FEATURE strengthen cloud security while enabling broader adoption across government and business.
Jessica Constantinidis, Innovation Officer EMEA at ServiceNow
From compliance to control Geopolitics has added another dimension to the sovereignty discussion.
Jessica Constantinidis, Innovation Officer EMEA at ServiceNow, said boards have increasingly begun asking a fundamental question:“ If the geopolitical winds change, who can switch us off?”
Five years ago, sovereign cloud was largely a compliance consideration. Trade tensions, foreign access laws and emerging AI regulation have since turned control of data and infrastructure into a board-level risk issue.
But Constantinidis sees an important distinction between the drivers of sovereignty in Europe and the Middle East.
“ The fundamental shift is from viewing sovereignty as a location requirement to adopting it as an operating model for resilience, risk management and control,” he said.
That shift is being accelerated by enterprises’ growing dependence on cloud platforms for critical workloads and the movement of sensitive information across AI models, applications and automated workflows.
Expectations are consequently expanding beyond data residency to encompass identity and privileged access, encryption, policy enforcement, auditability and operational oversight. Organisations also increasingly expect to demonstrate compliance continuously rather than at periodic checkpoints.
Retmi says the change is particularly visible in the public sector, where entities that were previously cautious about cloud adoption are now actively driving demand for Sovereign Public Cloud. In the UAE, this direction is reflected in the National Cloud Security Policy, which aims to
“ In this region there is an extra driver: national ambition. The UAE and Saudi Arabia treat data and AI as nation-building assets, so sovereignty arrived in the boardroom through strategy, not fear. That is a very different route from Europe, where it arrived through regulation,” she said.
Enterprise expectations have evolved accordingly, moving from“ keep us compliant” towards“ keep us in control”. Organisations increasingly want to understand who operates their infrastructure, which laws govern it and whether they retain the ability to exit a provider relationship.
“ That is resilience thinking, and it belongs at board level,” said Constantinidis.
Avoiding the sovereignty silo
Yet stricter residency and sovereignty requirements introduce another challenge. If every jurisdiction results in a separate technology environment, enterprises risk creating precisely the fragmentation that cloud was supposed to eliminate.
Muhammed Shabreen, CTO at CNTXT AI, said rebuilding an organisation’ s technology stack www. intelligentcio. com
INTELLIGENT CIO MIDDLE EAST
25