Why Sovereign AI Is Becoming a Business Resilience Issue
Key Takeaways
- •Forrester's report finds that AI sovereignty now concerns virtually every industry and is fundamentally about control and business resilience rather than isolation or regulation, as no legislation worldwide mandates it.
- •Dependence on foreign AI vendors creates a 'kill switch' risk: a foreign administration could cut off access to models or tools, causing direct economic losses such as production downtime in manufacturing.
- •Organizations are advised to evaluate their dependencies first and apply sovereign solutions mainly to mission-critical workloads, using approaches like air-gapped environments or local vendors alongside global providers rather than full dual stacks.
- •Common mistakes include failing to define the sovereignty problem before seeking solutions and conflating it with data protection issues such as the US CLOUD Act or FISA Section 702.
- •While most sovereignty indicators are expected to rise toward 2030, tech workforce sovereignty is projected to decline, complicating compliance as more regulations impose residency or citizenship requirements on IT workers.

As AI becomes an increasingly integral part of business processes, concerns around operational control, resilience, vendor concentration, and geopolitical risk are having a greater impact on how the technology is deployed, according to Forrester's latest report, The Top Trends in Sovereign AI.
Expanding on findings from the tech research firm's recent Global Sovereignty Forecast, the report argues that sovereignty is shifting beyond questions of data residency and regulation toward business resilience, operational control, and governance. The shift comes as a small number of US-based hyperscalers and model providers dominate global AI infrastructure, and as governments have shown a growing willingness to use technology access as a lever of statecraft — including recent US export controls on advanced AI chips and model weights. For organizations, that does not necessarily mean cutting themselves off from global technology providers. Rather, it means understanding where their dependencies lie, which workloads are most critical, and how they could continue operating if access to a key AI service were disrupted. It also aligns with a broader European policy push: the EU has made technological sovereignty an explicit priority, and initiatives such as Gaia-X and the EU AI Act's requirements for high-risk systems have sharpened attention on where AI is hosted, who controls it, and under which jurisdiction it operates.
In this Q&A, Dario Maisto, analyst at Forrester and author of the report, discusses how organizations can navigate these dependencies and what sovereign AI means in practice.
What are the key findings from Forrester's research, and were there any surprises?
Dario Maisto: We interviewed a range of organizations, including service providers and, primarily, end users, to understand how sovereign AI has evolved over the past year. One of the first findings was that sovereignty is relevant to organizations across virtually every industry, not just the usual suspects such as defense, government, and the public sector.
The second is that sovereignty is much more than data localization or data residency. At its core, it is about being in control. It is not about isolation.
The third finding is that sovereignty is increasingly a way to improve resilience. The more organizations rely on AI across their business, organizational, and mission-critical processes, the more they need to minimize, or at least control, their dependencies on foreign vendors, jurisdictions, and governments.
And finally, this is not fundamentally about regulation. There is no legislation whatsoever in the world that mandates sovereignty. This is really about tech and business leaders wanting to increase the resilience of their business.
What kind of danger does AI dependency pose?
Maisto: As AI becomes critical to business processes, having a dependency on a foreign vendor — and therefore potentially on a foreign jurisdiction — creates the possibility of a "kill switch." A foreign administration under whose jurisdiction a vendor falls could decide that you can no longer access its models, AI tools, or solutions. If your business processes depend on those tools, those processes could go down.
That has a very real business impact. In manufacturing, for example, organizations lose money every second they are unable to produce. The impact is potentially even more significant for industries dealing with fresh or perishable products. So, if a foreign government decision interrupts a service that an organization relies on for its AI, that is not an abstract geopolitical issue. It has a direct economic impact on the business.
How can organizations viably arm themselves against these risks?
Maisto: Up until a few years ago, we would often tell organizations in certain countries to run dual stacks: one with a vendor in one country and another with a different vendor elsewhere. Now we are seeing organizations take a more nuanced approach, separating mission-critical workloads from non-mission-critical workloads.
Depending on the industry, non-critical workloads may not require additional sovereign resources. Mission-critical workloads, however, have a much greater need for sovereign solutions.
