Essay · Sovereignty

Palantir is right about AI sovereignty. We built it for everyone.

Published 8 July 2026 · By Udal Systems

Last week Palantir posted a nine-point manifesto on AI sovereignty. The opening line carries the argument: sovereignty is the precondition for choice. Give it up, and you hand your institution's future decisions to someone else, someone unlikely to spend them on your behalf.

We agree with almost all of it. The manifesto says in public what our customers have been telling us privately for a year. The moment an AI agent touches your real data and your real systems, the question stops being what it can do and becomes who actually controls it. Your data, your model weights, your operational edge: the manifesto is right to call these treasure, and right to warn against transferring them at your peril.

There is one thing it leaves out. Read it closely and you notice who it is written for: the institution large enough to command a bespoke, forward-deployed engagement. The nation-state. The defence prime. The enterprise that can put a room of engineers on site for a year. In that telling sovereignty is real, but it arrives as a privilege, sized for the few organisations that can afford to negotiate for it.

We think that is the wrong shape for it. Sovereignty should not be a luxury good. It should be the default.

Owned, not rented, and not only for the giants

Udal takes its name from udal tenure, an old Norse and Scottish form of land ownership in which you hold your ground outright, free of any feudal superior. No lord above you, and no one who can take it back. We built the platform so that any regulated organisation can hold its AI agents the same way, rather than only the ones big enough to command a private deployment programme of their own.

That is the argument in a sentence. Everything Palantir says an institution should own, Udal lets you own on ground you already hold. It installs inside your own Kubernetes cluster, runs on your terms, and keeps the vendor firmly outside the boundary. You deploy it as a product. You do not have to be important enough to enter a relationship.

The manifesto's core claims read rather differently once sovereignty is something you install rather than something you are granted.

Your data is your treasure, so it never leaves

The manifesto warns that transferring your data hands over both your existing winning plays and the means of producing new ones. That is exactly why the only safe architecture is one where the data never moves in the first place. Udal runs inside your environment, so prompts, tool calls, retrieved context and outputs all stay within your perimeter. "Data never leaves" is not a contractual promise bolted onto a hosted service. It is how the platform is built, and it works the same way whether you are a central bank or a fifty-person fund.

Controlling your weights is controlling your fate

Weights are distilled institutional knowledge. Let someone else hold them and you let them migrate your advantage into their business. Udal is model-agnostic and self-hosted, so the models and their weights sit on your ground with everything else. You are not renting inference from a landlord who watches every query and learns from it. You are running your own.

Tokenmaxxing is false progress

The manifesto's sharpest point is about the addictive feeling of treating spend as a proxy for value, and the incentive to ship disposable scripts because the meter rewards volume rather than durability. We built the opposite incentive into the platform. Agents are authored as code, checked against policy and evals, and promoted through your pipeline like any other production software. Spend is capped by hard per-team budgets with automatic kill-switches. You get robust systems you can stand behind, and a bill that reflects value rather than one that manufactures the appearance of it.

Sovereignty does not slow you down

This is the objection we hear most, that owning your stack means a multi-year platform build before anyone writes a useful agent. It does not. Udal gives you the whole paved road on day one: author, check, promote, govern, observe. Governance, tamper-evident audit and cost control are there from the first agent you deploy, not at the end of a bespoke programme. Here, owning your stack and shipping quickly are the same road rather than a trade-off.

Provable, not political

The manifesto argues that technical decisions should be settled by track record rather than by whoever argues most persuasively in the room. Evidence settles them better still. Every decision, model call and tool use Udal makes is written to a tamper-evident, hash-chained audit log that your risk and security teams can actually inspect. Sovereignty you cannot prove is only a claim. Sovereignty you can hand to a regulator, a signer or an auditor is a fact.

Sovereignty as a default, not a privilege

The manifesto is a good document, and the industry is better for someone with Palantir's standing saying it plainly. If you do not own the thing, you do not control your future. Our only disagreement is about who gets to act on that advice.

A regulated bank should not have to be a defence contractor to keep its data inside its own walls. A government team should not need a nation-state's budget to run agents it can audit line by line. The controls that make autonomous systems safe to run in production, such as policy-as-code at every request, real permissions, PII redaction, dual control on high-stakes actions, hard budgets and a provable audit trail, are not exotic capabilities reserved for the largest institutions. They should ship in a box.

That is what we mean by owned, not rented. Not sovereignty for the few who can afford to negotiate for it, but sovereignty as the ground you start from, held outright with no lord above you, available to everyone who needs to govern an agent on ground they own.

Udal is a self-hosted platform for building, running and governing AI agents inside your own environment, built for regulated finance and government. Data never leaves your boundary.

Keep reading

Sovereignty, as a default.

See how Udal runs governed AI agents inside your own environment. Technical briefing, not a sales deck. A human replies within one working day.

Request access