With increasingly defined regulations to comply with and political tensions growing, business leaders are adopting AI sovereignty practices to weather the storm.
As AI seeps into the bedrock of enterprise operations, it becomes more akin to critical infrastructure than a mere add-on tool. And when AI is part of core operations, the question of who controls these enterprise systems becomes more critical than ever.
According to "The 2026 AI Index Report" from Stanford HAI, organizational AI adoption reached 88% in 2026. Yet increasing adoption rates don't mean the average business owns its entire AI stack, and vendors and governments are increasingly shaping access to AI products. Moreover, businesses that operate globally must comply with the regulations of multiple government entities.
Having sovereign AI in business means an organization can develop, deploy and govern AI independently of external infrastructure, hardware and models. Local implementation and oversight ensure the utmost control over governance and compliance, and greater assurance that systems will continue to work despite political or vendor disruptions.
Defining sovereignty is inherently complex. Enterprises must take into consideration a web of regulations, physical architectures, cross-border data flows and operational choices -- all within a fragmented global landscape and competing definitions. Writers in Stanford HAI's essay "AI Sovereignty's Definitional Dilemma" explained the conundrum as follows:
"The fact that sovereignty is used to describe both states' struggles over geopolitical autonomy and regulatory oversight and companies' efforts to secure organizational governance further complicates attempts to define AI sovereignty," the essay said.
Recently, boardrooms have taken AI sovereignty into their own hands. But complete sovereignty is challenging, especially for multinational businesses that rely on third-party technologies. So, many businesses are choosing selective AI sovereignty: opting in to sovereign implementation where it matters most to them, thereby safeguarding investments from compliance issues, vendor lock-in and unpredictable government interventions without forfeiting innovation.
"We're going from experimentation projects to real projects," said Eric Helmer, senior vice president and CTO of Rimini Street, a global third-party enterprise software company. "Now is the time to take a step back and build what is needed for an AI sovereignty model."
Fragmented regulations push enterprises toward sovereign AI
Disparate regulations and increasingly stringent compliance requirements have brought the question of sovereign AI to the forefront. In Europe in particular, the EU AI Act and its comprehensive regulations, which have recently begun to take effect, are prompting many global enterprises to prioritize sovereign AI.
There's substantial momentum on sovereign AI in Europe right now because of the AI Act, said Mark Beccue, principal analyst at Omdia, a division of Informa TechTarget. Compliance with those regulations is a huge driver of sovereign AI discussions for businesses.
For example, Omdia's 2026 report, "The Great Repatriation: Why Enterprises Must Act Now to Ensure AI Sovereignty," found that 51% of respondents said compliance with EU AI Act regulations was very important in accelerating their sovereign AI investment decisions. Additionally, 47% said compliance with extra or additional regulations from national jurisdictions within the EU was very important.
[Operating in multiple countries] really complicates things for these companies.
Mark BeccuePrincipal analyst, Omdia
Compared with growing AI compliance requirements in Europe, AI regulations in the U.S. are murky at best. The Trump administration's first slew of executive orders aimed primarily at reducing stringent rules on AI development and use -- such as the government's late 2025 EO, which limited states' abilities to set their own AI regulations. More recently, a June 2026 executive order established a framework for voluntary pre-release access evaluations for frontier models.
But with no set federal regulations yet, the U.S. approach to AI might be more fragmented than other global frameworks. To complicate matters, many companies don't operate in only one jurisdiction. Multinational companies often have offices, servers, data or infrastructure in jurisdictions with different AI regulatory requirements, making total compliance a major headache.
"[Operating in multiple countries] really complicates things for these companies," Beccue said. "The biggest worry they have is they don't want this to slow down their AI momentum, so they're looking at ways to meet the compliance needs of these various jurisdictions and not let it slow them down."
While the unique risks of AI bring added complexity, meeting the compliance needs of various governing bodies isn't entirely new for many enterprises. For example, in the world of ERP, handling data for a global company has historically been complicated, Helmer said. Some laws require certain data to remain within a country, and businesses must also contend with industry-specific compliance requirements.
"We're used to those regulations," Helmer said. "It complicates things even more when you bring in the world of automated agents."
Political and vendor disputes complicate the conversation
In the last few months, the Trump administration's interactions with major AI vendors have sparked debate over government involvement in the AI market. The added tension has also driven sovereign AI discussions in the boardroom, aimed at mitigating the risk of product blockage due to government intervention or vendor disputes.
Anthropic's June release of Claude Mythos and Fable 5 was live for only three days before a U.S. government export control directive forced the AI vendor to restrict access to foreign nationals both inside and outside of the U.S. The governmentcited concerns about national security, but the ripple effect raised other questions: What happens when a government embargoes access to a widely used model?
"We're certainly having conversations around sovereign implementation, especially with certain regions [and] some of the different confrontations and conflicts going on around the world," said Jill Knesek, CISO at BlackLine, a financial operations and accounting automation platform.
