The tell is in the API. When Corti and the Danish Center for AI Innovation announced their sovereign AI control layer on 20 August, the headline feature for engineers was that it speaks OpenAI’s dialect. Drop-in compatible. Point your client at a different endpoint, keep your SDK calls, keep your prompts, keep your evaluation sets, and nothing in your backend logic ever learns that anything moved.
That is a peculiar thing to ship if the pitch is independence from American AI. It is exactly the right thing to ship if the pitch is something narrower, less romantic, and considerably more useful. Which I think is what is actually happening in Copenhagen.
The product is called Corti Models. DCAI operates Gefion, Denmark’s national AI supercomputer, and Corti is the Copenhagen clinical-AI lab whose Symphony model runs inside health systems including the NHS, covering north of 100 million patients a year. The two took Corti’s governance stack, built to survive medical regulators, and pointed it at general enterprise workloads. Trifork, the Nasdaq Copenhagen-listed software house with about 1,100 engineers across sixteen countries, signed on as first adopter and implementation partner. It is available now, and the first workload they are chasing is not some grand national language model. It is AI-assisted coding. Developers are burning tokens on proprietary codebases, with the codebase staying inside European jurisdiction and finance getting a consumption budget it can actually see.
Corti’s Andreas Cleve frames it as European enterprises needing the world’s best models without becoming dependent on any single provider. DCAI’s Martin Svensson talks about turning sovereign infrastructure into something a business can buy. Both statements are doing quiet work around a sentence in the press release that names no names: recent disruptions in access to frontier models have highlighted the risks of depending on a single external AI provider.
We all know which disruption that is. On 12 June, the US Commerce Department sent Anthropic an informed letter under export control authority, barring foreign nationals from Fable 5 and Mythos 5. Anthropic could not verify citizenship at the API layer, so it pulled both models globally within a day. Access came back on 1 July after the controls were lifted, but by then Macron had stood up at the G7 and said Europe would not buy models from companies that can be switched off from one day to the next. Eighteen days offline did more for European sovereignty procurement than four years of Commission strategy papers.
So when the announcement cites GDPR, NIS2, DORA, and the EU AI Act as the regulatory backdrop, I want to be pedantic about it, because those four don’t do the same job, and lumping them together muddies the argument. GDPR is about where personal data goes. The AI Act is about what you can deploy and what you must document. Those are the two everyone reaches for. But the ones that make this product make sense are the other two. NIS 2 pushed a cybersecurity floor across the continent and dragged supply chain risk into scope, and DORA, which governs financial entities, is built almost entirely around ICT third-party concentration risk and operational continuity. DORA does not care that your data stayed in Frankfurt. It cares whether a critical service you depend on can vanish and what you do in the hour after it does.
June was not a data residency event. It was a continuity event. A vendor your production pipeline depended on went dark because of a decision made in a foreign capital, and nothing in your contract, your DPA, or your regional endpoint selection said anything about it. That is the risk category Corti Models is priced against, and it explains why the deliverable is an abstraction layer rather than a model.
Which brings me to the part I keep chewing on, and where the approaches across Europe visibly diverge.
France has spent three years betting on the model layer. Build a champion, fund it, let it carry the flag, accept that the frontier is expensive. That bet has produced real things, and it has also produced the Mistral and Microsoft arrangement I wrote about in August, where the sovereign champion’s distribution runs through Azure. Germany went at the compute layer instead: Deutsche Telekom’s Industrial AI Cloud opened in Munich in February with roughly ten thousand Blackwell GPUs and half an exaflop, built with Nvidia and Polarise, positioned openly as the seed of a future gigafactory. Brussels went at the rules and the megaprojects, with nineteen EuroHPC AI Factories running, a gigafactory tender open until 12 November and awards not landing until early 2027, plus the Cloud and AI Development Act adopted in June, which for the first time asks bidders to commit to a European-controlled software stack. That last requirement is the most interesting thing the Commission has done in this space all year, and almost nobody covered it.
Denmark did none of that. Denmark went for the control layer, the thinnest and cheapest slice of the stack, and arguably the only one a country of six million can credibly own.
