SovereignOS · Roadmap

A sovereign operating system for European organisations.

Your institution should decide where its data goes and how AI is used. SovereignEU is developing SovereignOS to put those decisions in your hands.

Public and private alliance Planned open source releases Designed to support EU AI and data protection obligations

Planned workstation operating system. Availability, supported devices and migration paths will be documented for each release.

What the alliance brings

One alliance, three roles inside your organisation.

SovereignEU is a European public and private alliance. It advances research, develops a planned sovereign operating environment, and helps your organisation assess and adopt it responsibly.

Open research & development

Sovereign AI advanced in the open, with European institutions and industry, so the foundations stay inspectable and shared.

Explore

SovereignOS & applications

A planned workstation operating system and a suite of organisational applications, designed around customer control.

Explore

Professional services

A measured path from one bounded use case to a validated deployment: assess, define, deploy, then verify and transfer.

Explore

The product surface · Roadmap

Working inside SovereignOS.

Pick an example task. SovereignOS keeps the work inside your data boundary, routes it to an approved local model, drafts with citations, and waits for a person before anything is shared.

SovereignOS · Regional administration · Customer boundary Local control

Prepare the mobility committee brief from approved project records.

Regional transport · 23 August 2026 Draft · source-linked

Decision brief: shared mobility procurement

A cited draft assembled only from records the organisation has approved, ready for a named official to review before anything leaves the building.

6 approved sources · 2 passages need review

01
Programme register
Regional transport 2026
02
Procurement policy v4.2
Legal & compliance
03
Committee record
14 July 2026
04
Accessibility standard
EN 301 549
DATA BOUNDARY
Internal records only
→ MODEL ROUTE
Organisation-approved local runtime
→ PROPOSED ACTION
Create a cited draft; do not distribute
EVIDENCE · Every claim traces to an approved source
Human approval required before anything is shared. Distribute
Organisation identity Local model route Signed update policy Reviewable activity record

Draft a reply to the accessibility enquiry, citing current policy.

Citizen services · 24 August 2026 Draft · source-linked

Reply: accessibility of the mobility portal

A plain language reply grounded in the accessibility standard and the current service policy, with each commitment linked to its source.

4 approved sources · 1 passage needs review

01
Accessibility standard
EN 301 549
02
Service policy v2.1
Citizen services
03
Portal audit
Q2 2026
04
Response template
Approved wording
DATA BOUNDARY
Internal records only
→ MODEL ROUTE
Organisation-approved local runtime
→ PROPOSED ACTION
Draft a reply for officer review
EVIDENCE · Commitments linked to policy in force
Human approval required before anything is shared. Distribute
Organisation identity Local model route Signed update policy Reviewable activity record

Summarise this quarter's programme spend for the board.

Finance · 25 August 2026 Draft · source-linked

Summary: Q3 programme spend

A board-ready summary built from the finance system of record, figures reconciled, variances flagged, nothing invented.

5 approved sources · figures reconciled to ledger

01
Finance ledger
Q3 2026
02
Budget baseline
Approved 2026
03
Commitments register
Live
04
Board reporting format
Standard
DATA BOUNDARY
Finance records only
→ MODEL ROUTE
Organisation-approved local runtime
→ PROPOSED ACTION
Draft a board summary; do not publish
EVIDENCE · Figures reconciled to the ledger
Human approval required before anything is shared. Distribute
Organisation identity Local model route Signed update policy Reviewable activity record

Roadmap interface concept, illustrative, not a released product.

How the platform is organised

Eighteen roadmap capabilities, four clear responsibilities.

Everything in SovereignOS belongs to one of four responsibilities, so an official always knows what a capability is for, and an evaluator knows where it sits.

Applications

The organisational apps people use every day, documents, knowledge, service desk, projects and more.

Explore

Intelligence

Document AI, assistants and fine-tuned models, governed, cited, and kept on approved routes.

Explore

Foundation

The AI native database, model runtime and identity layer the whole system stands on.

Explore

Trust

Guardrails, AI defense and post quantum cryptography, the controls that make the rest safe to use.

Explore

Sovereign Intelligence

How a governed answer is actually produced.

Five steps, each one accountable. Select a step to see what happens, and what stays under your control.

SovereignOS · Sovereign Intelligence Local route
01
Connect
In this planned workflow, your organisation chooses which records and systems SovereignOS may access.
02
Retrieve
It retrieves the specific passages that bear on the task, from sources you can name and inspect.
03
Reason
An organisation-approved model, on a local route, reasons over that evidence, through the approved model route for the deployment.
04
Act
It proposes a bounded action, usually a cited draft, and waits for a person before a consequential step.
05
Evidence
Every claim traces to a source, and the whole exchange is written to a reviewable activity record.

Roadmap interface concept, illustrative, not a released product.

Solutions by function

It meets each part of the organisation where it works.

The same governed core, shaped to the daily reality of programme teams, operations, IT and people functions.

Programme delivery

Keep delivery, decisions and evidence in one place, briefs drafted from the record, not from memory.

Operations & administration

The everyday apps and documents, with the boundary and the audit trail built in.

IT & service management

Requests, changes and service records, governed, traceable, and yours to run.

HR & people

Sensitive people processes handled inside your control, with human approval where it matters.

Governed by design

European governance built into the plan.

SovereignOS is designed around four obligations European officials already answer to.

Data protection

Designed to support GDPR obligations with a defined data boundary, lawful basis and retention policy for each deployment.

AI lifecycle governance

Plan how AI will be used, assess its risks and keep a record of changes.

Human oversight

A person can be required to approve sharing or consequential actions. The gate is part of the planned design and can be defined for the deployment.

Technical evidence

A reviewable activity record gives your organisation evidence to assess its obligations.

What “sovereign” actually means here

Six dimensions you can verify, not a slogan.

We hold ourselves to a definition an evaluator can check, across every dimension of control.

Data

Designed to let your organisation choose where data is processed and how approved models may use it.

Operational

You can run, pause and audit the system with operator access defined by your organisation.

Technology

Planned open source releases intended for inspection, adaptation and an orderly exit under their published licences.

Jurisdiction

Designed for deployments where jurisdiction, governance and access routes are reviewed and documented.

Knowledge

Your organisation can retain institutional memory under its own policy, with export and access rules defined up front.

Exit

A credible way out: your data and models are portable, so sovereignty is real, not rhetorical.

A measured path

Start with one bounded use case. Prove it. Then widen.

No attempt to transform everything at once. We begin where the value and the risk are both legible, and we transfer control to your team at the end.

SovereignEU · Delivery path Assess → transfer
01
Assess
We map one real, bounded use case with you, the records, the risk, the people who must approve.
02
Define
We define the data boundary, the model route and the exact action the system is allowed to take.
03
Deploy
We deploy inside your control, integrated with the systems of record it is allowed to see.
04
Verify & transfer
We verify against the definition, then hand run-and-audit control to your own team.

Start a conversation

Bring one bounded use case. We’ll show you the governed path to a validated deployment.

Public-sector teams across the union are planning for sovereign AI. A first deployment starts with a single, well-chosen decision.