In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. That question is now moving into AI, and most sovereign-AI debates answer the wrong version of it. The operative question is narrower: Once AI is embedded in public services, who controls the stack? The 5 layers of public-sector controlFor a CIO, sovereign AI means enforceable control across the AI lifecycle; model ownership is a separate question. Control has five layers: