |
Japan | Near-owner: materials, equipment, a fab restart and robotics; the frontier bought | Serious national layer: Japanese-first, mixed on weights, domestic switch scheduled | Norm-maker: promotion statute with no penalties, soft law carries the weight |
United Arab Emirates | Conditional holder: capacity on site under a licence with an expiry date | Real Arabic capability: first place on the sovereign model index, Chinese base under the flagship | Consolidator: one federal authority over an unenforced statute |
Saudi Arabia | Buyer at scale: hundreds of thousands of accelerators planned, capacity sevenfold to 467 MW | Aspirant on a borrowed foundation: flagship post-trained from a Chinese base | Mandate-holder: SDAIA since 2019, no comprehensive statute |
France | Tenant on the best energy position: all verified compute is imported | Exporter of a base: open weights on reported Apache terms, adopted widely | Late mover: penalty provisions still pending; the state's own auditor as a strength |
India | Platform, not owner: a flat subsidised fleet on entirely imported silicon | Mid-weight and real: Sarvam trained from scratch in India, not frontier | Voluntary by design: governance guidelines with no legal enforceability |
Italy | Public scientific base and a foreign-owned commercial build, limited by the grid | The strongest from-scratch national model layer in the series | Legal first mover in the EU: Law 132/2025 in force, implementation complete |
Germany | Strong operator, no producer: Europe's first exascale public system, the fab that did not arrive | Research grade: open multilingual research models, the commercial champion departed | The strongest national enforcement layer in Europe |
Spain | Public European core, private American perimeter, build concentrated in Aragon | Europe's strongest public model infrastructure, with an honest boundary | The Union's most granular supervisory architecture, statute still a bill |
United Kingdom | Genuine public asset and private build; the flagship growth zone lost its anchor tenant | Research sovereignty without ownership: the frontier laboratory is not British-owned | Regulator-led world-firsts; the AI Security Institute cannot compel access |
Singapore | Selector and host: megawatt rationing, research-scale sovereign compute | Regional specialist: SEA-LION on foreign bases, moved to Chinese ones in October 2025 | The most adopted voluntary governance stack in the field, binding no one |
Brazil | Hedged: one machine from each superpower on a scientific base, real and small | Portuguese-language depth on foreign foundations | Enables without statute: four instruments, one of them enforcing |
Portugal | Host: real infrastructure on a decommissioned industrial site, foreign-owned | The smallest defensible version of model sovereignty, executed openly | Adapter: the European framework applied cleanly and late, without a national layer |
South Africa | Host at continental scale: three quarters of Africa's capacity, none of the switches | Language-tier capable, frontier-absent; a national policy withdrawn after fabricated citations | Enforcer without a framework: serious action under laws written before AI |
Morocco | Announced far beyond operating: half a gigawatt announced twice, constraints of power and water | Language-layer contribution: Darija-first, research-grade, honestly not frontier | The cleanest extension model: existing data protection law extended to AI |
Qatar | Host with a doctrine: national champion and real capacity, every accelerator imported | The clearest stated sovereignty doctrine, delivered on a borrowed backbone | Strategy and guidance: the 2019 strategy still governs, sectoral rules enforce |
Bahrain | Lost: the series' first case of a cloud region destroyed by war | Procurement instead of weights: a managed doorway to third-country models | Procurement as regulation: policy in force, the AI law unenacted since April 2024 |
Russia | Sanctioned builder: a real installed base under a published fabrication ceiling | One integrated sovereign line, one substantial line, one on a foreign base | The fastest programme in the series, developmental in purpose |
Table 3: The verified index set, all twenty subjects
Country | Rank | Overall score | Policy Capacity (the trap value) |
United States | 1 | 88.37 | 92.50 |
France | 2 | 80.81 | 77.50 |
United Kingdom | 3 | 77.75 | 100.00 |
South Korea | 5 | 76.89 | 96.00 |
Germany | 6 | 76.78 | 84.50 |
Singapore | 7 | 76.41 | 85.00 |
China | 8 | 76.27 | 92.50 |
Spain | 13 | 74.22 | 92.00 |
Japan | 14 | 72.24 | 70.00 |
Saudi Arabia | 15 | 71.57 | 92.00 |
United Arab Emirates | 19 | 69.86 | 73.00 |
Brazil | 22 | 69.55 | 88.00 |
Italy | 25 | 68.81 | 69.50 |
India | 27 | 66.55 | 96.00 |
Portugal | 28 | 66.09 | 57.50 |
Bahrain | 48 | 59.57 | 46.50 |
Russia | 49 | 59.57 | 65.50 |
Qatar | 54 | 58.62 | 80.50 |
South Africa | 65 | 53.94 | 43.00 |
Morocco | 86 | 43.06 | 23.00 |
The publisher's January 2026 full-rankings table prints the rank and the six pillar scores and no overall column, so each overall above is recomputed from the publisher's own published pillar weights: Policy Capacity 10 per cent, AI Infrastructure 25, Governance 15, Public Sector Adoption 15, Development and Diffusion 25, Resilience 10. The method reproduces all nine overall scores the report states in its narrative exactly, and under these weights every row of the publisher's table keeps its published rank order with no exceptions. The index assesses 195 countries. Bahrain and Russia both compute to 59.57; the publisher ranks Bahrain 48th and Russia 49th, and the capstone uses the publisher's rank as the tiebreak. The full set was re-derived from the publisher's table for this capstone; one recorded figure was corrected in the process, and Morocco's overall is 43.06. Two reports in this series originally published a pillar value as an overall score and both were corrected on their live pages on 29 September 2026.

