Sovereign AI

Not Your Weights, Not Your Product

The Rundown

The most useful thing in Sonya Huang's opening is what it does not claim. Sovereign AI is not a call to slash the subscriptions and go pure open source. It is a claim about what the product is: your product owns its behavior, which means it must own the things that shape that behavior. That restates the app-layer debate as a custody problem.

The keyword is custody.

In the crypto years there was a slogan for the DeFi faithful: not your keys, not your crypto. Huang recycles it for AI in one line. Not your weights, not your product. The analogy is precise, and it is worth taking seriously. Custody is not a religious stance. It is a risk decision about what happens when the holder of an asset changes the terms, disappears, or starts behaving like a competitor.

For an AI product, the model is the crown jewel. If someone else holds that model on their servers, your entire product is a lease: the features depend on someone else's roadmap, pricing, and policies. That is fine for a commodity input. It is a strange way to build a moat.

Not your keys, not your crypto. Not your weights, not your product. For Huang, a product is truly yours when you can control and custody the weights inside it. Sonya Huang

None of this means the labs are the enemy. Huang says it plainly: the frontier APIs are wonderful for coding agents, for desktop work, for the tasks where strength out of the box is what you need. Her argument is narrower and stronger: the bigger the share of product value that lives in intelligence, the bigger the share of that intelligence the company should own. She boils the reason down to one sentence: intelligence is too core, too fundamental of a property to just outsource.

Four forces, and the fourth is new.

Sequoia works with dozens of companies that now build their own AI. Across those bets, Huang lists the reasons the shift happens, and the last two have the most interesting history.

1 · Cost
Success raises your bill
The more your AI product works, the higher your AI COGS. Ironically, the most advanced AI deployers were the first to own their models.
2 · Speed
Small beats big
In coding and security, a small distilled custom model beats a giant general one because latency is what users feel.
3 · Performance
New for 2026
A year ago you owned models to save money. Now, tuned open models can outperform closed ones on your specific domain.
4 · Destiny
Your own legs
Anthropic and OpenAI have been strong partners. Companies still want an independent base to stand on.

The performance point deserves the emphasis it gets. Twelve months ago, picking open weights meant accepting you did not care that much about quality. That trade is gone. With open models now starting close to the frontier, a company with strong evals, a tuned harness, and its own data can land at better-than-frontier behavior in its own domain. Renting was a compromise then. It is becoming a strategic decision.

The race moved one level down.

The old model of the AI market was a treadmill race for the application layer: whoever wrapped a model in the best UI, workflows, and go-to-market won. Huang argues that framing is out of date. The labs are charging down into products, and the application companies are charging up into the training loop. Both sides meet in the same place: the intelligence layer.

That is why Pat Grady's application-layer slide now carries a different punchline. The fight is no longer about the wrapping. It is about who can shape the intelligence itself, and the product is the intelligence. Her phrase for the result is the one to remember: the application companies are the newest neo labs. The examples she names are Harvey, Factory, Glean, OpenEvidence, Semgrep, and Ramp, with applied research spanning evals, harness engineering, and new fine-tuning techniques.

The product is the intelligence. The battleground is no longer just who controls the UI and the go-to-market. It is who can own and shape the intelligence inside the product. Sonya Huang

For a founder, that reframes the question of who your competitor is. It's not the other wrapper with the same API calls. It's every builder who owns more of the model, the data, and the learning loop than you do. Renting intelligence is still fine. But it is worth knowing that you are competing against people who tune it.

Own or rent: four questions, not a creed.

Huang's framework is deliberately unheroic. Sovereign AI is not binary. You are never 0% or 100% sovereign, and the right answer is a line drawn capability by capability. Four factors decide where the line goes.

Should you own this layer?
1. Is it a meaningful share of COGS that grows with usage?
2. Is speed a P0 for your users (not just nice to have)?
3. Would tuning on your own data beat the off-the-shelf API?
4. Is the data that improves the model highly proprietary?
Own it
Post-train the weights, cap the COGS, keep the tuning data inside your walls.
Rent it
Frontier API plus a harness is still the best deal when out-of-the-box strength wins.

