Skip to main content

Sovereign AI: Taking control of data, models and digital infrastructure

AI is increasingly being used in core processes. This raises the question of who has control over the data, models, infrastructure and decisions that organisations rely on. For executives and board-level leaders, sovereign AI is therefore not a technical discussion but a strategic trade-off involving control, dependency, and risk. 

The cloud and AI market relies heavily on a limited number of global technology providers1. They offer scale, innovative strength and mature services. At the same time, geopolitical tensions, new regulations and the use of AI in critical processes make it clear that organisations need to be more aware of where they accept dependency and where they need more autonomy. In addition, European alternatives are increasingly maturing and can compete with global players in an increasing number of areas.

Sovereign AI is not an all-or-nothing choice. It is not a question of building all the technology ourselves or letting go of existing partners, but of determining the degree of data sovereignty, model control, infrastructure management and vendor dependency that is appropriate for each process. Especially for public organisations, sovereign alternatives are becoming a key building block in a future-proof digital strategy.

What is sovereign AI and why is it urgent now?

Sovereign AI is the ability of an organisation or country to decide and act autonomously on AI systems that are essential for the economy, society and democracy. It extends beyond data alone: it also concerns hardware, AI models, training data and algorithmic control.

The key question for this theme: who really has control over the data, security, the capacity to innovate and keeping your organisation's digital processes running?

Three developments currently make sovereignty a board-level priority:

  1. Geopolitical tensions
    Due to increasing global tensions, control over digital infrastructure is more important than before. When critical infrastructure or access to it, is in the hands of foreign parties, geopolitical crises can have a direct impact on your operational continuity.
  2. Evolving regulatory requirements
    The European GDPR, DORA and NIS2 impose increasingly stringent requirements on data protection2. At the same time, US laws such as the CLOUD Act and the FISA Act give US government agencies potential access to data stored with cloud providers3. These providers have legal safeguards in place against this, but this remains a concern for organisations with sensitive data. This creates legal and operational risks. In addition, the revised National Cloud Policy (July 2026) limits data processing for government organisations in some cases to the EEA and Switzerland4.
  3. Technological acceleration
    The rise of AI in core processes increases the impact of digital dependencies. While the discussion about cloud providers is mainly about infrastructure and data storage, AI also touches on training data, model choices, compute capacity, algorithmic control and explainability. The more AI supports high-impact decisions affecting citizens, customers or vital processes, the more important it becomes to retain control over the full AI chain.

Watch the video: AI and sovereignty: how can you balance rapid AI innovation with long-term sovereignty in an uncertain geopolitical landscape?

"The key is to make a deliberate choice for each process: which data, systems and decisions do you really want to keep under your own control, and where do you accept dependency because the value outweighs the risks? That is a strategic leadership decision, not a technical one."

Bart Pustjens, Lead Partner Engineering, AI & Data, Deloitte Netherlands

The sovereignty scale: choosing what to control

Sovereignty is a scale, not an on/off switch. The position that an organisation occupies on this scale is determined by the balance between (social) value creation and risk acceptance.

An organisation that uses AI for its core processes cannot afford to lose control over AI models and data. At the same time, the risk acceptance must be in line with the sensitivity of the data and the extent to which a process is critical; Public, non-sensitive data require a different degree of sovereignty than medical records, personal data or running energy supplies. So it's about more than whether you use the cloud or not. It is also about who decides what happens to the models, the data and the insights within that environment.

Sovereign choices also entail risks and trade-offs. Full autonomy can lead to higher costs, slower access to innovation, more management complexity and additional requirements for physical security, power supply, continuity and scalability. For example, hosting models yourself or organising your own data centre capacity increases control, but also requires specialised expertise, redundancy, lifecycle management and incident response. Sovereignty should therefore not be confused with doing everything yourself; It is about a conscious balance between control, innovative capacity, costs and feasibility.

The six dimensions of Data & AI Sovereignty

AI sovereignty cannot be separated from cloud sovereignty. Many AI applications run on cloud infrastructure: data is processed in cloud environments, models are trained or accessed via cloud platforms and specialised compute power such as GPUs is often purchased as a cloud service. As a result, classic cloud questions about jurisdiction, access, security, continuity and vendor dependency have a direct impact on the degree of control an organisation can maintain over AI.

At the same time, AI adds an extra layer. AI is not only about where data is located or where systems run, but also about which data has shaped the models, who can restrict access to models, how easily they can be replaced, how decisions are made and whether an organisation can audit, modify or replace an AI application.

The EU Cloud Sovereignty Framework (v1.2.1) provides a useful starting point5. The framework identifies eight sovereignty objectives, including Data & AI sovereignty (SOV-3). For this article, we use this as an anchor and translate it into six practical dimensions with which allows executives to assess sovereign AI in practical terms.

