A year ago, we surveyed industry, research, and government experts across Europe and Asia to gauge awareness of data sovereignty against a backdrop of privacy and compliance concerns, and the rise of AI.
Twelve months on, geopolitical fault lines remain unsettled, and the AI build-out continues apace. Organisations everywhere are deploying frontier AI models and data pipelines that move data across jurisdictions by default.
So this year, in collaboration with Vanson Bourne, we surveyed 2,100 technical and C-suite leaders across eight markets in Europe and Asia, probing not just data sovereignty priorities and risks, but operational preparedness. If last year measured awareness, this year measured readiness.
Our survey found a stark gap between awareness and readiness. Sovereignty as a priority is not in question:
Readiness is another matter:
AI and Sovereignty Start With Control
That last figure sits alongside another: 93% say data management is critical to sovereignty. Organisations know where the foundation needs to be laid. Most have not laid it.
Well before AI, customers consistently raised a common concern regarding the growing risks and costs of managing fragmented, sprawling data estates. While AI did not create that problem, it has made these risks unsustainable.
Like AI, a practical sovereignty strategy rests on a fundamental truth: it starts with organisations gaining control of their data, and that is more than deciding where servers sit or which country’s flag flies above it. While cloud regions and national borders may affect access, residency alone is a passive proxy for sovereignty. True sovereignty means having absolute visibility, governance, and ownership over your data estate, giving you the power to control, move, and protect your data at any moment, regardless of where it resides.
The Regulation Challenge
Most organisations enter sovereignty through one door, such as security or compliance, applying point controls to data estates they have not been properly mapped—controls that do not travel well to meet a multitude of regulatory requirements.
Regional data frameworks keep expanding. Beyond the GDPR, the EU is rolling out a broader data strategy, European Technological Sovereignty Package, and the recent Digital Operational Resilience Act (DORA), while India’s Digital Personal Data Protection Act phases in through 2027 and ASEAN’s Digital Economy Framework Agreement (DEFA) heads for signature in November. Little surprise that 55% of leaders say they cannot keep pace.
The focus of these regulations is shifting. Older regulatory frameworks asked privacy questions—consent, processing, breach notification. The newer ones probe control and resilience, or who can be compelled to hand data over, whether a service can be withdrawn, how dependent organisations are on foreign providers.
Those are inventory questions, which an unmapped estate cannot address. No organisation can sustain three parallel compliance programmes, let alone eight, but one accurate data map can answer every regulator with a single source of the truth.
Organisations can only answer this by asking fundamental questions to establish visibility and control: what data exists, where its copies live, and who can access it at any given moment.
Our findings support this. When asked to rank what matters most in assessing cloud sovereignty, leaders put visibility and control over data access at the top, alongside encryption, compliance, and AI governance. The prioritisation is right, but the execution is not there.
Beyond Data Residency
Last year, we argued that sovereignty extends beyond physical location. We advocated for a flexible approach that balances an organisation’s business objectives with ever changing regulations.
That balance is evident in this year’s findings. An overwhelming 85% of respondents would give up advanced features in order to use a local or sovereign provider, with 87% prioritising local or sovereign environments for high-risk AI workloads. Yet only 20% cite concentration risk on overseas providers, while 39% say sovereign AI adds operational complexity.
The pragmatism cuts both ways.
With AI as the catalyst, we see more selectivity: the most sensitive data and workloads being pulled into sovereign environments, while others remain where they perform best. The AI build-out will land as a balance of sovereign and public infrastructure, not a retreat to either.
One global design customer typifies this approach, building sovereign versions of its SaaS tools, segmenting customers through encryption and a dedicated compute boundary.
Here too, the foundation is data management. Sovereignty requires continuous customer control of data. Location is variable; your ability to classify risk, enforce policy, and maintain ownership of your data, is the constant. The policies that govern it depend on understanding data’s meaning across applications, and not simply where it resides.
Sovereignty by Design
How, then, do organisations move from preparation to implementation? Take control of your data, shift the focus from national sovereignty to corporate sovereignty, an approach based on an organisations specific risk appetite and view on regulation. We call this sovereignty by design.
The aim is to let business needs and risks drive sovereignty decisions, not regulations alone. Some data and workloads genuinely need sovereign environments. Many others do not, and can remain with global cloud and SaaS partners, where speed, and scale still pay. This gives organisations graduated control based on risk profiles, instead of scrambling every time they face a new regional requirement.
Similarly, an important concept is the “Minimum Viable Company,” industry shorthand for the smallest set of critical services, data, applications, and skilled staff needed to keep operating through a denial-of-service or other disruption. Many organisations have not yet identified their MVC. Defining it turns open-ended risks into something a board can scope and fund.
Five steps to becoming sovereign by design:
Achieve visibility and control
Sovereignty starts with establishing control over your data estate—knowing what data you have, where it resides, who can access it. Crucially, it means maintaining the ultimate ownership to grant or revoke that access, while understanding vulnerabilities such as jurisdictional exposure and potential data exfiltration. All of this rests on strong data management capabilities.
Tier by risk, not by category
Define your MVC, then rank data, and applications, by strategic value and legal exposure. Apply sovereign controls where that exposure justifies it, not as a blanket policy.
Build a sovereign AI foundation
Prioritise sovereign environments for sensitive, high-risk AI data and workloads.
Let the board own it
Just 19% of organisations say their sovereignty strategy is board-driven. A further 36% still struggle for executive buy-in, while 56% lack the skills to execute even where a strategy exists. Elevating sovereignty from a departmental to board-level mandate is the fastest way to mobilise resources.
Make procurement and sovereignty one conversation
Evaluate providers on jurisdictional control and sovereign deployment options, not just features. Plan exit paths, data portability, and key custody terms before you need them.
With this approach, the data—not the application—becomes the control point, hosted and managed according to whether it must meet sovereignty requirements.
Without a strategy, sovereignty is all too often handled tactically. With one, organisations can meet evolving regulatory demands quickly and accelerate AI initiatives, because the data is understood, ownership is clear, and control is established.
Ultimately, managing data lays the groundwork for an enduring corporate sovereignty strategy. With a strong data foundation, organisations can stay competitive, achieve control and sovereignty over their data, and stay compliant in any jurisdiction or region.