As part of its ongoing feud with Anthropic, the Trump administration pivoted to OpenAI models for federal use cases and requested that the AI vendor limit the release of GPT-5.6 to "trusted partners," according to a CNBC report. The model access issues here are twofold: Government contractors, some of which built ecosystems around Claude, had to switch to OpenAI models. Enterprise users also had to reckon with the possibility that their access to third-party models could be limited or revoked entirely in the future.
We have to be aware of [government interventions]. We have to be able to understand how we can shift and maintain our capabilities if [blockages] occur.
Jill KnesekCISO, BlackLine
The Trump administration has also recently contemplated restricting access to Chinese AI models and hardware, citing national security concerns. For example, Moonshot AI's Kimi K3 sent the U.S. government and Silicon Valley into a tailspin, with the White House and lobbying AI vendors, such as OpenAI, quickly suggesting future bans on foreign products. The government is also considering import restrictions on Chinese data center devices.
"Different countries are setting up different rules, and everyone is worried about national security," said Darrell West, a senior fellow at the Brookings Institution's Center for Technology Innovation. "The question of what countries you buy models from is important." For example, not only do businesses need to evaluate the pros and cons of Chinese open-weight models, but they also need to consider possible government interventions, he added.
Interventions in the AI market highlight an enterprise blind spot and a new dimension to vendor lock-in. When government disputes cause service disruptions, businesses that rely entirely on a single vendor's models expose themselves to risk.
"We have to be aware of [government interventions]," Knesek said. "We have to be able to understand how we can shift and maintain our capabilities if [blockages] occur. Depending on what country we're doing business in, or our customers are doing business in, we also have to think about other nations and how they're going to react and respond."
Enterprise considerations for the sovereign AI stack
It's nearly impossible to be completely sovereign, especially for AI. To find a middle ground between completely open strategies and 100% local implementation, many businesses are turning to selective or hybrid AI sovereignty, in which certain aspects of their AI strategy are sovereign, while other aspects use cross-border components out of necessity.
"When you talk about AI sovereignty, there are a lot of parts and pieces," Knesek said. "Some of them are almost impossible to get for an enterprise. We're talking about [AI sovereignty], but more in a hybrid sense, not 'all in,' because that would be very complex. We are still going to be reliant on some third-party capabilities."
To achieve this hybrid autonomy, businesses focus on several distinct layers. Which to prioritize comes down to selectivity, with each business taking stock of its risk profiles and AI needs. To get started, businesses can focus on four areas: data control, model portability, build-versus-buy frameworks and compliance management.
Data control
Data sovereignty encompasses not only where data lives but also who has authority over it, including which laws apply and who has control. Data sovereignty for AI is crucial because AI uses massive amounts of data for training and inference, sometimes touching multiple data repositories, servers and systems to answer a query or complete an autonomous action.
Sovereign AI is all about data control, said Peter Liebert, CISO of Clari/Salesloft, an AI-driven revenue orchestration company. "Are you able to control the data flow, who accesses it, whether it's a model accessing it [and] what level of permissions that model has? Ensuring that you have visibility and provide the adequate access that's needed … that's a big component of [sovereignty]."
We have a zero-data-retention policy with all of our AI vendors, which is a critical core component of how we maintain our own sovereignty.
Peter LiebertCISO, Clari/Salesloft
As one of the first steps of sovereign AI frameworks, many businesses look to their data sovereignty practices for AI workloads. "You obviously have to build in the AI sovereignty on top of that data sovereignty," Knesek said. "They're merging together nicely in that sense."
One major way Clari/Salesloft is approaching data control is through its zero-data-retention policy, Liebert said. "We have a zero-data-retention policy with all of our AI vendors, which is a critical core component of how we maintain our own sovereignty," Liebert said. "We don't allow any of our own data or customer data to be fed into any of the AI solutions for training, et cetera. It doesn't matter what company we go with -- that is a hard requirement."
Model portability and model-redundant architecture
Businesses are increasingly considering model control as a key differentiator for sovereign AI. Especially as a response to increased vendor disruption and government intervention, having control over AI model access can be make-or-break for enterprise environments.
"Right now, there's very little portability of models," West said. "For example, if you buy one company's model and invest hours building an AI agent on that model, you can't really export your data and models you've built to another provider."
Limited model portability can be problematic for a business when facing vendor disruptions, government interventions, geopolitical events or AI model security incidents.
To compensate for reduced model portability, many businesses are turning to flexible model architecture, sometimes referred to as model-redundant architecture. By building a flexible architecture that isn't dependent on a single vendor or model, businesses can change courses more quickly and swap out models in the event of vendor or political disruption.
"We're segmenting out the different components of our overall AI stack," Liebert said. "We have the ability now to have different products in each one of those [sections of the stack] that are custom-tuned so that the model is interchangeable. That portability allows us to be a little bit more flexible in how we're doing things."