  1. Training data control
    Who decides which data is used to train, fine-tune or enrich models? And can the organisation demonstrate which data, domain knowledge or public information does and does not end up in the model? This dimension touches on quality, bias, representativeness, copyright, privacy and the risk that sensitive or strategic knowledge is unintentionally incorporated into models.
  2. Data sovereignty
    Where is data stored, processed and accessed including backups, logging, monitoring and support access? And under which legal frameworks does this data fall? In sensitive or critical applications, processing within European legal frameworks is often a necessary condition to guarantee control, compliance and trust. For less sensitive applications, a different risk assessment may be appropriate.
  3. Model sovereignty
    Who owns, manages and controls the AI models that the organisation relies on? Can the model be deployed on its own, adapted, replaced or hosted elsewhere if conditions change? Recent examples show that access to advanced AI models can be influenced by export controls, national security considerations or commercial conditions. For critical applications, model portability, fallback options and contractual safeguards are therefore essential.
  4. Compute sovereignty
    Where do your AI models run and who manages and controls that infrastructure? Does it need to be connected to the Internet? Think explicitly of GPUs, CPUs and TPUs, physical location, control over firmware and BIOS and access and maintenance rights. These factors largely determine the sovereignty surrounding (external) computing power and the applicable regulations.
  5. Algorithm transparency
    Can the organisation understand, explain, audit and correct how AI outcomes are created? And is it clear who is responsible for monitoring, bias detection, incidents, model changes or updates and compliance with AI governance? This dimension is important for compliance, risk management and trust, especially in applications that impact citizens, customers, employees or vital processes.
  6. Vendor lock-in
    Can the organisation switch providers, models or infrastructure without disproportionate cost, disruption or rebuilding the architecture? And is there a realistic exit strategy or fallback plan for data, models, configurations, prompts, embeddings, logging and integrations? This determines strategic flexibility, negotiating power and operational resilience in the long term.

AI exposes digital dependencies: without a firm handle on data, models and compute, control over AI outcomes remains limited.

Pouya Zarbanoui, Partner AI & Data Public Sector, Deloitte Netherlands

From strategy to execution: getting started with sovereign AI

  1. Start with the AI applications that matter
    Map out where AI touches on core processes, sensitive data, statutory duties or decisions that impact citizens, customers or employees. Look not only at the application itself, but also at the most important parties, systems and data flows on which it depends.
  2. Determine the importance of sovereignty per application
    Assess how sensitive the data used is, how important the process is, which legal frameworks the application falls under and what the impact is if access, quality or continuity is lost. This clarifies where stricter control is required and where external technology partners can add value.
  3. Deliberately choose where you need to retain control
    Determine the degree of control required over training data, data, models, computing power, transparency and switchability for each application. Not every dimension needs to have the same level of sovereignty: in some applications, data location is important, in others model access, explainability or continuity.
  4. Translate choices into concrete agreements and measures
    Define the requirements for data location, access, security, model use, auditability, switchability, contigency scenarios and periodic reassessment. This means that sovereignty does not become an abstract principle, but part of procurement, architecture, contracts and governance.
  5. Make explicit what role partners play
    Identify where global technology partners are appropriate, where European or sovereign alternatives are needed and where in-house or hybrid solutions add value. One AI solution can combine different levels of sovereignty: for example, European data processing, an external AI model for less sensitive applications and additional safeguards for critical processes.
  6. Ensure sovereignty decisions can withstand scrutiny
    A choice of sovereignty is only mature if it is substantiated and verifiable. This requires clear decision-making, ownership, contractual agreements, control mechanisms and periodic review. Without demonstrability, sovereignty remains an intention, not a control measure.

Digital sovereignty does not have to be an obstacle to innovation, but it is the prerequisite for sustainable success in an AI-driven world. There is no one-size-fits-all: you consciously choose the degree of sovereignty you want to achieve, weighed against the societal value and risk profile of the application in question.

A multicloud or hybrid strategy with a combination of closed and open-source models and modules offers the practical space to operationalise these choices without losing innovative power. In this way, speed remains available where it counts, while control is safeguarded where the risk is highest.

Determine your position on the sovereignty scale

Sovereignty is not an all-or-nothing choice, but a series of conscious considerations per process, per dimension. So the question is not whether you want to be sovereign, but where on the scale your organisation should stand for the various processes. Contact us to define that position together and take the first steps towards a scalable, sovereign data and AI architecture. Our team can help guide you through the process, from defining strategic choices to assessing sovereignty requirements and implementing practical solutions.

References

1 Netherlands Authority for Consumers and Markets (ACM) (2026). "Towards digital autonomy in the cloud, one step at a time." Speech Paul de Bijl, Chief Economist ACM. Consulted via: https://www.acm.nl/en/publications/speech-paul-de-bijl-towards-digital-autonomy-cloud-one-step-time.

2 European Commission. "Data protection"; European Commission. "AI Act"; European Commission/EU frameworks around DORA and NIS2. Consulted via: https://commission.europa.eu/law/law-topic/data-protection_en and https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

3 U.S. Department of Justice. "CLOUD Act Resources"; Office of the Director of National Intelligence. "FISA Section 702 Resources." Consulted via: https://www.justice.gov/criminal/cloud-act-resources and https://www.dni.gov/index.php/newsroom/reports-publications/reports-publications-2023/3672-fisa-section-702-resources.

4 Ministry of Economic Affairs and Climate Policy (2026). "Review of government-wide cloud policy 2026", 3 July 2026. See also the Dutch government (2026). "Strict rules for the use of cloud services by the central government." Consulted via: https://www.rijksoverheid.nl/actueel/nieuws/2026/07/03/strengere-regels-voor-het-gebruik-van-clouddiensten-door-de-rijksoverheid

5 European Commission Directorate-General for Digital Services (2025). "Cloud Sovereignty Framework Version 1.2.1 - Oct. 2025." Consulted via: https://commission.europa.eu/document/download/09579818-64a6-4dd5-9577-446ab6219113_en?filename=cloud-sovereignty-framework.pdf

Contact

Do you have any questions or would you like to know more about how Deloitte can help your organisation? Please feel free to contact our team.

Stay on top of AI

From the boardroom to the lab, Deloitte leverages deep industry knowledge to lead the AI conversation and uncover insights that understand this complex ecosystem. Sign up for our newsletter and stay up to date on AI.

Did you find this useful?

Thanks for your feedback