Ten industry leaders map the next frontier – from AI model sovereignty to the emergence of contractual guarantees that could redefine the storage market.
The assumptions shaping the data sovereignty conversation are crumbling. The residency-first mindset, the belief that a regional cloud bucket settles the question, and the idea that encryption alone closes the gap are giving way to a more complex reality. We asked ten senior figures from the storage, backup, and legal sectors where data sovereignty is heading over the next 12 to 18 months. Their responses suggest the debate is shifting beyond location and compliance to AI models, derived data, architecture, and commercial value, with contractual guarantees and control over intelligence becoming as important as protecting data from foreign courts.
The AI sovereignty chain
If regulated data cannot leave a jurisdiction, does the same apply to a model trained on it? Their answer was unequivocal: yes.
“This is the sovereignty frontier that almost no one has adequately addressed, and it is going to become one of the most contested questions in data governance over the next two years,” says Aleksander Ragel, CEO and co-founder of Leil Storage. “If you train a model on sovereign data – patient records, financial transactions, classified research – does the model inherit the sovereignty constraints of its training data? Legally, the answer is evolving. Practically, it should, because model weights encode statistical representations of that data, and in some cases, training data can be partially reconstructed from the model itself.”
Ragel describes an end-to-end sovereignty chain spanning raw data, training pipelines, model weights, inference outputs, and derived insights – where a single link outside an organisation’s jurisdictional control compromises the entire chain. This has direct implications for the warm storage tier supporting AI training datasets, which is “too active for tape, too voluminous for flash” and must be high-performance, cost-efficient, and architecturally sovereign.
Paul Speciale, CMO at Scality, believes sovereignty must extend across the entire AI lifecycle. “If your training data corpus is regulated, then the model weights derived from it, the embeddings indexed from it, the RAG pipelines retrieving from it, and the inference outputs based on it are all carrying along the sovereignty of their source, since you can’t strip jurisdiction by transformation. A fine-tuned model trained on EU patient data is, in effect, an EU asset, and running its inference path through a foreign GPU cloud reopens every question the training-data architecture tries to close.”
Speciale argues that “training, fine-tuning, inference, K:V cache, embeddings, checkpoints, and long-term retention all need to sit inside the same jurisdictional boundary as the source data, preferably under one operating model and layer. I expect this to become an explicit requirement in regulated-industry RFPs within the next year.”
Edwin Weijdema, field CTO EMEA and cybersecurity lead at Veeam, notes that “Sovereignty extends across the full AI lifecycle, including training data, models, and outputs. As regulation evolves, there is increasing scrutiny of how data flows within AI systems. Many organisations are still early in their AI adoption and lack visibility into these processes. Organisations must establish stronger data context, understanding the origin, movement and usage of data within AI workflows.”
Valery Guilleaume, CEO of Nodeum, says “Organisations should see sovereignty as extending beyond raw data to include AI models, outputs, and derived data. This is important because the real value and risk often lie in what is produced from the data, not just the data itself.”
As AI becomes increasingly central to enterprise strategy, sovereignty can no longer stop at the data itself. It must extend across the entire AI lifecycle, from training datasets to the models, outputs, and intellectual property they create.
Architecting for a jurisdictionally bound world
If AI models inherit the sovereignty obligations of their training data, organisations will need architectures designed for multiple jurisdictions. Contributors point to regional autonomy, visibility and infrastructure that enforces sovereignty by default.
Leil’s Ragelidentifies three architectural shifts: “Federated-but-autonomous storage clusters that operate independently in each jurisdiction with no shared control plane and no cross-border metadata leakage; physical-layer awareness, where storage platforms stop abstracting away the hardware and instead make data placement and behaviour visible. In a sovereignty context, that abstraction is a liability. You need a storage architecture that understands which drives hold which data, how that data is distributed across physical nodes, and how to manage data placement with jurisdictional intent.”
Tiger Technology’s CEO Alexander Lefterovadvocates provider-agnostic routing so different data categories land in the right jurisdictions automatically, with one overriding principle. “Prioritise the control plane first – if you do not govern your own data lifecycle policies, the rest of your sovereignty investment is built on sand. The most critical change is establishing clear data visibility and lineage. Organisations cannot protect or control data they do not understand.”
Veeam’s Weijdema emphasises visibility across “the full data lifecycle, from creation and processing through to backup, recovery, and deletion, ensuring consistent standards throughout.” Data portability is equally essential and architectures must allow organisations to “adapt quickly to regulatory, security, and geopolitical change without losing control.”
Tvrtko Fritz, CEO of euroNAS, comments “While cloud services will continue to play an important role, many organisations are likely to adopt a more selective approach, keeping their most critical data, intellectual property, and strategic workloads either on-premises or within trusted local datacentres. From a sovereignty perspective control and transparency will become key design principles.”
