Blog | Data Strategy & Insights | | 5 min read

Data and AI Sovereignty: Why Control Matters in the AI Era

Data and AI Sovereignty O’Reilly Report book cover

Summary

  • Data and AI sovereignty is about who ultimately controls data, infrastructure, models, and critical technology dependencies.
  • AI expands sovereignty beyond data residency to include where intelligence executes, how decisions are made, and who controls agent behavior.
  • Control, Enforcement, and Proof provide a practical framework for making sovereignty operational across enterprise architecture.
  • Sovereignty exists on a spectrum, so different workloads may require different levels of control across cloud, on-premises, and edge environments.
  • Hybrid sovereignty helps organizations balance flexibility with the ability to govern dependencies, manage risk, and adapt as technology and regulations change.

Keeping data within national borders does not necessarily make it sovereign. 

Your data might reside in an approved region while the infrastructure, software, AI models, or services processing it remain controlled by providers subject to different jurisdictions. A provider can change its terms, pricing, architecture, or availability. An AI model or API that supports a critical business process can change or disappear.

The more important question is: Who ultimately has control?

That question is at the heart of Data and AI Sovereignty: Understanding Sovereign Data and AI Across Cloud, On-Premises, and Edge, a new O’Reilly report by Actian CTO Emma McGrattan, Chief Researcher Steffen Kläbe, and Chief Evangelist Ole Olesen-Bagneux.

The report explores how organizations can make critical technology dependencies deliberate, visible, and manageable while retaining the ability to act when circumstances change.

Why Data and AI Sovereignty Matters Now

For decades, enterprise technology architectures were optimized for connectivity, scale, efficiency, and access to global technology ecosystems. Those priorities still matter. But the assumptions underneath them are changing.

Enterprises increasingly depend on cloud platforms, SaaS providers, external APIs, foundation models, and infrastructure they do not directly control. At the same time, regulation, geopolitical change, technology supply chains, and AI are creating new questions about where data can move, where intelligence can execute, and which organizations or jurisdictions ultimately have authority over critical systems.

Sovereignty is therefore becoming more than a compliance consideration. It is becoming an enterprise architecture concern.

Few modern enterprises can eliminate external dependencies, nor should they try. What matters is knowing which dependencies are critical, where they introduce unacceptable risk, and where greater control creates strategic value.

How AI Expands the Sovereignty Challenge

Traditional discussions of data sovereignty focused heavily on where information was stored and how it moved across borders. AI changes the scope of the problem.

Enterprise data can now become prompts, embeddings, model context, training data, and inputs to autonomous systems. AI systems may combine information across multiple sources, generate new knowledge, and take actions across different providers and jurisdictions.

That creates three related dimensions of sovereignty:

  • Data sovereignty focuses on control over data residency, movement, access, and jurisdiction.
  • AI sovereignty extends that concern to models, compute infrastructure, providers, and where AI executes.
  • Agentic sovereignty adds another layer as autonomous agents access enterprise information, build memory, make decisions, and take actions on an organization’s behalf.

As AI becomes more autonomous, sovereignty is no longer only about where information is stored. It is also about where intelligence is created, how decisions are made, and whether AI behavior can be constrained, explained, and verified.

Three Capabilities for Data and AI Sovereignty

The report frames sovereignty around three capabilities organizations can use to evaluate their architecture:

  • Control: Who determines how data, AI models, and agents can be accessed and used?
  • Enforcement: How are those decisions translated into operational policies and technical controls?
  • Proof: Can the organization demonstrate that those controls are working, including when something goes wrong?

These capabilities are interdependent. Control without enforcement remains policy. Enforcement without proof cannot be trusted. And proof without meaningful control provides little assurance.

Together, Control, Enforcement, and Proof provide a practical way to move sovereignty from an aspiration to an operational capability.

Data and AI Sovereignty is a Spectrum, Not a Binary Choice

Different data, applications, AI workloads, and infrastructure carry different levels of sensitivity, regulatory exposure, operational importance, and dependency risk.

The report introduces five sovereignty maturity levels that help organizations evaluate how much control they need and understand the trade-offs in complexity, cost, capability, and strategic freedom.

The highest level of sovereignty is not necessarily the right answer for every workload. Some workloads may appropriately run on global public cloud infrastructure, while sensitive data or business-critical AI may require greater control through sovereign cloud, domestic providers, on-premises infrastructure, or edge deployments.

Why Hybrid Sovereignty is the Practical Enterprise Model

For most enterprises, the practical answer is hybrid sovereignty.

Rather than applying the same sovereignty requirement everywhere, organizations can assess individual components and assign the level of sovereignty appropriate to their risk and business requirements.

The same principle applies to AI. The future of enterprise AI is not simply cloud versus on-premises. It is increasingly distributed across cloud, on-premises, and edge environments, with different sovereignty requirements for different workloads.

The architectural challenge is understanding where each model belongs and governing data and AI movement across those boundaries.

What This O’Reilly Report Helps You Understand

Data and AI Sovereignty: Understanding Sovereign Data and AI Across Cloud, On-Premises, and Edge provides a practical framework for moving the sovereignty conversation from geopolitical theory and compliance into enterprise architecture. You’ll learn:

  • How sovereignty extends across data, AI, and agentic systems.
  • How Control, Enforcement, and Proof make sovereignty operational.
  • How to assess different levels of sovereignty and their trade-offs.
  • How to develop a hybrid sovereignty strategy across cloud, on-premises, and edge.
  • How to assess your organization’s sovereignty readiness and prioritize next steps.

The report also includes a practical Sovereignty Readiness Checklist organized around Control, Enforcement, and Proof.

Sovereignty is a Continuous Journey

Technology providers change. Regulations evolve. New AI models emerge. New dependencies appear. That makes sovereignty less a destination and more an architectural capability that must evolve with the organization.

The objective is not isolation. It is to retain meaningful options: understanding the technologies your organization depends on, governing those dependencies deliberately, and preserving the ability to adapt when circumstances change.

As the report concludes, the goal is ultimately “the ability to engage with the world on your own terms and with confidence.”

Get the Full Report

Data and AI Sovereignty: Understanding Sovereign Data and AI Across Cloud, On-Premises, and Edge provides a practical framework for deciding where greater control matters.

Get Your Free Copy