In August we took apart the sovereignty-washing playbook: AWS builds a German GmbH with euro billing and German staff, and one fact stays unchanged — the parent is a US company, the CLOUD Act reaches control rather than location, and a subsidiary is a phone call away from a federal warrant. That argument was about cloud. Yesterday it found its sequel.
On September 8, Palantir and Nebius announced a "strategic partnership" to deliver "a complete sovereign AI stack to Palantir customers." Palantir named Nebius its "preferred sovereign AI infrastructure partner." The line that matters, from the release: "bringing Nebius compute and inference endpoints inside the Palantir enterprise perimeter."
Read that again. The sovereignty product is a perimeter. And the perimeter is Palantir's.
Who Holds the Authorization Layer¶
Palantir's contribution to the stack is what the release calls its "Sovereign AI Operating System, built on AIP, Ontology, Foundry and Apollo" — which "provides the authorization and isolation layer." Strip the product names and this is a plain architectural statement: the component that decides who can access what, and what stays isolated from what, is Palantir software.
Whoever holds the authorization layer holds the system. That is not rhetoric; it is how the architecture works. An isolation layer decides isolation. An authorization layer decides access. If a dispute ever arrives — a subpoena, a contract termination, a pricing renegotiation — the party controlling that layer controls whether your deployment keeps running and who can reach your data. Location of the GPU is the visible layer. The authorization layer is the control layer. Palantir is a US-headquartered company on Nasdaq, and the CLOUD Act reaches US companies through control, not geography — the legal spine of the August post applies to the software layer the same way it applies to the subsidiary.
The CEO's own quote says the quiet part in vendor dialect: "Our ontology and their infrastructure will undergird the sovereignty our partners are demanding." Not your sovereignty. The sovereignty being demanded, which they undergird. Infrastructure you rent, governed by an ontology you didn't build and cannot inspect.
The "Control" Count¶
The release uses some version of "control" four times, and every instance performs the same substitution:
- Customers get "control over their compute, data, and models" — by accessing Nebius infrastructure through the Palantir perimeter.
- Palantir's OS "lets organizations train models on their own proprietary data, and retain control of their compute, their models, their data" — where the retention mechanism is the Palantir stack itself.
- "Retaining control of both their data and the resulting model" — while the model runs on inference endpoints inside someone else's perimeter.
- Karp: models run "under conditions you control" — conditions defined by the platform.
Compare with the pattern from the AWS European Sovereign Cloud: every visible attribute of sovereignty (residency, branding, local entities) arranged around an unchanged control layer (US parent, CLOUD Act jurisdiction). Here the visible layer is "you can run open models" and the control layer is Palantir's authorization software. The sovereignty is in the noun. The dependency is in the architecture.
The release's own vision statement is honest if you read it slowly: "open models and looped customer data create the smartest domain intelligence." Looped. Your data circulates continuously through the vendor's loop — that is the product. Data that sits still under your own roof, that you could walk away from with everything intact, is the opposite of a loop. A sovereignty claim built on a data loop is a retention claim.
"Trusted Infrastructure," and What the Word Is Doing¶
The second vendor in the pair deserves its own paragraph, because the language around it is doing work. Nebius is described as infrastructure you can trust — "run their optimized open models on trusted infrastructure," in Volozh's words. What the release does not mention: Nebius is Yandex N.V. renamed. The Dutch-registered holding company spun out of its Russian business in 2024, its founder Arkady Volozh was under EU personal sanctions from 2022 until the Council lifted them in March 2024, and the company re-emerged on Nasdaq as an AI cloud. None of that makes Nebius an unfit supplier of GPU time. It does show what "trusted infrastructure" is: a brand position, not a property. Trust in infrastructure is a function of ownership, jurisdiction, and auditability — three things a press release cannot confer.
Open Models Are Not Open Infrastructure¶
The deal leans hard on open-weight models, and that is the most seductive part of the pitch — because open weights are real sovereignty progress, and this site has defended them at length. But weights are one layer of a stack. In this offering:
- The models are open — inspectable, adaptable.
- The infrastructure is Nebius's — rented, not owned.
- The authorization and isolation layer is Palantir's — proprietary, uninspectable.
- The integration layer (Ontology) is proprietary — and it is the piece that sees all your data flows.
A stack where you can inspect the least privileged component is not an open stack. It is a proprietary stack with open decorations. The EU's own sovereignty-scoring instinct — the Commission's Cloud Sovereignty Framework, built to separate sovereignty claims from sovereignty facts — would score this deployment the way it scores the AWS GmbH: on the control layer, not the brochure.
There is also a specific AI-domain tell. Real open-infrastructure AI exists at every layer: open training data, open code, open weights, on hardware the operator owns. The Palantir/Nebius offer is "open models inside a closed perimeter" — which is the enterprise version of sovereignty theatre, priced for enterprises, gated by enterprises, and revocable by enterprises.
The Part That Touches Towns¶
One line in the release should interest every fire hall and city council that has recently been courted by a data-center developer: Nebius and Palantir "will work together to accelerate the deployment of new compute capacity... including through modular data-center deployments at sites where power is already available."
Modular data centers arrive where the power already is — which is how the industry has been describing its expansion into towns all year, along with the water disputes, the tax abatements, and the teacher-bonus press releases. If a modular AI data center proposal reaches your council, the question that decides whether your community gains anything is not who operates it. It is who owns it, who pays for the power and the water, and what the community holds when the operator leaves. A Palantir-and-Nebius-branded module on municipal power is the precise inverse of the Hoopa Valley model: infrastructure arriving in your town that your town does not control.
What Actual AI Sovereignty Looks Like¶
The August post listed the architecture that holds up under legal pressure: hardware you own, open code with no license dependency, backups you can restore, federation on your terms. AI adds one layer, and it is the layer communities can actually have:
- Open-weight models on owned hardware. This is no longer aspirational. Useful open models run on a single workstation or a used server, and our own AI lab runs them that way. The capability floor keeps rising while the hardware cost falls.
- Inference you can audit. An open inference stack on your machine has no authorization layer held by a vendor. There is no perimeter to be inside of, because the perimeter is the box you own.
- Data that does not need a loop. The Palantir product requires data in motion through their ontology. Most community workloads — records, minutes, member communications — need data at rest, under the community's legal control.
None of this is the enterprise product. That is the point. The Palantir/Nebius stack exists because enterprises have compliance budgets and a CLOUD Act problem, and it will sell well. Communities do not need a sovereign AI operating system with an ontology. They need a box, an open model, and the absence of a vendor between them and both.
The Question to Ask¶
When a vendor says "sovereign AI," ask the same question the cloud version earned: if a dispute arrives, who holds the authorization layer — and where is that entity headquartered?
For the Palantir/Nebius stack the answer is Denver-listed and unambiguous. Sovereign AI, as currently sold, means running Palantir. The communities that figure this out before their procurement officers do will save themselves a decade of rent dressed up as independence.
Sources: Nebius — Palantir and Nebius partner to deliver a complete sovereign AI stack to Palantir customers (primary source, Sep 8, 2026), Cryptonomist — Sovereign AI Infrastructure: Palantir Nebius Partnership Highlights, RFE/RL — EU Removes Yandex Co-Founder Volozh From Sanctions List, Wikipedia — Nebius Group. Legal analysis of the CLOUD Act and subsidiary control: see Sovereignty Washing Is Not Sovereignty and sources therein.