Sovereignty of the decision, not just the data.
Data sovereignty answers where AI runs — confidential compute, hardware-attested enclaves, in-region residency. Sovereign Execution™ answers the harder question your regulator actually asks: who is allowed to act — and proves it. KYE Protocol™ sits above the sovereign stack. Even when a workload is isolated and attested, the action it triggers still needs authority, evidence, finality and replay-verifiable proof. Confidential AI protects the computation; KYE Protocol™ governs the consequence.
Two different questions — and you need both answered
If you are a CISO or counsel buying sovereign AI for a UK or EU institution, you are stitching together two layers that are often confused. KYE Protocol™ does not compete with the first; it completes the second.
Where does the AI run?
Confidential compute, trusted execution environments (TEEs), on-premises or in-region VPC deployment, and data residency. This is what confidential-AI and sovereign-infrastructure vendors solve: the model weights and the prompt never leave a boundary you control, and the hardware attests to it.
Who is allowed to act — and can you prove it?
Was this agent authorised for this specific action, under this purpose and scope, at the moment it happened? Sovereign Execution™ binds every consequential action to a sealed Authority Sourcing™ record, an Evidence Pack™, and a Replay-Proof™ verdict anyone can re-check offline.
Honesty boundary for a CISO. KYE Protocol™ does not provide data residency, confidential compute, or infrastructure sovereignty. It is the authority and evidence layer that runs on top of whoever does. KYE Protocol™ is complementary to confidential AI and sovereign infrastructure — never a replacement for them.
KYE Protocol™ sits above the sovereign stack
The sovereign-AI conversation usually stops at the infrastructure boundary. But a confidential, isolated, hardware-attested workload can still trigger a wire transfer, a denied claim, or a clinical recommendation — and none of that infrastructure tells you whether the action was permitted. Sovereign Execution™ is the layer that does.
What Sovereign Execution™ adds above confidential AI
Confidential compute makes the workload trustworthy to run; it says nothing about whether the action was permitted, irreversible-by-design, or defensible afterwards. Sovereign Execution™ closes those four gaps, each as part of the fixed KYE Protocol™ evidence family of 7 signed JSON schemas mapped to the EU AI Act™ Article 12 logging duty, NIST AI RMF and ISO/IEC 42001™.
- Authority — who may act. Every action is checked at the moment it happens against the acting principal's purpose, scope and limits via Authority Sourcing™, not against a config row someone could overwrite.
- Evidence — what actually happened. The inputs, the rules they hit, and the outcome are sealed into an Evidence Pack™ with an Ed25519 context seal, under write-once retention — so a confidential decision is still an auditable one.
- Finality — what cannot be quietly undone. Authority Finality™ means an irreversible action carries dual-channel sign-off and a revocation is itself a recorded event, so "who turned it off, and when" is never a guess.
- Proof — defensible to a third party. Replay-Proof™ lets a regulator or auditor re-verify the verdict offline from published keys alone, with no trust in KYE Protocol™ and no access to your confidential enclave.
This is not a new engine and not a parallel system. Sovereign Execution™ is the positioning name for what KYE Protocol™ already does — the Evidence Pack™ chain, the Authority Graph™, write-once audit retention and replay verification — framed for the sovereign-AI buyer who has already chosen where their compute runs.
Operationalize the regulation — don't route around it
For a UK or EU buyer, sovereignty is a means to a compliance end, not the end itself. Sovereign Execution™ is the tool that turns a framework obligation into a per-action control you can show a regulator, mapped across 243 frameworks.