Nodeum’s Guilleaume adds the mobility dimension: “The key architectural shift is moving from fixed, region-based storage to policy-driven data mobility across jurisdictions. Enterprises need to separate storage from control, so governance, access rules, and auditability stay consistent no matter where data moves or is accessed.”
Control as competitive advantage
If the AI sovereignty chain defines the technical challenge, it also creates commercial opportunity. Rather than viewing sovereignty simply as a compliance requirement, they increasingly see it becoming a source of competitive advantage.
Shimon Ben-David, CTO at WEKA, draws the sharpest line between control and economics: “The value of AI is delivered at inference. When you serve it to users at scale, that’s where the economics matter. Control your own data and the infrastructure that serves it during inference, and you control how efficiently your AI runs and what it costs.”
He continues, “Run inference on infrastructure you don’t control, and you inherit its inefficiencies, paying for capacity you can’t optimise. As token consumption grows, that cost compounds, and the gap between controlling your infrastructure and not controlling it widens with every token you produce.”
Leil’s Ragel identifies three commercial benefits. “First, AI readiness. Organisations that maintain sovereign control over their data assets – particularly large-scale training datasets – can deploy AI models without the legal uncertainty of processing sovereign data on third-party infrastructure. That is not a theoretical advantage; it is becoming a prerequisite for AI adoption.”
“Second operational resilience – when backup and archive tiers sit on-premises under the customer’s control, recovery time objectives become a function of hardware throughput rather than a cloud provider’s API rate limits or egress fees. Third is total cost of ownership at scale, where on-premises sovereign storage fundamentally changes the cost equation.”
Scality’s Speciale sees sovereignty moving from cost centre to market access precondition.
“A European bank, a French hospital network, a German automaker, a UK government supplier – none of them can win new contracts without demonstrable control over where their data lives and who can reach it. Sovereignty has become an actual precondition to creating revenue, not a tax on it. Organisations that can credibly say ‘your data, your jurisdiction, your keys, our infrastructure’ earn customer confidence that hyperscaler-only competitors cannot match. In an AI world where customer data is the moat, that guarantee is increasingly the product.”
Martin Kunze, founder and CMO of Cerabyte, sees sovereignty as a strategic capability. “Organisations that can preserve critical data without relying entirely on cloud providers, continuous power, or repeated migration cycles are less exposed to disruption, ransomware, vendor failure, geopolitical instability, and rising operational costs. If data can be preserved without continuous energy consumption for cooling and storage operation, the environmental footprint of long-term retention can be reduced significantly. Data sovereignty is not only a defensive measure, it becomes a strategic capability.”
What control actually means
If sovereignty is becoming a value driver, the obvious question is what qualifies as genuine control. The contributors converge on a definition that is more demanding than most current storage and backup models can satisfy.
Tiger Technology’s Lefterov distills it down to four simultaneous conditions: know where your data is at all times, decide what happens to it at every lifecycle stage, recover it independently of any single vendor, and prove it to an auditor. “Most backup and cloud-first models today fail on at least two of those four.”
Cerabyte’s Kunzesays “Most digital storage systems were designed for computational performance, not for secure, permanent, sovereign data preservation. They require active maintenance, regular media replacement, migration cycles, fixity checks, software updates, power, cooling, and operational expertise. As data volumes have grown, this complexity has pushed many organisations toward cloud services. However, cloud-based storage introduces new dependencies: on providers, contracts, jurisdictions, energy supply, network access, and political stability which makes it difficult to claim full sovereignty.”
The SLA horizon
If sovereignty is becoming an architectural principle, contributors believe the next step is contractual accountability. They see sovereignty SLAs emerging as the mechanism that turns technical capability into a procurement requirement.
Tiger Technology’s Lefterov expects SLAs within 18 months to build in contractual commitments on key management and portability. He says, “Start asking your vendors for sovereignty SLA commitments now – organisations that normalise these expectations in procurement will shape what the market delivers over the next two years.”
Scality’s Speciale frames SLAs as “the natural next step in contracts – not just uptime and recovery time, but jurisdictional guarantees, disclosure-order notification, and proof-of-placement evidence. The vendors who can deliver them will define the next decade of the storage market.”
Fritz from euroNAS focuses on in-region defaults as the most immediate development – “keeping critical data within trusted regional boundaries is likely to become a fundamental element of both risk management and competitive strategy.” While Paul Haswell, partner at Hill Dickinson takes the longest view, expecting all four developments to become standard “over the course of the next three to five years.”
Sovereignty is moving beyond compliance and architectural design towards contractual assurance. The ability to demonstrate, verify and guarantee sovereign control is likely to become an increasingly important differentiator as organisations evaluate future storage platforms.