Sovereign AI Race: Comparative Capstone (2026)
Implications
For the countries that have not yet entered the race
The series' clearest implication is about sequencing, and Morocco's report states it first because Morocco's constraints are the constraints most states share. Rules and institutions are cheap and they compound; write them first. The model layer is purchasable up to a point, because open weights let a state build language capability on a base it did not train, and the series found no state that entered that work seriously and finished with nothing. Compute is neither cheap nor purchasable at speed, and the states that tried to buy their way into it finished as tenants on better or worse terms. The order that worked, observed across the series, was regulation first, language second, people throughout, and compute whenever the industrial base or a long-horizon programme makes it possible.
For the technology providers and the states that host them
The Bahrain case repriced physical security for every hyperscaler region in a contested geography, and the series' Gulf reports record the market's response: site reviews, distributed designs, air defence considerations, underground construction. Providers now sell sovereign capacity to states whose sovereignty over it is contractual rather than physical, and the series documents what that contract is worth in an emergency. The honest reading of the twenty reports is that hosting arrangements will continue because the demand is real and the alternative is slower, and that the hosting states will keep buying because hosting beats absence. The providers' own interest lies in making the backup semantics of their regions legible to their customers, because the series' sharpest consumer lesson came from Bahrain: an availability zone is not a backup, and a region is not a second copy.
For institutional and enterprise buyers
The series' enterprise-facing findings repeat across seventeen reports: adoption is shallow where it is broad, integration lags usage, and the dependency a buyer holds is the dependency its provider holds. The practical rules extracted from the twenty reports are three. Know which jurisdiction your workloads' compute physically sits in, because licensing regimes attach to hardware and not to contracts. Know which country a model's base was trained in, because the 56 per cent adaptation rate means the model on your invoice may be a foreign foundation with a local wrapper. And keep an exit, because the series observed five separate instances of access terms changing on the supplier's schedule within its own publication window.
For University 365 and the education layer
The finding most relevant to this institution is the survivability order the series established. When the physical layer went, the trained people and the written rules remained, in Bahrain and in every other case where the layers were tested. That inverts the funding priority most national programmes follow, and it is the gap the CI-First approach addresses directly: the capacity to judge, verify and stay accountable is the taught outcome that no strike, licence change or supplier decision can revoke. The series' twenty reports are, taken together, the evidence base for treating that capacity as infrastructure.

Sovereign AI Race: Comparative Capstone (2026)
Education and Skills Impact
What twenty countries establish about the layer that survives
This series began with a question about states and ends with a finding about people. Across twenty countries, every layer except talent was lost, revoked, paused or found to be foreign at some point in the series' observation window. Compute was lost to war in Bahrain and exposed to licensing in the UAE. Model bases proved foreign in most of the world. Capital turned out to be pledged rather than spent in France and ambitious on paper in India. Regulatory statutes sat unenacted in Bahrain and Brazil. The trained workforce was the only layer that no external event removed, in any of the twenty cases.
The country reports each drew the education implication from their own evidence, and the pattern across them is consistent. The states with the deepest talent positions treated training as a permanent investment with a decade-long return: Japan's school-level build-out, China's 600-plus university programmes, Germany's research institutions, South Korea's contest-driven model programmes. The states with the weakest positions treated it as a procurement: India's ten-million pledge against a certified base an order of magnitude smaller, the Gulf's imported capability, Morocco's graduates leaving before their training paid back nationally. The difference between the two groups is not money, because Morocco's strategy is complete and its training real; it is whether the training is connected to the country's actual demand for builders. Portugal's report puts it most precisely: it owns its language and rents everything else, and its firms have not yet adopted what it built.
For University 365, the twenty-country evidence sharpens the CI-First argument from a philosophy into a measurement. The series' demonstration case showed that what survives a physical catastrophe is what people carry in their heads and hold each other to. Every country report in this series found some version of the same gap, between adoption and capability, between using AI and being able to judge it, and the gap was widest where the tools arrived fastest. That is the specific education problem the Co-Intelligence-First approach was designed for, and twenty countries of evidence now sit behind it.

