Here is a question most enterprise storage teams have not yet asked themselves: If regulated data cannot leave a jurisdiction, does the same rule apply to a model trained on it? The contributors Computer Weekly consulted for this article answered with an unambiguous yes – and argued that the implications reach well beyond compliance.
In this second part of a two-part series, Computer Weekly asked the same set of questions to 10 senior figures from the storage, backup and legal sectors – chief executives, chief technology officers, a CISO and a commercial lawyer – about the state of data sovereignty and where it heads over the next 12 to 18 months.
Their answers sketch a forward picture that is more complex and more commercially significant than the first part of the debate. Sovereignty, they argue, is no longer just about keeping data safe from foreign courts. It is about who controls the intelligence derived from that data, who can monetise it and who can offer contractual guarantees that turn architectural independence into a market advantage.
The model inherits the data
If regulated data cannot leave a jurisdiction, the contributors argue, the same logic applies to a model trained on it.
“This is the sovereignty frontier that almost no one has adequately addressed, and it is going to become one of the most contested questions in data governance over the next two years,” says Aleksander Ragel, CEO and co-founder of Leil Storage.
“If you train a model on sovereign data – patient records, financial transactions, classified research – does the model inherit the sovereignty constraints of its training data?” he adds. “Legally, the answer is evolving. Practically, it should, because model weights encode statistical representations of that data, and in some cases, training data can be partially reconstructed from the model itself.”
Ragel frames the challenge as an end-to-end sovereignty chain – the raw data, the training pipeline, the model weights, the inference outputs and the derived insights – where a single link processed outside the organisation’s jurisdictional control compromises the whole chain. That carries direct infrastructure implications, particularly for the warm tier of storage that houses training datasets – “too active for tape, too voluminous for flash”, in Ragel’s words.
Paul Speciale, chief marketing officer at Scality, extends the argument across the full artificial intelligence (AI) lifecycle: “If your training data corpus is regulated, then the model weights derived from it, the embeddings indexed from it, the RAG pipelines retrieving from it and the inference outputs based on it are all carrying along the sovereignty of their source, since you can’t strip jurisdiction by transformation.
“A fine-tuned model trained on EU patient data is, in effect, an EU asset, and running its inference path through a foreign GPU [graphics processing unit] cloud reopens every question the training-data architecture tries to close.”
The practical consequence, he argues, is that “training, fine-tuning, inference, KV cache, embeddings, checkpoints and long-term retention all need to sit inside the same jurisdictional boundary as the source data, preferably under one operating model and layer” – something he expects to become “an explicit requirement in regulated, industry RFPs [request for proposals]” in the next year.
Valery Guilleaume, CEO of Nodeum, captures the consensus: “Organisations should see sovereignty as extending beyond raw data to include AI models, outputs and derived data. This is important because the real value and risk often lie in what is produced from the data, not just the data itself.”
The AI sovereignty question, in other words, is not a theoretical edge case. It is the natural destination of the control-over-location logic – and it leads directly to the economic dimension.
Built for fragmentation
If AI workloads must sit inside the same jurisdictional boundary as their source data, the architecture beneath them must be built for a fragmented, jurisdictionally bound world by design. The contributors identify converging imperatives: Federated autonomy, physical-layer awareness and jurisdictional alignment treated as a procurement criterion.
Ragel calls for federated-but-autonomous storage clusters that operate independently in each jurisdiction, with no shared control plane and no cross-border metadata leakage – and for platforms that stop abstracting away the hardware. “In a sovereignty context, that abstraction is a liability,” he says. “You need a storage architecture that understands which drives hold which data, how that data is distributed across physical nodes, and how to manage data placement with jurisdictional intent.”
Speciale echoes the federated model, adding: “Default to regional autonomy: Each jurisdiction gets its own data plane for storage, keys, identity, audit. And each one should be able to operate independently if the global connection is severed.” The pattern, he says, is “multi-jurisdiction by design: distributed by default, governed centrally, with the data plane enforced by infrastructure rather than asserted by contract”.
Alexander Lefterov, founder and CTO of Tiger Technology, keeps the priority on the control plane. “Prioritise the control plane first – if you do not govern your own data lifecycle policies, the rest of your sovereignty investment is built on sand. The most critical change is establishing clear data visibility and lineage. Organisations cannot protect or control data they do not understand.”
