Digital sovereignty has emerged as a central concern for modern software-intensive systems, driven by the dominance of non-sovereign cloud infrastructures, the rapid adoption of Generative AI, and increasingly stringent regulatory requirements. While existing initiatives address governance, compliance, and security in isolation, they provide limited guidance on how sovereignty can be operationalized at the architectural level. In this paper, we argue that sovereignty must be treated as a first-class architectural property rather than a purely regulatory objective. We introduce a Sovereign Reference Architecture that integrates self-sovereign identity, blockchain-based trust and auditability, sovereign data governance, and Generative AI deployed under explicit architectural control. The architecture explicitly captures the dual role of Generative AI as both a source of governance risk and an enabler of compliance, accountability, and continuous assurance when properly constrained. By framing sovereignty as an architectural quality attribute, our work bridges regulatory intent and concrete system design, offering a coherent foundation for building auditable, evolvable, and jurisdiction-aware AI-enabled systems. The proposed reference architecture provides a principled starting point for future research and practice at the intersection of software architecture, Generative AI, and digital sovereignty.
翻译:数字主权已成为现代软件密集型系统的核心关切,这主要源于非主权云基础设施的主导地位、生成式人工智能的快速普及以及日益严格的监管要求。现有举措虽分别涉及治理、合规性与安全性,但未能就如何在架构层面实现主权提供充分指导。本文主张,主权应被视为首要的架构属性,而非纯粹的监管目标。我们提出一种主权参考架构,该架构整合了自主主权身份、基于区块链的信任与可审计性、主权数据治理,以及在明确架构控制下部署的生成式人工智能。该架构明确指出生成式人工智能的双重角色:既是治理风险的潜在来源,又能在适当约束条件下成为合规性、问责制与持续保障的赋能工具。通过将主权定义为架构质量属性,本研究在监管意图与具体系统设计之间架起桥梁,为构建可审计、可演进且具备司法管辖意识的人工智能赋能系统提供了连贯的基础。所提出的参考架构为软件架构、生成式人工智能与数字主权交叉领域的未来研究与实践提供了原则性起点。