Dr. Aditya Vikram Kashyap, AI governance and innovation leader exploring how autonomous systems reshape institutions, markets and power.
A NIST concept paper published in February stated the shift more plainly than most strategy decks: Enterprises are moving AI from generating text and graphics to taking actions, such as deploying code to production. Short sentence, large consequence. The sovereignty debate has not caught up with it.
That debate has three columns. Model sovereignty asks who controls the intelligence. Data sovereignty asks who controls the information. Compute sovereignty asks whose machines it runs on. Europe has begun formalizing the question: The proposed Cloud and AI Development Act would introduce a single EU-wide framework to assess cloud and AI sovereignty. It is a serious instrument. But the sovereign-AI debate still gravitates toward where models, data and infrastructure sit, and where an agent sits is the least interesting thing about it.
Agents are interesting because they act. One can move money, rotate a credential, reprice a contract, patch a production system or hand the job to a second agent that does. The moment an institution delegates that, a fourth column appears, and it governs the value of the other three.
Execution sovereignty is the authority an institution keeps over what its autonomous systems may do, on whose behalf they act, what they may pass onward and when that authority can be narrowed or withdrawn. Data sovereignty settles who owns the information. Execution sovereignty settles who decides what a machine may do with it at two in the morning without asking anybody.
The difference is architectural. A model gives an agent capability. Something else gives it permission. The specifications hardening around agents are careful about this line. The Model Context Protocol’s authorization specification binds an access token to the server it was issued for and requires servers to reject tokens that were not.
Agent2Agent handles identity at the protocol layer rather than inside its own semantics, expects credentials to be obtained out of band and leaves the authorization decision to the receiving agent. That restraint is correct. An interoperability standard has no business deciding who may do what inside your institution. But it means the deciding happens somewhere else: in the identity provider, the policy engine, the log, the revocation path. That is the control plane, and it is rarely what institutions negotiate hardest over.
Picture a domestic bank running agents across treasury operations and supplier payments. Data stays in country, workloads run in country and the supervisor is satisfied. But the agents’ machine identities are issued by an external provider, the policy engine that decides which actions clear is a managed service and the model behind the agents updates on a schedule the bank does not set. None of that is illegitimate, and none of it shows up on a data-residency dashboard. If the provider changes a default, tightens a limit or suspends the service, the bank’s payments do not slow down. They stop.
Financial supervisors have been circling this without naming it. DORA obliges banks to maintain documented exit strategies for critical technology services, and last November, the European supervisory authorities published their first list of critical ICT third-party providers. Those are control-rights instruments wearing resilience clothing, and the test they imply generalizes. Of any deployment, ask who can widen its permissions without your sign-off, who can narrow them, who can see what it did, who can halt it mid-action and who can move it elsewhere when the relationship sours. If the answer to more than one is “not us,” the system is hosted domestically and governed abroad.
This is why localization and sovereignty keep getting confused. A domestically hosted model whose agents authenticate through a foreign identity service and obey a foreign policy engine has weak execution sovereignty. A foreign-built agent running under your identity infrastructure, your authorization policy and your audit trail, with a technical and contractual ability to revoke and replace it, may have strong execution sovereignty. Location is a fact about infrastructure. Sovereignty is a fact about control rights.
European law already carries the instinct, applied to older technology. The Data Act requires cloud providers to remove the obstacles that stop customers from switching away. The AI Act requires high-risk systems to be built so a person can disregard, override or interrupt them through a stop button. Read through this lens, both look like early execution-sovereignty provisions written before the phrase existed. Neither yet contemplates an agent that delegates to another agent at four in the morning.
None of this is an argument for building everything at home. Interdependence is how anyone gets good technology, and states most determined to escape it can end up with worse systems and the same dependencies under new labels. The goal is narrower than autarky. Dependency is fine. Dependency that hardens into a veto over consequential machine action is not, and the distance between the two is a design decision, made early, usually by people nobody told was making a sovereignty call.
Skip the grand historical analogies. The narrower point is harder to dismiss: the identity, delegation and revocation machinery for agents is being drafted now, mostly by engineers, in documents no board will read. NIST’s AI Agent Standards Initiative is conducting fundamental research into agent authentication and identity infrastructure. What gets settled there will set how much authority institutions keep over the systems acting in their name.
The sovereign-AI conversation has so far been an argument about provenance. Where was the model trained, where does the data rest and whose chips are in the rack? Those questions had a good run and they are not wrong. They describe a world in which machines produce answers and people do the acting. That world is closing. What replaces it is one where institutions hand real authority to software, then discover during an incident how much of that authority they never held. The question worth asking is no longer where the intelligence came from. It is who can tell it to stop and be obeyed.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


