Sources and provenance — Who actually holds the controls

Sources and provenance for Who actually holds the controls · v0.2 · 8 September 2026

How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.

Status of these claims#

What this publication does not claim, and what is outstanding against it in the register.

Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.

What this publication rests on, and how solid each part of it is. Who actually holds the controls is an essay, and this page describes it as one.

What it cites from outside#

This publication cites outside sources, and they are listed below — each with what it supports, and with what it does not support. That second column is the one that matters: the common failure is not a fabricated source, it is a real source stretched past its finding.

NVIDIA, Sovereign AI (vendor’s own public page)

other

Supports. Quoted definition — “a nation’s domestic capability to produce artificial intelligence using its own infrastructure, data, workforce, and business networks,” goal “to protect and preserve local languages, values, culture, and history” — used to show the vendor definition of sovereignty covers productive capacity only.

Does not support. “There is no term in it for who may inspect the system, no term for who may change what it is permitted to do, and no term for who may stop it.” Does not establish or address institutional authority.

Microsoft Sovereign Cloud (Microsoft’s own documentation)

other

Supports. Quoted: “a suite of capabilities and deployment models designed to help governments and regulated industries meet stringent data residency, compliance, and operational sovereignty requirements without sacrificing the benefits of hyperscale cloud innovation”; and Microsoft’s own concession that the strongest tier “don’t deliver the full cloud value” — used to show even the vendor treats sovereignty as a purchased trade-off.

Does not support. Describes control tiers and trade-offs, not who may inspect, change, or stop the system on the institution’s behalf.

⚠️ Retrieval. ⚠️ Post-cutoff. “The page carries a July 2026 date and is post-cutoff.”

Microsoft Azure Local, disconnected-operations documentation

other

Supports. Quoted: “when you run disconnected, data, operations, and control remain within your organization’s boundaries,” set against its own eligibility terms (“You need an eligible agreement with Microsoft,” active support plan required, “valid business need,” approval within ten business days, annual capacity-based licence) — used to show technical control coexisting with supplier discretion over whether it may be run at all.

Does not support. Establishes the terms of this one specific offering, not that all sovereign-cloud products carry the same conditionality.

⚠️ Retrieval. ⚠️ Post-cutoff. “The pages carry 2026 dates and rest on retrieval.”

AWS sovereignty commitments (AWS’s own page)

other

Supports. Quoted: “additional access restrictions that limit all access to customer data unless requested by the customer or a partner they trust,” and the ability to “sustain operations through disruption or disconnection” — used, with NVIDIA and Microsoft, to show vendor definitions concern control over assets rather than authority.

Does not support. “Again there is no term for authority.” Does not address inspection, alteration, or stopping rights.

French Senate commission of inquiry into public procurement, testimony of Anton Carniaux (Microsoft France), 10 June 2025, the Senate’s own record

evidence

Supports. Sworn answer, quoted: “Non, je ne peux pas le garantir, mais, encore une fois, cela ne s’est encore jamais produit” (No, I cannot guarantee it, but that has never yet happened) — used as the strongest evidence that residency is not authority, since French-held data remains reachable by US legal process the institution cannot resist.

Does not support. “The qualifier is on the record and it matters: no such transfer is claimed to have occurred.” Establishes structural exposure, not that any transfer has happened.

Te Kāhui Raraunga, Māori Data Governance Model — Tuia te korowai o Hine-Raraunga, 2023, authored by Kukutai, Campbell-Kamariera, Mead, Mikaere, Moses, Whitehead and Cormack

framework

Supports. Quoted: Māori data sovereignty “extends beyond mainstream concepts of data sovereignty which are primarily concerned with data residency and jurisdiction,” under the banner “Māori authority over Māori data” — cited as the body that made the authority-vs-location argument before this series did.

Does not support. Cited for the general authority-vs-residency argument, not as an AI-specific governance instrument (that is the 2025 companion framework).

