Making Fetch a Thing
Sovereign AI is now having its moment – at the Enterprise level.
There’s a particular moment when a phrase stops being something a few people say and becomes something everyone says. Marketers chase it, founders pray for it, and most of the time it simply refuses to arrive. In Mean Girls, Gretchen spends the whole movie trying to make “fetch” happen, until Regina finally tells her to stop, because it is never going to happen. That’s the usual ending. The saying dies in the small crowd that liked it first.
“Sovereign AI” was Gretchen’s fetch for the past few years, because it just didn’t matter to most people. The term lived in geopolitics: Gulf states buying compute campuses, Brussels drafting EuroStack white papers, ministries worrying about where the GPUs sleep at night. But pitching sovereignty at the enterprise level – on-premises deployment, managing your own models, no IP leaks, cost optimization – mostly earned you a polite glaze. I’ve given that pitch, a lot, and I can report the glaze firsthand.
Why the cold shoulder? Because enterprise AI just had not yet matured enough. Since the dawn of ChatGPT, companies have wanted to move fast, and nobody got fired for buying the proprietary API and getting as many people as possible to use it. Enterprise sovereignty reads as paranoia with a hosting bill.
Then Alex Karp went on Squawk Box last Wednesday and said the jig is up. Enterprises are burning money on frontier-lab tokens, getting nothing back, and surrendering their IP along the way. Told he sounded angry, he explained the anger wasn’t his; he was channeling the voice of American business. Palantir’s sovereignty manifesto went around X. The All-In crew spent an episode declaring him exactly right, and by Friday, every analyst in America was telling every CEO in America to watch the clip. After years of nobody caring, the American enterprise reached a consensus in a week.
Sovereign AI, our new fetch, happened. And the reason it happened is the whole story. Enterprise use of AI has matured, and the threat model has flipped. Sovereign AI used to be insurance against your adversary. Now it’s insurance against your vendor, because the moment enterprises started suspecting the token stream was teaching a frontier lab their own business, sovereignty moved from the geopolitics panel to the risk register. Karp changed what the word protects against, and in doing so turned a nation-state abstraction into a line item the CFO actually cares about.
Some receipts arrived last week to support this. Chamath’s 8090 ran a real enterprise task through four configurations and found an open-source model inside their harness came in 16.4x cheaper than the frontier alternative. Coinbase cut its AI spend nearly in half by defaulting engineers to open-weight models. The analysts re-sized on cue: McKinsey now puts sovereign AI at $600 billion by 2030, with up to 40 percent of AI workloads headed to sovereign environments, and Gartner expects 65 percent of governments to mandate sovereignty requirements by 2028. The commercial world caught up for commercial reasons, which is how these things always actually happen.
What sovereign actually means for the enterprise
For decades the deal on enterprise software ran backward. You bought a vertical SaaS product and reshaped your process to match its object model. You stood up a data warehouse and paid a toll every time you wanted your own data back. More recently you picked a model and prayed the vendor didn’t change the terms, the price, or the weights underneath you. Every layer asked you to bend. That’s the tax nobody put on the invoice, and “sovereign AI” is mostly a new name for finally refusing to pay it.
So write the definition down plainly, because the people selling sovereignty this week have every incentive to keep it vague. Sovereign, in the enterprise sense that matters, means five things working in concert. Model-agnostic, so you route to whatever is best or cheapest this quarter and swap it next quarter without a migration. A flexible data layer, where your semantic model is yours and portable rather than compiled into someone’s platform. Cloud, on-premises, and edge, so the same system runs in a hyperscaler, in your own racks, or on a disconnected box, depending on the workload rather than the vendor’s preference. Data rights you actually hold, including a clean opt-out from your data training anyone’s next model. And agentic software that conforms to how your business works, instead of a product you contort your business to fit. None of that is paranoia. It’s the stack a competent CTO would draw on a whiteboard if no vendor were in the room.
Notice what’s missing from that list: ownership. You don’t have to own the frontier model, and you shouldn’t want to. You have to be able to leave it. Sovereignty is a set of exits, not a set of deeds.
Watch who’s selling fetch
Which is where the week’s loudest sovereignty champion gets interesting, because the platform doing the most to sell the word is also one of the harder ones to leave. Lock-in isn’t a character flaw. It’s gravity, and every successful layer of software develops it.
But name it evenhandedly. Karp asks who owns the weights when a lab trains on your workflows. Fair. The mirror question is who owns the application when your engineers build it inside an ontology, because workflows compiled into a semantic model don’t decompile, and the ontology is itself ten-to-fifteen-year-old technology, a very good answer to the data-integration problem of 2012 that agents increasingly route around rather than through.
The new Nvidia partnership delivers Nemotron models, on Nvidia silicon, through Palantir’s platform, which is three layers of single-vendor dependency sold as independence. They even named the offering a Sovereign AI Operating System, and the operating system is history’s most successful lock-in architecture. Sometimes a product roadmap is honest by accident.
None of this is sinister. Gravity is what Palantir’s shareholders pay roughly 230 times earnings for. But run the company through its own definition and it doesn’t clear the bar it set. Sovereignty as “own everything, from us” is the old dependency with better branding and worse exit terms. The tell is that Palantir already sells against its own pitch: Karp spent part of the interview touting their ability to switch between models, and switching is the portable definition of sovereignty, productized, one layer up. His product agrees with this essay in the places his manifesto doesn’t. Funny enough, The Onion made this call the day before the interview happened.
So what
Most of the week’s commentary missed the actual point. The armchair pundits graded Karp’s delivery, LinkedIn discovered the Zoomer phrase “crashed out”, and almost nobody wrote down what the moment means. What it means is that enterprise AI just entered a new phase, the one where a technology stops being a demo and starts being infrastructure, with all the messy adoption fights that implies. That’s not a reason for anxiety. It’s a reason to be excited.
If sovereignty means exits rather than ownership, then every layer of the stack has to compete for the customer on the merits, every quarter, forever. The model vendors compete on capability and price. The data platforms compete on how cheaply they let your data leave. The vertical apps compete on whether they still earn their seat once an agent can do the workflow without them. And the orchestration layer competes on whether it stays honestly model- and data-agnostic or quietly becomes the new lock-in with a friendlier logo. That competition is the whole prize. It is the first arrangement in the history of enterprise software where the buyer holds the leverage by design instead of by accident.
And the buyer can build this today, which is what’s actually new. The pieces exist. Open-weight models are good enough for most workloads and cheap enough to run yourself. Routing layers make model-swapping a config change. Data stays portable if you insist on it in the contract. On-prem and edge inference are real, not aspirational. An enterprise willing to architect for optionality can assemble proprietary models where they matter, open models where they don’t, a data layer it controls, and a harness shaped to its business, without surrendering the whole loop to any single vendor. The only thing standing between most companies and that stack is the habit of buying the bundle because the bundle is easier to buy.
Every company in this fight has incentives pulling toward some flavor of capture, mine included, and that’s fine, because it puts all of us in a real competition to deliver value instead of collecting rent. Sovereign AI isn’t a new category, and it isn’t a manifesto. It’s the enterprise stack we should have been able to buy all along, finally in reach because the models got cheap and the buyers got nervous at the same time.
Fetch is a thing now. The only question left is whether it becomes everyone’s or one company’s, and that gets decided by how people buy, not by who gives the best interview.



Fetch gives you the HTTP primitives, but the real win is when those primitives don't require a central choreographer, when the network itself handles request/response without a single point of coordination. That's when you get the resilience properties that matter: if one node vanishes, the fetch still completes. The question worth asking is whether we're building toward that or just optimizing the centralized call stack.