← All posts / Industry

Your Data, Your Models, Your Decisions: Microsoft Formalizes Sovereign AI With a Nvidia-Co-Signed Framework

Microsoft has published a formal Sovereign AI framework built on four principles — control, choice, flexibility, resilience — split across Sovereign Public and Private Cloud tiers, with a Nvidia-co-authored white paper bundling Confidential Computing, NVIDIA AI Enterprise, Nemotron and RTX PRO as the reference stack.

Your Data, Your Models, Your Decisions: Microsoft Formalizes Sovereign AI With a Nvidia-Co-Signed Framework

Sovereignty has spent two years as the AI industry’s favorite talking point — invoked in every European procurement document, waved at every press conference, and defined by nobody. On October 5, 2026, Microsoft finally gave it a product architecture. In a company blog post authored by Didier Ongena, the company’s Public Sector & Sovereignty Leader, Microsoft formalized a Sovereign AI framework built on four principles, announced two deployment tiers — Sovereign Public Cloud and Sovereign Private Cloud — and published a white paper co-developed with NVIDIA that names a specific reference hardware and software stack. The slogan Ongena returns to throughout is blunt: “your data, your models, your decisions.”

The timing is not accidental. Sovereign AI has become one of the fastest-growing procurement categories in regulated sectors, with governments and enterprises across Europe, the Middle East and Asia demanding AI capabilities without surrendering jurisdictional control over data, models and operations. Oracle, AWS and European hyperscalers have all pitched their own answers. Microsoft’s move puts a formal brand and a named partner stack against all of them — and the choice of NVIDIA as co-author signals whose silicon the reference architecture is built around.

What Microsoft actually defined

The core of the announcement is a definition, and it is more precise than most. Microsoft defines sovereign AI as “the design, deployment, and operation of AI workloads under defined controls for data, access, governance, infrastructure, and operations.” Five control surfaces, explicitly enumerated — not a vague gesture toward “data residency.”

On top of that definition sits a four-principle framework:

  • Control — who can access data and systems, including administrative access, and where processing occurs.
  • Choice — the ability to select and change models without redesigning the underlying platform.
  • Flexibility — the ability to move workloads across cloud, data center and edge environments as requirements evolve.
  • Resilience — the ability to keep critical functions running when connectivity is interrupted or operating conditions change.

The framework’s most practical contribution is its insistence that organizations start from the workload, not the architecture. Ongena frames digital sovereignty as a “risk-management principle”: before choosing a deployment model, ask what data the workload touches, who needs access, what must keep working during a network disruption, and how easily models or infrastructure can be swapped later. For many workloads, the honest answer will be the public cloud. Others need infrastructure under the organization’s own authority. Some need to run fully disconnected.

Two tiers, one operating model

That spectrum maps to the two product tiers at the center of the announcement. Sovereign Public Cloud covers workloads whose control requirements can be met inside Microsoft’s public cloud through governance, encryption and confidential computing controls. Sovereign Private Cloud, built on Azure Local and Foundry Local, extends the same AI capabilities into environments that remain under the customer’s own authority — including connected, intermittently connected, and fully disconnected deployments.

The design goal, Microsoft says, is that organizations “should not have to reinvent their AI operating model for every environment.” A government ministry running inference at the edge and a bank running agents in a private data center should be able to share identity, governance and development tooling. Microsoft Foundry and Foundry Local carry the model-development layer across both tiers, supporting what Microsoft describes as a broad model ecosystem so teams can evaluate and swap models against workload requirements while keeping governance consistent.

Resilience gets unusually specific treatment for a vendor blog post. Microsoft advises organizations to identify which functions must continue during a connectivity disruption, which can pause, and what data or services each depends on — and then to “test those assumptions under the conditions the workload may actually face.” For critical infrastructure and defense-adjacent workloads, that is not abstract: it is the difference between a system that works on paper and one that works when the network does not.

The NVIDIA stack underneath

The white paper is where the announcement becomes concrete. Developed “with contributions from NVIDIA,” it bundles a specific reference stack: NVIDIA AI Enterprise for production AI software, frameworks and inference; the Nemotron model family and NVIDIA’s physical AI models as default model options; NVIDIA RTX PRO infrastructure for demanding inference, agentic and reasoning workloads at the compute layer; and NVIDIA Confidential Computing to protect sensitive data, models and AI workloads during processing — the layer Microsoft calls out as covering the full span “from the underlying cloud infrastructure to the applications running on top.”

Dave Salvator, NVIDIA’s Director of Accelerated Computing Product Marketing, is quoted in the post: “AI workloads will continue to become more capable and more distributed. Organizations need accelerated computing, software, and model choice that can follow those workloads across cloud, data center, and edge environments.” The subtext is the actual product story: the same NVIDIA hardware and AI stack runs across Azure and Azure Local, so a sovereign deployment in a customer-controlled facility is not a second-class citizen — it inherits the same silicon foundation as the public cloud.

Microsoft closes its argument on adaptability rather than geography: “Durable AI strategies will be built for change. Organizations need enough control to use AI confidently, paired with enough choice to keep adopting better technology, and an architecture that can adapt when requirements change.”

Analysis: packaging, but packaging that matters

The skeptical read is easy: this is largely packaging. Microsoft has sold sovereign cloud variants for years — its European sovereign offerings predate this announcement by a wide margin, and Azure Local already existed. No launch customer is named, no contract value is disclosed, no regulator has endorsed the framework, and the blog post itself does not specify pricing. The four principles are the kind of language any vendor could adopt tomorrow.

But packaging is precisely what sovereign AI has been missing. The category’s buyers — defense ministries, health systems, critical infrastructure operators, banks under DORA-style operational resilience rules — do not procure on principles; they procure on named SKUs, reference architectures and auditable control mappings. Formalizing “sovereign AI” into a two-tier product structure with a co-signed vendor white paper converts a diplomatic conversation into a line item. It also pre-answers the procurement question that has stalled many European AI projects: can we get frontier capabilities without depending on a US-headquartered public cloud’s standard operating model? Microsoft’s answer is now formally yes, at two levels of control.

Two open questions will determine whether this is more than branding. First, silicon: the reference stack as published is NVIDIA end-to-end, and Microsoft’s own material leaves unanswered whether AMD or custom accelerators will qualify for the sovereign reference architecture — a live issue given European strategic-autonomy politics and AMD’s active sovereign-cloud positioning. Second, disclosure: until Microsoft names a Sovereign Private Cloud customer in the European public sector, the framework’s disconnected-operation claims remain vendor assertions. For now, the move’s significance is structural — the largest US cloud vendor has stopped treating sovereignty as an exception to its operating model and started treating it as a product.