Programme C
Sovereign and Secure AI
AI that serves heritage, language and education can be trusted only as far as the systems it runs on. This programme brings the practice of information security to those systems, so that institutions and public bodies keep control of them.

Planned Work on this programme is planned to begin in 2027.
Aim
Catalogues, text corpora, language models and search indexes have become part of the way heritage and knowledge are passed on. If an index is altered unnoticed, if a text in a corpus is changed without a trace, or if a model runs somewhere its users cannot see, the error or the dependency spreads into every answer built on it.
Information security has long asked the questions that matter here. Are the data intact? Is their origin known? Who controls the system, and where does it run? This programme turns these questions into practical guidance for heritage institutions, universities and public bodies: how to protect the integrity of their data, how to keep the decision over where their systems run and which models they use, and how to make all of this verifiable to others.
Three concerns
Information security
Threat models and protective measures suited to libraries, archives, museums and universities, rather than models carried over unchanged from commercial IT.
Sovereign operation
Hosting and the choice of model follow the needs of the institution. Where each component runs is disclosed, so that no institution depends on arrangements it cannot see.
Integrity protection
Corpora, indexes and models are protected against manipulation, with logging and auditability, so that every change can be traced and checked.
For whom
- Heritage institutions that run, or plan to run, digital catalogues, text corpora or search services.
- Public bodies responsible for heritage, language policy or digital infrastructure.
- Funders who need to judge whether a digital heritage project is secure and verifiable.
First verifiable output
A public security and architecture document. It will set out a threat model, describe how the integrity of indexes is protected and disclose the model profiles in use, that is, which model runs where. The document will carry a version number and is intended to undergo external review.
How progress is measured
- The version of the security and architecture document, and whether it has been reviewed externally.
- The number of institutions that use the document in their own work.
Values will be published only once the programme has begun, each with its date and source.
What this programme does not do
- We do not certify institutions or systems, and we claim no certification of our own.
- We do not offer paid security consulting under the Initiative's name; paid advice takes place outside the Initiative.
- We do not require any institution to hand over its data or to depend on a particular cloud provider.
- We do not describe a model profile as in operation until it runs at a named location.
- We take no side between states and accept no interference in the results of our work.