Logo
FrontierNews.ai

The Sovereign AI Definition Problem: Why One in Three Leaders Can't Explain It

One in three business leaders cannot clearly explain what sovereign AI is, according to new research, even as organizations worldwide accelerate adoption of systems designed to keep sensitive data and AI models under their own control. The IDC study, commissioned by Cohere, surveyed enterprise decision-makers across regulated industries and found a significant gap between the urgency companies feel to implement sovereign AI and their actual understanding of what it means.

What Exactly Is Sovereign AI, and Why Are Definitions So Fuzzy?

IDC defines sovereign AI as "the ability for an organisation to have free choice and control over the design, development, deployment, accessibility, operation, maintenance and governance of its AI systems and applications, as well as the underlying technology foundations they depend on." In simpler terms, it means your organization owns and controls its AI, rather than relying on external providers or cloud platforms that might access your data.

Among leaders who could articulate a definition, interpretations varied widely. About 52% described sovereign AI in terms of location or national control, while 35% framed it around digital independence. The disconnect matters because different roles within organizations view sovereignty through different lenses. Line-of-business leaders see it as a tool for managing business risk, data security, and privacy, while IT leaders focus on regulatory compliance.

"True sovereignty gives enterprises invaluable levels of control, customisation and secure deployment; resilience is the foundational benefit that underlines what accessing AI from an external API can't give, but its value goes beyond simply protecting data," said Joëlle Pineau, Chief AI Officer at Cohere.

Joëlle Pineau, Chief AI Officer at Cohere

Which Industries Care Most About Sovereign AI, and Why?

Data leakage and compliance concerns drive sovereign AI adoption across every sector surveyed. Financial services professionals top the list, with 82% citing data leakage and privacy as their primary barrier to adoption. Manufacturing follows at 77%, telecommunications at 75%, healthcare at 74%, and energy at 70%.

Beyond regulatory pressure, enterprises see sovereign AI as a path to stronger security, reduced dependence on external providers, and competitive advantage. In Canada, 35% of surveyed leaders said competitive advantage drives their sovereign AI strategy. Telecommunications providers lead on this front with 37%, followed by manufacturing at 32%.

The real-world stakes are high. Cohere points to its work with the Aston Martin Formula One team as an example of how sovereign AI delivers practical value beyond data protection. The F1 team processes massive volumes of telemetry, diagnostic, and simulation data under severe time constraints. By deploying sovereign AI architectures close to their operational data, they ensure real-time analytics without exposing sensitive intellectual property or relying on external APIs.

How to Evaluate Whether Your Organization Needs Sovereign AI

  • Data Sensitivity: If your organization handles financial records, patient data, trade secrets, or critical infrastructure information, sovereign AI allows you to process that data without sending it to external cloud providers or third-party AI services.
  • Regulatory Requirements: Organizations in finance, healthcare, energy, and telecommunications face strict compliance rules about where data can be stored and processed. Sovereign AI deployed on your own infrastructure simplifies regulatory alignment.
  • Competitive Advantage: If your AI models or training data represent core business differentiation, keeping them under your control prevents competitors or cloud providers from accessing proprietary insights.
  • Operational Resilience: Sovereign AI systems that don't depend on external APIs or internet connectivity can continue operating even if your cloud provider experiences an outage or restricts access.

The "Sovereignty Washing" Problem: Not All Sovereign Claims Are Equal

A troubling finding emerged from the research: over 80% of UK decision-makers report relying on public or private clouds for regulated AI processes, raising questions about whether true sovereignty is even possible on third-party infrastructure. Many organizations may believe they have sovereign AI simply because their data is hosted in a particular region or on a private cloud, when in reality they still depend on external providers for critical functions.

Pineau cautioned against what she calls "sovereignty washing," where solutions marketed as sovereign don't actually deliver diversification or resilience. "True sovereignty can include cloud infrastructure, but simply hosting data in a particular region or private cloud doesn't automatically make an AI system sovereign," she explained. "It also requires a set of technical guarantees about who controls the model, data, access, updates and deployment, and what dependencies remain on an external API".

Pineau

Only 13% of leaders report being "very widely" aware of sovereign AI, revealing a fragmented understanding across global organizations. This awareness gap means many companies may be making AI investment decisions without proper context or technical understanding of what they're actually buying.

What Does Sovereign AI Look Like in Practice?

The concept gained fresh credibility when Dream, an Israeli sovereign AI company focused on government and critical infrastructure, announced that its autonomous cybersecurity research system called Hero achieved a 96.6% score on UC Berkeley's CyberGym benchmark, the highest ever recorded on that test.

CyberGym evaluates AI systems against more than 1,500 real-world security challenges drawn from open-source projects. Unlike benchmarks that test theoretical knowledge, CyberGym measures whether AI systems can perform practical vulnerability research, analyzing code and binaries, using security tools, and developing working proof-of-concept exploits.

Dream's achievement demonstrates a key principle: specialized AI systems built for specific missions and equipped with the right tools can outperform larger general-purpose models. Hero operates entirely on Dream-controlled infrastructure with no public internet access and no external AI model APIs. All data, model activity, and research remained within an environment fully controlled by Dream.

"The CyberGym result demonstrates that the AI race will not be determined solely by who builds the largest general-purpose model. Specialized systems, deeply trained for a specific mission and equipped with the right tools, can achieve extraordinary capabilities," said Shalev Hulio, co-founder and CEO of Dream.

Shalev Hulio, co-founder and CEO of Dream

Meanwhile, Palantir Technologies has positioned itself as a sovereign AI infrastructure provider for businesses and governments. The company emphasizes enabling organizations to use advanced AI while maintaining control over their data, intellectual property, models, and critical operations. Palantir's government business generated $990 million in the second quarter of 2026, up 79% year over year, while commercial revenues hit $945 million, growing at an even faster 109.7% pace.

The company closed 220 deals worth at least $1 million in the second quarter, with more businesses and government agencies adopting its Artificial Intelligence Platform (AIP). The U.S. Army recently handed Palantir's subsidiary a production contract for eight TITAN systems, AI-equipped ground vehicles that had spent years in prototype and are now headed to the field.

The Bottom Line: Clarity Matters as Sovereign AI Adoption Accelerates

The research reveals a critical challenge facing enterprises: adoption is accelerating, but understanding is lagging. Organizations must bridge the awareness-to-action gap by creating a strategic vision and plan to achieve genuine ownership over their AI systems. This means moving beyond marketing claims and evaluating whether proposed solutions actually deliver the technical guarantees required for true sovereignty: control over models, data, access, updates, and deployment, with minimal dependencies on external APIs or providers.

As governments and enterprises worldwide race to build or acquire sovereign AI capabilities, the ability to clearly define and evaluate what sovereignty actually means will determine which organizations succeed in maintaining control over their most sensitive data and operations.