From Sovereign Cloud to Sovereign AI: Why Data Residency Is No Longer Enough

Cloud & Infrastructure • 18 hours ago • Shruti Das

As AI becomes embedded in critical enterprise and government workloads, cloud sovereignty is expanding beyond where data is stored. The next phase is about controlling where AI is processed, who operates the infrastructure, which technologies it depends on and which jurisdiction ultimately has authority over it.

For years, cloud sovereignty was largely discussed as a data-location problem.

Where is the data stored? Which country’s laws apply? Can an organisation guarantee that sensitive information remains within a particular geographic boundary? Those questions remain important. But the rapid expansion of AI is exposing their limitations.

An AI workload does not simply store data. It processes data, creates models and embeddings, relies on specialised accelerators, moves information across high-speed networks and may depend on software and infrastructure operated by organisations headquartered in another jurisdiction. That is turning sovereignty into a much broader infrastructure question.

For enterprises, the question is increasingly shifting from “Where is my data?” to “Who ultimately controls the infrastructure and AI systems that process it?” This shift is creating a new market for sovereign AI infrastructure — and it could significantly change how enterprises approach cloud architecture.

Sovereignty is moving up the infrastructure stack

Traditional cloud sovereignty focused primarily on data residency and regulatory compliance. Sovereign AI introduces several additional dimensions.

An organisation may want its data stored within national borders, but that alone does not necessarily establish control over the infrastructure processing that data. It may also need assurances around who can access the environment, where administrators are located, who controls encryption keys, where AI models and derived data are processed, and which legal jurisdiction governs the provider.

Microsoft’s current guidance for sovereign AI, for example, distinguishes between data, operational and technological sovereignty. Its framework considers not only where training and inference data are stored and processed, but also encryption-key control, confidential computing, operational oversight and model provenance. That distinction is important because AI creates more assets that enterprises need to protect.

A conventional application may involve databases, application code and user information. An AI system can involve training datasets, fine-tuning data, model weights, embeddings, vector indexes, prompts, evaluation data and inference workloads. Sovereignty therefore has to follow the entire AI workload, not simply the database.

Why AI is making sovereignty more urgent

The timing is not accidental. AI is becoming embedded in increasingly sensitive business processes, from financial services and healthcare to defence, public services and industrial operations. At the same time, geopolitical tensions are making organisations more conscious of their dependence on technology providers and infrastructure located outside their own jurisdictions.

Gartner forecasts worldwide sovereign-cloud IaaS spending of $80 billion in 2026, up 35.6% from 2025. It expects sovereign cloud spending to shift around 20% of current workloads from global to local cloud providers, with governments, regulated industries and critical infrastructure among the major buyers.

But the emerging sovereign AI market is going beyond conventional cloud localisation.

Gartner describes sovereign AI infrastructure as a response to both geopolitical and regulatory pressures, with specialised providers emerging alongside hyperscalers. Its research points to a growing need for what it calls a “sovereign stack” — infrastructure and services designed to provide greater operational autonomy and protection from external jurisdictional influence. The implication is significant: sovereignty is becoming an infrastructure architecture decision rather than simply a compliance checkbox.

The sovereign AI stack

A useful way to understand this transition is to think about sovereignty as a stack. At the bottom is physical infrastructure: data centres, power, cooling, networking and hardware. Above that sits compute infrastructure: GPUs and other accelerators used for training and inference. Then comes the cloud and software layer, including operating environments, orchestration, storage and AI platforms. Above that are models and data. Finally, there is the operational and governance layer: who can administer the systems, who holds encryption keys, who can access the data, how incidents are handled and which laws govern the environment.

An organisation can therefore have data physically located inside its country while still having limited sovereignty over other parts of the stack. That distinction is becoming increasingly relevant as AI workloads become more specialised. True sovereignty is not necessarily achieved by moving a workload to a local data centre. It requires understanding which parts of the AI stack are actually under local control.

The hardware question is becoming unavoidable

This is where sovereign AI begins to overlap with the broader AI infrastructure race. AI infrastructure depends heavily on advanced accelerators, networking equipment and specialised components. Many countries remain dependent on international supply chains for these technologies. That creates an uncomfortable contradiction.

