#030 - European AI independence is fiction. We do not have the model.
An energy executive once asked for every AI workload to run on infrastructure controlled in Poland.
The instinct was defensible. The price was not.
The proposal treated a public FAQ assistant, an employee knowledge tool, a finance workflow and an operational technology system as the same sovereignty problem. Maximum control was purchased for every workload. Nobody could show whether the extra cost bought a material reduction in risk.
The right AI sovereignty policy does not choose a single model. It decides which workloads earn which degree of control, and then pays for that honestly.
And underneath the pricing question there is a harder one the Poland proposal never reached.
Sovereignty you can buy. Independence you cannot, because we do not have the model.
The wrong denominator
Sovereignty is usually discussed as a property of a model. It is actually a property of a workload, its deployment path and the controls around it.
A European model running through a global control plane may fail a strict residency requirement. A US model deployed inside a controlled European environment may satisfy more requirements than its passport suggests.
Model origin matters, but it is not a substitute for checking where data is processed, who operates the service, who holds the keys, and how you exit.
One workload, or nothing is comparable
Most sovereignty comparisons fail before they begin, because each option is quietly measured against a different amount of work. Then the cheapest number wins an argument it never actually entered.
So fix the workload and never move it.
A thousand people. Twenty tasks each, on each of twenty-two working days. Every task sends in about ten thousand tokens, roughly a fifteen-page document, and gets back about five hundred, roughly a paragraph.
Multiply it through and you get 440,000 tasks a month. That is 4.4 billion tokens going in and 220 million coming back out. Every route below carries exactly that, which is the only reason any of the money columns can be compared.
The workload, held still
| 1,000 people Γ 20 tasks a day Γ 22 working daysthe whole company, every working day of the month | = | 440,000tasks per month |
| 440,000 tasks Γ 10,000 tokens inabout a fifteen-page document per task | = | 4.4Binput tokens |
| 440,000 tasks Γ 500 tokens outabout a paragraph per task | = | 220Moutput tokens |
| 4.62 billion tokens a month, spread evenly across the hoursevery route below carries exactly this, and nothing else | = | 1,800tokens per second, average |
Now the question most business cases skip entirely, which is whether the machine can keep up.
Spread evenly across a month, 4.6 billion tokens works out at roughly 1,800 tokens per second. Real usage is not evenly spread, of course. It lands in office hours. So call the busy-hour rate four to eight times the average, somewhere between 7,000 and 14,000 tokens per second.
A single server with eight H200 accelerators handles around 17,600 tokens per second at published reference throughput. So one machine covers this workload with room left over, and the thing that actually decides how big the server has to be turns out not to be speed at all. It is memory, because you need enough of it to hold the model.
That detail matters more than it looks. It means the sovereign cost below is a floor, not a meter. You buy the box to hold the weights, and then the box sits there costing the same whether you send it one task a month or four hundred thousand. Cloud is the opposite: you pay per token, so the bill tracks the work almost exactly. Everything strange in the table further down follows from that one asymmetry.
Set the floor before you choose
Then set a quality floor.
Mine is 25 on the Artificial Analysis Intelligence Index. Below that you are not choosing a cheaper model. You are choosing one that fails the task and sends the work back to a person, which is the most expensive outcome available.
Now apply that floor to the open-weight field, meaning models whose weights you can actually download and run on hardware you control. At least fourteen clear 25. Exactly one of them is European.
The European shelf is emptier than it looks
That one European model is Mistral Medium 3.5, which scores 30. Its licence is a modified MIT that says, in plain terms, that you may not exercise any rights under it if your company's global monthly revenue exceeded twenty million dollars last month. Not annual revenue. Monthly. And it attaches to your employer's consolidated revenue, not just your own entity.
Which excludes almost exactly the set of organisations that convene sovereignty programmes in the first place.
So look at what is actually left on the shelf once that model is set aside.
