Sanjay Dhawan, CEO at SymphonyAI. 30 years leading global tech companies. Engineer by training, operator by practice.

Most AI vendors have a data sovereignty story that explains on-premises options, residency agreements and private cloud configurations, but almost every one of them is answering the wrong question.

Enterprise AI procurement generally treats sovereignty as a data-location problem. Negotiate the right contract, keep the data in the right jurisdiction and satisfy the legal team.

What those agreements rarely address is the intelligence itself: the model that acts on your data, trains on pooled inputs from across the AI vendor’s customer base and improves in an environment you don’t control.

While this concern also matters for compliance reasons, the more consequential issue is competitive. Every interaction your operations have with an AI system—every process anomaly detected, every transaction flagged, every demand signal interpreted—is a data point that could be making your AI sharper.

Instead, in most current deployments, your data is making the vendor’s shared model marginally better for every customer they have, including your competitors. You are contributing to an intelligence asset you don’t own.

Answering A Different Question Than Where Servers Sit

From what I’ve seen, the fine print in most enterprise AI agreements does not deliver the level of data control that buyers assume they have.

Enterprises are connecting sensitive operational, financial and customer data to shared cloud infrastructure under terms that provide far less visibility than their governance frameworks require.

Meanwhile, the EU AI Act’s risk-tiered compliance requirements and the Financial Conduct Authority’s model risk management expectations have shifted data governance from a planning exercise to a standing requirement. In the United States, the April 2026 interagency model risk management guidance from the Office of the Comptroller of the Currency, Federal Reserve and FDIC reset the baseline for how banks are expected to govern the models they rely on, while leaving generative and agentic AI outside its scope entirely.

H2O.ai, Palantir and IBM have all made public sovereign AI commitments in the last twelve months. When the market hardens around specific architectural definitions, organizations that haven’t built to those standards will find themselves explaining gaps rather than leading the conversation.

A Structural Problem ​

General-purpose AI vendors and hyperscalers are built cloud-first, which is what makes them capable at scale and also what shapes the sovereignty options they can offer.

While data residency agreements and private deployments are available, what’s harder to source from that architecture is a system designed to keep improving with no external data dependency at all. The economics simply run the other way: the more isolated the deployment, the less the shared model gains.

Frontier providers’ models are powerful because they train on vast pooled data. That creates a trade-off worth sizing during evaluation rather than discovering in production: the more isolated the deployment, the fewer of those pooled-data advantages carry over.

But it also raises another diligence question: What specifically changes about model performance when the external data pipeline is closed, and how is that measured?

The Role Of Vertical AI​ In Data Sovereignty

One option for addressing that concern is vertical AI. Full disclosure: My company builds vertical AI for industrial, financial services and retail organizations. But, in a broad sense, vertical AI works differently than other models by architecture, not by configuration option.​

With this model, a platform built from the ground up can come with domain intelligence already embedded. Because the model improves on your data in your environment, the intelligence it develops over time is a proprietary asset that reflects your operations, your customers and your accumulated process knowledge.

Vertical AI is not a free trade. A platform built for financial crime detection is exceptional at financial crime detection but likely unremarkable at everything else, which means most organizations will run it alongside general-purpose tools and manage more than one AI relationship rather than fewer.

Isolated deployments also move infrastructure, monitoring and lifecycle responsibility back inside the enterprise—sovereignty means owning the maintenance, not just the model.

And a model improving on your data will lag the frontier on general capability advances, because it is not training on the same pooled data.

However, there is still a strategic question across industries: Is the AI you are building an asset your organization accumulates, or a service you are renting on someone else’s terms?​

To answer this question, an operations leader in manufacturing should ask AI vendors what happens to model performance when the external pipeline is closed. The answer defines whether you are building a proprietary operational capability or a subscription model.

When developing their AI strategy, risk and compliance leaders should factor in that the financial crime patterns, risk signals and behavioral data your institution has accumulated over decades are among your most valuable assets. A sovereign AI deployment can mean those patterns train a model that belongs to you, helping to ensure your examiners can audit it and your competitors cannot access it.

Meanwhile, for CDOs and CTOs, the AI systems being deployed today will be difficult to migrate in three years. Who owns the model improvements those systems generate will determine whether your organization enters that period with a compounding advantage or a dependency that is difficult to unwind.​

Looking At AI Sovereignty Differently

Sovereign AI is sometimes positioned as a defensive posture—a compliance cost, a risk mitigation—but that framing misses what is actually at stake.

The organizations that build AI infrastructure they genuinely own are not just protecting themselves, but building an intelligence asset that compounds in their favor—one that grows more precisely calibrated to their specific context every year, and cannot be replicated by your competitors.

What I have observed consistently as my company has worked on over 1,500 production deployments is that once an enterprise resolves the ownership question, the conversation changes from protecting data to building advantage. The organizations that have made that shift are not asking whether their AI is secure. They are asking what it will know in two years that no competitor’s system can replicate.

Sovereignty should not be the destination, but it is a precondition for building AI that is genuinely yours.​​​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version