Level 1, 2, or 3: Choosing the Right Sovereignty for Your Organization
A hospital and a marketing agency both need sovereign AI. They do not need the same kind. A defense contractor handling classified documents and a manufacturing company protecting product specifications operate under different legal obligations, different threat profiles, and different operational constraints. The SIA standard defines three sovereignty levels precisely because three genuinely different regulatory contexts exist — and deploying the wrong level is as expensive as deploying the wrong architecture, because the level is the architecture.
Before choosing between Level 1, Level 2, or Level 3, three questions must be answered: What data will the AI process? What regulations govern that data? What is the cost of a breach or audit failure? The answers to those questions determine the level. Budget follows from the level — the reverse does not work.
The Selection Framework
Four criteria determine the right sovereignty level for any organization. The first is regulatory requirement: what do applicable laws actually mandate? HIPAA — the US health privacy law that governs every healthcare provider and insurer — requires that protected health information not be transmitted to unauthorized parties, with penalties up to $1.9 million per violation category per year for willful neglect. GDPR requires that personal data of EU residents be processed under specific contractual, architectural, and geographic protections. ITAR — the International Traffic in Arms Regulations — prohibits any electronic transmission of controlled defense technical data without authorization.
Data classification is the second criterion: what type of data will the AI actually access? Patient records, client financial statements, classified technical specifications, and public marketing copy face different regulatory treatment. The AI is indifferent to classification — it will process whatever it can access. Sovereignty level determines whether that processing happens in an environment that satisfies the applicable requirement.
Risk tolerance — the third criterion — asks what the organizational consequence of a data breach or audit finding would be. TikTok's €530 million GDPR fine, issued by the Irish Data Protection Authority in May 2025 for transferring EU user data to servers outside Europe without equivalent protections, is one data point. EU AI Act enforcement in 2026 carries penalties up to €35 million or 7% of global annual revenue for non-compliant high-risk AI deployments. Each penalty scale translates to a minimum sovereignty level.
The fourth criterion is the operational model: which external AI access, if any, is appropriate for productivity purposes? Organizations with purely internal data flows face a different answer than organizations with mixed-sensitivity workloads where public research queries and confidential strategy work happen on the same platform.
Every organization can answer these four questions. The level that satisfies the strictest applicable criterion is the correct level.
Level 1: Hybrid Sovereign
Level 1 is the architecturally correct choice for most organizations. It is not a compromise. A Level 1 deployment uses the same four SIA components — Router, Vault, Recorder, Firewall — as Level 2 and Level 3. What differs is the perimeter policy: specific cloud AI endpoints are authorized for non-sensitive queries, while sensitive queries route to infrastructure the organization controls.
Think of the Router as a mail room that reads the sensitivity label on every envelope before choosing which courier to use. A query about formatting standards goes to a cloud model. A query referencing client negotiating positions stays local. The classification happens automatically, based on rules the organization defines. The cloud AI never sees the data that shouldn't leave the building.
A manufacturing company using AI for quality control documentation, general research, and internal communications is a Level 1 candidate. Most content is not competitively sensitive. For the content that is — trade process specifications, proprietary formulations — the Router classifies and routes it to local infrastructure. Level 1 deploys in 8–10 weeks and operates at 99.9% availability.
The critical distinction: Level 1 provides full sovereignty applied proportionately. An organization at Level 1 is not partially sovereign — it is sovereign for the data that requires sovereignty, and cloud-efficient for the data that doesn't. Getting this classification right is the primary governance mechanism. Which is also the primary risk: Router misconfiguration or query misclassification can route sensitive data to a cloud endpoint. For organizations where that risk is architecturally unacceptable — where the regulation requires more than a policy and a correctly-configured Router — Level 2 is the answer.
Level 2: Data Sovereign
Level 2 exists for organizations where data cannot leave the building — by law, not by preference. The same four components are present. The perimeter policy changes: zero data exits the organization's infrastructure, under any circumstances.
Take a hospital deploying AI for clinical documentation. Every patient record accessed by the AI is protected health information under HIPAA. Under HIPAA's Security Rule, the covered entity — the hospital — is responsible for demonstrating that PHI was not transmitted to unauthorized parties. A Level 1 configuration provides a policy that routes PHI queries to local infrastructure and architecture that enforces it. A Level 2 configuration makes external transmission technically impossible, not just policy-prohibited. That distinction closes the gap between "our policy prevents it" and "our architecture makes it impossible" — and it is the gap that determines audit outcomes.
The Recorder — the SIA component that logs every AI interaction with full context, immutably — exists at all three levels. At Level 2, it produces an audit trail demonstrating all AI processing happened on organization-controlled infrastructure. A HIPAA auditor asking "show me where the AI accessed PHI and whether it left your systems" receives a complete, architecture-enforced answer, not a configuration review.
Law firms face the same requirement under professional secrecy obligations. Once a client's litigation strategy flows through a cloud AI endpoint, professional secrecy is structurally compromised — not because the provider is malicious, but because the architecture permitted the transmission. Level 2 makes that transmission architecturally impossible. A legal technology vendor that can demonstrate Level 2 deployment wins contracts from law firms that require client confidentiality protections. Sovereignty, correctly configured, is a market access credential in regulated industries.