That does not necessarily mean running two completely separate stacks. Organizations can mitigate geopolitical risks in different ways, such as connecting an air-gapped environment to their public cloud environment, or using a local vendor alongside a global one.
For multinational organizations operating across 50 countries, for example, it is simply not feasible to have 50 different vendors. It would be an architectural nightmare, aside from the cost. Instead, organizations might use different solutions from the same global vendor depending on the criticality of the workload or sensitivity of the data. A hyperscaler might provide a public cloud environment, a private cloud solution, or an air-gapped environment depending on the requirements.
How does the increasing use of AI require organizations to rethink governance?
Maisto: AI deployments across organizations create new areas of governance, risk, and compliance. At the same time, AI tools can also help organizations identify vulnerabilities in seconds rather than months, so governance is needed across the entire stack.
AI is becoming a technology that is truly embedded in the business and, to some extent, vital to it. That requires oversight that goes far beyond the IT department.
We are already seeing organizations change their structures to address this. One client, for example, had a relatively small IT department and was receiving requests from every business unit. Rather than having everything go through IT, the organization attached an IT resource to each business unit. That shortens the distance between IT and the business and ensures that people with the right technical skills are directly supporting the business.
This is increasingly important because AI can dramatically accelerate processes. Something that previously took three months might now be completed in a couple of weeks. Think about medical trials, for example. Every second you lose can now be worth many times more than it was in the past, which is completely changing the way organizational models should be built around AI tools.
Has geopolitical instability made sovereignty a more pressing issue?
Maisto: Yes, although there is an interesting tension here. As technology becomes more specialized, organizations need specialized people who may not be available locally. Our Tech Sovereignty Forecast shows that while sovereignty indicators are generally expected to increase towards 2030, tech workforce sovereignty is actually expected to decrease. That is the only indicator going in the opposite direction.
At the same time, some regulations already mandate residency or citizenship requirements for IT workers in specific industries, technology sectors, or workloads. As geopolitical instability increases, we are likely to see more of these requirements. That makes the problem even harder — what was initially a business continuity and risk management issue is becoming, in some industries, a regulatory requirement while the shortage of specialized technology workers remains.
Training is one way to address this. Another is through acquisitions, joint ventures, and partnerships. We are already seeing service providers acquire local consultancies and companies, giving them a legal framework and a local workforce that can help meet clients' sovereignty requirements.
What mistakes are organizations making when trying to establish AI sovereignty?
Maisto: The first mistake is failing to define the perimeter of the problem. People say "sovereignty" without necessarily defining what they mean, and they talk about regulation without identifying which regulations actually apply to them. They then start looking for solutions before they have clearly defined the problem. When I review the cloud, AI, or sovereign AI strategies of clients, one of my first questions is: What problem are you actually trying to solve?
Another common mistake is assuming that sovereignty is all about data. People often begin the conversation about sovereignty by discussing regulations such as the US CLOUD Act or FISA Section 702. But those are fundamentally data protection issues, rather than sovereignty problems.
For example, if your data is hosted on the infrastructure of a US hyperscaler but is encrypted, and you retain the encryption keys outside the hyperscaler's environment, you have a different risk profile. You may be able to address the issue without migrating your data to a new provider, which would bring additional migration and egress costs.
The key is to frame the problem correctly and understand the regulatory environment you actually need to address. Some vendors can use the sovereignty narrative as a way of selling their services, so organizations need to be careful about that.
What should be the first practical step for an organization looking to improve its AI sovereignty?
Maisto: The first step is to evaluate your dependencies. This is not about isolation, and it is not about achieving complete independence. It is about understanding and managing your dependencies. Organizations need to establish what they depend on, where those dependencies are located, and what the consequences would be if they were disrupted. Only then can they determine what needs to be sovereign and what does not.
I would caution against thinking of AI sovereignty simply as a bilateral problem involving one particular country or vendor. Depending on where you operate and what your business does, you may have a completely different problem.
That is why sovereignty is a much more complex issue than simply saying, "Keep your data in your country." The right approach depends on the specific risks, dependencies, and business requirements of each organization.
Editor's note: This interview has been edited for clarity and conciseness.