Guilleaume adds the mobility dimension: “The key architectural shift is moving from fixed, region-based storage to policy-driven data mobility across jurisdictions. Enterprises need to separate storage from control, so governance, access rules and auditability stay consistent no matter where data moves or is accessed.”
The suppliers best positioned to deliver these architectures transparently – because their platforms are designed for jurisdictional containment rather than retroactively constrained – are likely to define the procurement conversations of the next several years.
From cost centre to competitive edge
If the AI sovereignty chain and the architectural shifts define the technical response, the economic case turns sovereignty from a defensive posture into an offensive strategy.
Shimon Ben-David, CTO at WEKA, locates the value at the point of inference. “The value of AI is delivered at inference,” he says. “When you serve it to users at scale, that’s where the economics matter. Control your own data and the infrastructure that serves it during inference, and you control how efficiently your AI runs and what it costs.”
He adds: “Run inference on infrastructure you don’t control, and you inherit its inefficiencies, paying for capacity you can’t optimise. As token consumption grows, that cost compounds and the gap between controlling your infrastructure and not controlling it widens with every token you produce. The organisations that treat control over their own data and AI infrastructure as an economic asset will turn it into a competitive moat.”
Speciale sees sovereignty moving from cost centre to market-access precondition. “A European bank, a French hospital network, a German automaker, a UK government supplier – none of them can win new contracts without demonstrable control over where their data lives and who can reach it,” he says. Organisations that can credibly promise “your data, your jurisdiction, your keys, our infrastructure”, he adds, earn a confidence hyperscaler-only competitors cannot match. “In an AI world where customer data is the moat, that guarantee is increasingly the product.”
Lefterov makes the link between sovereignty and value explicit: “Well-governed data – segmented, AI-accessible, with clear retention policies – is an asset. A pathology archive you can run AI against is a research advantage. The same archive locked in an opaque third-party system is a liability. Sovereignty and value creation are the same problem viewed from different angles.”
The test of real control
If sovereignty is becoming a value driver, the obvious question is what qualifies as genuine control. The contributors converge on a definition more demanding than most current storage and backup models can satisfy.
Ragel distils it to four simultaneous conditions: “You know where every byte of data physically resides; no external party can access it without your explicit authorisation; your ability to operate, recover and migrate is not dependent on any third party’s continued cooperation; and you can prove all of the above to a regulator.”
The last criterion is where most of the industry falls short. Most current models, he argues, fail on at least two of the four – cloud storage on jurisdictional independence, traditional on-premise on operational independence, and nearly all legacy architectures on provability.
Martin Kunze, founder and CMO of Cerabyte, frames the gap in terms of what most storage systems were designed for: “Computational performance, not for secure, permanent, sovereign data preservation.”
Lefterov reaches the same conclusion, arguing that organisations must know where their data is, decide what happens to it at every lifecycle stage, recover it independently of any single supplier and prove it to an auditor. “Most backup and cloud-first models today fail on at least two of those four,” he says.
The gap between the definition of control and the reality of current infrastructure is, in effect, the commercial opportunity.
The contractual horizon
If the definition of control exposes the gap, the natural commercial response is a contractual instrument that makes sovereignty guarantees enforceable. The contributors see sovereignty SLAs as the most significant market development of the next 18 months.
Ragel describes sovereignty SLAs as “the most commercially interesting development. We will see procurement teams demanding contractual guarantees about jurisdictional exposure, control-plane independence, and data access vectors – not just uptime percentages. Vendors that can offer this transparently, because their architecture is inherently sovereign rather than retroactively constrained, will win.”
Speciale agrees, framing SLAs as “the natural next step in contracts – not just uptime and recovery time, but jurisdictional guarantees, disclosure-order notification, and proof-of-placement evidence. The vendors who can deliver them will define the next decade of the storage market.”
Lefterov expects SLAs within 18 months: “Start asking your vendors for sovereignty SLA commitments now – organisations that normalise these expectations in procurement will shape what the market delivers over the next two years.”
Weijdema sees “early forms of sovereignty service commitments likely to emerge in vendor agreements, although consistency will continue to evolve”. The sequencing that emerges is consistent: in-region defaults arrive first, multi-jurisdiction architectures follow as standard, sovereignty SLAs emerge within 18 months as the procurement differentiator, and AI data-origin tagging takes longest to mature.
The commercial arc is clear, according to these contributors. Sovereignty began as a compliance obligation – now, it is becoming an architectural property and is heading towards being a contractual guarantee – one that will separate the storage market into those who can offer it and those who cannot.
S 004