Jacob Boelen, Seal, ca. 1704. The Metropolitan Museum of Art, public domain.
- Sovereign AI has become a sales label across the Caribbean and Latin America, applied to products where every answer is generated by a foreign foundation model.
- There are three categories with different risk profiles: sovereign AI, a self-hosted open-weight model, and a foreign model behind a local interface.
- Seven tests separate them. Four are cheap and quick, and three of the popular ones can be defeated by a competent vendor who wants to defeat them.
- The test a vendor cannot talk around is a demonstration with outbound access to foreign model providers blocked. A local model keeps answering. A wrapper stops.
- Buying a rebranded foreign model is often sensible. Believing you bought something else costs you, in residency evidence you cannot produce and continuity you do not hold.
A vendor selling into a Caribbean bank, ministry or insurer in 2026 knows which words open the door: sovereign, local, regionally hosted, trained on Caribbean data. I have sat on both sides of that conversation for years, as the person building AI systems and as the person a board calls in the week before it signs. In most of those rooms, what is described as sovereign AI turns out to be an application layer, built locally and often built well, that sends every query to OpenAI, Anthropic, Google or a hosted open-weight service in North America or Europe.
Many of those products are good. The trouble is the description. Directors approve purchases on the assumptions it creates: that the data stays here, that the vendor controls the system, that regulatory exposure is contained. When those assumptions are wrong, the usual place to find out is an audit.
What sovereign AI has to mean
Sovereignty over a capability means you decide, on your own terms, whether it keeps running and who sees what passes through it. For an AI system that comes down to three conditions, all of which must hold:
- The party you contract with owns the model, or licenses weights on terms it controls, so it can keep serving you if the original supplier changes its mind.
- Inference runs on hardware the vendor or you operate, in a place either of you can name.
- That place is written into the contract. A regulator asking where customer data is processed wants a document, not a slide.
Two things often passed off as sovereignty fail these conditions. A local interface over a foreign model is a product decision: the branding on the login page has no bearing on where the tokens are processed. Fine-tuning a hosted foreign model on your own data moves you further away, because you have now sent the training data across too, and the resulting weights sit with the provider.
| Attribute | Sovereign AI | Self-hosted open-weight model | Foreign model, local interface |
|---|---|---|---|
| Where inference runs | Vendor or buyer infrastructure, named location | Your own servers or your own cloud tenancy | The foundation-model provider's data centres |
| Who can switch it off | The vendor, under your contract | You | The provider, and the government that regulates it |
| Data residency evidence | Contractual and auditable | Verifiable by inspection | Governed by the provider's terms, not the vendor's |
| How it is priced | Compute, capacity or licence | Hardware and operations | Per token, with a margin added |
| What breaks it | Vendor failure | Your own operations | Provider outage, policy change, export restriction, price move |
The middle column is where most serious Caribbean deployments should probably sit, and it gets the least attention because nobody has a sales team selling it. Open-weight models can be downloaded, run on modest hardware once quantised, and settle the residency question: the model is on a machine you can walk up to.
Why wrapper products exist, and when the label becomes a problem
Building an application on a frontier model is legitimate work. Someone has to design the workflow, connect the systems, handle the edge cases and answer the phone when it breaks at eleven at night. A local firm that does that well is worth paying.
The vocabulary is what changed. Two years ago these products were sold as AI-powered. Now the same products are sold as sovereign, because governments across the region began asking about data residency and the word tested well. The engineering stayed put while the label moved. A label describing something the product does not do turns a commercial claim into a governance problem.
Fraudsters have picked up the same vocabulary. The Trinidad and Tobago Securities and Exchange Commission has issued repeated investor alerts about schemes using AI-generated deepfake videos of public figures, and "proprietary AI" is a standard part of the pitch. Once sovereign AI means nothing in particular, it gives free cover to people whose product is a spreadsheet and a Telegram group.
Seven tests you can run on a vendor in an afternoon
These are the checks I run, ordered from cheapest to most decisive. Each one is marked with what it proves, because a test that gives a false clearance is worse than none.
Test 01
Ask the model what it is
Type the question into the product: what foundation model are you built on, what is your architecture, who trained you. Ask again in different words, and once more deep inside a longer conversation, because guardrails are usually written for the obvious phrasing.
What it proves. A leak is strong evidence: a model that names GPT, Claude or Gemini has told you the answer. A denial proves little, because a system prompt can instruct a model to deny it and models often misidentify themselves. I have seen a self-hosted open-weight model insist it was made by OpenAI, which was false and would have failed an honest vendor unfairly. Use this to catch carelessness, not to clear anyone.
Test 02
Watch the traffic during a query
Ask your IT team, or use a free proxy tool such as HTTP Toolkit, to record the network calls a client makes while the product answers a prompt. Look for requests to api.openai.com, api.anthropic.com, generativelanguage.googleapis.com and the common hosted-inference endpoints.