Sovereign AI Race: Comparative Capstone (2026)
The CI-First Perspective
What twenty countries establish about capability, appearance, and the layer that survives

The dark hall below, the lit classroom above, and the plans carried out. University 365 Research Center.
The Co-Intelligence First framework asks whether an arrangement amplifies human capability or substitutes for it, and where the risk of AI Imposture sits. Applied to twenty states, the framework's central question sharpens into something the series could not have answered from one country: which parts of a sovereign AI position are capability, which parts are appearance, and which parts survive when the appearance is removed.
The series' answer is its structural finding. Measured across twenty subjects, the layers divide by what backs them. Compute is capacity, and capacity is rented, licensed, bought or inherited; none of the twenty acquired it through a sovereign AI programme, and the three that own it inherited it from industrial history or built it under exclusion. Models are capability up to the base: a state that trains a language layer owns something real, and a state that adapts a foreign base owns a derivative whose foundation it does not control. Capital is capability where it is owned and exposure where it is passive. Regulation is capability wherever it is enforced, because enforcement is a domestic act no external actor can revoke. And talent is capability in the strictest sense, because it is the only layer that lives in people rather than in arrangements.
The appearance side of the ledger runs through every report in the series, and the capstone can now name the pattern. Imposture in the sovereign AI field is almost never fabricated capability; it is real capacity described as ownership. The Gulf states describe hosted hyperscale capacity as national achievement and are describing real capacity accurately, while the switch sits in a foreign capital. European states describe supervisory architectures and AI factories as sovereignty while the compute and the models beneath them are imported. India describes a mission and the compute beneath it is a flat plateau of rented silicon. None of these is a false statement, and each became a softer version of the same error: treating the arrangement as the asset. Bahrain is the series' sharpest case because the arrangement was removed by force and the difference became visible in a single event.
The framework's practical claim, stated across twenty countries, is about where to put the durable investment. The Bahrain ledger is the demonstration: rules, data governance, language work, curriculum and trained people survived the loss of the physical layer intact, in the only case in the series where the physical layer was actually lost. No other layer in any of the twenty countries proved that way, because no other layer was tested that way. The series therefore ends with the CI-First proposition intact and now evidenced at state scale: the human capacity to judge, verify and stay accountable is the layer no licence, strike or supplier decision can revoke, and it is the layer the twenty country reports consistently found underfunded relative to its survivability.

Sovereign AI Race: Comparative Capstone (2026)
What This Means for You and Us
For a reader in a country that rents its compute
You are in the majority position of this series: seventeen of the twenty subjects rent, host or buy the physical layer. The practical guidance the series generated is specific. Write your rules first, because they are cheap, they compound, and they survived every shock observed. Build your language capability, because open weights make it the one technical layer a small budget can genuinely own. Describe your own position accurately, calling hosted capacity hosted, because a national narrative that one event can falsify is itself a liability. And treat training as infrastructure rather than as a programme, because it is the layer the series watched survive everything else.
For a reader watching the series
Twenty reports and one capstone later, the series' postures are the map to watch. The owner states will keep owning, because their positions rest on industrial history rather than on programmes. The states in the middle groups will keep making trade-offs between layers they can afford. And the demonstration case will be tested again somewhere, because the conditions that produced it have not changed: compute is concentrated, hosting is widespread, and the geographies where the two meet are contested. The observable items to watch are the ones named in The Road Ahead.
For University 365
This series is the institution's largest applied AI research output, and its findings bear directly on what University 365 teaches. The capability gap the twenty reports documented, between using AI and being able to judge it, is the specific gap the Co-Intelligence-First approach addresses, and the series' survivability finding is the strongest evidence base the approach has: what survived the destruction of a national compute layer was exactly the human judgement capacity the approach treats as the taught outcome. The U365 method's relevance to the countries in this series is not promotional but structural, and the series' reports say so where the evidence supports it and stay silent where it does not.

