AI Sovereignty: Why Compliance Is Not Control
Last updated: July 2026
Most organisations have confused AI sovereignty with AI compliance. They are not the same thing, and the gap between them is where the risk lives.
Compliance is about whether you are allowed to operate. Control is about whether you can keep operating when somebody else changes their mind.
You can be fully compliant and completely exposed. Most organisations are.
What leaders actually mean by AI sovereignty
In our forthcoming AI Ireland Leaders Survey 2026, we asked 215 leaders how important sovereign AI requirements are in their roadmap. The full findings publish later this year. These two are worth sharing now.
68.6% said critical or important. Only 5.1% said not relevant.
That looks like a mature answer. Then we asked a second question, and it fell apart.
We asked which sovereignty controls matter most to them:
| Control | Share |
|---|---|
| Regulatory compliance | 30.5% |
| Data residency | 28.1% |
| Operational control | 12.4% |
| Local model hosting | 8.6% |
| Auditability | 8.6% |
| Vendor independence | 4.8% |
| Customer-managed keys | 1.9% |
Nearly six in ten define sovereignty as regulatory compliance or knowing which country their data sits in.
Fewer than one in twenty mention vendor independence. Fewer than one in fifty mention holding their own keys.
So leaders say sovereignty is critical. Then they choose the controls that keep a regulator happy rather than the controls that keep them running.
That gap is the whole problem.
These figures come from research that has not been published yet. If you want the full findings when they land, request a copy.
Compliance and control solve different problems
Both of the top two answers are sensible. Neither is sovereignty.
Compliance protects you from a regulator. It answers the question “are we allowed to do this?”
Data residency tells you which building your data sits in. Useful, and often legally required.
Neither one does anything about:
- A supplier changing its commercial terms at renewal
- A price rise you did not budget for
- A model you built on being retired
- A government restricting what can be sold to you
None of those are legal problems. They are continuity problems.
And continuity is not legal’s job. It is operations. Which means in most organisations, nobody owns it.
That is the structural reason this gets missed. Compliance has an owner and a budget line. Somebody’s performance review depends on it. Control has neither, so nobody is watching it.
The layer underneath is more concentrated than the rest of your supply chain
Almost all of the money going into AI is going into infrastructure. Data centres, processing semiconductors, network fabric, AI-optimised cloud.
That infrastructure is owned by a handful of companies. You can count them on two hands.

Total AI spending against end-user spending on models and platforms. Two separate Gartner forecasts, measured differently.
This is not a conspiracy. It is what happens when something costs hundreds of billions to build. Capital intensity concentrates ownership. It always has.
But think about what it means for your business. You almost certainly have multiple suppliers for logistics, for energy, for professional services, for hardware. You reviewed those relationships. You have alternatives named somewhere.
The layer underneath your AI strategy is more concentrated than any of them, and most organisations have never mapped it.
The three week example
Here is why this stops being theoretical.
In June 2026, Anthropic suspended access to its Fable and Mythos models to comply with United States Department of Commerce export controls. Not a security incident. Not an outage. A government introduced a restriction, and the provider complied.
The controls were lifted at the end of that month and access was restored on 1 July.
Roughly three weeks.
Now think about the organisations building on those models. Their data was hosted in the West. Their contracts were in order. Their data protection assessments were fine. Their compliance posture was, in every respect, correct.
None of it mattered. The capability was simply unavailable.
No data processing agreement covers that. No residency clause covers that. It was not a compliance failure, because there was no compliance failure.
Three weeks is an instructive length of time. Long enough to hurt if a customer-facing process depends on it. Short enough that most organisations would have improvised rather than planned, and then told themselves it was fine.
The big idea: compliance is not control
Compliance asks whether you are permitted.
Control asks whether you can continue.
An organisation with perfect compliance and a single AI supplier has answered the first question and ignored the second. That is the position most organisations are in right now, and their own leaders would tell you sovereignty is critical to them.
Saying it is critical is not the same as owning it.
Four things to do about AI sovereignty

None of these require you to rebuild anything.
- Name your single points of failure. Which AI capabilities does your business now depend on, and how many suppliers sit behind each one? Most organisations have never written this down. Writing it down is most of the work.
- Run a thirty day test on paper. If your main provider were unavailable for a month, what is the plan? You do not need to build the alternative. You need to know whether one exists.
