
Carolyn Geason-Beissel/MIT SMR | Getty Images
As multinational companies implement artificial intelligence workflows and look to adopt AI across their global operations, they are increasingly running up against country-specific regulations and policies that aim to govern AI and align its use with national priorities and local cultural norms. These regulations and policies — which fall under the umbrella of “sovereign AI” — govern where data is stored and processed, whose infrastructure is used for training and operating AI models, and how algorithmic decisions are reviewed and enforced in a given jurisdiction. Many markets are now developing their own sovereign AI frameworks to reduce dependence on the United States and China, where nearly 70% of leading AI models originated.
This creates a strategic dilemma for multinationals. Relying on global AI platforms maintains operational consistency but deepens exposure to geopolitical disruption and local market access risk. Localizing data, infrastructure, and models earns regulatory trust but incurs significant cost and complexity when a company operates across dozens of jurisdictions with differing requirements. The challenge is that policies vary significantly by country and are evolving rapidly, making a single global AI strategy untenable, and fully independent local systems impractical.
Most companies are responding defensively, treating sovereign AI as a compliance obligation managed by legal or IT teams. Our December 2025 survey of 1,928 executives across 28 countries reveals a striking gap: Sixty percent of respondents said that rising geopolitical risk makes them more likely to pursue sovereign technology solutions, yet only 15% have made AI sovereignty a CEO or board-level priority, and fewer than 13% see it as a growth driver rather than a cost.
In this article, we argue that sovereignty is better understood as a continuum of choices and that the companies best positioned to scale AI globally are those that treat those choices as a source of competitive advantage rather than a constraint to be minimized.
The Sovereign AI Landscape
The regulatory landscape governing AI has shifted significantly in recent years, from relatively narrow data residency rules to a far broader set of requirements governing models, infrastructure, and how algorithmic decisions are made and enforced. Most major markets are now developing their own sovereign AI frameworks, resulting in a patchwork of locally governed ecosystems, each with distinct rules, data standards, and expectations for responsible use.
The complexity is already visible at every layer of the technology stack. Companies operating in European Union member states must conduct formal risk assessments, maintain detailed technical documentation, and submit it to national market surveillance authorities under the EU AI Act. (The AI Act is now in active enforcement, with its most comprehensive requirements for high-risk AI systems taking effect in August 2026.) Simultaneously, they must comply with prior standards and policies, like GDPR (General Data Protection Regulation), NIS2 (Network and Information Security 2), and DORA (Digital Operational Resilience Act). Companies must also prepare to align with the sovereignty package announced by the European Commission in June 2026, which includes two legislative proposals and a strategic road map to bolster the EU’s AI sovereignty.
Meanwhile, companies looking to do business in Saudi Arabia must navigate strict data localization requirements — including obligations to store nationally sensitive data within the country — alongside cross-border transfer rules that require adequacy assessments or contractual safeguards, all within a governance framework that is still taking shape. There is no dedicated AI law, and binding obligations currently flow from data protection and cybersecurity regulations rather than AI-specific legislation. The same governments driving these requirements are also pouring billions of dollars into building the infrastructure and incentives to enable sovereign AI solutions.
Companies have started to develop strategies to navigate this fragmented landscape. We know from our consulting work that three global banks are rethinking their tech strategy in the EU: They’re limiting further migration of sensitive systems into foreign public cloud systems and instead building a shared platform in their home countries.
In the U.K., senior leaders of multinational banks are exploring a domestic alternative to Visa and Mastercard to reduce reliance on U.S.-owned payment networks. These are early signals of a structural shift in how multinationals must think about AI infrastructure. This raises an urgent question for CEOs: How do you scale AI globally when the rules governing it are local, fragmented, and still being written?
To answer this question, CEOs need to make three strategic choices: where accountability for decisions should sit, how much sovereignty their operations require, and which external partners can help them execute.
1. Make sovereignty a strategic priority.
The first and most urgent CEO decision is raising AI sovereignty to the level of a strategic concern. Our survey found that most organizations delegate decisions regarding AI sovereignty to chief data/AI officers (37%) or compliance/risk officers (28%), while only 15% of organizations have made it a CEO- or board-level priority. When sovereignty sits in IT or compliance, it results in fragmented decisions across business units, inconsistent approaches across markets, and missed opportunities to turn sovereignty into local advantage. Sovereign AI is not an IT architecture choice. It is a strategic bet involving geopolitics, capital allocation, supply chain resilience, and long-term competitiveness, and the decisions it requires can be made only at the top.
What does that look like in practice? Consider BNP Paribas, one of the largest banks in the EU. Since 2023, it has built a deepening partnership with Mistral AI, Europe’s leading sovereign AI model provider, culminating in a groupwide multiyear agreement in 2024 and a renewed three-year extension in 2025 covering software, co-development research, and on-premises deployment. The bank also backed Mistral financially, participating in both its 385 million euro ($445 million) funding round in 2023 and its $640 million Series B in 2024. The partnership is driven by the C-suite with sovereignty as a key consideration. Keeping AI on-premise, under the bank’s direct control, ensures sensitive data stays within European regulatory jurisdiction. Such decisions — say