There is a decent argument that this is the smart move. Gefion is 191 DGX H100 systems, 1,528 H100 GPUs, sitting in a Digital Realty hall in Copenhagen on renewable power. It ranked 21st on the TOP500 when it lit up in late 2024. Against Munich’s ten thousand Blackwells or Mistral’s eighteen thousand Grace Blackwell superchips in Essonne, that is not a compute play, and DCAI is not pretending otherwise. The B300 cluster now going in is explicitly described as an inference platform for Denmark and the Nordics, not a training rig. Copenhagen has looked at the training race, correctly concluded it lost, and gone hunting for the chokepoint it can actually hold: the place where the enterprise decides which model gets which request, on whose budget, with what logging.
Here is my problem with it, and I have not been able to resolve it from the public materials.
Model-agnostic routing is only sovereign for the models whose weights are actually sitting on Gefion. If Corti Models is hosting open-weight models on Danish iron, then yes, a foreign export directive genuinely cannot reach them, and the layer does what it says on the tin. If it proxies requests to Anthropic, OpenAI, or Google with nicer governance wrapped around the call, then on 12 June that platform would have returned the same errors as everyone else, just with a Danish audit trail attached. The announcement says it lets enterprises access, manage, and deploy leading AI models, and supports sovereign cloud plus on-premises deployment, which is doing a lot of load-bearing ambiguity. My read is that it is both, and that the sovereignty guarantee is really a portability guarantee: when the American endpoint dies, you fail over to weights already resident in Copenhagen without rewriting anything. That is genuinely valuable. It is also a materially weaker claim than the word sovereign implies, and I would rather they said it plainly.
The 5 to 10x cost reduction is a vendor number, and I would not build a business case on it without an audit. Read closely, it is mostly not a compute-price claim anyway. It is a governance claim. Centralized budget control, one contract instead of six, engineers who can no longer quietly expense frontier tokens against an unmonitored card. Anyone who has watched a developer org discover agentic coding knows most of that saving is behavioral, not architectural.
And under it all, the hardware is Nvidia, the fab is TSMC, and the B300 is going in on the same allocation queue as everyone else’s. I called this rented sovereignty when Armenia did its version, and the label fits here too, though Denmark is being more honest about the scope of what it is claiming. Denmark also signed the EuroHPC gigafactory joint procurement agreement, so this is a hedge inside a larger dependency, not a replacement for it. The gap between sovereignty governance and sovereignty infrastructure has been the recurring shape of every one of these stories, and a control layer narrows it without closing it.
I am skipping the healthcare angle entirely here, which is a bit perverse given Corti is a clinical lab and Gefion was funded by the Novo Nordisk Foundation. The interaction between the AI Act’s high-risk regime, the medical device rules, and a routing layer that decides which model touches patient data is a whole separate post, and I do not want to do it badly in three paragraphs.
What I keep landing on is that this is the first European sovereignty product I have seen that is designed around the actual failure mode rather than the rhetorical one. The rhetorical failure mode is that American companies read your data. The actual failure mode, demonstrated in June with a letter, is that access is a lever somebody else’s government gets to pull. You do not fix a lever problem by owning the data. You fix it by owning the switch that decides where the request goes next, and by having somewhere for it to go.
Denmark bought the switch. Whether there is enough behind it when the lever gets pulled again is the part nobody can answer yet, and the enterprises signing up are betting there will be. European buyers have been retreating from that bet all year, so I will be watching who actually signs after Trifork. One implementation partner is a launch. Three is a market.
Sources
- DCAI and Corti Launch Sovereign AI Control Layer for European Enterprises, Trifork First to Adopt as Implementation Partner (Trifork, 20 August 2026)
- DCAI and Corti Launch Sovereign AI Control Layer on Gefion Supercomputer (HIT Consultant, 20 August 2026)
- Denmark Launches Leading Sovereign AI Supercomputer (NVIDIA)
- DCAI Becomes 1st in Denmark to Deploy NVIDIA DGX B300 for Gefion Supercomputer (HPCwire)
- AI sovereignty for Germany and Europe: Deutsche Telekom launches one of Europe’s largest AI factories with NVIDIA (Deutsche Telekom)
- EU Strengthens Sovereign Computing Infrastructure with AI Gigafactories (Telecom Review Europe)
- Europe’s software sovereignty requirements for AI Gigafactories and CADA (OpenNebula)
- Fable of the Mythos saga: Ad hoc US AI model controls could help China (PIIE)
- Austria urges Anthropic to move to the EU to avoid US controls (BankInfoSecurity)
- Denmark launches sovereign AI on Gefion to boost public sector (CFOtech)