- Agree your exit terms before you need them. Notice periods, data export formats, what happens when a model is deprecated. These are straightforward to negotiate when you are signing and impossible when you are leaving.
- Keep what you own in formats you control. Your prompts, your evaluation sets, your test cases, your data. Those move with you. The supplier relationship does not.
One thing I am not saying. I am not telling you to run multiple providers or host your own models. For most organisations that is expensive, slow, and solves a problem they have not yet measured.
I am telling you to know your exposure and price it deliberately, rather than discover it during a bad fortnight.
Where things stand right now
This section is updated periodically. Everything above holds regardless.
Regulation is arriving on a schedule you do not set. In the EU, the Digital Omnibus on AI was adopted in June 2026, deferring high-risk obligations for stand-alone systems to December 2027 and for AI embedded in regulated products to August 2028. But much of the transparency regime under Article 50 still applies from 2 August 2026, and the general purpose AI obligations have applied since August 2025. A lot of leaders heard “delayed” and stopped reading.
The open versus closed split is not East versus West. In July 2026, twenty five American companies published a letter urging Washington not to restrict open-weight models. Within a day the list had roughly doubled. Signatories included Nvidia, Microsoft, Meta, IBM, Dell, Palantir, Mistral, Hugging Face, Mozilla and the Linux Foundation. The divide is about business models, not borders. Companies that sell compute and infrastructure want open weights. Companies that sell closed frontier models are more cautious.
Open-weight models now reach the frontier within months. That changes the calculus on independence. It does not remove the concentration risk, because the infrastructure underneath is still owned by the same handful of firms.
Frequently asked questions
What is AI sovereignty? In practice, most organisations use it to mean regulatory compliance and data residency. A more useful definition is the degree to which you can continue operating if a supplier, or a government, changes the terms.
Is data residency enough for AI sovereignty? No. Data residency tells you where your data is stored. It says nothing about whether the capability processing that data will still be available to you next quarter.
Do we need to run our own models to be sovereign? For most organisations, no. Self-hosting is expensive and slow, and it solves a problem you should measure before you buy. Start by mapping your dependencies and agreeing exit terms.
Who should own AI sovereignty in an organisation? Not legal alone. Compliance sits with legal, but continuity sits with operations. If nobody owns the continuity question, it does not get asked.
How do I explain this risk to a board? Frame it as supplier concentration, which boards already understand. Ask how many suppliers sit behind the AI capabilities the business now depends on. The answer is usually one, and usually nobody has checked.
The bottom line
Stop asking where your data lives.
Start asking who can switch it off.
Bring this to your leadership team
This is one of the sessions I deliver to boards and executive teams who have moved past “should we use AI” and are now asking harder questions about dependency, resilience and control.
If you are planning a leadership offsite, a board strategy day or a conference where the audience holds budget, this is the talk that changes the conversation.
About the author
Mark Kelly is an AI keynote speaker and workshop facilitator. He has delivered over 300 keynotes, trained more than 10,000 leaders and reviewed over 1,000 AI projects across sectors. He is the founder of AI Ireland.
Survey methodology
AI Ireland Leaders Survey 2026, second half. These findings are being shared ahead of publication. The full report is due later in 2026. 215 responses, self-selected from the AI Ireland network and not a representative sample of the wider economy. Role mix: 25.1% C-suite or VP, 23.7% Director or Head, 23.7% Manager or Lead, 13.0% Architect or Engineer. Sovereignty figures are drawn from questions 11 and 12. Q11 n=214, Q12 n=210. Percentages rounded to one decimal place.
References
- Anthropic, statement on Fable and Mythos model access, July 2026. https://www.anthropic.com/news/fable-mythos-access
- Council of the European Union, “Artificial intelligence: Council gives final green light to simplify and streamline rules”, 29 June 2026. https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
- Freshfields, “The final Digital Omnibus on AI: key amendments to the AI Act”, 2026. https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber
- CNBC, “Nvidia, Microsoft, Meta warn against premature restrictions of open-weight models”, 24 July 2026. https://www.cnbc.com/2026/07/24/nvidia-microsoft-meta-open-weight-ai-models.html
- AI Ireland Leaders Survey 2026, second half. 215 responses. Unpublished at the time of writing. Full findings due later in 2026.