A country may build a large domestic AI data centre, keep sensitive information inside its borders and employ local operators — while still depending on foreign suppliers for the most important hardware and software components. The result is partial sovereignty. This does not make the infrastructure useless. In many cases, local infrastructure can dramatically improve data control, resilience and compliance. But enterprises and governments need to distinguish between data sovereignty, operational sovereignty and technological sovereignty rather than treating them as interchangeable.

Gartner’s definition of technological sovereignty specifically includes the ability to develop, own and manage essential digital technologies without undue reliance on foreign providers. That makes hardware supply chains part of the sovereignty discussion. And it means the sovereign AI debate cannot be separated from the semiconductor and infrastructure ecosystem supporting AI.

Governments are beginning to build sovereign AI infrastructure

This is no longer purely a theoretical discussion. Countries are increasingly investing in domestic AI infrastructure as part of broader national technology strategies. South Korea, for example, is expanding a sovereign AI infrastructure programme involving NAVER, NVIDIA and Brookfield. The planned expansion would take an initial 55 MW AI factory deployment to 200 MW by 2028, with NAVER describing the longer-term ambition as gigawatt-scale sovereign AI infrastructure serving enterprises, industries and government.

Europe is taking a different but related approach. The European Commission has introduced a Cloud Sovereignty Framework that evaluates providers across 48 criteria spanning strategic, legal and jurisdictional, data and AI, operational, supply-chain, technological, security and environmental considerations. The framework was used in a €180 million procurement for sovereign cloud services for EU institutions.

The significance is broader than the individual procurement. It demonstrates that sovereignty is becoming something organisations can attempt to measure, procure and contract for rather than simply describe as a policy objective.

The enterprise version will be more selective

The rise of sovereign AI does not mean every enterprise should abandon global hyperscalers and build everything locally. That would be economically unrealistic for most organisations. Instead, the more likely outcome is workload-level sovereignty.

An enterprise could continue running ordinary applications on a global hyperscaler while placing selected workloads — such as government contracts, sensitive financial data, healthcare systems or critical industrial AI — on infrastructure with stronger sovereignty guarantees. This approach also reflects the economics of AI. Building or procuring highly sovereign infrastructure can carry what Gartner describes as a “sovereignty premium.” The additional cost may be justified for workloads where regulatory exposure, national-security considerations, intellectual property or operational resilience are more important than achieving the lowest possible infrastructure price.

The question therefore becomes less about whether an organisation needs a sovereign cloud at all and more about which workloads actually require it.

Sovereignty creates a new cloud procurement problem

The biggest change may ultimately occur in procurement. Traditional cloud evaluations tend to focus on familiar variables: price, performance, availability, service breadth, security and support. Sovereign infrastructure introduces another set of questions.

Who owns the data centre?

Who controls the hardware?

Where are administrators located?

Who controls the encryption keys?

Can foreign authorities legally compel access?

Where are AI models trained and hosted?

Where does inference take place?

Who controls the underlying software?

Can the provider operate the environment without depending on personnel or systems outside the required jurisdiction?

What happens if geopolitical conditions change?

The European Commission’s framework illustrates how broad this assessment can become: sovereignty can encompass legal jurisdiction, supply chains, technology, operations, security and sustainability in addition to data itself. For enterprise buyers, sovereignty is therefore becoming a due-diligence exercise across the entire technology stack.

The risk of building sovereignty the wrong way

There is, however, an important caveat. Sovereignty does not automatically mean better technology. A locally controlled infrastructure platform can still have weaker performance, higher costs, limited scalability or greater operational complexity than a global hyperscaler. There is also a danger of creating fragmented technology environments in which every country builds its own stack, duplicates infrastructure and reduces interoperability.

Gartner has warned that geopolitical and regulatory pressures could contribute to increasing regional fragmentation of AI platforms. It predicts that by 2027, 35% of countries could be locked into region-specific AI platforms using proprietary contextual data. For enterprises operating across multiple markets, that could create a new form of complexity. The challenge will therefore be finding the right balance between control and interoperability.

