Sovereign AI has become hard to avoid in APAC policy calendars — and not only for governments. Technology vendors pitch it in procurement decks. Telecom operators and cloud providers build “sovereign” product lines around it. Banks, hospitals, manufacturers and public agencies are being asked whether their AI runs on someone else’s terms. The phrase now sits where digital policy, national security and industrial strategy overlap, which is why ministers, regulators and chief executives across the region are paying attention even when they disagree on what it requires.
At its core, sovereign AI is about retaining control while still using global technology: over language and cultural fit, where data is held and how it is governed, who provides compute, which rules apply, and which partners a market will accept. It is timely to examine now because no single market can realistically own the full AI stack. Chips, foundation models, cloud platforms and application layers still flow across borders.
So which parts of the stack will a government or industry insist on controlling, and what will it outsource or share? The focus on this has sharpened in recent months.
On 11 November 2025, Taiwan’s National Science and Technology Council Minister Cheng-Wen Wu joined the National Center for High-performance Computing to present TAIDE and the TAIWAN AI RAP platform under an explicit sovereign AI frame. Vietnam’s AI law took effect on 1 March 2026; on 30 June, the prime minister announced 46 high-risk AI systems for tighter oversight. On 29 June, Prime Minister Anwar Ibrahim launched Malaysia Digital 2030, setting out a path from technology consumer to “AI nation.” On 20 July, Minister for Digital Development and Information Josephine Teo opened the Singapore Data Festival with a different vocabulary — data before AI, GenAI privacy guidance, chatbot transparency — while ministerial interviews made clear that Singapore does not equate hub success with building a local frontier model. APEC digital and AI ministers met in Chengdu on 23 July under a shared empowerment theme, while acknowledging that member economies would keep different approaches.
This analysis looks at how that sovereignty conversation is playing out in four markets — Taiwan, Vietnam, Malaysia and Singapore — where the rhetoric is loud but the mechanisms diverge. Taiwan is fine-tuning open foundations for Traditional Chinese and pushing TAIDE into clinics and SMEs. Vietnam is writing national AI infrastructure into statute and publishing risk catalogues while operational detail is still catching up. Malaysia is trying to move from consumer to producer while debating what “local data” means in practice. Singapore is tightening data governance and infrastructure mapping without branding a national frontier LLM as the hub’s success metric.
These state-led plans will meet consumer habits already forming on global platforms. In Southeast Asia, nearly 70% of Gemini prompts are submitted in native languages, led by Vietnam at 89%, Thailand at 87% and Indonesia at 84%.
Key considerations
Sovereign AI in APAC is functioning less like one national factory and more like a toolkit: governments choose which controls to tighten — language, data, compute, law or partnerships — rather than building the same product in every market.
NVIDIA’s public-sector framing emphasises domestic infrastructure, data, workforce and business networks to protect local languages and culture. Accenture’s 2025 survey of government and industry leaders points to a less absolute approach. Countries do not need to cut themselves off from global AI; they need to decide which parts of the AI lifecycle — building, training, deploying and governing systems — must remain under national oversight. They can still work with global partners, but on terms they can set and revise. The CNAS Sovereign AI Index reaches a similar conclusion in harder numbers: NVIDIA GPUs appear in 52% of tracked infrastructure projects and foreign partners in roughly 70%. For most emerging economies, managing dependency is more realistic than trying to remove it altogether.
That produces several distinct paths, each reinforcing a different part of sovereign AI:
• Language and culture — fine-tune or build models that read correctly in local scripts and contexts, without claiming frontier-scale parity with the largest labs.
• Infrastructure and law — designate national AI platforms, mandate where critical workloads run, and publish risk catalogues before every detail is settled.
• Data and industrial policy — shift from technology consumer to producer, govern what counts as “local” data, and bring government services in-house.
• Rules and safeguards — prioritise data governance, disclosure and infrastructure mapping over launching a flagship national model.
• Data residency — keeping data in-country can be important, especially for regulated workloads. But it does not by itself decide who controls the model, the chips, the operating rules or the ability to move to another provider.
Residency is therefore a key consideration, but only one part of the design. A country may keep sensitive data at home yet remain dependent on a foreign model, chip supplier or cloud operator. Meaningful sovereignty also requires clear rules over those dependencies and a credible ability to change course when they no longer serve the public interest.
Taiwan: language as the main emphasis
Taiwan’s Trustworthy AI Dialogue Engine (TAIDE) programme is the clearest APAC example of sovereignty pursued through linguistic and cultural fit rather than frontier-scale nationalism. Run under the National Science and Technology Council, TAIDE is framed as reducing reliance on training data skewed toward mainland Chinese usage and political context, and as supporting Traditional Chinese outputs aligned with Taiwan’s institutions.
The programme’s own lineage undercuts any claim of full stack independence. Official releases build on open foundations — Llama 3 and Llama 3.1 variants, and Gemma-3-TAIDE-12B-Chat continual pretraining on Traditional Chinese corpora. An NSTC official quoted in Nikkei Asia described the approach as “standing on the shoulders of giants”: foreign foundation models plus Taiwan data for differentiation. Academia Sinica researcher Huang Hen-Hsen argued that without its own AI capability a society risks handing over its “brain”; TAIDE is cast as a linguistic and social bulwark, not as proof that Taiwan can match frontier labs on raw scale.
