Intelligent CIO Middle East Issue 130 | Page 26

FEATURE
Muhammed Shabreen, CTO at CNTXT AI country by country is a common mistake.
“ That’ s how you end up with ten environments no one can maintain. The better path is one common architecture with sovereignty applied as a layer, not a rewrite,” he said.
The key is workload classification. Only genuinely sensitive information and workloads should carry the full sovereignty overhead, while less sensitive workloads retain greater flexibility. Policy-ascode can then automate the enforcement of requirements rather than relying on manual compliance processes.
“ The goal is to be locally compliant, globally coherent,” said Shabreen.
Retmi agrees that regulatory pressure can encourage organisations to create separate environments for individual jurisdictions. The result, however, can be fragmented architectures that sacrifice the consistency, interoperability and scale that made cloud attractive in the first place.
He argues that sovereignty, innovation and agility are not inherently competing priorities. The trade-off emerges when organisations treat them as such.
Building sovereignty into the architecture from the outset allows consistent controls, workload portability and common operating models to coexist with residency and jurisdictional requirements.
“ Operational agility comes from standardisation and automation, not from creating multiple oneoff environments,” said Retmi.
Residency is not sovereignty
Perhaps the most persistent misconception is that keeping data within national borders automatically makes an environment sovereign.
Shabreen argues that in-country hosting means relatively little if control remains with an external entity, encryption keys are held elsewhere or the infrastructure is administered from abroad.
“ Residency is the doormat, not the house,” he said.“ Real sovereignty is about control over data, operations, keys and your legal exposure.”
For CNTXT AI, that control begins at the data layer itself. Sovereignty cannot simply be created by renting GPUs within a particular geography. It requires governance and control of the data using that infrastructure.
Constantinidis draws the same distinction.“ Residency is geography. Sovereignty is control,” she said.
She breaks true digital sovereignty into three layers. Data sovereignty determines who can access information and under which jurisdiction. Operational sovereignty addresses who runs the platform and controls encryption keys. Technical sovereignty considers whether an organisation can exit, port workloads and continue operating if its relationship with a provider ends.
26
INTELLIGENT CIO MIDDLE EAST www. intelligentcio. com