Data & AI Series: The Growing Need for Technological Sovereignty

Four professionals reviewing a digital display and documents at a global technology conference

We are living through something most people haven’t quite named yet, but governments and tech strategists are feeling it every day. Technology has become the new weapon of state power. Whoever controls the AI, the chips, the cloud infrastructure, they effectively control economies, citizen data, and national security. And right now, most countries continue to be unaware or are trying to figure out what does it mean for them?

That’s an uncomfortable truth sitting underneath all the excitement about AI.

It’s not a concern yet, but its moving in that direction!

Think about what happened when governments directed AI companies to suspend access to frontier models overnight. Fable 5, Mythos 5, gone with no warning and no appeal. Or when major AI chips were flagged as export control violations anywhere in the world they were used, regardless of who bought them or where they sat. Or when reports emerged of advanced AI models being used to identify thousands of zero-day vulnerabilities across every major operating system and browser.

AI-enabled cyberattacks surged 89% globally in 2025. Nations running their critical infrastructure on foreign platforms have virtually no defense. And here’s the part that should concern every policymaker and business leader: data sitting on foreign tech is ultimately accessible to the powers that govern that tech, regardless of which country it physically sits in.

We’ve been so dazzled by the possibilities of AI that we haven’t stopped to ask a harder question. Who really owns the decisions being made people, businesses and the economy as a whole?

Few countries have started making moves, it may not be enough, but it’s a start nevertheless!

What strikes me when I look at how other nations are moving is the speed and the deliberateness of it.

Saudi Arabia, starting with less AI infrastructure than many countries have today, built an Arabic-native sovereign LLM across 50+ ministries in three years. Every government service now runs on Saudi-owned AI.

The UAE built Falcon, ranked the world’s top open-source model, and mandated that all government AI decisions run on sovereign infrastructure.

France made SecNumCloud certification non-negotiable for sensitive government workloads. Germany built Gaia-X as a sovereign alternative to dominant global hyperscalers. Singapore launched a national AI strategy with a government-wide mandate that bypassed individual agency RFPs entirely and trained 340,000 citizens on AI governance in the process.

Vietnam passed ASEAN’s first standalone AI law in December 2025. Indonesia issued ASEAN’s first sovereign cloud tender the same year and institutionalization of Danantara brought in the necessary control and direction to the sovereign objective.

The harder conversation: where do you draw the red line?

Here’s what I keep coming back to. With AI models now so widely accessible, citizens everywhere are using them constantly, for work, for personal decisions, for everything. And in doing so, they’re feeding enormous amounts of local, cultural, professional, and sensitive national information into global models.

We genuinely don’t know how that information will be used. By whom. For what purpose. Under what legal jurisdiction.

And I want to be clear; this is not an argument to ban AI or shut every door. The innovation potential is real, and no country benefits from cutting itself off entirely. But it is very much a reason to be deliberate about where you draw the line or where you start maximizing value from it responsibly with the right controls around it.

Every country, every government, every policymaker needs to honestly answer some version of these questions:

  • What decisions about our citizens should never be made on foreign infrastructure?
  • What data must stay not just locally stored, but locally governed?
  • Where are we comfortable letting global innovation in, and where do we need sovereign control?
  • What happens to our economy if a foreign power cuts off our access to these platforms tomorrow?

There’s no universal answer. But not having an answer is itself a choice, and it’s a dangerous one.

This is where government and policy leadership becomes non-negotiable

Markets will not solve this on their own. The incentives simply aren’t aligned for it. Global tech platforms benefit from data flows and dependency. Enterprises default to the cheapest and most capable option, which is almost always foreign. Individual citizens aren’t thinking about jurisdictional risk when they ask an AI assistant to draft their email.

Governments have to set the frame. That means a few concrete things.

Policies with teeth: Procurement circulars, certification requirements, GLC mandates. Governments need to require sovereign-certified infrastructure for sensitive workloads, the way France and Germany have done.

Legislation that actually keeps pace: AI governance acts, cloud data acts, IP protection frameworks, data protection enforcement upgrades. These need to be treated as national security instruments, not just regulatory compliance exercises.

A layered sovereign stack, built deliberately: From physical infrastructure like local data centers and air-gapped zones, all the way up through sovereign cloud platforms, data sovereignty layers, locally-governed AI models, and citizen-facing applications. Each layer matters. A gap in any one of them undermines the whole thing.

Talent and institutional capacity. You can mandate sovereign AI all you want, but if you don’t have the engineers, the certification bodies, the academic pipelines, and the governance expertise, the mandates will not have any impact.

International coordination. Bilateral data treaties, regional governance forums, shared standards. Sovereign doesn’t mean isolated, it means having the agency to choose your partnerships on your own terms.

The window is narrowing

Countries that are moving fast on this are building compounding advantages, technical capability, regulatory frameworks, talent pipelines, economic leverage, that will be very hard for others to close later.

Countries still debating whether this is urgent are accumulating a very different kind of compounding problem.

AI is not going to slow down and wait for policy to catch up. The real question is not whether to engage with it. It’s whether you do so on your own terms, or on someone else’s.

Leave a comment