Andrew Slater, Cloud Portfolio Director at Node4, explains why AI, regulation and geopolitical uncertainty are making data sovereignty an increasingly important consideration for businesses.
Until relatively recently, data sovereignty was a niche technology and compliance issue, occupying a relatively minor place in conversations about digital transformation. That has now changed quite dramatically, with geopolitical tensions and much more active regulators forcing businesses to take a closer interest in where their data is held and who ultimately controls it.
The other variable, of course, is AI. Many applications require access to large volumes of data, from personal information and commercially sensitive material to intellectual property and operational records, which may be spread across different systems. Behind the regulatory nuance is one core issue: can each business retain meaningful control over the systems and providers handling its most sensitive information?
For a UK or European business using a US hyperscaler, for example, it is important to establish whose laws take precedence. It must also understand the potential consequences of falling short of its regulatory obligations and build a data sovereignty strategy accordingly.
Isn’t residency enough?
To be clear, sovereignty is broader and more impactful than residency. Data residency refers to the physical location in which data is stored and, in some cases, processed. It can be important for meeting various contractual, sector-specific or data protection requirements, but it does not by itself answer every question about control.
Data sovereignty considers the laws that apply to the data, who owns and operates the infrastructure, and who may be able to access or administer it. The US CLOUD Act, for example, can require qualifying US providers to disclose data within their possession, custody or control, even when it is stored outside the United States.
This means that businesses need to understand the legal and operational model behind the service, rather than assuming that a local region guarantees full sovereignty. These questions become particularly relevant where the data supports regulated decisions or highly sensitive AI use cases.
Getting serious about sovereignty
For businesses where AI is becoming more deeply embedded, projects can create new data flows. Information that begins in an internal system may subsequently be processed through a cloud platform or third-party AI service, potentially placing sensitive data under different legal jurisdictions or governance models.
These aren’t just theoretical concerns. As AI adoption accelerates, governments and regulators are responding by placing greater emphasis on digital sovereignty and reducing dependence on foreign-controlled infrastructure. In other words, the direction of travel is increasingly towards localised sovereignty and limiting the exposure of domestic or regional businesses to foreign laws.
In June 2026, for instance, the European Commission adopted a proposal for the Cloud and AI Development Act (CADA), with the aim of at least “tripling the EU’s data centre capacity within the next 5 to 7 years and fully meet the needs of EU businesses and public administrations by 2035.”
Moreover, to strengthen Europe’s digital sovereignty in the cloud sector, the Act will “work in tandem with a proposed single EU-wide cloud policy for public administrations and public procurement. This combined approach will foster the growth of European cloud providers and prioritise the use of highly secure cloud capacity for highly critical use cases.”
That policy direction does not mean that businesses need to retreat from the public cloud. It does, however, reinforce the need for a more considered approach to deciding where particular data and applications should sit.
Putting sovereignty into practice
For many, hybrid cloud can provide a practical way forward. It combines public cloud services with private cloud or dedicated environments that a business can control more closely, allowing workloads to be placed according to their sensitivity and regulatory requirements.
But how do you begin building a sovereign strategy? It starts with understanding your workloads, rather than treating every application the same.
- Identify your data. Understand what data each application or workload uses, whether it contains sensitive material, and which legal, regulatory or commercial requirements apply.
- Place workloads deliberately. Match each workload to the environment that best reflects its requirements. Highly sensitive or regulated applications may be better suited to a sovereign environment, while lower-risk workloads can continue to benefit from the scalability and flexibility of the public cloud. The environments can then be connected and managed as part of a single architecture, allowing data to move securely where appropriate.
- Review regularly. AI projects evolve quickly. Applications that begin as limited pilots often become connected to more valuable or sensitive sources of data, so sovereignty decisions should be revisited as deployments mature.
Ultimately, businesses do not necessarily need to choose between innovation and control. By understanding the sovereignty requirements of each workload and placing data in the environment that best meets its needs, organisations can make more informed decisions about how and where AI is deployed.
Many AI initiatives may still be in their early stages, but that is precisely why organisations should consider these issues now. Establishing the right data and infrastructure strategy before projects scale can provide greater flexibility, resilience and control as AI deployments evolve.