The working examples make it concrete. In coding, agent features are mostly rented today: they need strong out-of-the-box performance, and latency is not the deciding constraint. Tab autocomplete went the other way, custom models run on sovereign intelligence because those calls are constant, the wall-clock matters, and per-token cost racks up. Security companies own their models for speed and to post-train in bespoke ways. Biotech firms move to their own models because the training data itself is the moat.

Notice the momentum inside that list. The rentals shrink. What was rented five years ago, autocomplete, you now own. The line drifts, and it drifts toward owned.

Small team. Loud research.

The organizational counsel is contrarian. Most companies will be tempted to hand sovereignty work to the internal AI platform team, the group that already services everyone else, and that on the surface looks efficient. Huang says to resist it. Platform teams play defense. Intelligence work needs people playing offense: people who think on the frontier and produce research, not tickets. She points to examples where the leader came from either a research background or a hard engineering background, so there is no single resume for the job.

Scale is not the point either. Harvey, a company that has published a surprising amount of research this cycle, runs its research group with about seven people. Small de novo teams get very far, especially when they stand on the half-dozen vendors that now sell lab-grade tooling to everyone.

Then the part everyone underestimates: legibility. Right now every enterprise buyer is quietly choosing their AI champion. They hear the same pitch from every vendor and they are trying to guess which one is sophisticated enough to take them somewhere real. Published research is the tiebreaker. Huang's blunt version: legibility means excellent technical marketing. A separate branded research group, tasteful papers, honest benchmarks. In this market, research output is a procurement signal, and the teams that act like a lab are the teams that get chosen.

The roadmap is an unglamorous grind.

The technical path Huang lays out is deliberately boring until it isn't. Strategy first. Then evals, which she calls unglamorous and not fun, and exactly the part you want most of early. Then harness engineering, model routing, and context design. Then, where needed, post-training, and in rarer cases mid or pre-training. Then the final stage, the point of the whole exercise: an online learning system where live customer data makes the model better with every interaction.

The sharpest concrete example comes from the companion write-up: Harvey built a legal agent benchmark by converting real legal work into testable tasks. The numbers give you a sense of the scale of the grind:

1,200+
Agent tasks in Harvey's Legal Agent Benchmark
24
Legal practice areas covered
75,000+
Expert-written rubric criteria
~7
Researchers behind Harvey's published work

Her stack picture is the honest one. In a closed-model world, the whole architecture compresses into a frontier API call, an out-of-the-box harness, and some prompt work. That is a high floor and a low ceiling, because you can never feed your own production data back into the model. Open the box and the stack splits: production is now a harness mounted on a model you control, and the development stack is your evals, your domain data, and your learning loop. Pandora's box, she calls it. Lower floor, much higher ceiling.

Who is still renting.

The rallying call is persuasive, and a skeptic still has the last word in this one. Sovereign AI replaces dependencies rather than deleting them. The weights are open, but the chips, the serving infrastructure, the fine-tuning vendors, and the time of the seven-person research team are all still rented. A company that quotes "own the weights" has simply moved the rent further down the stack.

There is also a policy layer under the momentum. Huang notes the megaphone arrived fast: Karp urging enterprises to own their means of production, Nadella calling API purchases a double payment in money and revealed know-how, and Jensen Huang personally pushing to keep open-weight models available, which drew a wave of support. Open weights are championed by powerful companies with their own reasons: Nvidia sells the hardware those models run on, and Meta and others gain distribution and ecosystem leverage. So the open ecosystem is real, but it is subsidized. Treat it as durable engineering and not as a stable political guarantee.

What does not get subsidized is the loop: your evals, your harness, your domain data, the online learning that compounds on customer behavior. Those are yours to build even if you never touch a single weight. And building them is the part that actually decides the quarter, because they are what make the intelligence yours, whatever base model sits under it.

Bottom Line

Own your intelligence does not mean training your own weights. It means owning the loop: the evals that measure the system, the harness that controls it, the domain data that feeds it, the online learning that compounds on every customer interaction. That loop is what turns a generic model into a product with taste, and it is the part you can start building today without a single GPU.

The frontier labs will keep building the giant brains, and you should use them. The quiet commercial point of this whole event is the counterweight: the best product companies are growing their own little geniuses, fast, opinionated, and tuned to the work they see every day. In that world, the moat is not the API. It is the custody.