Counterpoint Research's Sovereign AI LLM Index, published in August 2026 and reported again on 21 September, found that 56% of more than 170 “national” AI models across over 80 countries are adapted models built by modifying an existing base model. When a national AI is built by modifying someone else's model, who is left responsible for checking the base it stands on? Neither the modifier nor the base provider: it is the organisation that deploys the AI.
01Over half of sovereign AI models are built on someone else's base model
The grounds for that answer can be laid out briefly at the start. The starting point is 56%. More than half of the large language models that countries have built as their own AI were not trained from scratch. They are someone else's base model with additional training on top.
Three parties shape how such a model behaves: the provider who built the base, the party that modified it, and the organisation that puts the modified model to work. Here is where responsibility sits for each, and where it stops.
Base provider
Disclaims liability for damages in its licence.
Modifier
Under EU guidance, duties cover only the modification.
Deploying organisation
Is left to check the base's name, licence and scale of modification.
The base provider disclaims liability for damages through its licence. Under the guidelines the European Commission issued under the EU AI Act, the modifier's duties extend only to what it changed, unless the change used a large share of compute. That leaves the deploying organisation.
So anyone bringing in an AI labelled “national” or “built for our company” needs to check three things as part of adoption: the name of the base, its licence, and the scale of modification. The rest of this column tests that conclusion through the index's definitions, where these models are used, the rules and contracts involved, the numerical line at which duties switch, and what may come next.
02An adapted model is an existing base with added training, and it makes up 56%
First, what exactly the 56% counts. Counterpoint's index covered more than 170 current models across over 80 countries. It scored them on four criteria: who owns the model, whether the base was built in-house, how deeply it handles local languages, and whether it is actually in use.
The index sorted models into two kinds: base models trained from scratch, and adapted models made by further training an existing base. The second kind made up 56%.
That definition draws a clear boundary. The word “sovereign” tells you that ownership or operation sits within a country. It does not tell you that the base was built there. In an adapted model, local-language work and fitting to particular tasks may be done at home, but much of the underlying knowledge and behaviour is inherited from the original base.
Press coverage of the index also ranked which bases were used most often. I could not confirm that ranking in the index itself, so I do not use it here. What I could confirm is that more than half of these models stand on someone else's base.
That alone is enough to raise the question. In more than half the cases, the party that built the base and the party that delivers the model as a national AI are different people.
03Adapted models enter government and business, and review often cannot tell their base
Adapted models are going into public services and business operations in many countries. What matters there is how the base looks from the user's side. The first clue is the name, and whether a name reveals the base depends on the base's licence.
| What to look at | Llama 3.1 Community License | Apache 2.0 (e.g. Qwen2.5) |
|---|---|---|
| Name of derived models | Must begin with “Llama” | No rule |
| Display duty | Show “Built with Llama” | Include licence text and notices |
| Very large users | Over 700 million monthly users need a separate licence | No limit |
Meta's Llama 3.1 Community License requires anyone distributing an AI model built with it to put “Llama” at the beginning of the model's name, and to display “Built with Llama”. Services with more than 700 million monthly active users need a separate licence. A model built on this base therefore shows its lineage in its name.
By contrast, some Qwen2.5 models are released under Apache 2.0. That licence requires the licence text and copyright notices to travel with the work, but it sets no rule for naming derived models. If the modifier gives the model a new name, the name says nothing about the base.
Corporate adoption reviews usually begin with a product name and the vendor's description. Since a product name does not necessarily show the base, a reviewer who wants to know where the model came from has to ask for documents beyond the name.
04Responsibility breaks because modifiers answer only for changes and base providers disclaim
So a name may hide the base. Why, then, does nobody explain it? Two mechanisms overlap: regulation and contract.
On the regulatory side, the European Commission's guidelines on general-purpose AI models, published in July 2025, set out the modifier's position. Unless the training compute used for the modification exceeds one-third of the compute used to train the original model, the modifier does not become a new provider. Its documentation duties then cover only the added compute and data.
On the contractual side, the Llama licence limits Meta's liability for damages. Some other licences for openly distributed base models include such limits too, though I have not checked them all.
Put the two together and you arrive at the right-hand end of the figure. The base provider disclaims responsibility through its licence; the modifier explains only its own changes. At the moment of adoption, nobody is obliged to tell the deploying organisation what the base was trained on or what biases it may carry.
No one has cut corners to produce this. A provider distributing to many users under one licence cannot answer for every use. Requiring every modifier to explain the whole base would put heavy duties on small changes. Each line is drawn for a reason, and where those reasons meet, a gap opens in front of the organisation that deploys the model.
