Every business using AI should be asking a simple question: Who actually controls the technology and data we increasingly depend on?

That question sits at the heart of AI and data sovereignty, an issue that is rapidly moving from government policy discussions into boardrooms.

Much of the debate focuses on geopolitics, particularly the risks of countries relying on foreign technology, infrastructure and AI capabilities. But businesses face their own sovereignty problem.

Our data is constantly being stored, analyzed and acted on by systems owned and controlled by other organizations. Increasingly, we also rely on their AI models to create content, make decisions and carry out important business processes.

That creates new risks. A data breach, change in terms and conditions, court ruling or government intervention could suddenly affect how we access our data or use essential AI services.

So, AI sovereignty is becoming a business resilience issue. And every organization needs to understand where it is exposed, who controls the technology it relies on and what happens if that control suddenly matters.

If your personal data ends up on someone else’s computer, who owns that record of your data?

In reality, there’s no simple answer. Depending on where you live, it may legally still be yours. But they have control over it, and the ability to do pretty much anything they want with it.

When we introduce AI into the equation, things become even trickier. AI churns through huge volumes of data, using it to create content, ideas, and actions. So sovereignty raises questions about who controls the way it does this, and who owns the end result.

An example of when this mattered: In 2025, OpenAI was ordered by a US court to keep records of ChatGPT discussions that users had deleted. This is likely to have included huge numbers of conversations that users assumed would never be visible to anyone.

For several months, this meant that businesses using it risked anything they put into it being exposed through US court records and filings.

Yes, there are plenty of other reasons why businesses should certainly not be entering sensitive or private information into ChatGPT. But this serves as a particularly stark example.

So sovereignty, as a strategy, is about knowing who has control of your data and the algorithms you use. As well as taking steps to ensure you can stay safe when things happen that are out of your control.

As individuals, we have the right to protect our private information, and as businesses, we have obligations to protect information that others share with us.

Sovereignty means bringing these under our control. It doesn’t mean “own everything”. Businesses might not have the space or budget to rebuild their entire AI stack on-premises and entirely under their ownership and control.

Likewise, going back to doing everything in our day-to-day lives offline that we’ve got used to doing across a multitude of apps and services isn’t a realistic option for everyone.

But they can audit their AI dependencies, make sure they understand their agreements, assess their unique risks, and have plan B’s firmly in place.

Other issues raised by sovereignty do, however, mean it’s important that both businesses and individuals are able to claim and exercise ownership rights over things they create or build.

Who owns what AI creates? Well, it’s up in the air, but several high-profile legal judgments have concluded that AI can’t be considered a creator for copyright purposes. In other words, companies are generating and using content and assets with ownership that could, at some point, be disputed.

Failing to understand how risks are relevant to them, and why avoiding or mitigating them needs to be tackled strategically, is likely to cause big problems for a lot of businesses, as the implications of sovereignty become more widely felt.

So what can we do to prepare ourselves?

Gartner predicts that countries will have to spend at least one percent of GDP on infrastructure development to maintain sovereign control of their AI.

Businesses planning on protecting their own interests in the same way should similarly treat it as a strategic line item.

This spending doesn’t have to go on GPU clusters and open-source infrastructure to run in-house, on-device AI.

For most businesses, using it to identify exposure to sovereignty risks, thoroughly understand who has control over its assets and functions, and prepare responses to potential sovereignty events is likely to be more appropriate.

And as well as businesses, we as private individuals should be alert to how legal rulings and international disputes could impact our ability to use and control our data.

The ability to monitor and manage jurisdiction of where we keep and process personal information is now a critical skill for everyone, not just data protection professionals.

Ultimately, navigating the challenges thrown up by AI sovereignty issues should be seen as an opportunity to guide businesses toward becoming more resilient, agile and self-supporting, making them stronger and more competitive in these fast-changing times.