Silicon Valleys Journal
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
Silicon Valleys Journal
No Result
View All Result
Home Technology & Industry AI

Data Sovereignty in the AI Era – Part One: Why picking a cloud region is not a sovereignty strategy

By Federica Monsone, Founder and CEO of A3 Communications

SVJ Thought Leader by SVJ Thought Leader
September 10, 2026
in AI, C-Suite Perspective, Cloud Computing, Cybersecurity, Enterprise Tech, Future of Silicon Valley, Leadership & Perspective, Policy & Regulation, Technology & Industry
0
Data Sovereignty in the AI Era – Part One: Why picking a cloud region is not a sovereignty strategy

Leaders from the storage, backup, and legal sectors agree that data sovereignty has moved beyond residency. Increasingly, organisations need to think less about where data is stored and more about who controls it.

Ask an enterprise storage team if their data is sovereign and the answer often begins with a location: Frankfurt, London or an EU-West cloud region.

According to the ten industry leaders we spoke to, that answer is becoming one of the biggest misconceptions in enterprise IT.

Bringing together CEOs, CTOs, a CISO, and a commercial lawyer, we asked the same questions about the state of data sovereignty and where it is heading over the next 12 to 18 months. Although their perspectives differ, the thoughts are remarkably consistent on one point: sovereignty is no longer determined by geography alone. It is increasingly defined by operational control, legal jurisdiction, and architectural independence.

The residency trap

“The most dangerous assumption is that sovereignty is solved by choosing a cloud region,” says Aleksander Ragel, CEO and co-founder of Leil Storage.

That observation becomes the foundation for almost every discussion that follows. Across the board, contributors argue that organisations continue to mistake data residency for data sovereignty, despite the two describing fundamentally different things.

Paul Speciale, CMO at Scality, puts it simply: “Residency is about geography, whereas sovereignty is about which laws can reach your data, and those are not the same conversation.”

Alexander Lefterov, founder and CTO of Tiger Technology, explains why the distinction matters. “Under the US CLOUD Act, American authorities can compel US-owned providers to hand over data stored in Frankfurt or Dublin without telling you. Sovereignty is about who controls the stack, not where the servers sit.”

For Edwin Weijdema, field CTO EMEA and cybersecurity lead at Veeam, the misconception runs much deeper than physical location. “Many still equate sovereignty with data residency, assuming that keeping data in a specific country or region automatically ensures compliance and control. In practice, residency is necessary but not sufficient. Sovereignty also depends on jurisdictional exposure, access and key management, operational control, and the ability to demonstrate governance end-to-end.”

Other contributors reinforce the same shift from different perspectives.

Kim Larsen, CISO at Keepit, believes many organisations are still approaching sovereignty from the wrong perspective. “The most outdated assumption is that sovereignty can be solved by ‘building a new Microsoft’, replacing one hyperscaler with another. That misses the point. Sovereignty isn’t about scale, it’s about control.”

Meanwhile, Martin Kunze, founder and CMO of Cerabyte, believes organisations are beginning to ask far more fundamental questions. “The key question will no longer be only ‘Where is my data stored?’ but ‘Who can access it, who can influence it, what infrastructure does it depend on, and can I preserve it independently under disruption?'”

Taken together, the message is clear. Data sovereignty is no longer a procurement decision based on geography. It is becoming an architectural discipline built around control, independence, and accountability.

Regulation is reshaping sovereignty

If operational control defines sovereignty inside an organisation, the external landscape is changing just as quickly. Across the panel, there is broad agreement that the era of a single global approach to data governance is giving way to an increasingly fragmented regulatory world.

“We are already there,” says Leil’s Ragel. “The EU has GDPR and the evolving Data Act, China has its Data Security Law, India has the DPDP Act, and the US has an increasingly fragmented landscape of state and federal privacy laws. These are not converging, they are diverging, and every major trade tension accelerates that divergence.”

Keepit’s Larsen believes organisations are already beginning to feel the impact. “We’re already seeing the emergence of data blocs, driven by regulation like the EU Data Act and broader geopolitical tensions. This will fundamentally reshape data flows. Organisations will face stricter constraints on where data can be stored and how it moves across borders.”

