FEATURE
There is also an important regional dimension. Constantinidis says frameworks in the UAE and Saudi Arabia increasingly classify data and workloads rather than simply drawing geographical boundaries around them, an approach enterprises should consider when designing their own sovereignty strategies.
AI raises the sovereignty stakes
The rapid adoption of AI is making these questions even more consequential.
According to Retmi, sovereign cloud and sovereign AI are becoming inseparable. Sovereign cloud provides the foundation for keeping data, models and workloads under national jurisdiction and governance, but AI requires organisations to extend sovereignty across the entire lifecycle.
AI environments concentrate some of an enterprise’ s most valuable assets, including proprietary training and fine-tuning data, model weights, inference workloads and the applications built around them.
Each creates new questions. Organisations need to know where workloads execute, who can access them, how information is handled throughout the AI lifecycle and which jurisdiction governs the infrastructure.
Compute itself is consequently becoming a strategic asset. Enterprises want access to high-performance AI infrastructure, but increasingly without surrendering control over where workloads execute or how models and data are governed.
Beyond the compliance checklist
AI environments concentrate some of an enterprise’ s most valuable assets, including proprietary training and fine-tuning data, model weights, inference workloads and the applications built around them.
Operationally, they should understand where administration and support are performed and by whom. Governance requires scrutiny of the provider’ s ownership and legal structure, because these ultimately determine exposure to external jurisdictions.
Exit planning should also begin before the contract is signed.
“ The real test isn’ t‘ does this tick the box today’. It’ s‘ does this still protect me when situations or the provider relationship changes tomorrow’,” said Shabreen.
Constantinidis similarly argues that CIOs should demand evidence rather than relying on generic compliance claims.
“ Checklists tell you what a provider says. I want to know what they can prove, in this jurisdiction, not in a brochure written for Frankfurt,” she said.
She recommends asking who controls encryption keys and whether customers can hold them themselves; who operates the environment and under which jurisdiction; whether a foreign authority could compel access; how workloads, data and workflows can be moved elsewhere; and whether the sovereign platform receives the same innovation roadmap as the provider’ s mainstream cloud services.
That final question will become increasingly important as AI innovation accelerates. Sovereignty cannot come at the expense of access to new capabilities.
“ A sovereign cloud that cannot keep pace with AI simply relocates your problem,” said Constantinidis.“ Choose the partner that answers in evidence, not adjectives.”
For CIOs evaluating sovereign cloud providers, compliance certification is therefore only the beginning.
Shabreen recommends examining three areas: technical capability, operational arrangements and governance. On the technical side, CIOs should determine who ultimately controls access to their data, understand the degree of vendor lock-in and establish whether workloads could operate disconnected if necessary.
The sovereign cloud conversation has therefore moved well beyond the location of a data centre. As enterprises become more dependent on cloud and AI, sovereignty is increasingly about maintaining control over the technology, data and infrastructure on which the organisation depends.
For CIOs, the challenge is to achieve that control without sacrificing the innovation, interoperability and agility that drove enterprises towards cloud in the first place. • www. intelligentcio. com
INTELLIGENT CIO MIDDLE EAST
27