At an NCHC highlights presentation on 11 November 2025, NSTC and NIAR officials used sovereign AI language directly and named live deployments: Kaohsiung Veterans General Hospital’s ER-Pulse shift-change system, built on the TAIWAN AI RAP platform; KETHY’s clinic search app on TAIDE; education, agricultural and SME customer-service cases.
Sovereignty on the ground in Taiwan is not only TAIDE. From March 2026, the National Health Insurance Administration’s AI-on-DM diabetes risk tool — developed with Google Health — runs at roughly 20,000 primary care clinics, cutting a complications assessment from about 20 minutes to 25 seconds. The same month, NHIA added a Gemini-powered assistant to the Health Bank app. Alongside TAIDE’s local-language work, these public-service cases show how agencies can use foreign models while retaining responsibility for deployment.
For operators, Taiwan’s priority is explicit. Sovereignty means outputs that read correctly in Traditional Chinese, run where agencies require them, and do not inherit mainland political defaults from base training. Foreign open weights and NVIDIA hardware are tools, not contradictions — provided agencies can set and enforce the appropriate deployment, audit and exit conditions.
Vietnam: statute, infrastructure and oversight
Vietnam’s Law on Artificial Intelligence (No. 134/2025/QH15), in force since 1 March 2026, moves sovereignty from slogan to infrastructure designation. Article 16 defines national AI infrastructure as strategic infrastructure financed by the state, enterprises and social organisations. The state is to build shared compute, data, training and testing platforms, foundation and multipurpose models, and Vietnamese and ethnic-minority large language models.
The operating rules are still forming on two tracks. Article 16 creates a requirement for “important” AI applications in essential sectors to deploy on national AI infrastructure, but the prime minister’s operational list has not yet been published. That is separate from the high-risk catalogue. Decision No. 33/2026/QD-TTg names 46 high-risk AI systems across six sectors — transport alone accounts for 31 — with enhanced governance, conformity assessment and human-oversight requirements and sector-specific compliance deadlines into 2027. It gives operators clearer obligations for high-risk systems even while the national-infrastructure deployment list remains unpublished.
Vietnam’s national data strategy for 2026–2030, approved in July 2026, reinforces this direction: technological self-reliance in AI, high-performance computing and core data platforms, alongside stronger national data sovereignty. FPT Software has marketed an NVIDIA-accelerated “AI Factory” and Au Lac AI Alliance for Vietnamese LLMs and onshore data. Those announcements show how industry is responding to policy, but they do not carry the force of the law.
Vietnam’s emphasis is legal: the statutory conditions under which critical applications may be required to run, who builds shared platforms, and how ethnic-language models sit inside state infrastructure. Foreign GPUs and partners remain visible in the ecosystem. Sovereignty here rests on statutory boundaries, not chip autarky.
Malaysia: from consumer to producer — and from capacity to supply chain
Malaysia’s sovereignty discussion is increasingly about physical infrastructure as well as data governance.
On 29 June 2026, Prime Minister Anwar Ibrahim launched Malaysia Digital 2030 (MD2030), the 2026–2030 action plan published by MyDIGITAL Corporation under the Ministry of Digital, to shift the country from technology consumer to producer of home-grown innovation. The Ministry of Digital leads “Towards an AI Nation 2030.” The National Artificial Intelligence Office (NAIO) is tasked with leading the National AI Action Plan 2030. Official materials cite targets including digital economy contribution at 30% of GDP and 500,000 high-value digital jobs. Anwar directed that government digital services be developed internally under the Ministry of Digital and National Digital Department to safeguard national data sovereignty and reduce dependence on external providers.
The “mere consumer” framing belongs here, not in Vietnam. It reflects Malaysia’s priority: move from relying mainly on imported systems and platforms to building more domestic capability, products and high-value work.
Johor shows why. Malaysia has become a major host for regional data-centre investment and is beginning to attract the power, cooling and manufacturing activity around it. That makes MD2030’s producer ambition more concrete, but investment is not the same as sovereign capability. The test is whether Malaysia can build local skills, suppliers and regulatory capacity around foreign-backed assets, and set the terms under which infrastructure is built and used.
It also brings harder choices about power, water, land use and community acceptance. Those questions deserve fuller treatment in a separate examination of Johor’s data-centre boom. For this analysis, their relevance is clear: infrastructure can give a country more options, but it does not by itself settle who controls data, procurement or the services built on top of it.
Control over physical infrastructure is only one part of that test. Elina Noor, nonresident scholar at the Carnegie Endowment, has argued that “local” models fail if “local data” inherits unreformed categories — colonial census frames of Malay, Chinese and Indian that do not match how Malaysians live and identify. Her point is that local ownership of a model changes little if its training data still carries inherited categories and exclusions. Malaysia’s challenge is to examine where data comes from, whose experience it represents and what it leaves out, not only to localise model weights.
