AI sovereignty picked up several very different definitions this week, and the strangest one came from New Delhi, not Brussels.

Twenty-nine countries signed onto Beijing’s World AI Cooperation Organization in July, and not one of them is in the European Union. That fact did more work at this weekend’s BRICS summit in New Delhi than anything actually said from the podium. Xi Jinping pitched a China-led open-source AI community, offering seminars and joint model development to member states, and invited the room into the WAICO framework his government had already stood up two months earlier. The joint declaration from the summit didn’t even mention it, instead calling for vague international cooperation on AI resource access. Xi’s own pitch didn’t carry the room he was standing in.

Compare that to what Europe already wrote down. The AI Act’s exemption for truly open-weight models waives the technical documentation requirement, the obligation to supply it downstream, and the need to appoint an EU representative, provided the weights and architecture are actually public and the license allows real use and modification. That exemption has a hard stop at systemic risk, where every obligation applies regardless of license, and since August 2nd the European Commission has had the power to demand evaluations, restrict market access, and fine violators 3 percent of global turnover. I’ve been skeptical of plenty coming out of Brussels this year, the “Made in EU” industrial law that somehow never mentions software among it, but the AI Act’s openness ceiling is a real one. It’s written down, and reviewable in court if a company ends up on the wrong side of it.

China doesn’t have an equivalent line, and that’s not an oversight, it’s a live argument Beijing hasn’t settled with itself. Xi told the country’s own AI summit back in July that development and security need to stay balanced, and a state-linked social media account used to test policy positions has floated restricting the most capable model features from general release. China’s commerce ministry reportedly spent a month this summer debating whether to curb overseas access to Qwen, Doubao, and GLM, the same week its state security minister was publicly accusing unnamed countries of using “blacklists and closed ecosystems” to sever global AI supply chains. Beijing wants credit for openness abroad while it’s still arguing internally about how open it can afford to be at home. Z.ai already found out what that ambiguity costs, when nobody outside China could verify its claim that its cheapest model runs entirely on domestic chips.

What really stopped me was India, and it isn’t even trying to answer the same question. While Brussels legislates and Beijing courts allies, New Delhi’s Ministry of Electronics and Information Technology is rolling out a cloud sovereignty framework that skips the diplomacy entirely: physical air-gapping for mission-critical government data, full stop. No alliance to join, no exemption to qualify for, just a hard requirement that sensitive systems sit isolated from the public internet so a foreign hyperscaler’s compliance with the US CLOUD Act becomes irrelevant by construction. The Hindu Business Line reports MeitY has been working through this with domestic cloud providers for weeks, building out the parameters government entities will have to meet, and it lands as part of a broader Sovereign AI push that’s explicit about not wanting national digital assets hostage to any single provider’s stability or any foreign government’s policy shifts.

I don’t think India’s approach scales the way Europe’s does. Air-gapping mission-critical systems is a blunt tool: it produces no case law, gives nobody outside India’s government a way to audit whether the isolation is real, and does nothing for the much larger pile of non-critical government and commercial data still sitting on AWS, Azure, and Google Cloud same as before. Ryanair went all-in on Google Cloud the same month Airbus was pulling workloads off AWS specifically over CLOUD Act exposure, and that tension doesn’t disappear just because New Delhi solved it for one category of system.

Still, of the three postures on the table this week, India’s is the one that doesn’t depend on anyone else’s promise. Europe at least wrote its promise down somewhere a court can enforce, and Beijing hasn’t even finished arguing with itself about what its own promise should say. New Delhi skipped the promise altogether and built a wall instead, and that looks a lot less paranoid next to AWS shipping a flagship AI assistant that skips its own European sovereign cloud the same week. I’m not touching whether air-gapping actually holds up against a state-level attacker motivated enough to try, that’s a security research question I’m not equipped to answer from here. And Mistral hosting DeepSeek-architecture and GLM weights outright is its own reminder that the line between sovereign and foreign AI infrastructure was blurry before India drew a new one. Three governments answered the same underlying question differently this week, and the one that trusts nobody’s word is currently looking like the least naive.

Sources