Definitions and terminology
Use sovereignty, privacy, residency, control, portability, and assurance precisely.
A controlled, versioned foundation for designing AI systems whose boundaries, dependencies, behavior, and evidence can be understood and verified.
The public layer is designed to be useful on its own. Structured programs, production-grade labs, answer keys, maintained compatibility matrices, and customer-specific patterns remain part of private delivery.
Public scope
Use sovereignty, privacy, residency, control, portability, and assurance precisely.
Separate workload, control, evidence, supply-chain, and operational responsibilities.
Map actors, data flows, import paths, runtime zones, egress, tools, and approval points.
Reason about model, retrieval, artifact, identity, prompt, tool, and operational abuse paths.
Turn architectural intent into testable technical and operational control objectives.
Record what was approved, deployed, evaluated, changed, and observed.
SAI-100 · Version 1.1.0
Establish the vocabulary, deployment boundaries, shared responsibilities, and control objectives needed to reason about sovereign AI systems.
Scope purpose, actors, assets, data, models, dependencies, and environment.
Show where trust changes and where information or control can cross.
State what must be prevented, allowed, observed, approved, and retained.
Identify how each material decision and control can be verified.
Turn gaps into prioritized technical and operational work.
Core principle
A system becomes more sovereign as the organization can make, enforce, verify, and change material decisions across the dimensions below.
Location, access, lineage, retention, and allowed movement
Provenance, licensing, packaging, evaluation, approval, and retirement
Runtime boundary, dependencies, identity, networking, storage, and hardware
Updates, observability, reliability, incidents, capacity, and recovery
Decisions, configurations, hashes, evaluations, audit events, and verification
Reusable starter artifacts
These are editable starting points, not completed evidence or production approval records.
Shared module registry
Every module declares visibility, content maturity, and verification separately. An outline in the registry does not mean a complete lab or assessed program is available.
Establish the vocabulary, deployment boundaries, shared responsibilities, and control objectives needed to reason about sovereign AI systems.
Model data flows, actors, assets, attack surfaces, trust zones, and risk scenarios for private AI workloads.
Design vendor-neutral architecture layers, deployment patterns, assurance points, and decision records.
Control the import, verification, approval, storage, promotion, and offline build of AI software and model artifacts.
Evaluate model fit, licensing, provenance, packaging, approval, updates, and retirement inside a controlled lifecycle.
Select and operate model runtimes, routing patterns, hardware profiles, capacity controls, and reliability targets.
Build grounded retrieval with controlled ingestion, citations, access enforcement, evaluation, lineage, and safe no-answer behavior.
Propagate identity and enforce inspection, DLP, routing, endpoint, and response policies at controlled AI boundaries.
Turn policies and control objectives into verifiable runtime, release, decision, and audit evidence.
Measure workload health, behavior, evaluation quality, capacity, cost, incidents, and operational evidence.
Operate restricted AI workloads with controlled networking, storage, GPU access, security contexts, updates, backup, and recovery.
Constrain agent tools, identity, memory, approvals, execution, and signed action evidence.
Publishing boundary
Apply the knowledge
Use the Body of Knowledge independently, or discuss a private cohort and customer-hosted lab aligned to your roles, architecture boundary, and implementation backlog.
No public checkout, account, or sensitive architecture upload required