Singapore: agency without the slogan
Singapore’s approach begins with data, accountability and the conditions under which AI is deployed, rather than treating a national frontier model as the test of success. On 20 July 2026, Minister for Digital Development and Information Josephine Teo opened the Singapore Data Festival with IMDA’s line: “data before AI.” The same week, the Personal Data Protection Commission issued guidance on responsible use of personal data in generative AI, while IMDA released voluntary chatbot transparency guidelines, with early adopters including DBS, Google, Meta, OCBC and Singapore Airlines.
The Digital Infrastructure Bill consultation, which ran from 1 to 22 July 2026, adds another part of that approach: mapping and licensing foundational digital infrastructure and data-centre operators so critical capacity is visible and governable. In a June interview with Tech in Asia, Teo said Singapore does not “start with the assumption” that its AI hub depends on frontier models being developed locally. The aim is practical control over data, decisions and AI workflows, not ownership of every part of the stack.
Teo’s speech on 20 July also carried a regional warning. An ASEAN red-teaming exercise found a harmful request refused in English but answered in Khmer when local phrasing defeated safeguards. Linguistic and cultural risk is a regional governance issue, not only a model-size problem.
Singapore’s emphasis is governance and partner discipline inside a hub that still depends on global model providers. Sovereignty is operable rules, disclosure, infrastructure mapping and substitution options — not a national GPT marketed to investors.
The demand-side clock: language on platforms
While state programmes move through budgets, consultation and legislation, consumer habits can form much faster.
Google’s 2026 Gemini Southeast Asia reporting states that nearly 70% of prompts in the region are submitted in native languages rather than English. Vietnam leads at 89%, Thailand at 87% and Indonesia at 84%. Google also cites AI Singapore’s SEA-HELM leaderboard in describing Gemini as the best-performing model across several Southeast Asian languages. That is Google’s claim, based on the AISG methodology, and Relay Asia has not independently verified the underlying results.
Singapore’s adoption pattern diverges from the region’s language intensity. Google’s first-party 2026 Gemini Southeast Asia report and accompanying slide extracts supplied to Relay, citing internal data for January–March 2026, rank Singapore first globally for Gemini adoption per capita, with active users more than doubling in the final months of 2025. Singapore also leads Southeast Asia for daily engagement — about 10 prompts per user per day — and is the only market in the six-country sample where prompts come more from computers than phones: roughly 40% mobile, 58% computer and 2% other in the first quarter of 2026. Indonesia, by contrast, drew 82% of prompts from mobile. Users in Malaysia, the Philippines and Singapore are more likely to use Gemini in English than their neighbours in Vietnam, Thailand and Indonesia, where native-language prompts exceed 80%.
The implication is not that Gemini has “won” APAC sovereignty. It is that language fit delivered through a global platform may establish user habits before national LLMs mature — a risk policymakers should test, not a causal conclusion from usage data alone. Vietnam’s statute could require designated essential applications to use national infrastructure, while Vietnamese users overwhelmingly prompt in Vietnamese on a US-platform consumer app. Taiwan fine-tunes open weights for Traditional Chinese while Gemini reports extreme native-language use across Southeast Asia. Language as a sovereignty priority cuts both ways: local corpora and ethnic LLMs on one side; platform defaults and mobile interfaces on the other.
Open weights, partners and what sovereignty cannot promise
Open weights offer a practical middle ground. TAIDE’s use of Llama and Gemma shows how a market can adapt a downloadable foundation model with local data and deploy it on its own infrastructure, without having to invent a frontier model from scratch. That does not remove outside dependencies: the hardware may still be foreign, the underlying model may embed choices made elsewhere, and local training data can still reproduce the categories and blind spots Malaysia is debating.
Partnership is therefore the default, not a failure of ambition. Most APAC markets cannot fabricate GPUs or fund a frontier lab alone. Accenture estimates that only around one-third of workloads may need this level of sovereign control; the rest can use global services if the rules, data protections and exit options are credible. CNAS’s data reinforces the point: foreign partners and NVIDIA hardware remain normal across sovereign AI projects.
Cloud providers can offer useful in-country storage, access controls and local operating arrangements. Those are valuable safeguards, particularly for regulated workloads. They should not be confused with control over model behaviour, chip supply or the ability to change providers.
For policymakers and operators, the harder work begins after an announcement: identifying the gaps in local capability, testing the trade-offs in live deployments, and updating rules as the technology and supply chain change. Sovereignty will be judged less by a national label than by whether policies, procurement and partnerships give a market practical room to act when it needs to.
What to watch
• Learning across markets: Whether governments assess other markets’ experience — Taiwan’s local-language deployment, Vietnam’s statutory boundaries, Malaysia’s data questions and Singapore’s governance-first model — and adopt practices that strengthen their own sovereignty goals.
• Rules that still need detail: Vietnam’s Article 16 essential-sector deployment list, Malaysia’s implementation under MD2030, and Singapore’s final Digital Infrastructure Bill obligations.
• Supplier power: How NVIDIA, hyperscalers and other providers shape what “sovereign” is practical through chips, cloud capacity, operating terms and local partnerships.
• Proof in deployment: Whether announced programmes improve public services and enterprise capability while preserving audit rights, exit options and clear accountability.
---