Sovereign AI does not mean isolated AI

The strongest sovereign AI strategies are unlikely to be completely isolated environments. Instead, enterprises will increasingly build tiered infrastructure architectures. Low-risk workloads can remain on global cloud platforms. Sensitive workloads can move to sovereign regions or dedicated environments. Highly regulated workloads can run on infrastructure with stronger operational and jurisdictional controls. And the most critical systems may require deeper technological independence. This creates a hybrid model rather than a binary choice between hyperscaler and local provider.

It also explains why the rise of sovereign AI is happening alongside the rise of neoclouds. Specialised providers can offer infrastructure designed around particular performance, deployment or sovereignty requirements, while hyperscalers continue to provide global scale and broad platform capabilities. The cloud market could therefore become more heterogeneous rather than less.

What enterprise technology leaders should evaluate

As sovereign AI moves from policy discussions into infrastructure decisions, CIOs and infrastructure leaders should examine several dimensions before choosing a provider:

  • Data sovereignty: Where are training data, inference data, models and derived AI assets stored and processed?
  • Operational sovereignty: Who operates the infrastructure, and where are privileged administrators located?
  • Technological sovereignty: How dependent is the environment on foreign hardware, software and infrastructure suppliers?
  • Legal sovereignty: Which jurisdictions and laws can potentially govern the provider or its operations?
  • Supply-chain resilience: Can critical hardware and infrastructure components be replaced if geopolitical or commercial conditions change?
  • Key management: Who controls encryption keys and other security mechanisms?
  • Model control: Where are models hosted, modified, fine-tuned and governed?
  • Portability: Can workloads move to another provider or jurisdiction if requirements change?
  • Interoperability: Can sovereign workloads still connect to the wider enterprise technology environment?
  • Cost: What sovereignty premium is the organisation willing to pay for greater control?

These questions should be evaluated at the workload level, rather than applied uniformly across the entire enterprise.

The bigger shift: sovereignty is becoming an infrastructure strategy

The most important change is that sovereignty is moving from the legal and compliance departments into the infrastructure architecture. For years, enterprises could largely treat cloud as a global utility. Data could be stored in regional zones, applications could span multiple geographies and infrastructure decisions could be driven primarily by economics and performance.

AI complicates that model. When an organisation’s most valuable intellectual property increasingly resides in models, datasets and AI workflows, the infrastructure processing those assets becomes strategically important. At the same time, geopolitical tensions, regulatory requirements and technology supply-chain dependencies are making questions of control harder to ignore. That is why the next phase of cloud sovereignty will not be defined simply by where a server sits. It will be defined by who controls the infrastructure, who operates it, who supplies its critical technologies and which laws ultimately have authority over it.

The sovereign cloud era is therefore evolving into the sovereign AI era. And for enterprise technology leaders, the strategic question is no longer simply “Where should our data live?” It is becoming: “Which parts of our AI infrastructure must we control?”

Key Takeaways

  • Cloud sovereignty is expanding beyond data residency. Enterprises increasingly need to consider where AI workloads are processed, who operates the infrastructure and which jurisdiction governs it.
  • AI creates more assets that require sovereignty. Training data, model weights, embeddings, inference workloads and other AI artefacts can all become strategically sensitive.
  • Sovereign AI involves multiple layers of control. Data, operations, technology, hardware, supply chains and legal jurisdiction all matter.
  • Governments are investing in sovereign AI infrastructure. National AI strategies are increasingly incorporating domestic computations, data centres and AI platforms.
  • Enterprises are likely to adopt workload-level sovereignty. Not every workload needs a sovereign environment; sensitive and regulated workloads may require stronger controls than ordinary applications.
  • Sovereignty can come with a cost. Enterprises need to weigh the sovereignty premium against regulatory exposure, resilience, security and strategic control.
  • The future is likely to be hybrid rather than isolated. Global hyperscalers, neoclouds and sovereign infrastructure providers can coexist within the same enterprise architecture.