Mistral Large 3 is Europe's flagship open model. 675 billion parameters, genuinely Apache 2.0, genuinely downloadable, no revenue cap, no conditions. It scores 16. Mistral's best permissively licensed model, Small 4, scores 20. Both sit below the bar, and unlike the licence argument there is no quibble available here. The weights are free and the quality is not there.
Apertus, from ETH Zurich and EPFL, is the most genuinely open thing Europe has built. Open weights, open training data, open method, Apache 2.0. The 70-billion-parameter version scored 2. Its 2026 successor has not been benchmarked yet.
Aleph Alpha was Germany's national champion. It released Pharia under a licence restricting use to research and education, and in April 2026 it was acquired by Cohere, of Canada. Its founder's own summary of why: no European company can build a frontier model in isolation.
The publicly funded efforts are real and mostly permissively licensed. EuroLLM. Salamandra in Spain. Teuken from Fraunhofer. TildeOpen in the Baltics. PLLuM and Bielik in Poland. Not one of them appears on the index at all. OpenEuroLLM, the flagship European programme, has not released a model.
Now the comparison that should sting.
LG's K-EXAONE 2.0 is a 750-billion-parameter Korean model scoring 31, released under Apache 2.0 with no conditions attached. NVIDIA's Nemotron 3 Ultra scores 38. Inkling, from Thinking Machines, is 975 billion parameters at 42, also Apache 2.0. DeepSeek V4 Pro scores 53 under a plain MIT licence.
Korea and the United States both publish frontier-adjacent open weights that any European company may download and run tomorrow morning, without asking anyone's permission or signing anything.
We have no freely licensable open-weight model above a serious quality bar. Not one. No amount of infrastructure in Poland fixes that, because the missing ingredient is not a datacentre. It is a model. Sovereignty we can buy, and the rest of this issue puts a number on it. Independence is a different thing, and it is not on the shelf. This is the finding most sovereignty conversations never quite reach, because they start with where the servers will sit rather than with what will run on them.
1 Β· Sovereignty by workload
Four routes, one workload
Every row carries the identical workload, which is the only reason the money columns can be compared at all. Cost is shown per model rather than per tier, because on the cloud routes the choice of model moves the bill hard and on the sovereign routes it does not move it at all.
| Workload | Required route | Model | Intelligence | Per month | Per 1,000 tasks | vs cheapest |
|---|---|---|---|---|---|---|
| Tier 1Critical infrastructure and OTGrid control, safety systems, defence | Air-gapped, centralOpen weights only | Inkling975B / 41B active, Apache 2.0 | 42.3 | $33,900 | $77 | 5.3x |
| Nemotron 3 Ultra550B / 55B active, OpenMDW | 38.3 | $33,900 | $77 | 5.3x | ||
| Tier 2Core finance and material IPTrading logic, M&A strategy, proprietary R&D | Controlled privateOpen weights only | Inkling975B / 41B active, Apache 2.0 | 42.3 | $24,000 | $55 | 3.8x |
| Nemotron 3 Ultra550B / 55B active, OpenMDW | 38.3 | $24,000 | $55 | 3.8x | ||
| Tier 3Regulated core operationsERP and CRM logic, forecasting, code assistance | EU regional processingClosed cloud allowed | Gemini 3.7 FlashGoogle EU multi-region | 56 | $6,400 | $15 | 1.0x |
| Claude Sonnet 5AWS EU geo, standard price | 55 | $18,400 | $42 | 2.9x | ||
| Tier 4Enterprise knowledge and public-facingInternal search, reporting, support bots, web FAQ | EU regional APIClosed cloud allowed | GPT-5.6 SolOpenAI EU regional, 10 percent residency uplift | 57 | $26,100 | $59 | 4.1x |
| Gemini 3.7 FlashGoogle EU multi-region | 56 | $6,400 | $15 | 1.0x |
Tier 1
Critical infrastructure and OT
Grid control, safety systems, defenceTier 2
Core finance and material IP
Trading logic, M&A strategy, proprietary R&DTier 3
Regulated core operations
ERP and CRM logic, forecasting, code assistanceTier 4
Enterprise knowledge and public-facing
Internal search, reporting, support bots, web FAQBoth models in Tiers 1 and 2 show the same cost because both sit on the same node. Intelligence is the Artificial Analysis Intelligence Index for the exact variant named, audited 2026-08-24. It is a general capability screen, not a workload acceptance test. Every figure is rounded to the nearest hundred dollars, because the underlying hardware quotes span a thirty percent range and more precision than that would be invented. Cloud prices are list, before negotiated discount. Claude Sonnet 5 is at the standard 3 and 15 dollars per million, not the promotion ending 31 August 2026.
Tiers 1 and 2 are the ones that need downloadable weights. An air gap has no vendor control plane to phone, and a customer-operated private deployment cannot depend on one either. That rules out every closed model for those two tiers regardless of what it scores, which is why Tier 1 and Tier 2 top out at 42 while Tiers 3 and 4 reach 57.
Tiers 3 and 4 can use European regional cloud, where the closed frontier models are both stronger and, if you choose carefully, far cheaper.
Now read the last three columns properly, because they do two different things.
On the sovereign routes, the two models cost exactly the same. That is not a rounding artefact. It is the floor-not-a-meter point from earlier: the hardware is bought to hold the weights, so once the node exists the model running on it does not change the bill.
On the cloud routes the model choice moves the bill enormously. Gemini 3.7 Flash scores 56 and costs 6,400 dollars a month. Claude Sonnet 5 scores 55 and costs 18,400. GPT-5.6 Sol scores 57 and costs 26,100.
Read that last pair again. One point of measured intelligence, four times the price.
The bill is not the GPU
Now price the sovereign side properly, because this is where most sovereignty business cases quietly fall apart.
A sovereign node is not a server. It is a server, a room and a team.
The server is the easy part, and the part everybody costs correctly. Roughly 400,000 dollars for an eight-way H200 system delivered in Europe, spread over 36 months, plus ten percent a year for support.
The room is the part that gets forgotten. Power, at fifteen cents a kilowatt hour. Cooling, which is not a separate line here because a power usage effectiveness of 1.4 already carries it. Rack space, uninterruptible power, a generator, fire suppression, network and storage. For Tier 1, a cage and an access audit on top.
The team is the part that decides the answer. Air-gapped operation means no remote vendor support, an offline signed update pipeline, change-control evidence for a system sitting next to live operations, and physical access procedures. That is closer to two full-time engineers than to the three quarters of one a connected deployment needs.
And the cloud routes are not free of people either. Somebody still runs the evaluations, watches the monitoring and maintains the gateway. A quarter of a role, costed identically, so that both sides of the comparison carry their humans rather than only one side doing so.
2 Β· What each route actually costs
A server, a room, and a team
The same 440,000 tasks, priced four ways, with every line the buyer actually pays. The last two columns are both cloud routes at the same quality band, which is what makes the gap between them worth staring at. Tiers 1 and 2 run the same eight-way H200 node at roughly 400,000 dollars delivered in Europe. Cooling is not a separate line because PUE 1.4 already carries it.
| Line | Tier 1air-gapped | Tier 2controlled private | Tiers 3 and 4Gemini 3.7 Flash | Tier 4GPT-5.6 Sol | Layer |
|---|---|---|---|---|---|
| Hardware amortisation, 36 months | $11,100 | $11,100 | β | β | hardware |
| Hardware support, 10 percent a year | $3,300 | $3,300 | β | β | hardware |
| Energy, cooling included via PUE 1.4 | $1,100 | $1,100 | β | β | facility |
| Space, rack, UPS, generator, fire | $1,500 | $1,500 | β | β | facility |
| Network and storage | $1,400 | $1,400 | β | β | facility |
| Physical security, cage and access audit | $500 | β | β | β | facility |
| Token charges at this workload | β | β | $4,500 | $24,200 | tokens |
| People | $15,000 | $5,600 | $1,900 | $1,900 | people |
| Full-time engineers assumed | 2.00 | 0.75 | 0.25 | 0.25 | |
| Total each month | $33,900 | $24,000 | $6,400 | $26,100 | |
| Per 1,000 tasks | $77 | $55 | $15 | $59 |
People costed at a fully loaded senior platform engineer, 90,000 dollars a year. The cloud routes carry a quarter of a role for evaluation, monitoring and gateway work, so both sides of the comparison include their humans. The 0.75 for a connected on-premise deployment rests on published cost models. The 2.0 for air-gapped does not. It is the least evidenced number here and the one that moves the answer most. Run it at one engineer and the Tier 1 total falls to 26,400 dollars. Run it at two and a half and it reaches 37,700. I have used two, and it is a judgment rather than a measurement.