Rather than building a single global architecture, contributors increasingly see organisations adopting multiple regional environments governed by common policies but designed to meet local legal requirements.

Scality’s Speciale describes the shift as a move away from unrestricted global data movement. “The ‘free flow of data’ narrative of the 2010s is being replaced by managed flow with consent, contracts, and conditions at each border. The practical effect is that organisations operating globally can no longer assume one cloud architecture serves the whole world. They will architect for regional autonomy with global governance, with multiple data planes each compliant with its local regime, unified by metadata and policy rather than by replication.”

Veeam’s Weijdema believes organisations should resist treating sovereignty as a one-time compliance exercise. “Both regulation and geopolitical conditions continue to evolve, meaning organisations must treat sovereignty as an ongoing discipline. Strategies must be continuously reviewed and adapted to remain effective.”

Tvrtko Fritz, CEO of euroNAS foregrounds the national-interest dimension. “Governments are likely to introduce additional regulations governing where certain categories of data, intellectual property, and critical business information can be stored, processed, and accessed,” he notes, and counsels organisations to “prepare for a future where digital sovereignty is a permanent consideration in IT strategy.”

Valery Guilleaume, CEO of Nodeum offers a slightly different angle, suggesting the focus will be “less on strict geopolitical separation and more on careful compliance with regional regulations governing storage, movement, and access to data.”

Why jurisdiction matters more than geography

If regulation explains why sovereignty is changing, jurisdiction explains why simply storing data locally is no longer enough.

Throughout the responses, contributors repeatedly returned to one point: organisations tend to focus on where data is stored, while paying far less attention to which legal systems ultimately govern access to it.

As Ragel from Leil puts it: “Legal jurisdiction will matter more, and it is the dimension most enterprises are still underweighting.”

He continues: “A petabyte of data stored in Frankfurt means very little if the storage platform’s parent company can be compelled by a US federal court to hand over that data regardless of where it physically sits. The CLOUD Act made this explicit, and we have not yet seen the full implications play out in enforcement.”

Larsen from Keepit believes another major legal challenge may bring these issues back into sharp focus. “We’re likely heading toward another ‘Schrems moment,’ which will bring the question of US access laws back into sharp focus.”

He adds: “Even if data sits in Europe. It may still be exposed to foreign jurisdiction depending on the provider. Organisations should respond by reducing reliance on providers subject to conflicting laws, and by designing architectures where control, access, and encryption remain firmly in their own hands.”

Paul Haswell, partner at Hill Dickinson, believes organisations should view location and jurisdiction as inseparable. “Where data is stored and who can access it cannot be separated, the two issues go hand in hand. Organisations will need easy and safe access to their data, and easy and safe access might be contingent on making sure that the data is located and protected in one’s home jurisdiction.”

Tiger’s Lefterov believes organisations should extend that thinking into procurement itself. “Location, you can see on a map. Legal reach is invisible – a foreign authority can compel your provider without notifying you.”

He continues: “Treat provider jurisdictional footprint as a procurement criterion, not an afterthought – where the parent company is incorporated matters as much as where the data centre is located.”

The result is a fundamental change in how sovereignty is evaluated. Geography remains important, but it is no longer enough on its own. Organisations increasingly need to understand not only where their data resides, but who ultimately has the legal authority to reach it.

What comes next

The contributors are clear that data sovereignty has outgrown its traditional definition.

Choosing where data is stored remains important, but it is no longer sufficient on its own. Organisations are increasingly expected to demonstrate who controls their data, who can access it, which legal frameworks apply and whether their infrastructure can operate independently of external jurisdictions.

The consequence is that sovereignty is becoming an architectural decision rather than a procurement exercise. It is influencing how organisations design storage platforms, manage encryption keys, approach resilience and evaluate technology suppliers.

For many, that represents a significant shift in thinking. Rather than asking whether data resides in the correct location, enterprises are beginning to ask whether they genuinely control it throughout its lifecycle.

