Someone in your organisation already answered this. Probably wrongly.
Sovereignty questions about AI arrive in the shape of a form. A procurement questionnaire asks where the data is hosted, someone types a region name, the box goes green and the deal proceeds. The question has been answered, in the sense that a field is populated. It has not been decided, in the sense that nobody weighed what the organisation gave up.
Writing in MIT Sloan Management Review on 16 July 2026, Mauro Macchi, Ajoy Menon, Mauro Capo and Surya Mukherjee report an Accenture survey of 1,928 executives across 28 countries, conducted in December 2025. Sixty per cent of respondents said rising geopolitical risk makes them more likely to pursue sovereign technology solutions. Only 15 per cent have made AI sovereignty a CEO or board-level priority. Fewer than 13 per cent see it as a growth driver rather than a cost.
Read those three numbers together and the gap is the story. A clear majority of executives believe the world has changed in a way that pushes them towards sovereign choices. A small minority have put the question anywhere near the people who can actually make a choice about it.
The shift: three questions wearing one label
The reason sovereignty gets delegated is that it sounds like a technical property with a true or false answer. It is not. The MIT SMR authors describe it as governing where data is stored and processed, whose infrastructure is used for training and operating AI models, and how algorithmic decisions are reviewed.
Those are three different decisions with three different owners and three different costs. An organisation can run in an Australian region on infrastructure owned offshore. It can use a locally hosted model trained somewhere it has never inspected. It can have flawless residency and no ability to explain a decision the system made about a customer. Each combination is coherent. None of them is captured by a single box on a form.
This is why the authors argue that sovereignty "is better understood as a continuum of choices" rather than an either or proposition, and that the organisations best positioned to scale AI globally treat those choices as a competitive advantage rather than a constraint.
The Australian Government reached the same conclusion years ago for its own hosting, which is a useful thing for an Australian leader to be able to cite. The Hosting Certification Framework exists to help government customers source hosting that meets enhanced privacy, sovereignty and security requirements, and it frames the benefit as ensuring arrangements comply with data sovereignty, ownership structure, liability, supply chain and transparency arrangements. Its three levels are instructive. Certified Strategic represents the highest level of assurance and is available only to service providers that allow the government to specify ownership and control conditions. Certified Assured provides safeguards against change of ownership or control through financial penalties. Uncertified offers minimal protections, and the framework says plainly that a customer may still use it where their own risk assessment determines it appropriate.
That is a ladder, not a gate. The Commonwealth does not require its highest tier for everything. It requires a deliberate choice of tier, made against the sensitivity of the data and the customer's own risk profile. Any organisation can copy that structure tomorrow.
The operating move: a sovereignty position per data class
The failure mode is not choosing wrongly. It is choosing once, organisation-wide, and then discovering that the single position is too restrictive for the low-risk work and too permissive for the sensitive work. Here is a pattern that survives contact with a real portfolio.
1. Define three or four data classes, not thirty. Public and internal material with no personal information. Customer or employee personal information. Sensitive information and anything regulated. Material that would damage the organisation if a third party retained it. Most AI use in most organisations falls into one of those, and the classes are stable even as the tools change.
2. Set a sovereignty position for each class across the three dimensions. For each class, state where processing may occur, whose infrastructure is acceptable, and what review of algorithmic decisions is required. Write it as a sentence a manager can apply, not a matrix nobody opens.
3. Attach a named cost to each step up. This is the step leaders skip and the one that makes the decision real. Moving a class to a more sovereign posture usually costs capability, money, speed, or provider choice, and often several at once. If nobody can say what the step costs, nobody has actually made a trade.
4. Decide the calibration yourself, per use case, and record why. The MIT SMR authors' second recommended move is calibrating sovereignty to industry and use case. Calibration is a leadership act because it is where risk appetite is expressed. A recorded sentence explaining why the customer-facing assistant sits at a stricter position than the internal drafting tool is worth more than any policy document.
5. Build the provider mix deliberately. The third recommended move is building hybrid ecosystems of global and local AI providers. A single-provider strategy is simpler and concentrates the exposure the survey respondents are worried about. A deliberate mix costs integration effort and buys optionality. That is a portfolio decision, and it belongs next to your other portfolio decisions rather than inside a procurement process.