Level 2 deploys in 10–12 weeks and operates at 99.99% availability. The infrastructure investment above Level 1 is dedicated compute and storage. The correct cost comparison is not Level 2 versus Level 1 — it is Level 2 versus the cost of a HIPAA violation or GDPR enforcement action. That comparison resolves consistently.
There is a second-order benefit that compliance teams consistently underestimate. A financial services firm at Level 2 can deploy AI for credit analysis, client reporting, and compliance monitoring — use cases that a Level 1 configuration might not support under MiFID II or SOX audit requirements. The right sovereignty level does not restrict AI use. It unlocks the highest-value AI use cases the organization's regulatory context permits.
Level 3: Full Sovereign
Level 3 is required for defense, intelligence, and critical infrastructure where physical network isolation is mandated. Hardware, AI models, data, and logs are physically isolated. No internet connection exists. No external service access. The Firewall — which at Level 2 blocks unauthorized egress — at Level 3 is replaced by architecture that contains no network connections to block.
A defense contractor analyzing classified technical documents under ITAR faces a specific legal constraint: ITAR prohibits any electronic transmission of controlled technical data without authorization. "No unauthorized transmission" under ITAR does not mean "we monitor what leaves." It means no transmission pathway can exist for controlled data. Level 3 is the architecture that satisfies that requirement.
Level 3 deploys in 12+ weeks and operates under custom SLA arrangements. It is appropriate for defense, intelligence, and critical infrastructure. It is not appropriate for organizations that don't face those specific requirements.
The 'More Is Better' Mistake
Choosing Level 3 when Level 1 is appropriate is not conservative. It is wasteful, and the costs are real. Consider the organization that deployed Level 3 for a marketing analytics use case — maximum security for minimum-sensitivity data. Full air-gap preventing the cloud AI integrations the marketing team needed. Frustrated users who found workarounds. AI adoption effectively zero. The outcome: maximum sovereignty at maximum cost, with minimum compliance benefit and minimum productivity gain.
Over-engineering sovereignty increases budget consumption, extends deployment timelines, creates operational friction, and reduces AI adoption — without improving compliance outcomes for the data that actually required protection. Security clearance levels in defense apply exactly this logic: unclassified, confidential, secret, top secret. No one argues that all government data should be classified top secret because "more security is better" — it would make the system unworkable. The SIA levels apply the same calibrated-to-need principle that defense data classification has used for decades.
Level 1 is not a compromise. Level 2 is not an upgrade. Level 3 is not the goal. Each level is the correct architecture for a specific regulatory context and data classification. Getting the level wrong is as expensive as getting the architecture wrong — because the level is the architecture.
What All Three Prevent
In April 2023, engineers at Samsung pasted semiconductor source code into ChatGPT three times in a single month. Proprietary chip designs, test sequences, meeting notes — permanently on OpenAI's servers, outside Samsung's control. The incident would have been prevented at any of the three SIA levels. Level 1 would have routed source code queries to local infrastructure. Level 2 would have ensured all AI processing stayed within Samsung's environment. Level 3 would have made external AI access architecturally impossible.
All three levels prevent the Samsung outcome. What differentiates them is not whether sensitive data is protected — it is how much of the operational model the organization maintains locally, and which regulatory context each configuration satisfies. Samsung, as a technology company with mixed data sensitivity, belongs at Level 1 or Level 2 depending on the use case — not Level 3.
The Enforcement Timeline
EU AI Act enforcement is arriving in phases through 2025 and 2026. Article 26 of the EU AI Act places compliance responsibility on the organization that deploys the AI — not the company that built the model. A healthcare provider using a cloud AI tool for clinical documentation is the responsible deploying organization under Article 26, regardless of the provider's own compliance status.
Organizations deploying high-risk AI — the EU AI Act's category that includes healthcare diagnostics, credit scoring, and employment screening — without Level 2 or Level 3 infrastructure face a compliance gap that enforcement will identify. The audit trail built from deployment day is a different asset than the audit trail built from the day a corrective action began.
Level decisions made at deployment are rarely revisited voluntarily. An organization at Level 1 that grows into Level 2 requirements faces a real migration: architecture expansion, workflow redeployment, updated compliance documentation. Each workflow added to a Level 1 deployment adds to the migration scope if Level 2 becomes required. Getting the level right at deployment is not only cheaper — it is the only path that builds a defensible audit record from the beginning.
The Determinable Decision
Most organizations belong at Level 1. The organizations that need Level 2 generally know they do — their regulations have told them. Healthcare, financial services, and legal organizations subject to HIPAA, MiFID II, or professional secrecy obligations face requirements that determine the level. Defense and intelligence organizations subject to ITAR or national security classification requirements face requirements that determine Level 3.
Level selection is a compliance determination, not a budget optimization. The SIA standard specifies what each level provides. The applicable regulation specifies what each organization must provide. The correct level is where those two specifications meet — and it is determinable before deployment, not during an audit.
Organizations that align their sovereignty level to their regulatory context before the first AI workflow is deployed are the organizations that face enforcement from a position of documented compliance. The others face it from a position of remediation.