Leonard Chan Tik-yuen says true AI sovereign capability means being able to inspect, repair and, when necessary, replace that steering mechanism
When a jurisdiction says it possesses a “sovereign artificial intelligence model”, one question is too rarely asked: If that model fails, is attacked or must be replaced tomorrow, does society have the capacity to act? A “sovereign model” may be a noun; “sovereign capability” must be expressed through a series of verbs. The former concerns what one owns. The latter concerns what one can do.
The growing interest in sovereign AI is entirely understandable. As AI enters public administration, finance, healthcare, education and critical infrastructure, no jurisdiction should surrender sensitive data, strategic capabilities, value judgments and final accountability wholesale to an external platform. Sovereign models offer an important reminder: Societies can remain open to global innovation without handing over the steering wheel.
Yet sovereignty should not be vested in one model alone. The deeper test is whether Hong Kong can inspect, audit, replace or, when necessary, rebuild any AI system used in the public interest. Can it retain control over data, rule-setting, independent evaluation and ultimate accountability? Owning a sovereign model without these capabilities is like buying a sports car without a driving license, trained mechanics or spare parts. One may hold the key, but ownership alone does not put the car safely on the road.
Hong Kong has already taken an important first step by building local large AI model and application-development capacity. The next stage must add the institutional ability to govern well and switch when necessary. Research may be undertaken by government, companies, universities, research institutes or open-source communities — and a more diverse field is generally a healthier one. Public responsibility, however, cannot be outsourced to any participant, however trusted it may be. The identity of an owner should never entitle a model to a discount on governance standards.
This is not distrust of developers; it is sound institutional design. Rule-setting, model supply, evaluation and procurement should not be concentrated in the same hands. Structural overlaps can weaken confidence even when everyone acts in good faith. AI governance therefore requires disclosure of interests, recusal where appropriate and independent verification.
Transparency must be calibrated rather than treated as an instruction to disclose every parameter, dataset and line of code to everyone. Regulators need data-governance records, evaluation evidence and incident logs. Professional users need limitations, version changes and testing methods. Citizens should know when they are interacting with AI, how their information is used, and where to seek correction or appeal. Transparency means giving each responsible party the information needed to discharge its duty.
International experience already offers useful benchmarks. Stanford University’s 2025 Foundation Model Transparency Index assesses major developers against 100 indicators. It covers disclosures about data, model information, computational resources, use and downstream impact. Its findings also make an important distinction: Open weights may correlate with transparency, but do not by themselves establish comprehensive transparency. Hong Kong could develop a local public scorecard for models entering public procurement or high-risk services, applying the same yardstick regardless of where or by whom a model was developed.
The evaluation process must itself be trustworthy. Whenever a model claims superior local performance, four questions follow: Who designed the benchmark, how is the test set protected and updated, was the scoring independently conducted, and can the result be reproduced? Developers should provide the technical evidence, but should not be the sole judges of their own products. Without a credible degree of separation between development and evaluation, even an impressive score may struggle to become public trust.
I would subject every model entering the public sphere to three tests. The first is substitutability: If a supplier or component becomes unavailable, can the service migrate within a reasonable period? This prevents lock-in. The second is auditability: Can an independent party examine data governance, security controls and real-world performance? This prevents the black box from becoming a shield. The third is accountability: If an AI-supported service causes harm, can responsibility be traced through development, deployment, use and decision-making? Imagine an elderly resident missing a benefit application because a government AI assistant supplied incorrect information. “The model made an error” is not an adequate answer unless someone corrects the decision and remedies the harm.
Failure to pass all three tests need not prohibit every use. It should, however, limit a model’s access to high-risk applications and public decision-making.
Hong Kong is not starting from zero. The Digital Policy Office’s Hong Kong Generative Artificial Intelligence Technical and Application Guideline addresses data leakage, model bias, error, accountability and information security. Version 1.1 applies a four-tier classification — unacceptable, high, limited and low risk — with proportionate requirements that include prohibition, conformity assessment, human oversight, transparency, opt-out arrangements and auditing. The next task is to translate these sound principles into testing, labels, certification and procurement practices that industry can apply and residents can understand.
This is where Hong Kong can occupy what I call a “third space”. It is not a vague compromise between systems. It is an institutional interface. On one side are Hong Kong law, national security, the “one country, two systems” principle and the city’s multilingual environment. On the other are internationally recognized governance languages such as the US National Institute of Standards and Technology’s AI Risk Management Framework and ISO/IEC 42001 for AI management systems.
Consider a multinational bank deploying an AI risk system in Hong Kong while facing local regulation, cross-boundary data requirements and overseas compliance expectations. If Hong Kong can provide third-party evidence that different markets understand and accept, that service may be more valuable than endorsing any single model. Its common law system and professional expertise could also support AI audit, mediation and arbitration. Hong Kong would export not merely technology, but trust recognized across markets.
A trustworthy AI ecosystem should therefore allow many models to flourish. The government’s role is to establish the standard, not pre-select the champion. Public procurement should be competition-neutral, multi-vendor and designed for switching, while public investment should also support Cantonese and local-context benchmarks, independent testing, audit tools, secure computing, specialized models and startups.
Flagship projects create visibility; diversity creates resilience. Three practical steps should follow. Hong Kong should establish a public AI evaluation platform independent of any supplier, with technical, legal, industry and resident participation. Public procurement should require high-risk systems to demonstrate portability, substitutability and traceability, backed by credible exit arrangements. Institutions involved in rule-setting, benchmark design or procurement should declare their roles, recuse themselves where their products are concerned, and accept external validation.
These measures would not create barriers. They would give established and future participants a fair opportunity to compete and to be tested under common rules. They would also strengthen Hong Kong’s ability to connect national priorities with international practice — not by choosing between them, but by turning institutional compatibility into economic value.
Sovereign models remind Hong Kong not to surrender control. Sovereign capability ensures that control survives changes in technology and suppliers. In the end, individuals and businesses will not trust an AI system because of its label or ownership, but because it can pass consistent, independent and reproducible tests.
Rather than debating which model represents Hong Kong, we should build Hong Kong’s capacity to govern any model. Sovereignty determines who holds the steering wheel; trust determines whether people are willing to get into the car. True sovereign capability means being able to inspect, repair and, when necessary, replace that steering mechanism.
The author is founding chairman of the Hong Kong Innovative Technology Development Association.
The views do not necessarily reflect those of China Daily.