What it proves. A hit is conclusive. A clean trace means almost nothing, because a competent product calls the provider from its own backend and the client only ever talks to the vendor's domain. You can still learn where the vendor's endpoint resolves and how long the round trip takes. If time to first token from a client in Kingston or Bridgetown matches a North American round trip, put that in a written question to the vendor.
Test 03
Which weights are loaded, and under what licence
A team running its own model can answer this in one sentence. They will name a base model and a licence, or say it is their own architecture and describe the training in enough detail to survive a follow-up question. A team reselling API access will answer with capability language about accuracy and speed.
What it proves. A lot, quickly, and it is hard to fake in front of anyone technical. Bring an engineer to this meeting. If your organisation does not have one, that is the strongest argument for having a trained AI Officer in the room before signature.
Test 04
Read the sub-processor list
Every serious vendor publishes, or will provide on request, the list of third parties that process customer data on its behalf, normally as a schedule to the data processing agreement. Read it for names, and read the clause around it for how changes are notified.
What it proves. This is the most useful of the paperwork tests, because it is contractual. A foundation-model provider listed as a sub-processor for inference settles the question. So does the absence of any list, or a clause letting the vendor change sub-processors at its discretion without notice.
Test 05
Correlate the outage history
OpenAI, Anthropic and Google Cloud publish incident histories at status.openai.com, status.anthropic.com and status.cloud.google.com. Take the dates of your vendor's last several outages and lay them against those histories.
What it proves. Matching dates are good evidence of dependency. Non-matching dates prove less, because a well-built wrapper fails over between two or three foreign providers and stays up through any one outage. That design is more resilient than a single dependency. It is still not sovereign, and your prompts may land at any of several providers depending on the hour.
Test 06
Look at what the invoice is counting
Pull an actual invoice, not a rate card. Sovereign and self-hosted systems price on capacity: GPU hours, node hours, throughput, seats tied to provisioned hardware. Resold products price on tokens, requests or credits, because that is how their own costs arrive.
What it proves. Moderate evidence, easily disguised by credits and seat bundles. The sharper question is what happens to your bill if usage triples, and whether the vendor will commit to a fixed price at that volume. A vendor whose costs scale with your tokens cannot, and its explanation will answer the original question.
Test 07
Block the outside world and see what still answers
Ask the vendor to run the product on a network where outbound traffic to the major foreign model providers is blocked at the firewall, or to deploy into your own cloud tenancy or rack where you control egress. Give them notice and time to prepare.
What it proves. Everything the other six were reaching for. A model on infrastructure you control keeps answering with the internet cut off. A rebranded foreign product returns an error or a canned response, whatever the architecture diagram says. Run this when the answer matters. Most vendors will try to swap it for a written assurance.
Where these tests fail, including mine
Publishing a diagnostic weakens it. Any vendor reading this can write a system prompt that defeats Test 1 and rehearse a fluent answer to Test 3. I think the trade is worth it: the buyers who need this have no framework today, and the vendors who would game it were already ahead of them.
What survives is the part that costs money to fake. A vendor cannot fake an egress-blocked demonstration. Nor can it fake a sub-processor schedule its own lawyers have signed, because misstating sub-processors in a data processing agreement is a breach of contract with consequences. If I could keep only two tests, I would keep 4 and 7.
The harder limitation is mine. This framework treats sovereignty as a property of one vendor relationship, when the real exposure is usually the total. An organisation with a local core system, a foreign transcription tool nobody logged, a browser extension three people in finance installed and a customer service bot from a fourth supplier has no sovereignty position at all. I have watched an institution pass every test on its flagship AI system and still send its most sensitive material through a note-taking app that joined meetings uninvited. In the organisations I have worked with over the past two years, the inventory that would have caught that usually did not exist until we built it.
Four costs of a wrong label
Data residency you cannot evidence. A prompt containing customer records or board papers sent to a foreign endpoint is a cross-border transfer. Jamaica's Data Protection Act, Barbados' Data Protection Act and similar laws across CARICOM treat that as a regulated act that needs a lawful basis and, usually, documentation. Your compliance officer will be asked for a data flow diagram. If the vendor cannot say where inference happens, the diagram cannot be drawn, and a technical detail becomes an audit finding.
Regulatory exposure that follows the data. Any organisation serving EU customers, or supplying a client that does, is within reach of the EU AI Act, where penalties for prohibited practices run to €35 million or 7% of worldwide annual turnover, and other breaches to €15 million or 3%. GDPR fines reach €20 million or 4%. For a mid-sized Caribbean institution the likelier risk is a supervisory finding that governance over a material third party was undocumented. That is much easier to trigger and harder to explain to a board.
