AI sovereignty now reaches the data center floor. Palantir and Armada sell it as one stack
Palantir and Armada pair a sovereign AI operating system with modular data centers for open-weight models. Sovereignty is moving down to physical infrastructure.
Listen to this article · 6 min
AI-generated narration of the full article.

Until recently, “sovereign AI” mostly meant a deployment option: run the software in your own environment instead of the vendor’s cloud. We wrote about that version when IBM made Bob self-hosted. The October 1 partnership between Palantir and Armada pushes the definition several layers down, to the model weights, the hardware and the building the hardware sits in.
The announcement is a vendor partnership, and “sovereign” is a marketing word as much as a technical one. Still, it describes a real shift in what some buyers mean when they ask for control.
What was announced
Per the joint Business Wire release, the partnership combines:
- Palantir’s Sovereign AI Operating System, built on AIP, Ontology, Foundry and Apollo, and a reference architecture Palantir developed with NVIDIA earlier this year;
- Armada’s Galleon modular data centers, which Armada says are manufactured in the United States and allied nations;
- the Armada Platform, a software layer for fine-tuning and inference, and the Sovereign AI Grid, which connects individual deployments into a distributed system.
The target is governments and enterprises that want to run and adapt open-weight models, NVIDIA Nemotron among them, on infrastructure they control, with air-gapped operation where required, real-time monitoring of power, cooling and compute, and deployment in months rather than years. Palantir’s chief executive put the thesis bluntly: sovereignty is not something you rent; it means owning the weights, the data and the hardware, and knowing where that hardware was built.
Three weeks earlier, Palantir named Nebius its preferred sovereign AI infrastructure partner, bringing Nebius compute and inference endpoints inside the Palantir perimeter, including through modular data-center deployments at sites where power is already available. Two partnerships in one month point the same way: the software vendor is assembling the physical layer.
- Applications and agents
- Model weights
- Data and fine-tuning
- Software delivery and updates
- Compute hardware and its origin
- Facility, power and cooling
- Where self-hosting usually stops: Applications and agents
- What full-stack sovereignty adds: Model weights · Data and fine-tuning · Software delivery and updates · Compute hardware and its origin · Facility, power and cooling
Layers the partnership says the customer controls
What full-stack sovereignty actually decides
Model choice narrows to open weights. Owning the weights means running models whose weights you can obtain and license. That excludes the frontier models offered only as hosted APIs. Teams need to test whether the open models they can run are good enough for the tasks in scope, and plan for the fine-tuning work that usually closes the gap.
Hardware provenance becomes a requirement. “Knowing where the hardware was built” is not rhetoric for US federal buyers and contractors, who already live with supply-chain rules such as Section 889 of the 2019 defense authorization act on covered telecommunications equipment. Expect provenance questions to spread from defense to critical infrastructure and to regulated enterprises that sell to government.
The update channel is the real boundary. A sovereign stack still receives software. Palantir’s Apollo exists precisely to deliver it continuously. In a connected deployment, ask what the vendor can push, who approves it and what telemetry goes back. In an air-gapped one, ask how updates and security patches cross the gap and how long that takes. Sovereignty claims live or die on these details.
Operations become yours, or a contractor’s. Modular data centers reduce construction time, not operating responsibility. Someone has to run power, cooling, hardware failures, model serving, capacity and security at each site. Decide who before the hardware ships.
Who should care, and who should not
Most enterprises do not need their own data center to use AI responsibly. For them, the custody discipline we described in our piece on custody as the first architecture question, knowing where sessions, traces and indexes live, delivers most of the value without owning hardware.
Full-stack sovereignty makes sense where the requirement is physical: defense and intelligence programs, critical infrastructure operators, remote industrial sites with poor connectivity, and public bodies whose rules exclude foreign-operated infrastructure. For those buyers, a packaged stack can be faster than assembling hardware, models and software from separate vendors.
Questions to ask any sovereign AI offer
- Which layers do we control, contractually? Weights, data, hardware, facility and operations, one by one.
- What can the vendor push, and what comes back? Updates, telemetry and remote access, in writing.
- Which models, at which quality? Run your own tasks on the open models offered before signing.
- Who operates each site day to day, and with what clearances?
- What does it cost to run? Power, cooling, GPUs and staff over five years, not only the purchase price.
The bottom line
Sovereignty is turning into a full-stack architecture, from the model down to the building. Palantir and Armada sell that as a package; Palantir and Nebius offer a variant on someone else’s infrastructure. For the few organizations that truly need physical control, this shortens a long road. For everyone else, the useful lesson is the layer-by-layer question: for each part of your AI system, who controls it, and what can reach it from outside?