05The line making a modifier a new provider is one-third of the original compute
The limit on a modifier's duties comes with a number attached, and past that number the limit falls away.
| What to look at | Modification at or below one-third | Modification above one-third |
|---|---|---|
| Modifier's status | Not a new provider (duties cover the change) | New provider |
| Scope of documentation | Added compute and data only | The whole model |
| If original compute is unknown | Use one-third of 10^25 or 10^23 | Same |
If the compute used for modification exceeds one-third of the original model's, the modifier becomes a new provider with duties covering the whole model. When the original compute is not known, one-third of 10^25 or 10^23 serves as the substitute benchmark, because a modifier may not know how large the original training run was.
High-risk uses come under a separate rule. Article 25 of the AI Act treats anyone who puts their name or trademark on a high-risk AI system already on the market, or who substantially modifies one, as a provider. If a sovereign model is used for a high-risk purpose, attaching a name to it can bring provider duties with it.
Conversely, if the use is not high-risk and the modification falls below the line, the modifier's account stops at the added training. Whether local-language work or task fitting used more than a third of the original compute is something you can only learn by asking the modifier.
06Checking a base comes down to its name, its licence and the scale of change
The line shows that modifications below it do not carry an account of the base forward. Three things follow that should change how a deploying organisation decides.
What a name can tell
Llama derivatives can be traced by name; Apache 2.0 bases carry no naming rule.
Scale of change
Below one-third of original compute, no one is obliged to explain the base.
Moves to reduce dependence
The index report notes countries moving to rely less on foreign bases.
First, what a name can tell you. Llama derivatives can be traced by name because the licence says so; models built on Apache 2.0 bases have no naming rule. Because traceability by name depends on the licence, deployers need to ask the vendor for the base model's name and version, not just the product name.
Second, the scale of change. Below one-third of the original compute, EU guidance leaves no one obliged to explain the base to the deploying organisation. Asking the modifier about the base will not produce an answer as a matter of duty. The deployer ends up reading the documents the base provider has published.
Third, moves to reduce dependence. The index report notes that countries are moving to rely less on foreign open base models. If a base's origin becomes a matter of national policy, disclosure of the base could one day become a procurement condition. That is an inference from the report, not something it states.
An adoption procedure can be written in four steps: ask for the base's name and version, read its licence, ask about the scale of modification, and record all of it before deciding. At every step, record when no answer was given. Whether to adopt an AI for which answers are missing can then be decided by looking at that record.
07If countries move off foreign bases the 56% may fall, but this is unverified
The third point raised moves to reduce dependence. It is worth separating what is known from what is not about how that could show up in the ratio and in disclosure.
All that is known is that the index report describes this direction. How much money countries will put into building their own bases, and when the share of base models might grow as a result, cannot be read from the report.
From here I am inferring. I set out two main paths (a mix of the two is also possible). If more countries build their own bases, the share of adapted models falls and the origin of the base can be explained within the country. If building from scratch proves too costly, sovereign AI by modification remains, and the job of checking the base stays with the deploying organisation.
Which path is taken can be checked by watching how the 56% moves in the next index. Today there is no basis for putting a number on where the ratio is heading. Nor has any country yet made disclosure of the base a procurement condition that I could confirm.
For the deployer, however the ratio moves, the work of checking the base of the model in front of it stays the same.
- 56% of sovereign AI LLMs are adapted from existing bases, so a 'national' label says nothing about where the base came from.
- EU guidance limits a modifier's duties to its changes unless it uses over one-third of the original compute, so for adaptations below that line no one is obliged to explain the base.
- Checking the base's name, licence and scale of modification falls to the deployer, so these three checks belong in its adoption procedure.
For a national AI built on someone else's model, the responsibility to trace the base rests neither with the modifier nor the base provider but with the deployer, which should check name, licence and scale of change, and record them before deciding.
A label such as “national” or “our own” tells you who delivers a model, not what it stands on. Asking about the second is the user's job.
- Counterpoint Research. NVIDIA Dominates With 92% Share in Counterpoint Research's Sovereign AI LLM Index. August 2026. (publisher and timing of the index)
- Communications Today. Middle East leads global sovereign AI race. September 2026. (56% adapted models, over 170 models in more than 80 countries, four criteria, moves to reduce dependence on foreign bases)
- Meta. Llama 3.1 Community License Agreement. 23 July 2024. (naming rule for derivatives, display duty, monthly-user condition, limitation of liability)
- Qwen / Hugging Face. Qwen/Qwen2.5-7B-Instruct. 2024. (release under Apache 2.0)
- Regulation (EU) 2024/1689. Artificial Intelligence Act, Article 25: Responsibilities Along the AI Value Chain. 2024. (those who rebrand or substantially modify high-risk systems become providers)
- European Commission (overview at artificialintelligenceact.eu). Overview of Guidelines for GPAI Models. July 2025. (the one-third compute line and the scope of a modifier's duties)
