# What AI Sovereignty Looks Like in Practice

> The operating model that lets regulated providers use AI without exporting their knowledge: classification, approved tools, audit trails, named accountability.

The quality manager from the start of this series needed thirty seconds and a tool that could tidy her wording. Any control that costs her more than that will be ignored.

That is the test most AI policies fail. They are written as documents: a list of prohibitions, a register nobody reads, an approval process that takes longer than the task it governs. Staff do not consult them at 9pm with a deadline. They paste.

Sovereignty is an operating model, not a policy document. It has to change what happens at the moment of the paste, which means it has to be built, not just written. Five moves do most of the work.

## Classify your data in three buckets

Most classification schemes die of their own precision. Ten categories with a matrix of permitted uses is a scheme nobody applies under pressure. Three buckets work: data that can go to any approved tool, data that can go only to tools your organisation controls, and data that never leaves your systems. Resident records sit in the third bucket. The wording of a public policy paragraph sits in the first. The middle bucket is the judgement call, and it is where the leakage from this series lives: incident summaries, rostering workarounds, funding interpretations.

## Make the approved path the easy path

Shadow AI exists because the sanctioned option is worse than the unsanctioned one. If the approved tool is slower or gated behind a request form, staff will use the better one in a private browser tab, and you will carry all of the risk with none of the visibility. The bar is simple to state: at least as good as the public one, and reachable in one step with sign-in already handled. This is a procurement and engineering decision, not a compliance one.

## Log the moment that matters

You do not need to log everything. You need to be able to answer, months later: what was the model given, what did it produce, and who signed off before it informed a decision about care or money. If AI touches a serious incident report, the audit trail should show the draft, the human edit and the approval as separate facts. That record is what turns "the AI got it wrong" from a crisis into a correction.

## Keep the intelligence you build

The prompts, templates and review workflows your team develops are assets. Store them in systems you control, in formats you can move. If a vendor relationship ended tomorrow, the knowledge of how your organisation uses AI should stay behind. Check the retention terms while you are there: if the vendor keeps your inputs to improve its models, that is the problem from the first post in this series, happening on schedule.

## Put a name against every use

For each approved use, one person is accountable for the outcome, and they know it. Not a committee, not "the AI", a name. This is the cheapest control on the list and the one that changes behaviour fastest, because a named owner starts asking the other four questions without being told.

## Where this lands

This needs no transformation program. A provider can classify its data in a workshop and put names against uses in an afternoon; standing up the tooling takes weeks, not quarters. What it needs is a decision that AI usage is worth governing before the habits set.

This series has made one argument across three posts. Your operational knowledge is valuable enough to train your future competitor. The frameworks you already have will not notice it leaving. And the fix is an operating model that makes the sovereign path the easy one.

The quality manager doesn't need a lecture about pasting. She needs a tool she can reach in thirty seconds that her organisation stands behind. Build her that, and sovereignty stops being a strategy paper and becomes the way the place works.

I help regulated organisations build this operating model. There's more on the [about page](/about/) if that's useful.

---

Source: https://kads.au/writing/what-ai-sovereignty-looks-like-in-practice/
Author: Kads Aziz
