Risk management is one of the most important areas of focus in AI for boards today. However, very few boards are focused on AI sovereignty, and more specifically selective AI sovereignty. For example, a recent IBM survey[1] found that 71% of executive surveyed would find it very difficult to switch AI models or vendors today. In fact, AI model selection today is often not strategic, and some companies are using different models for different tasks, or geographies, or other, without careful analysis or planning. Furthermore, data residency has become an important consideration, from a business, but also sometimes regulatory perspectives. In fact, regulators are increasingly placing stricter requirements around model transparency, and AI accountability more broadly. Even putting AI aside for a moment, data residency should be a major governance topic. Recently, AWS permanently lost customer data due to strikes in the Middle East[2].
AI sovereignty is about the organization's ability to build, deploy and govern AI using its own infrastructure, data, models and talent and in ways that align with its own set of rules, regulatory framework, security needs and values[3]. It is about control and governance.
Key elements of AI sovereignty are:
· Data sovereignty: The enterprise should maintain control over how data is collected, processed and used. The data the enterprise uses to train the AI would remain its property and is not shared with the model vendor or any other entity, and it should remain local. The board should ensure that the company can govern, report on or relocate the data specifically as needed, when needed. Increasingly, enterprises are gravitating towards open-weight AI models for tasks that have compliance requirements or that use proprietary data. This ensures that data is not streamed to external vendor servers for inference.
· Confidential inference - is a security method that keeps data, AI prompts and model weights encrypted while an AI processes them in the cloud[4]. This is a hardware-level security technology that enables AI sovereignty; it keeps data private and ensures the cloud provider cannot read it.
· Model Sovereignty - refers to the organization's ability to control, own and govern the AI models it uses. For example, the board should ensure that the company can swap models and does not have vendor lock in and that it can access other models with the same infrastructure. Related to this topic is the debate about open weights and closed weights models. Models are the parameters adjusted during training. Making the weights open allows the organization to own the weights it builds on[5], run it on its own hardware or cloud so that sensitive data remains within its parameters, and allows it to improve the technology and perform its own tests. It is akin to rent versus buy and avoids vendor lock-in. It is not appropriate for every task, and in some cases, especially when data security is not a main requirement, the use of frontier models (which typically have closed weights), makes more sense.
· Infrastructure sovereignty - the organization chooses the hardware where the AI workloads run and who can access hardware. It can move workloads while maintaining continuity. This ensures that AI systems can scale and recover
· Operational sovereignty - the organization has control over how AI systems, infrastructure, data and workloads are run, managed and maintained[6].
· Technical sovereignty - the organization controls the evolution of its systems and has the right talent to manage and evolve those systems.
However, AI sovereignty carries a significant premium in terms of infrastructure, energy overhead, talent and other, and therefore has significant TCO implications . For example, the organization needs to create its own environment of GPU clusters, and provide power, and specialized expertise to maintain the open weight models and the operating environment. This said, some telcos are offering Gen AI as a service, in a managed services model. Furthermore, the local models may not have the processing throughput the frontier models provide. Therefore, the enterprise needs to carefully evaluate its sovereignty needs and determine the tradeoffs. Some tasks can run on frontier models, while others, that use proprietary data, or are subject to specific regulations, could run within the organization's perimeter.
Selective AI sovereignty enables the organization to strike the right balance between business and operational risks, regulatory compliance, speed to market, cost, and other parameters. It provides openness and control where they matter most, without imposing the cost of total independence everywhere, and is essential for strategic and capital flexibility.
AI orchestration makes selective AI sovereignty achievable by coordinating the full landscape of AI activity across the organization. It essentially makes AI governance programmable[7].
The role of the board in providing the framework and guidance regarding selective AI sovereignty is essential. It is the board's responsibility to reduce risk concentration and to ensure the organization retains strategic flexibility and control.
[1] https://www.ibm.com/downloads/documents/us-en/16ddce7b71d48f55
[2] https://arstechnica.com/gadgets/2026/09/iran-strikes-on-amazon-data-centers-caused-permanent-loss-of-customer-data/
[3] https://www.mckinsey.com/featured-insights/mckinsey-explainers/what-is-sovereign-ai
[4] https://www.anthropic.com/research/confidential-inference-trusted-vms
[5] https://www.weforum.org/stories/artificial-intelligence/open-weight-ai-the-difference-between-renting-and-owning-tech-sovereignty/
[6] https://www.ibm.com/think/topics/ai-sovereignty
[7] https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/ai-orchestration-layer