Most businesses are using AI day to day, some are deep into AI adoption, but far fewer have asked where that AI lives, who governs it, and what happens when the answer to both is “not here.” That’s why it felt only right to dive into a subject that’s gaining real urgency in Australia right now, with very real consequences for Australian businesses – sovereign AI.

And who better to guide us through our first Referrer’s Lunch of the year than two of the most relevant voices on Australia’s sovereign AI right now: Simon Kriss, Founder and CEO of Sovereign Australia AI and Jon Whittle, Former Director of CSIRO’s Data 61 and author of AI for Business.

Between them, they gave us access to decades of AI research, responsible AI leadership, and on-the-ground experience in building sovereign capability in Australia, setting a strong foundation for the discussion that followed.

What is Sovereign AI?

And what does it really mean for Australia to have sovereign AI capability?

Put very simply, it means for Australia to own and control our AI capability end to end, from the physical infrastructure through to the models powering the tools we use every day. By that definition, Simon and Jon argued that we’ve got a clear gap to close.

Jon set the scene with a story from his early career at NASA, when he was tasked with building an AI to write software for space missions. At the time, he considered it effectively impossible. His point illustrates just how fast AI capability has moved, and how consequential that acceleration is for a country like Australia, which hasn’t built its own foundational technology. He also noted that despite ranking fourth in the world for fundamental research output, Australia spends around 1.5% of GDP on research and development – against an OECD average of roughly 3%. We’re generating the ideas. We’re just not commercialising them.

Simon pointed out that the absence of an Australian foundation model is the central gap (which his company, Sovereign Australia AI, is actively working to close). Without one, every layer – the 5-layer application stack – is built on infrastructure owned and controlled by foreign entities.

The real shift is less about conversational AI. It’s about what AI is increasingly capable of underneath that – and our role in that picture is worth examining.

The 5-layer application stack

The sovereign AI application stack is a great framework for making the concept tangible, helping us think about where sovereign control exists and where it doesn’t.

Sovereign AI Application Stack​ from the May 2026 Referrer's Lunch presentation

  • Data Centres. Where data is physically stored and processed. Offshore compute means foreign jurisdiction, regardless of what’s built on top. This is also where national priorities like renewable energy come into play.
  • Foundation Models. The large language models (LLMs) powering tools like ChatGPT, Gemini, and Claude. The US and China account for the overwhelming majority of the world’s models. Australia builds none, and the opportunity to leverage Australian and First Nations datasets and problems remains largely untapped.
  • Agentic Platforms. Autonomous AI systems that act without a human trigger. A simple query might send a small volume of data offshore. An autonomous agent running continuously, with no human in the loop, could generate millions of tokens, all processed and stored under foreign governance. The question of where and under whose laws it happens becomes urgent at this layer.
  • Responsible AI. The standards, guardrails, and alignment to Australian values and law that govern how AI operates. This layer only holds if the layers beneath it are also sovereign. Australian ethical guidelines cannot be enforced on a model owned, trained, and operated by a foreign entity.
  • Applications. The tools organisations use day to day, and the layer where AI is applied for national benefit and productivity gains. By the time you reach this layer, the sovereignty decisions have already been made.

What’s missing from Australia’s sovereignty conversation

Simon was clear on one thing: hierarchy matters. Most of us already accept data sovereignty in principle. We understand why sensitive data shouldn’t sit on overseas servers. But when AI sovereignty comes up, even in government conversations, the discussion tends to stop at data centres and applications.

The middle of the stack (where models are hosted, who owns them, and under whose governance inferences are processed) goes largely unaddressed.

Simon’s challenge was to apply that same logic up the stack. If processing a 100-token query offshore felt manageable, what happens when an autonomous agent generates 10 million tokens of response, continuously, with no human trigger, stored and processed under a foreign jurisdiction’s laws? Where that is processed, stored, and governed stops being an abstract question very quickly. The risk compounds as AI systems become more autonomous.

Take the US for example. Every organisation using US-based AI tools should understand the US Cloud Act and its implications. Because American authorities have the power to compel access to data held by US companies regardless of where that data physically sits. Even if you stop using an offshore AI tool, your data may already be in its training set, and removing it isn’t simple.

 

Group discussions

Armed with Jon and Simon’s insights, the conversation turned to the room. Guests split into groups to tackle two key questions.

They first asked: What should be sovereign?

  1. Sovereignty as risk management. The group viewed sovereignty through the lens of national security, economic control and alignment to Australian values. They used port infrastructure as a comparison: Australia controls its ports to avoid sovereign risk and applies the same logic to AI infrastructure.
  2. Data control and model ownership. The discussion highlighted concerns about Australian prompts and data flowing into offshore models, with little visibility over how those inputs are used or who benefits from them.
  3. Government’s role in shaping AI sovereignty. The group questioned whether all AI should be treated as strategically sensitive, whether Australia has already lost ground, and how the government should support sovereign capability through policy, funding and incentives.
  4. Cultural and geopolitical risk. The groups also discussed data leakage, shifting alliances, and the risk that globally trained models could erode Australian vernacular, identity and ways of thinking over time.

The second question asked: “What should your business be investing in now, and planning for next?”

  1. Productivity opportunity vs sovereignty awareness. AI is already being used to supercharge work across staff and teams, but sovereignty considerations are often not factored into how deployments are evaluated.
  2. Regulation lag. Organisations are adopting AI faster than governments can regulate it, often operating across borders without clear guardrails in place.
  3. Start small and build capability. The discussion challenged internal bans on AI, comparing them to organisations that once blocked internet access in its early days. It pushed a simple message: start somewhere, avoid trying to boil the ocean, and invest in training people properly.
  4. Governance as a foundation. Internal policy, procedures, guardrails and compliance frameworks are positioned as the foundation for meaningful AI adoption.

To sum up

As a builder and user of AI, align.me has direct experience with the questions raised at the lunch. We’ve moved away from certain consumer-facing AI tools and use Claude via AWS Bedrock, running around 30 agents within our own proprietary platform and another 20 across back-office functions.

But sophistication of setup isn’t the same as sovereignty. Hugh Macfarlane, align.me founder and CEO, flagged what he called the SaaSpocalypse – the idea that more businesspeople will become builders of SaaS replacements using AI-powered coding. For anyone building in that direction, sovereignty isn’t an afterthought – it’s a foundational decision that only gets harder to revisit the further you go.

The afternoon didn’t resolve the question of sovereign AI – it wasn’t meant to. What it did was make the question harder to ignore. The more useful ask for Australian businesses isn’t whether to use AI. It’s whether you actually know what you’ve built, who governs it, and what that means when the stakes get higher.

A big thank you to everyone who attended 

Thank you for sharing your afternoon with us for a conversation that really mattered. Sovereign AI is a discussion that’s only going to become more relevant for Australian businesses, and the businesses that start working through these questions now will be better positioned for what’s coming. We’re looking forward to continuing the conversation with you as this story unfolds.

Author - Brett Bonser

It's rare to come across business leaders who have an intimate understanding of both sales and marketing - and yet, Brett Bonser's experience in facilitating hundreds of sales and marketing projects for some of the world’s biggest brands, proves that he truly is a Sales and Marketing expert.