A year ago, Cloudflare argued that AI sovereignty comes down to choice: the ability to pick the right model for the job and swap it when circumstances change. On 2026-10-01, their anniversary post (One year later: Sovereign AI and the fight for choice) checks the math — and for builders, the useful part isn’t the policy framing. It’s what the past twelve months say about designing products that survive losing access to a model.
Two new open models worth requesting
The concrete news: EuroLLM and Apertus are coming to Workers AI, with access open by request today.
EuroLLM covers 35 languages including all 24 official EU languages, built by a consortium spanning Instituto Superior Técnico, the University of Edinburgh, Sorbonne University and others, trained on the MareNostrum 5 supercomputer. Apertus, from ETH Zurich, EPFL and CSCS, is Switzerland’s first fully open large model: architecture, weights, training data, and methods all published, trained on over 10,000 GH200 GPUs with 40% of its data in non-English languages, and designed with the EU AI Act and GDPR constraints in mind.
If your product serves multilingual users — especially low-resource language communities that mainstream models under-serve — these are worth an access request. Both come from public institutions, so the licensing and provenance questions are unusually clear.
What people actually shipped
The more instructive part of the post is what happened after last year’s national models landed on Workers AI. They didn’t sit idle. Three examples from Asia-Pacific buildathons:
- Form Mitra (India): a voice-guided assistant walking rural and visually impaired citizens through dense government forms in 22 Indian languages, built by IIT Delhi students using AI4Bharat’s IndicTrans2.
- MedBridge (Singapore): patient health conversations in 14 languages, including Hokkien and Cantonese, bridging gaps between Southeast Asian nurses and elderly local patients.
- Anshin Concierge (Japan): residents describe a problem in plain words and get routed to the right Tokyo Metropolitan Government desk in one tap.
Notice the pattern: none of these are frontier-model showcase demos. They win on language coverage and accessibility — exactly where open, regionally-trained models outperform.
Model choice as a security architecture
The strongest argument in the post is about defense. Cloudflare’s Security team spent the year building a harness — an orchestration layer that runs multiple models in parallel to hunt vulnerabilities, verify findings, and prioritize threats. They open-sourced it and published their approach. The design principle: because it works with any model, closed or open, losing access to one provider doesn’t switch your defenses off.
That’s the same instinct behind setting a routing layer to pick models for you — treat any single model as a replaceable component, not a dependency. The post reports that when governments saw the harness, the common reaction was relief, followed by practical questions about running it under their own rules. That’s why the workshops launching in Singapore this October matter: sovereignty isn’t real until someone on your team can stand the thing up.
The takeaway for your stack
Zero-sum sovereignty thinking says every model another country controls is one you can’t trust. The past year’s evidence points elsewhere: open models from public institutions produced tools for underserved users, and multi-model architectures turned provider access risk from existential into manageable.
Practical next step: audit where your product hard-depends on one model — inference, safety filters, translation — and ask what happens if that access narrows without warning. If the answer is “nothing works,” that’s your roadmap.
Sources
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