Māori Artificial Intelligence Governance Framework, 2025, contributed to by Chris Cormack, Erena Mikaere and Te Taka Keegan

framework

Supports. Quoted on cloud jurisdiction risk (“Both the USA and China assert jurisdiction over data stored by companies headquartered in their respective countries”) and “Māori authority over data regardless of storage location or AI processing jurisdiction” — used to extend the authority-vs-residency argument into AI and as the source of the fifth of the five questions (decommissioning as a partnership decision).

Does not support. The document records but does not itself adopt the framework’s further position that Generative AI “built on Māori data but not built by Māori should be prohibited” — flagged as “worth recording rather than softening,” not asserted by this series.

Te Mana Raraunga, 2016–18 principles (Māori Data Sovereignty Network)

framework

Supports. Named as the specific document Dr Karaitiana Taiuru’s 2025 critique concerns — used to distinguish a critique of a document from a critique of the organisation.

Does not support. The document is explicit that a critique of these 2016–18 principles “is not a critique of a body, and this series does not conflate the two”; Te Mana Raraunga as a network “remains active” and held a 2025 hui.

Dr Karaitiana Taiuru’s critical analysis of 20 September 2025

paper

Supports. Cited for the finding that Te Mana Raraunga’s 2016–18 principles do not reach “AI bias, training sets, predictive policing or digital colonialism,” and are “largely not implemented in practice” despite academic influence.

Does not support. A critique of one set of 2016–18 principles; not evidence about Te Mana Raraunga as an organisation today.

EU AI Act, Article 14(4) and Article 26(2)

regulation

Supports. Quoted: Art.14(4) requires a person able to “decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output” and to “intervene… or interrupt the system through a ‘stop’ button…”; Art.26(2) requires deployers to “assign human oversight to natural persons who have the necessary competence, training and authority” — used as a genuine legal answer to part of the fifth of the five questions.

Does not support. “It governs the relationship between the overseer and the system, not between the institution and the vendor. A stop button that halts a system the supplier can restart, or withdraw, or alter, answers a smaller question than the one asked here.”

NIST AI Risk Management Framework

Supports. Cited as asking organisations “to establish mechanisms to supersede, disengage or deactivate systems performing inconsistently with intended use.”

Does not support. “The assumption is that the deploying organisation possesses the technical ability; the framework has no occasion to ask whether a third party could countermand it.”

EU Data Act, Article 23

regulation

Supports. Quoted: requires providers to remove “pre-commercial, commercial, technical, contractual and organisational obstacles” to switching provider and porting data “including to on-premises infrastructure,” with functional equivalence — described as “the single most useful existing lever an institution has.”

Does not support. “It concerns data portability rather than agent governance, and the AI Act does not cross-reference it” — and it is a statutory answer available to a European institution, explicitly “not” to an American one.

NIST SP 800-53, control IA-9 (Service Identification and Authentication)

standard

Supports. Cited as the nearest thing to a requirement that an AI agent hold an identity of its own — “requires that system services and applications be uniquely identified and authenticated before communicating.”

Does not support. “It appears in no baseline. Not Low, not Moderate, not High, not Privacy, not the operational-technology overlay.” Existing does not mean applied.

⚠️ Retrieval. Document flags its own search limit: “Two searches were run for it, both keyword-based… which means they shared an assumption… The finding is therefore: no requirement was found. It is not: none exists.”

What it derives from#

Foundational documents. These are positions this project has taken, not findings.

Record What it is Status
CON-02 The sovereignty test draft v0.1

Evidence#

None. This publication references no evidence record. That is the correct description of what it is rather than a gap: it is an essay, reasoning from the foundational documents above rather than reporting a measurement. Where it states a number, that number is marked in the text as what it is.

Also referenced#

Record What it is Status
CON-03 Member ownership of member infrastructure draft v0.1
CON-11 Enumerated dependency draft v0.1
FIG-27 Five gates, and who can open each drawn for this publication · figures/FIG-27.svg

Generated from the corpus, not written by hand: this page cannot claim a source the corpus does not hold, and it changes when the records do.

Alongside: the publication · questions and answers