The argument laid out a year ago was that AI sovereignty is a question of choice: the freedom to pick the right tool for a job and to switch when circumstances change. Since then the debate has hardened. Frontier models have been turned into attack tools, access to some of them now depends on geography, and pressure to restrict open models keeps growing. Read that way, sovereignty looks zero-sum — every model under another country's control is one you cannot rely on, so the rational move is to wall yourself off.

The last twelve months point the other way. India, Japan and Singapore leaned on open-sourced models, and builders across Asia-Pacific turned them into tools for rural citizens, elderly patients and their nurses. Our own security team assembled defenses that work with whatever model is available, so losing access to a single provider does not switch those defenses off. Working on a better Internet has always meant widening the set of options rather than narrowing it. That is why we pursue open standards that head off vendor lock-in, why much of what we ship is free at the start, and why our network spans more than 335 cities in 125+ countries, with AI inference GPUs in more than 230 of them.

EuroLLM and Apertus arrive on Workers AI

At the India AI Impact Summit 2026 in New Delhi, Matthew Prince framed decentralized, affordable AI access as a matter of national resilience. The addition of models from India, Japan and Singapore a few months earlier had served as the first proof of that idea. The summit series moves to Geneva in June 2027 under the mission "prosperity and progress for all."

Two European models now join them, and both can be requested today.

EuroLLM covers 35 languages, among them all 24 official EU languages — several of which existing open models serve poorly. It was built by a consortium including Instituto Superior Técnico, the University of Edinburgh, Instituto de Telecomunicações, Université Paris-Saclay, Unbabel, Sorbonne University, Naver Labs and the University of Amsterdam, with backing from Horizon Europe, the European Research Council and EuroHPC. Training ran on the MareNostrum 5 supercomputer, and the consortium reports results above comparable-sized models on EU multilingual benchmarks and machine translation. Access on Workers AI can be requested here.

Apertus, Latin for "open," is Switzerland's first large-scale, fully open multilingual model. It saw more than 15 trillion tokens across over 1,500 languages, with 40% of the training data in non-English languages. ETH Zurich, EPFL and the Swiss National Supercomputing Centre (CSCS) developed it under the Swiss AI Initiative — public institutions building for the public good. Architecture, weights, training data and methods are all published. Compliance with Swiss and European rules such as the EU AI Act and GDPR shaped the design: training opt-outs are respected, personal data removed and memorization prevented. It was trained on CSCS's Alps supercomputer with more than 10,000 GH200 GPUs, and its developers report substantial gains over leading closed and open models on rare and regional languages, from Romansh and Swiss German through low-resource languages across Asia and Africa. Access on Workers AI can be requested here.

What the earlier national models produced

The models added in the previous cycle did not stay on the shelf. Hundreds of students, startups, small businesses and public servants built on them after they went live on Workers AI, many during buildathons run with local partners. Three examples:

  • Forms without the reading. Form Mitra (India) addresses benefit paperwork written in dense English, which shuts out rural, low-literacy and visually impaired applicants. Students at the Indian Institute of Technology Delhi built it at a buildathon run with CyberPeace: a voice-guided assistant that leads users through a form in any of 22 Indian languages, powered by AI4Bharat's IndicTrans2.
  • Clinical conversation in the patient's own dialect. Many nurses caring for Singapore's elderly come from elsewhere in Southeast Asia and do not speak local dialects, so clinical details can be lost in translation. MedBridge (Singapore) guides patients through health conversations in 14 languages, Hokkien and Cantonese included.
  • One-tap routing to the right service. For elderly residents, people with disabilities and anyone uneasy with digital tools, deciding which public service to call in a crisis is its own burden. Anshin Concierge (Japan), built as a hackathon prototype, lets people describe the problem in their own terms — "my knees hurt," "a strange screen appeared on my phone" — and connects them to the correct Tokyo Metropolitan Government support desk by phone or web page.

A security harness that works with any model

Governments want AI pointed at defending essential services and national infrastructure. The same frontier models that locate vulnerabilities at scale can locate them for defenders. But a defense resting on a single model is only as reliable as continued access to it, and governments have watched that access narrow with little notice.

We hit the same wall — in security we are our own first customer. Over the past year our Security team, together with groups across the company, built defenses with no dependency on one model: a harness, an orchestration layer coordinating multiple models in parallel to hunt vulnerabilities, verify findings and prioritize threats. We published our findings on running frontier and open models side by side, open-sourced the harness so any organization can operate it with models of its choosing, and documented the layered architecture we use to keep attackers armed with frontier models from finding those vulnerabilities at all. Because it accepts closed or open models, losing one provider does not disable the defense.

Walking governments through it drew relief first, then practical questions about standing it up in their own environments under their own rules. Those briefings turned into requests for hands-on training, so today we are launching a workshop program for government cybersecurity agencies and critical infrastructure operators. Participants build their own AI security harness and layered defenses and leave able to adapt both to their organization. The modules are plug-and-play and designed to slot into national AI skilling and cyber resilience programs. The first workshop takes place in Singapore this October during Singapore International Cyber Week.

Working with partners

None of this was solo work. Partners including CyberPeace in India and Code for Japan turned open models into tools people actually use. National AI programs, cyber agencies and critical infrastructure operators who want more options than they have today can write to [email protected]. Request access to EuroLLM and Apertus, or begin with the harness.

Choice was our answer to AI sovereignty a year ago. This year made the case that it is the answer to AI security as well.