Dipesh holds the position of Senior Vice president at Cyble Inc., a cybersecurity company focused on observing and managing cyber threats.gettyOver the past year, I have noticed a new term appearing in almost every enterprise technology discussion I participate in: AI sovereignty.It comes up in board meetings, procurement reviews, regulatory discussions and customer workshops. The interesting part is not that people are talking about it. The interesting part is that everyone seems to mean something different by the term.A few months ago, I was speaking with the technology leadership team of a large European financial services organization. Their board had directed that all future AI initiatives must comply with "sovereign AI" requirements. On the surface, that sounded straightforward. It wasn't.Legal interpreted sovereignty as the retention of data within specific geographic boundaries. Procurement viewed it as a way to reduce dependence on foreign technology providers. The CIO was focused on operational control and long-term flexibility. By the end of the discussion, three groups were using the same word to describe three completely different objectives.At one point, the CIO looked across the table and asked a simple question: "Does this mean we need to build our own LLM, or can we still use Azure?"It was a fair question. More importantly, it exposed the problem. The global conversation around AI sovereignty is accelerating much faster than the industry's ability to define it consistently.Why Sovereignty Became Such A Big DealPull on the thread, and the worry makes sense. For twenty-odd years, we've handed more of the stack to a handful of global providers. Cloud, security, the everyday software everyone lives in. AI just turned up the volume. Once these systems start shaping decisions that actually matter, the obvious question is who's really in charge. You, your regulator or the vendor whose logo sits on the contract?Governments are scrambling to answer that, which is partly why the word got so slippery. To one camp, sovereignty means doing it all yourself: your own chips, models and data centers. That ambition trips up even wealthy countries. To another camp, it's far more modest. Know what's under the hood, be able to audit it, keep the freedom to walk if things change. Same word, two different destinations, usually blurred in the same meeting.The Money Behind The MessageSo nearly every vendor now has a sovereignty pitch. Sovereign clouds, sovereign partnerships, the lot. But localization isn't sovereignty. Parking data in-country or signing a local supplier doesn't make you independent. Often you've just swapped one dependency for another, sometimes a stickier one. Sovereignty became a sales category before anyone agreed what it meant.The Challenge Facing Enterprise LeadersFrom a leadership perspective, the sovereignty debate creates three practical challenges.The first is regulatory uncertainty.The regulatory environment surrounding AI is evolving rapidly. Definitions that appear clear today may change tomorrow. New frameworks continue to emerge across different jurisdictions, and organizations operating globally must often comply with multiple interpretations simultaneously. I have already seen customers receive different guidance from legal teams, regulators and industry bodies regarding what constitutes sovereign AI.That creates uncertainty when making multi-year technology investments.The second challenge is dependency risk.One of the most common questions I ask enterprise customers is simple: "If your primary AI provider changed pricing significantly, restricted access to capabilities or altered commercial terms, what would you do?" The answer is often revealing.Many organizations discover that they have greater dependency than they originally realized.The third challenge is strategic prioritization.Not every component of an AI ecosystem needs to be sovereign. In fact, pursuing sovereignty at every layer can quickly become economically unrealistic. The real challenge is determining which capabilities are genuinely strategic and which are simply operational necessities. Those decisions differ from one organization to another.A government agency, a defense organization, a financial institution and a retail company will all reach different conclusions.A More Practical ApproachStop chasing sovereignty as an absolute. Treat it as risk management. The point isn't total independence, it's knowing where you stand and staying in control. I tell customers to sit with four questions. Where are you actually dependent? Map the stack honestly, and you'll usually find a surprise or two. Where does your edge really come from? Rarely from owning infrastructure, usually from your data and know-how. How easily can you move workloads, models and data if you need to? And where do open models buy you leverage? Often the freedom to move beats the pride of owning.The Conversation Boards Should Be HavingOne concern I have with the current sovereignty debate is that it sometimes focuses on the wrong question.Boards frequently ask: "How do we become sovereign?"A better question might be: "What level of dependency are we comfortable accepting?"No organization operates in complete isolation. Every enterprise depends on suppliers, partners, service providers and technology ecosystems. AI will be no different. The objective should not be eliminating dependency altogether. The objective should be to understand dependencies and ensure they remain manageable.That requires transparency, governance and strategic planning. It also requires honest conversations with technology providers. When vendors present sovereignty solutions, enterprise leaders should look beyond the marketing language.Ask who controls the infrastructure.Ask who controls the models.Ask what happens if regulations change.Ask what happens if commercial priorities change.Most importantly, ask what your exit strategy looks like.The quality of those answers often tells you far more than the word "sovereign" ever will.The Bottom LineAfter years helping companies through cloud, security and now AI, I've learned that strategies rarely fail on the technology. They fail because people underestimate how dependent they've become. Sovereignty will shape enterprise strategy for years, but resilience matters more than independence. The winners won't be the ones who own every model and every GPU. They'll be the ones who know where they're dependent, where they have choices and where they hold leverage. That's a far more useful definition of sovereignty, and for most leaders, probably the only one worth chasing.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
The Real AI Sovereignty Debate: What Enterprise Leaders Need To Know
I've learned that strategies rarely fail on the technology. They fail because people underestimate how dependent they've become






