Enterprise AI strategy is traditionally defined by the models you use, the capabilities you can access, and how quickly you can deploy. Today, new pressures are forcing a shift: Organizations can’t focus only on how they use AI; they must also decide where that intelligence lives.
Governments are deciding where AI can run, who controls the infrastructure, and which vendors qualify for regulated markets. Sovereign AI—”a country's ability to develop, host, and control its own AI using its own data and infrastructure”—is no longer a legal or procurement footnote. It’s a C-level priority shaping market access, operating costs, and competitive position.
What: IDC predicts that “by 2028, 60% of multinational firms will split AI stacks across sovereign zones, tripling integration costs as regulatory fragmentation and supply chain risks slow strategic scaling.”1 This will force organizations to run parallel environments with expensive middleware and governance layers.
More than 140 countries now have data protection laws, according to Forcepoint. Many require sensitive data to stay within national borders.
So what: The fragmentation IDC is projecting is in part being driven by new regulations and the growing recognition that a single-geography dependency on advanced compute is a strategic vulnerability no board can afford to ignore.
For example, more than 90% of the world's most advanced chips are manufactured in Taiwan, according to the International Trade Administration. That concentration creates systemic risk at the infrastructure layer of global AI.
CEOs who’ve assumed a unified global AI architecture should now model what a regionalized stack would cost. That decision may soon be made for them by regulators, supply chains, or events.
A recent NTT DATA report revealed that 35% of chief AI officers globally identified “enabling private and sovereign AI as their top barrier to [AI] adoption, often requiring significant changes to their existing infrastructure.”
What: The European Commission formally proposed the Cloud and AI Development Act (CADA) on June 3, 2026. It’s meant to reduce the EU’s reliance on non-European cloud providers.
The law introduces a four-tier sovereignty assurance framework for public sector cloud and AI services. The highest-level category requires full EU ownership and control, complete transparency over software supply chains, and freedom from third-country interference.
So what: CADA is the next step in the EU’s increasing efforts to promote responsible AI, including digital sovereignty (EU AI Act, NIS2 Directive, and DORA).
Organizations can act now to secure European market access. However, as more of these regulations take effect, the window for proactive strategy closes, and latecomers will be left scrambling.
- In-country data centers
- Graphics processing unit (GPU) compute delivered through SoftBank and Sakura Internet to keep data within Japanese borders
- Cybersecurity cooperation with national institutions
- A commitment to train 1 million engineers by 2030
BT and Nscale announced a partnership to deliver up to 14 megawatts of NVIDIA-powered sovereign AI data center capacity across three BT sites in the UK. Customers such as Airbus are pushing for a European sovereign cloud to support operations.
So what: When the world's largest cloud providers are competing on who can localize AI infrastructure most credibly, the market has moved. Sovereignty is now a sales argument at the hyperscaler level.
For enterprise CEOs, this signals both opportunity and urgency: The infrastructure layer of sovereign AI is being contested in real time, and the vendors, partners, and procurement criteria are shifting.
Leaders should audit hyperscaler dependencies and start building the local partner relationships that sovereign markets may require before a regulatory deadline forces their hand.
What: The ServiceNow Enterprise AI Maturity Index 2026 found that:
- Only 16% of organizations have replaced fragmented legacy systems with an integrated platform.
- Just 20% have implemented AI testing, auditing, and risk assessment processes.
- The average AI governance maturity score is 53 out of 100.
- Only 13% of non-Pacesetter organizations (those without the most advanced AI models) regularly communicate with regulators to stay informed on evolving AI standards, compared to 64% of Pacesetters.
So what: The governance discipline that external sovereign AI mandates require is exactly what most organizations haven’t built on the inside. Governments in Europe, Japan, and other regions are writing procurement requirements that presuppose clean data, traceable workflows, and auditable AI decisions.
As sovereignty rules harden, AI maturity could be the difference between organizations that will qualify for regulated markets and government contracts and those that won’t.
Fujitsu began manufacturing “Made in Japan” sovereign AI servers in March 2026 under the Economic Security Promotion Act. Japan is also the architect of data free flow with trust, the G7's bridging doctrine between open data flows and localization.
Government AI GENAI is now rolling out across 100,000 public officials, setting de facto audit and compliance standards the private sector will follow.
So what: Japan is running a deliberate and instructive strategy: deregulate to accelerate adoption, lock down the infrastructure layer, and use government AI deployment to set the compliance bar for regulated industries.
It’s a preview of a pattern emerging globally. Nations aren’t choosing between open AI and sovereign AI. They’re building both simultaneously, at different layers.
The organizations that understand this distinction will design flexible architectures, prioritizing sovereignty where it’s needed most and allowing free flow where it will have the strongest advantage. Those that treat sovereignty as an all-or-nothing endeavor across their entire AI strategy will pay for the misread.
Taken together, these signals point to a fundamental shift in how AI competitive advantage will be defined. The models you use and the speed of deployment are still necessary, but they’re no longer sufficient.
Whether your AI architecture can operate across sovereign jurisdictions—without tripling integration costs or locking you out of regulated markets—is now equally important.
Organizations are already more likely to adopt sovereign cloud services, specifically as a result of recent geopolitical events, according to CIO Dive. That preference is hardening into procurement rules and regulatory requirements across the world's largest economic blocs at the same time.
The organizations setting the pace share a pattern that maps directly to what sovereign AI demands: governance built before deployment, unified data, and the discipline to engage regulators as a strategic activity rather than a reactive one. That discipline is no longer just good AI hygiene. It’s the price of market access and competitive advantage.
If your most important markets tightened their AI sovereignty requirements tomorrow, would your architecture be an asset or a liability?
Find out how ServiceNow can help you control and govern your AI.
1 IDC blog, The high cost of sovereignty in the age of AI, February 2026