When it comes to sovereignty and governance and compliance, it's [asking] what do you need to have inside your own data walls? What can [be] SaaS or an outsourced model?
Eric HelmerSenior vice president and CTO, Rimini Street
Increased model portability through a model-redundant architecture gives businesses greater purchasing leverage, Helmer added. If businesses can swap out models, vendors can't as easily keep them locked in their systems, making vendors more likely to work with businesses on opportunistic deals.
Model portability helps AI market vendors remain competitive, too, West said. "If you can't change companies in terms of the models you're using or the AI agents you've built, that's very anti-competitive," he said.
Build-versus-buy frameworks
Part of building a flexible AI stack means choosing from varying tech options: local builds, third-party models and open source. A large part of sovereign AI is a build-versus-buy conversation, with businesses choosing what areas they need to invest in for optimal control versus areas where they are comfortable using third-party or open source products.
"When it comes to sovereignty and governance and compliance, it's [asking] what do you need to have inside your own data walls? What can [be] SaaS or an outsourced model?" Helmer said. "I don't think you have to have one or the other. I think we're going to have some sort of hybrid approach."
BlackLine is always considering whether to build an agent internally or buy one, Knesek said. The balance lies between its commitment to customers to deliver good products and its need for control, given government decisions and competing regulations.
"Anything that we're implementing, we want to have full control of," Knesek said. "We want to know that the products and the tools and the agents we're building are all coded internally and have gone through proper rigor, and that we can maintain them without having them leverage outside public-type tools."
Aside from building models and infrastructure internally when possible, some businesses are approaching the "buy" part of the build-versus-buy conversation by adopting a multi-third-party model approach, choosing multiple vendors and models for different areas of the stack.
A November 2025 Omdia study, "Emerging Trends in AI Models: Opportunities and Risk Amid the Rapid Evolution," asked respondents about their use of AI models and providers. The study found that, on average, 54% of respondents used two to three model providers, and 44% used three to five generative AI models.
"Lots of these companies are using lots and lots of models," Omdia's Beccue said. "You don't see a lot of people locking in on certain things that they can't really replace pretty easily."
Clari/Salesloft has "planted [its] flag," so to speak, with two AI vendors, Liebert said. This brings advantages, such as access to the latest models and preferred pricing on tokens. However, avoiding vendor lock-in is still an important part of the equation.
"We still have to be careful and not get locked in too much with one [tool], because we know absolutely without a shadow of a doubt that in one year the industry can be completely different. We are flexible to the greatest extent possible, but we also need to make sure that there is a level of stability," he said.
Compliance management
Compliance with regulations is often the primary instigator of sovereign AI discussions. It can be tricky for businesses to reconcile varying regulatory standards across industries and regions worldwide.
The ISO 42001 is something that we feel very strongly about. We believe, as an international standard, it'll hold up to most regulations around the globe.
Jill KnesekCISO, BlackLine
As part of its sovereign AI strategies, BlackLine views compliance management as an identify-the-highest-bar scenario, Knesek said. By choosing to comply with the most comprehensive or strict regulatory bar it can find, it has some assurance of compliance. That way, any new jurisdictions or requirements will hopefully fall at or below BlackLine's current compliance level, she said.
For BlackLine, the highest regulatory bar was the ISO 42001. ISO 42001 is an international standard for AI management systems, providing requirements for businesses on the development and use of their AI systems. It helps businesses implement AI governance that complies with prevailing regulations and manage risks.
"We need to be able to demonstrate that we've got the rigor and the governance and compliance controls internally to be able to build [AI] in a safe and secure fashion," Knesek said. "The ISO 42001 is something that we feel very strongly about. We believe, as an international standard, it'll hold up to most regulations around the globe. [It] was a very good investment, and it's built a very strong foundation. And so far, we think that's probably still the high bar."
Some businesses are also opting to navigate AI regulations on a case-by-case basis. The goal of scaling AI is to have platforms and technology in different areas of the world doing similar things while being subject to different rules, which is difficult, Brookings' West said. However, businesses can often assess how to navigate national laws to scale AI while remaining compliant.
For example, a business serving customers in a country where its operations don't align with prevailing regulations can sometimes locate its cloud or data center in another country, West said. By shifting the bulk of its services outside the country's jurisdiction, the business can gain some control over regulatory requirements.
However, governments are beginning to demand that data be stored in the country where AI operations occur, creating new geopolitical tensions as smaller countries lobby for new AI data centers, West added. In the future, the bulk of data centers -- largely in the U.S., Europe and China -- might disperse across more jurisdictions, each with its own regulatory requirements.
"Global companies need to think about what's most important to them and what's most important in the future of their business and choose jurisdictions that are most favorable to them on those dimensions," he said.
Olivia Wisbey is a site editor for Informa TechTarget's AI & Emerging Tech group. She has experience covering AI, machine learning and other emerging technologies.