---
title: "KYE Protocol™ — KYE™ Sovereign AI Profile™ | Authority Finality™ for sovereign AI ecosystems"
description: "KYE™ Sovereign AI Profile™ — the runtime authority, delegation, state, audit, Decision Map™, signed-signal and evidence-pack layer for national AI…"
url: https://kyeprotocol.com/sovereign-ai-profile/
lang: en
source: "KYE Protocol"
---

> KYE™ Sovereign AI Profile™ — the runtime authority, delegation, state, audit, Decision Map™, signed-signal and evidence-pack layer for national AI…

KYE™ Sovereign AI Profile™

# Sovereign AI needs sovereign authority.

Sovereign AI is usually framed as _where_ AI runs. KYE Protocol™ answers a different question: _who or what_ is allowed to act through it, delegate to it, audit it, and revoke it.

Sovereign cloud controls where workloads run. KYE™ controls who or what is authorised to act through them.

_KYE™ Sovereign AI Profile™ is a v1.1 preview profile; the conformance suite freezes with the v1.1 release._

Why sovereign AI needs sovereign authority

## Sovereign compute is necessary; not sufficient.

A nation can build the full sovereign AI stack — AI cloud, GPU clusters, sovereign LLMs, local language models, national data spaces, sector-specific agents, public-sector AI services, regulated sandboxes — and still not be able to answer the operational questions that matter to oversight bodies, courts, ombudsmen, and citizens:

- Which ministry, agency, bank, hospital, contractor, model, agent, API, dataset, workflow, or vendor was allowed to act?
- On behalf of whom — which citizen, business, account, or principal?
- Under what authority — which delegation, consent, or statutory grant?
- Against which data, system, model, citizen, account, asset, or workflow?
- In what state — was the actor compromised, suspended, or in recovery?
- With what audit trail and what evidence a regulator, court, auditor, or oversight body can verify offline?

That is the gap KYE™ Sovereign AI Profile™ closes. EU programs (AI Factories, AI Factory Antennas), Canadian programs (Sovereign AI Compute Strategy), and equivalent national initiatives create compute and model capacity. KYE™ Sovereign AI Profile™ sits on top — the runtime authority graph for AI agents, models, datasets, APIs, workflows, contractors, and public services that run on that capacity.

Sovereign AI object model

## Entities, capabilities, authorities, state.

### Entity types

government\_department · public\_agency · regulator · municipality · national\_ai\_operator · citizen · business · civil\_servant · contractor · vendor · ai\_agent · model · dataset · api\_client · workflow · compute\_cluster · sandbox · sector\_gateway · oversight\_body

### Capability types

citizen\_service\_action · benefit\_eligibility\_assessment · document\_review · case\_triage · fraud\_detection · policy\_analysis · permit\_processing · healthcare\_triage · tax\_workflow · open\_finance\_action · critical\_infrastructure\_action · defence\_workflow · public\_procurement\_action · regulatory\_submission · dataset\_access · model\_deployment · model\_inference · agent\_execution

### Authority types

public\_service\_authority · agency\_delegation · ministerial\_authority · regulatory\_authority · citizen\_consent · contractor\_authority · vendor\_access\_authority · dataset\_access\_authority · model\_operation\_authority · cross\_agency\_delegation · emergency\_authority · oversight\_review\_authority

### State dimensions

entity\_state · authority\_state · delegation\_state · credential\_state · model\_state · dataset\_state · compute\_state · risk\_state · recovery\_state · compliance\_state · oversight\_state

KYE™ Sovereign AI apps

## Five planned apps for sovereign AI ecosystems.

### KYE™ Sovereign AI Authority Gateway™

Runtime authority gateway for national AI agents, public-sector workflows, regulated AI services, datasets, models, APIs, and cross-agency actions. Checks agencies · agents · models · datasets · APIs · contractors · citizens · workflows · regulated services before AI-powered actions execute. **Govern who or what can act across sovereign AI infrastructure.** Before the action runs, KYE™ proves the actor was authorised, the delegation was in scope, the model state was healthy, and the audit chain was bound. **Open:** sovereign AI authority schemas · cross-agency delegation schema · sample decision payloads · webhook verifier · SDK examples.

### KYE™ National AI Agent Registry™

Register and govern AI agents, models, tools, datasets, capabilities, owners, maintainers, risk states, and permitted actions across a national AI estate. One authority graph for every AI system in scope. **Open:** agent + model + dataset registry schemas · capability-grant schema · risk-state vocabulary · sample agent passport.

### KYE™ Public Sector Decision Map™

Replay why an AI-assisted public-sector action was allowed, denied, escalated, or routed for human review. Worked example: _citizen request → public agency → AI agent → dataset / model / tool → legal / policy authority → human oversight rule → decision → audit event → evidence pack._ **Open:** Decision Map™ schema · sample chains · signature verifier.

### KYE™ Sovereign AI Evidence Pack™

Export evidence for AI-assisted public decisions, dataset access, model deployment, agent actions, contractor access, and emergency overrides. For auditors, regulators, courts, ombudsmen, and oversight bodies. **Open:** evidence-pack schema · sample packs · signature-verification library · offline replay tool.

### KYE™ National Sandbox Authority Harness™

Test AI agents and regulated workflows with synthetic entities, scoped authority, Decision Maps™, evidence packs, self-audit, and conformance reports. For FCA-style sandboxes, UAE Open Finance, public AI pilots, healthcare sandboxes, pension sandboxes, and national innovation programs. **Open:** sandbox authority schemas · synthetic test fixtures · sample evidence payloads · sandbox connector manifest.

