Sovereign AI

Know where your data is stored, and who can read it.

Sovereign AI means your information stays under Australian law, on infrastructure you can point to. For some work that matters a great deal. For other work it does not. We help you tell the difference.

Book a conversation (opens in a new tab)

In plain terms

Four questions to ask of any AI tool.

If a supplier cannot answer these clearly, you do not yet know what you are buying.

  1. Where is it stored?

    Which country holds your information, both while the tool is working and afterwards.

  2. Who can read it?

    Which people and which companies can see what you put in, including the supplier's own staff.

  3. Which law applies?

    If a foreign court or government asked for your information, whether the supplier would have to hand it over.

  4. Is it used to train anything?

    Whether what you type today improves a product your competitor uses tomorrow.

What has changed

Capable models can now run on your own hardware.

Until recently the best AI models were only available as a service from a handful of overseas companies. To use them, your information had to travel.

Open weight models have changed that. A business can now run a capable model on servers it controls, with nothing leaving the building.

This removes the sovereignty obstacle. It does not remove the data quality one. A private model fed poor information gives poor answers, privately.

What we do

We design private systems, and we run our own.

SAS Asset Management owns and operates GPU servers in Australia. We use them for our own analytics and AI work, which is how we know what it takes to keep one running.

For clients, we design systems that run privately: on your premises, or on Australian infrastructure that you or we control. The design sets out what runs where and why.

Where information is covered by the Privacy Act, critical infrastructure rules or a customer contract, we start from the obligation and work back to the architecture.

In practice. Client data files are processed on local equipment. They are never placed in a code repository, public or private.

An honest account

Sometimes a cloud service is still the right answer.

Most of our delivered client work to date has used a commercial cloud AI service, under contract terms that stop the provider keeping the information. For the work involved, that was the right call.

Private infrastructure costs more and needs looking after. For public information, routine drafting and early experiments, a well chosen cloud service is often cheaper, faster and safe enough.

What matters is that the choice is made on purpose, for each kind of information, and written down.

A starting point

Matching the information to the place.

Kind of informationExamplesWhere we would start
PublicMarketing copy, published policies, product descriptions.A commercial cloud service.
InternalMeeting notes, procedures, routine correspondence.A commercial cloud service with retention switched off, under a written policy.
ConfidentialCustomer records, staff records, pricing, contracts.Private infrastructure in Australia.
RestrictedInformation covered by regulation, security requirements or strict contract terms.On your premises, with nothing leaving the building.
A general guide only. Your contracts and legal obligations decide the detail, and we recommend your own legal advice.

Questions we are asked

Before you decide where it runs.

Is a private system as capable as the big cloud ones?

For many business tasks, yes. For the most demanding reasoning, the largest cloud models are still ahead. The design matches the model to the task.

Do we need to buy servers?

Not always. Private infrastructure can be rented in Australia. Buying makes sense when the information cannot leave your premises or the workload is steady.

Is an Australian data centre enough?

It answers where the information is stored. It does not answer who can read it or which law applies to the company that runs it. Ask all four questions.

Do you hold a security certification?

No. We maintain an information security management system aligned to ISO 27001, and we do not hold independent certification. We would rather tell you that than let you assume.

Next

Find out where your information sits today.

The readiness check includes two questions on exactly this. Or talk it through with us.