Microsoft Couldn't Answer That Question Under Oath

Microsoft Couldn't Answer That Question Under Oath

On June 9, 2025, Anton Carniaux, Microsoft's legal director for France, sat before a French Senate commission investigating public procurement and testified under oath. A senator asked him a narrow question. Could he guarantee that data belonging to French citizens, held under French public contracts, would never be handed to United States authorities without French consent? He said he could not. He added that no such demand had ever been made. Both halves of that answer were honest, and the second half didn't help. The room had not asked whether it had happened. The room had asked whether it could. The answer was that a company operating under U.S. jurisdiction cannot promise otherwise, no matter where the servers sit or how the contract is written. That exchange is the sovereignty problem in one sentence. It is not a breach. It is a jurisdiction. The debate moved from cloud to AI, and got much larger What was a procurement argument about email and storage is now a national-strategy argument about intelligence itself. The Center for a New American Security's Sovereign AI Index tracked 184 government-backed sovereign AI initiatives across 67 countries and the European Union as of August 2026 — including 41 new projects launched in the first half of 2026 alone, more than governments launched in all of 2024. The money follows. McKinsey's December 2025 analysis put sovereign AI on track to become a $600 billion market by 2030, and found that 71% of the 300 executives, investors, and government officials it surveyed called sovereign AI either an existential concern or a strategic imperative. And the reason for the urgency is a distribution problem. Oxford researchers found in 2025 that only 32 countries host an AI data center at all. More than 150 countries host none. The United States and China together operate over 90% of the world's specialized AI compute. European companies operate six major AI computing hubs. American companies operate 87. Most of the world is renting its intelligence from someone else's jurisdiction. That was tolerable when the workload was storage. It is a different proposition when the workload is the reasoning a company or a country runs its decisions through. Sovereignty is four things, and most deployments only buy one Across the major frameworks — McKinsey, NIST, Cisco, HPE — the same four pillars keep appearing under slightly different names. Infrastructure sovereignty is the one everyone buys: compute, storage, and network inside a controlled environment. The test is whether an organization can point to where inference physically happens and prove it matches its regulatory obligations. Data sovereignty goes past storage residency to training-data provenance, inference routing, output logging, and the audit retention the local regulator actually requires. Model sovereignty does not mean training your own model from scratch. It means knowing what each model can see and do, and being able to swap it out without rebuilding everything around it. Operational sovereignty is who can access the system, change its configuration, and audit its behavior. This is the pillar most enterprise AI deployments quietly fail, and it becomes the critical one the moment agents start taking actions on the organization's behalf. Buying a data center in-country satisfies the first pillar and none of the others. That is how an organization ends up with a sovereign address and a dependent architecture. Why "build the whole stack yourself" isn't the answer either The maximalist version of sovereignty — own every layer, from silicon to weights — is available to almost no one. The World Economic Forum and Bain projected in a January 2026 white paper that AI-dedicated infrastructure investment will grow 10–15% annually to more than $400 billion per year by 2030, with the U.S. and China alone capturing roughly 65% of global AI investment. Their conclusion was deliberately unromantic: sovereignty should be understood as strategic interdependence, not full-stack ownership. That reframing is correct, and it leaves a gap. If a nation or an enterprise is going to depend on infrastructure it does not wholly own, the dependency has to be structured so that no single party — vendor, host country, or attacker — ever holds enough to matter. Self-hosting is where most organizations stop. It answers "whose cloud is this." It does not answer "what happens when this one environment is compromised." A single point of failure is still a single point of failure when it belongs to you. Aphanarc is built around that gap. Rather than processing and storing sensitive data in one place, it atomizes compute, model execution, and data handling, so no single location ever holds the complete picture. There is no intact environment to subpoena, seize, or misconfigure, because the workload is never assembled into one. It does not resolve every sovereignty question — model provenance, export controls, and hardware supply chains remain their own negotiations — but it removes the structural condition that makes the others so consequential. The answer Carniaux couldn't give Carniaux was not being evasive in Paris. He was describing his architecture accurately. Microsoft can process French data in French data centers, under French contracts, with French staff, and still be unable to promise the outcome, because the data exists somewhere complete enough to be compelled. That is the question worth carrying into every AI procurement conversation now. Not whether the vendor is trustworthy — most of them are — and not where the servers are. It is whether the architecture on the other end is structurally capable of answering yes, or whether it can only offer a good record and a sincere assurance. A promise is only as good as the jurisdiction behind it. An architecture that never assembles the data does not need one. About Aphanarc Aphanarc is agentic AI for enterprises and privacy-focused users who can't risk proprietary data, internal expertise, or company knowledge being absorbed by centralized AI systems. Rather than routing workloads through a single centralized server, Aphanarc atomizes compute, model execution, and data handling by design. Sensitive information is never fully processed, stored, or reconstructed in one place, leading to private, safe AI. In development since 2024, Aphanarc gives organizations access to powerful, high-performance AI without paying centralized-cloud premiums or trading away privacy and control.

Original Source

Read the full article at Hackernoon →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.