6. Review it on a date, not on an incident. Geopolitical settings, provider ownership and product availability all move. Put a date on the position and treat drift as expected rather than exceptional.

What stays with the leader?
Three things stay with the leader and cannot move.
The risk appetite. No framework, adviser or model can tell you how much capability your organisation is willing to give up to hold a stricter position. That is a statement about what the organisation is for, and it is made by the person accountable for the result.
The trade, said out loud. The most common way this decision goes wrong is that the cost is never named, so the organisation quietly takes the cheapest option and calls it a risk decision. If the answer is that a use case will run on a global provider because the sovereign alternative is materially worse and the data class permits it, that is a defensible position. It is only defensible if someone said it.
The accountability when it is tested. A sovereignty position gets examined at the worst possible moment, usually during an incident or a regulatory question. The person who signed it answers for it. This is the same principle as decision rights in an AI-enabled team: the tooling will happily assume an answer you never gave.
What is not in scope here is the compliance mapping underneath the position. Where regulated data or prudential obligations are involved, the detailed work of vendor due diligence remains a compliance function's job, and we have covered what CPS 234 due diligence on AI vendors requires. The leadership decision is which position applies. The compliance work is proving it holds.
Worked example. [ORGANISATION] groups its AI use into three classes. Internal drafting and research on public material sits at the lowest position: any reputable provider, no residency requirement, no formal decision review. Customer personal information sits one step up: processing in an Australian region, a provider with contractual commitments on retention and sub-processing, and a documented human review point before anything reaches a customer. Regulated case material sits at the top: a named provider list, no consumer-tier tools, and a recorded review of any automated output that affects an individual. [EXECUTIVENAME] signs the three positions, and the cost of the top position, a narrower provider pool and slower delivery for [TEAM], is written into the same page rather than discovered later.
The failure nobody counts
Almost every discussion of sovereignty assumes the risk runs one way, towards being too permissive. In practice the more common failure inside large Australian organisations is the opposite, and it is invisible because it produces no incident.
An organisation sets one strict position because it is the safest thing to write down. Every AI use case is then measured against the standard required by its most sensitive data, whether or not the use case touches that data. The internal drafting tool, the meeting summariser and the research assistant all get assessed as though they were handling regulated customer records. Approval takes months, the approved option is the least capable one on the market, and staff quietly use something else on their phones.
That outcome is worse on both counts. The organisation has paid the full cost of a strict posture and acquired an unmanaged shadow estate as well. Nothing in a risk report will show it, because unrealised capability is not an event and shadow usage is not reported. The only person positioned to notice is the leader who set the position, which is another reason the position cannot be delegated and then forgotten.
The honest caveats
Two, and both matter for how confidently you should carry this into a board paper.
The survey is global. The 1,928 executives span 28 countries, and Australia is not broken out in what has been published. The direction of travel is credible and it lines up with Australian policy settings, but a specific percentage is international evidence rather than a local measurement, and it should be presented that way.
The second caveat is about vocabulary. Sovereign AI has become a term used for at least three distinct things: national capability building, provider-level residency and control commitments, and an individual organisation's posture on its own data. This piece is about the third. The first is a matter of national policy, and Australia's position on it, including the decision not to legislate a standalone AI Act, is set out in Australia will not pass an AI Act. The related but separate question of where a specific model physically runs is covered in the strongest open model is now Chinese, and the day-to-day mechanics of matching a data class to a model tier in model routing moves your data.
Bottom line
Sovereignty is not a compliance property your vendors either have or lack. It is a set of positions your organisation chooses, each with a price, and the choosing is leadership work. Fifteen per cent of executives have picked it up. The rest have a position anyway, arrived at by whoever last filled in a form.
Do this Monday
- Write down your three or four data classes on one page, before touching any tool list
- For each class, state the position on processing location, infrastructure ownership and decision review
- Name the cost of moving each class one step stricter, in capability, money or provider choice
- Take the two most sensitive AI use cases and record your calibration and the reason in one sentence each
- Put a review date on the page and an owner's name at the top
TheAICommand. Intelligence, At Your Command.



