A vendor says “sovereign AI,” a buyer nods, and both may leave with different ideas about what was promised.
Where the data is stored.
Where are your databases, documents and backups? Who can access them, and who manages the encryption keys?
Local hosting can address storage requirements. You also need to understand how access is managed and what your provider commits to.
Owned by: infrastructure and procurement.
Where the data goes when the system runs.
An application hosted in your country can still send prompts, documents and customer information elsewhere for processing.
Having a hyperscaler region in Canada or Europe does not mean every AI model is available there. Availability depends on the model, its version and the deployment type. Some deployments route requests across a wider geography.
The practical question is: can the model you need process your data within your required boundary, with enough capacity for your workload?
That may mean choosing another model, hosting one yourself, or balancing capability, cost and control. A provider’s local presence is a starting point. You still need to check the services your application actually uses.
Owned by: architecture, with procurement verifying the commitments.
Who controls what the system may decide and do.
What can the agent access? Which decisions can it make? Which actions need human approval? Can you review what it did, stop it and revoke its access?
These questions matter more as AI moves from answering questions to taking action. Running on your own hardware does not answer them. Control needs to be built into permissions, process rules, approval steps and audit records. Instructions to the model alone are not enough.
Owned by: risk, security and whoever is accountable for the process.
Whether you can leave.
Can you move your data, replace the model or change providers without rebuilding the whole application?
If your chosen model is retired or becomes unavailable in your region, do you have a workable alternative?
Open standards, replaceable components and a practical migration plan help preserve those choices. The cost and effort of switching matter as much as the ability to export your data.
Owned by: technology leadership and whoever maintains the system.
Why the distinction matters.
These questions need different work, budgets and owners. Treat them as one, and you may budget for hosting, then discover the other requirements later.
They also fail independently. A system can keep all its data in the country and still give an agent too much authority. It can have strong controls and still be difficult to move.
The next time someone offers you a sovereign AI solution, ask which of these four questions they have answered, and which they are leaving to you.
Author Profile:
Praveen Ramachandran is co-founder and director of AOT Technologies, with over two decades of experience in system integration, application modernization, and reusable software. His work and thought leadership focus on helping enterprises and governments build scalable, adaptable and secure systems.