3 Β· Where the money goes
On one side servers, on the other salaries
Share of each route's monthly bill, same workload throughout.
Tier 1 air-gapped, 33,900 dollars
Tier 2 controlled private, 24,000 dollars
Tiers 3 and 4 on Gemini 3.7 Flash, 6,400 dollars
Tier 4 on GPT-5.6 Sol, 26,100 dollars
5.3 timesWhat the identical workload costs air-gapped inside your own perimeter, against the cheapest compliant European cloud route at a higher quality. Nearly half of that sovereign bill is salaries.
The bottom two bars are the same workload on the same kind of route, one index point apart in quality and four times apart in price. Sol carries almost nothing but tokens, which is exactly why picking it without doing this arithmetic is so expensive.
What this actually adds up to
Five things fall out of holding one workload still and pricing it honestly. The first is the one everybody expects. The rest are not.
One. Sovereignty costs about five times the compliant cloud route. The identical work runs for 6,400 dollars a month on European regional cloud and 33,900 air-gapped inside your own perimeter. That is 5.3 times, or roughly 330,000 dollars a year of difference. It is a real number and a payable one, and it is a great deal smaller than the numbers that usually get quoted in these conversations.
Two. Almost half of the sovereign bill is salaries, not silicon. Salaries are the single largest line in the Tier 1 bill, slightly ahead of the hardware everybody actually argues about and roughly three times the cost of the room. Which means the sovereignty premium is mostly a hiring decision wearing an infrastructure costume. Run Tier 1 at one engineer instead of two and the premium falls to about four times. Run it at two and a half and it rises to about six. I have used two, and it is the least evidenced number in this issue.
Three. Choosing the wrong cloud model costs nearly as much as sovereignty does. GPT-5.6 Sol and Gemini 3.7 Flash are one index point apart. On this workload Sol costs 26,100 dollars a month and Gemini costs 6,400. That is a 4.1x penalty for a difference in measured capability you would struggle to detect in production, incurred by a procurement decision nobody escalates, on a route nobody thinks of as expensive.
Four, and this is the one worth taking to your board. The wrong cloud choice costs more than the right sovereign one. Running GPT-5.6 Sol on a public European API costs 26,100 dollars a month. Running Inkling on hardware you own, in a controlled private deployment, with your own staff and your own keys, costs 24,000. The sovereign route is cheaper, and it is cheaper while also giving you control. Every organisation currently arguing about whether it can afford sovereignty should first check whether it is already paying more than sovereignty costs, for less.
Five. Sovereignty is buyable. Independence is fiction. Tiers 1 and 2 require open weights, and Europe does not have one above the bar that a large company may legally self-host. The best available options for a European sovereign deployment today are American and Chinese and Korean models running on American hardware in a European room. That is a genuine form of sovereignty. It is control over data, keys, and exit. It is not independence, and the two get conflated constantly.
What to actually do on Monday
Classify by control first, and be honest that most workloads land in Tier 3 or 4. Set a quality floor and hold it, because a cheap model that fails the task is the most expensive thing in the building.
Then price every candidate against one fixed workload, with the people counted on both sides. A cost per task only means something when every option underneath it is carrying the same work. And before you spend a year on the sovereignty question, spend an afternoon on the procurement one.
Your move.