Sovereign connectors

## Where the Sovereign AI Authority Gateway™ plugs in.

| Connector | Purpose | Status |
| --- | --- | --- |
| National digital ID | Citizen + business identity binding into the entity registry. | Reference pattern |
| Government API gateway | Authority pre-check on every government-API call. | Reference pattern |
| Health API | Sector overlay; consent + clinical-context binding. | v1.1 preview |
| Open finance API | PSD3 SCA + sector-sandbox bridge. | Shipping (KYE™ Payments Profile™) |
| Tax / benefits / case-management | Public-services authority + audit binding. | v1.1 preview |
| Model registry | Model entity + risk state + permitted-action binding. | v1.1 preview |
| Dataset catalogue / data spaces | Dataset access authority + provenance binding. | v1.1 preview |
| National cloud | Workload-binding evidence (sovereign region + tenancy + isolation). | Reference pattern |
| Public-sector IAM | Workforce + contractor identity feed. | Shipping (OAuth / OIDC / SAML / SPIFFE) |
| SIEM / SOC | Signed event stream into the national security operations centre. | Shipping (Splunk / Sentinel exporters) |
| GRC | Control-mapping evidence fed into the governance system of record. | Shipping (289 control mappings) |
| Audit / evidence archive | Long-term retention for evidence packs + Decision Maps™. | Reference pattern |
| Regulator portal | Per-supervisor access to evidence + conformance reports. | v1.1 preview |
| Ombudsman evidence | Citizen-grievance replay surface. | v1.1 preview |

Governance fit

## EU AI Act · ISO 42001 · NIST AI RMF · OECD principles.

KYE™ Sovereign AI Profile™ does not claim to make a deployment “compliant” with the AI Act, ISO 42001, NIST AI RMF, or any framework. What it does is produce the _evidence layer_ those frameworks ask for: human oversight, record-keeping, traceability, accountability, incident review, regulatory assurance.

- **Make authority explicit.** Every action carries a delegation chain back to a named principal and a statutory or consent basis.
- **Make state visible.** Compromised, suspended, or in-recovery actors cannot act; the state is part of the decision.
- **Make decisions replayable.** Decision Map™ per action; signed; verifiable offline.
- **Make evidence exportable.** Evidence packs in OSCAL + native + COSE-receipt formats.
- **Make revocation immediate.** Cascade revocation propagates across the authority graph in seconds, not minutes.
- **Make oversight inspectable.** Ombudsman / supervisor access portal sees the same signed evidence the operator does.

For the framework-by-framework control bindings see [frameworks.html](https://kyeprotocol.com/frameworks/) and [oscal.html](https://kyeprotocol.com/oscal/).

What ships today

## Sovereign authority schemas. Apache 2.0.

Governments and sovereign AI programs need transparency, auditability, and inspectability. Open schemas increase trust.

| Layer | What you get |
| --- | --- |
| Profile | Sovereign AI authority schema, public-sector authority schema, cross-agency delegation schema, model / dataset authority schema, public-service evidence-pack schema, signed webhook / event schema, sample Decision Map™ JSON, conformance fixtures, SDK support, MCP read-only tools, sample connector manifests. |
| Apps | Reference architectures · sample app manifests · SDK examples per app. |
| Runtime | KYE™ Reference Gateway™: PEP middleware · embedded ePDP · conformance runner. |

Connector profile family

## Nine sovereign-related profiles, gated to v1.1.

- **KYE™ Sovereign AI Profile™** — the umbrella profile bundling the entity / capability / authority / state surface above.
- **KYE™ Public Sector Profile™** — agency + civil-servant + citizen-service authority binding.
- **KYE™ National AI Agent Profile™** — registry + capability + permitted-action binding for AI agents at national scale.
- **KYE™ Government API Authority Profile™** — pre-authorisation hook for every government-API call.
- **KYE™ Public Services Evidence Profile™** — evidence-pack format for citizen-impacting AI-assisted decisions.
- **KYE™ Sovereign Data Access Profile™** — dataset + data-space authority + provenance.
- **KYE™ Sovereign Model Registry Profile™** — model entity + risk state + permitted-action binding.
- **KYE™ Cross-Agency Delegation Profile™** — ministerial + agency + regulatory delegations across an estate.
- **KYE™ National Sandbox Profile™** — supervisor + participant authority binding for regulated sandboxes.

All nine sovereign-related profiles are v1.1 preview. The schemas, vocabulary, and conformance fixtures freeze with the v1.1 release; The schemas are open; the runtime engine is the planned commercial layer.

Adjacent reading

## Where to go next.

[KYE™ Connector Profiles™](https://kyeprotocol.com/connector-profiles/) [KYE™ App Store](https://kyeprotocol.com/apps/) [Frameworks & mappings](https://kyeprotocol.com/frameworks/) [Pilot snapshots](https://kyeprotocol.com/customers/) Talk to the team

## Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Try the sandbox →](https://kyeprotocol.com/sandbox/demos/)

**Independent — no government affiliation.** KYE Protocol™ is an independent protocol and is **not affiliated with, endorsed by, or part of** any government, regulator, or official “Sovereign AI” programme. References to regulators and frameworks describe the requirements KYE™ helps you evidence — not any official relationship.

Canonical KYE™ surfaces referenced on this page: [Authority Graph™](https://kyeprotocol.com/authority-lifecycle/) · [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) · [KYE Protocol™](https://kyeprotocol.com/).