That change is likely to reshape procurement conversations over the next 12 to 18 months as organisations look beyond geography towards operational independence, legal certainty, and demonstrable control.

In Part Two

Understanding what data sovereignty means is only the first step. The next challenge is determining how those same principles apply to AI.

If organisations are expected to retain sovereignty over their data, what happens when AI models are trained on it? Do model weights, inference pipelines, and derived insights inherit the same sovereignty obligations? And if they do, how will storage architectures, procurement strategies and vendor guarantees need to evolve?

Shimon Ben-David, CTO at WEKA, points to a parallel misreading in the AI domain: “Sovereign AI is often misread as a mandate to pull every AI workload back from the cloud and run everything on-premises. The future is hybrid.”

In Part Two, our contributors examine why AI is rapidly becoming the next frontier for data sovereignty and why organisations that solve these challenges first may gain advantages that extend well beyond compliance.

Previous Post

Crypto Businesses Cannot Thrive Without World Class Execution

Next Post

Data Sovereignty in the AI Era – Part Two: Beyond compliance: why data sovereignty will become an AI-era competitive advantage

SVJ Thought Leader

SVJ Thought Leader

Next Post
Data Sovereignty in the AI Era – Part Two: Beyond compliance: why data sovereignty will become an AI-era competitive advantage

Data Sovereignty in the AI Era - Part Two: Beyond compliance: why data sovereignty will become an AI-era competitive advantage

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

December 27, 2025
The AI Cold War and How to Prepare for It

The AI Cold War and How to Prepare for It

May 1, 2026
AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

November 24, 2025
The UK’s Seed-to-Series A gap is growing. Should we fix it?

The UK’s Seed-to-Series A gap is growing. Should we fix it?

November 25, 2025
The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

1

50 Key Stats on Finance Startups in 2025: Funding, Valuation Multiples, Naming Trends & Domain Patterns

0
CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

0
Clarity Is the New Cyber Superpower

Clarity Is the New Cyber Superpower

0

Famous Isn’t the Same as Matchable

September 10, 2026
Real-Time AI at the Ballot Box: How Multimodal Machine Learning Brings Accountability to Political Advertising at Scale

Real-Time AI at the Ballot Box: How Multimodal Machine Learning Brings Accountability to Political Advertising at Scale

September 10, 2026

Where RAG Actually Breaks: Four Failure Points, One Accuracy Score

September 10, 2026
The AI Valuation Trap: Why Profitable AI Businesses May Be Harder to Sell

The AI Valuation Trap: Why Profitable AI Businesses May Be Harder to Sell

September 10, 2026

Recent News

Famous Isn’t the Same as Matchable

September 10, 2026
Real-Time AI at the Ballot Box: How Multimodal Machine Learning Brings Accountability to Political Advertising at Scale

Real-Time AI at the Ballot Box: How Multimodal Machine Learning Brings Accountability to Political Advertising at Scale

September 10, 2026

Where RAG Actually Breaks: Four Failure Points, One Accuracy Score

September 10, 2026
The AI Valuation Trap: Why Profitable AI Businesses May Be Harder to Sell

The AI Valuation Trap: Why Profitable AI Businesses May Be Harder to Sell

September 10, 2026

About & Contact

  • About Us
  • Branding Style Guide
  • Contact Us
  • Help Centre
  • Media Kit
  • Site Map

Explore Content

  • Events
  • Newsletter
  • Press Releases
  • Reports & Guides
  • Topics

Legal & Privacy

  • Advertiser & Partner Policy
  • Communications & Newsletter Policy
  • Contributor Agreement
  • Copyright Policy
  • Privacy Policy
  • Prohibited Content Policy
  • Terms of Service

Tiny Media Brands

  • Silicon Valleys Journal
  • The AI Journal
  • The City Banker
  • The Wall Street Banker
  • World Lifestyler
  • About
  • Privacy & Policy
  • Contact

© 2025 Silicon Valleys Journal.

No Result
View All Result

© 2025 Silicon Valleys Journal.