Sovereign AI Race: Comparative Capstone (2026)
The Road Ahead
Three observable developments would change this capstone's assessment, and each is stated with the indicator that would settle it.
Whether the compute race's terms change again. The series observed licensing terms move five times inside its own publication window: the diffusion rule rescinded, H200-class exports moved to case-by-case review, a 25 per cent tariff imposed, the UAE's licence-free authorisation granted with an expiry date, and Gulf capacity struck. The indicators to watch are the April 2027 expiry of the UAE authorisation and whether any operator converts to the corporate nationalities the condition names; whether the American case-by-case regime widens or narrows; and whether any state's licence-free treatment is withdrawn, because the first withdrawal would convert every hosting arrangement's fine print into front-page risk.
Whether the model race's base layer diversifies or consolidates. The series' 56 per cent adaptation rate measures how much of the world's sovereign model capability stands on a handful of foreign foundations. The indicators are the base choices of the next wave of national models, particularly in Africa and Southeast Asia where the series found the newest programmes, and whether the European open consortia ship competitive bases, because a genuinely open European base would change the dependency arithmetic for every state in the rules postures.
Whether the rules race holds under enforcement. The European enforcement phase began in August 2026, South Korea's grace period ends, and India's data protection rules phase in over eighteen months. The series' finding that rules are the survivable layer depends on enforcement following enactment, and the first serious test will be whether the European framework's high-risk obligations, now deferred to December 2027 and August 2028, arrive on schedule and whether the first major enforcement actions change corporate behavior. A rules race that produces instruments without enforcement would repeat the incompleteness the series documented in five of its twenty subjects.
One further indicator sits over all three: whether any state in the ambition-without-compute posture converts hosting into owned capacity, because the series found no case of it and would have to revise its central rule if one appeared.

Sovereign AI Race: Comparative Capstone (2026)
Sources and Methodology
Methodology
This capstone is built from the twenty country reports of the Sovereign AI Race series and from no new primary research, with two documented exceptions: the re-derivation of the full Oxford Insights index set from the publisher's January 2026 report, and the cross-checking of every cross-series figure against the report that originally published it. Each country report carries its own methodology statement, its source tiers and its confidence limits, and the capstone inherits those limits in full. Where a figure in this report appears in a country report as a claim, a vendor metric or a government target, it appears here with the same status, and the capstone adds no figure that a country report did not establish except the index re-derivation described above and the cross-series counts of postures and races, which are this report's own tabulation of its twenty subjects.
The index set in Table 3 was recomputed from the publisher's own full-rankings table using the publisher's own pillar weights, a method that reproduces all nine overall scores the publisher states in its narrative exactly and preserves the published rank order of every row in the table. During this re-derivation one recorded figure from the series' working notes was found to be inconsistent with the publisher's row and was corrected: Morocco's overall is 43.06. The correction affects no published report, because the Morocco report cites the 2024 edition of the index and states so.
Principal sources
The series record. The twenty country reports of the Sovereign AI Race series, published September 2026, used as the capstone's primary source for every country-level statement, posture assignment and race assessment. The full list is: UAE, Saudi Arabia, China, USA, France, India, Morocco, Japan, South Korea, Singapore, Germany, United Kingdom, Brazil, Spain, Italy, Russia, Portugal, South Africa, Qatar and Bahrain.
Index and analyst sources, as cited in the country reports. Oxford Insights Government AI Readiness Index 2025 (January 2026 report and full-rankings table); Counterpoint Research sovereign AI model analysis, including the adapted-model and chip-share findings of 5 August 2026; Stanford HAI AI Index 2026; CNAS sovereign AI project tracking, 2026.
Primary sources for capstone-level statements. The Federal Register rule and licence condition cited for the UAE compute layer, as recorded in the UAE report; the AWS statement of 15 September 2026 on the Bahrain region, as recorded in the Bahrain report; the European Commission's AI Act implementation timeline and the Digital Omnibus record, as cited in the France, Germany, Spain and Portugal reports; Reuters reporting on the AWS Bahrain region and the UAE data centre plan revision.
Editorial compliance. No em dashes anywhere in this report, including inside quotations. No banned filler phrases. Government targets and vendor figures are labelled as claims wherever they appear.

Sovereign AI Race: Comparative Capstone (2026)
About This Report
Sovereign AI Race: Comparative Capstone (2026) is the closing report of the Sovereign AI Race series: twenty country reports and one comparative capstone, assessing how states attempt to control the production of artificial intelligence inside their jurisdiction, using one five-layer framework and one metric set applied identically to every subject: compute, models, capital, regulation, and talent. The capstone compares the twenty on the frame the series fixed, sets out the five postures the series found, and states how each subject finished in the three races the series separates: compute, models and rules.
The capstone has no prior University 365 report on its own subject, because it is the series' first comparative volume, and it carries no "What Changed Since" treatment of its own. The series' individual reports carry that treatment against the earlier 2025 landscape reports where one existed, and this capstone draws on those comparisons as recorded in each report.
Author: Hubert Graef, Dean of Research, University 365 Research Center.
Series: Sovereign AI Race, the comparative capstone, following twenty country reports.
*Published by University 365 Research Center. CI-First is University 365's Co-Intelligence First framework, a method constant of the institution.*
Revision 2, 30 September 2026, 18:34 UTC. Published 30 September 2026.









Comments