Continuity you do not hold. A rebranded product inherits every provider decision: a model version retired, an acceptable-use change, a regional access restriction, an export control order. Any can land without notice, and your vendor's service agreement will call the outage outside its control, correctly. If an AI system sits inside a process you cannot run by hand, that dependency needs its own line in your business continuity plan.
Prices you cannot negotiate. When the upstream price moves, your vendor has no cushion and nothing to bargain with. Multi-year budgets approved on per-token products carry a pass-through risk nobody at the table priced. The vendor's refusal to hold a price at volume is often the first reliable signal about the architecture underneath.
Checks for individuals using consumer apps
Consumer apps now carry the same claims: local AI, private AI, runs on your device. Three checks cover most of it:
- Read the privacy policy for names of third parties. A policy that promises security and encryption and names nobody has told you nothing.
- If an app says it runs on your device, switch on aeroplane mode and ask it a question. It takes ten seconds.
- Keep national ID numbers, medical detail and banking credentials out of free assistants. Assume what you type may be kept and read by a human reviewer, because in many products it may be.
In any investment pitch, treat "proprietary AI" or "sovereign AI" as a warning. Regional regulators have issued alerts about this pattern, and the technology language does the job that "offshore" and "hedge fund" did in older schemes.
Before You Sign
- Named locationWrite the inference location, the operating entity and the region into the contract, not the proposal
- Sub-processor listComplete, with advance notice of changes and a right to exit without penalty when one is added
- Audit or attestationA right to verify where processing occurs, or an independent attestation you can hand a regulator
- Exit termsExport of your data, prompts, embeddings and any fine-tuned artefacts in a format you can use elsewhere
- Price protectionA cap on pass-through increases, or a right to leave when upstream pricing moves beyond an agreed band
- Egress testA pre-signature demonstration with outbound access to foreign model providers blocked
"I am not asking anyone to stop buying foreign models. I use them. I am asking buyers to know which one they bought, because the version of this that ends badly is not a bad product. It is a board that told its regulator the data stays here, in good faith, because that is what the brochure said."- Adrian Dunkley, AI Boss
What I would do on Monday
- Risk or IT lead: build the AI inventory within 30 days. List every AI product in use, including the ones nobody procured, with a named owner for each. Its length is usually the first finding.
- Procurement: send one email this week. Ask every AI vendor on the list for its current sub-processor schedule, and flag any that have not replied within ten working days.
- Risk committee: require Test 7 for regulated data. Make an egress-blocked demonstration a condition of signature or renewal for any system that touches customer, patient or payment data.
- Legal: add the six "Before You Sign" clauses to your standard AI contract. Use them in every new AI purchase and at each renewal.
- Business continuity manager: list foreign-model dependencies. For each AI system inside a process the business cannot stop, write down the manual fallback and how long you could run on it.
- Board: name one owner. Give a single person the standing to ask for the sub-processor list and the training to read the answer.
That last point is the argument behind the AI Officer Programme I teach through StarApple AI. The Caribbean AI Risk Management Council has published a risk-register version of this diagnostic in the format audit committees already use, and the Caribbean AI Association has argued that this disclosure should be a regional procurement standard, not a favour each buyer negotiates alone.
Frequently Asked Questions
Which Caribbean countries have data protection laws that cover sending prompts abroad?
Jamaica's Data Protection Act 2020 has been in force since December 2023, and Barbados' Data Protection Act 2019 is in force. The Bahamas, the Cayman Islands and several other territories have their own statutes, while Trinidad and Tobago's Data Protection Act 2011 has been only partly brought into force. Each regulates transfers of personal data outside the country, so check the current text and your regulator's guidance for the jurisdictions you operate in.
Is there a major cloud region in the Caribbean?
None of the three largest cloud providers operates a full region in a CARICOM state; the nearest are in the United States and Latin America. So hosted inference from AWS, Azure or Google Cloud normally leaves the country. Local data centres and colocation facilities exist in several islands and are the usual home for a self-hosted model.
Which open-weight models can a Caribbean organisation run itself?
Families such as Llama, Mistral, Qwen, Gemma and OpenAI's gpt-oss publish downloadable weights. Their licences differ: some are Apache 2.0, others carry use restrictions or attribution terms, so have a lawyer read the licence for the exact model version. Smaller models in the 7 to 14 billion parameter range run on a single modern GPU server once quantised.
How is data residency different from sovereignty?
Residency is about where data is stored and processed. Some foreign providers now let customers choose a processing region, which can fix where the data sits. It does not change who owns the model, who can switch it off, or whose export controls apply, which are the questions sovereignty adds.
Who pays for an egress-blocked test, and how long does it take?
Ask the vendor to carry the cost, as it would for any proof of concept, and allow a few weeks' notice. Your side needs a network or cloud tenancy where you control outbound rules, and someone to watch the firewall logs during the session. A half-day demonstration with your own prompts is usually enough.