AI Leadership & Perspective

AI Sovereignty for UK Enterprises: Control the Stack or Accept the Risk

By Collin Hogue-Spears, Senior Director of Solution Management at Black Duck

As AI moves from experimentation into core public services and regulated industries across the UK, spanning financial services, healthcare, utilities, and government, the definition of “sovereignty” is shifting. It’s no longer about whether an organisation or nation can build its own large language model. The more immediate, operational question is simpler and more urgent: who controls the AI stack? 

In July 2025 the UK’s Competition and Markets Authority concluded what most CIOs already knew: competition in UK cloud is not working. AWS and Microsoft each hold 30 to 40 percent of UK cloud spend, switching is costly, and even central government runs on the same two providers.  

Then in March 2026 the CMA stepped back, dropping plans to designate the pair on cloud infrastructure in favour of voluntary commitments on egress fees and interoperability. Brussels moved the opposite way that same month, proposing a Cloud and AI Development Act to legislate sovereignty into public procurement. For a UK enterprise the lesson in both is identical: no regulator is going to hand you control of your AI stack. You engineer it, or you inherit the dependency. 

For CIOs and security leaders, sovereignty is not a theoretical debate about national capability. It’s a governance problem that surfaces during audits, regulatory reviews, and incident response: Can you prove where your data flows, how decisions are made, and whether you retain control if a provider changes terms or fails? 

Most organisations are not failing on access to AI. They are failing on control. 

From Capability to Control 

Much of the current AI conversation focuses on capability: what models can do, how they compare, and how quickly they are improving. But for UK CIOs and CISOs, the bigger risk lies in silently losing authority over how those capabilities operate within the enterprise. 

In regulated environments, this distinction matters. A bank that cannot explain an AI-assisted credit decision, or an NHS trust that cannot reconstruct how a model influenced a diagnostic pathway, is not facing a performance issue; rather, it’s facing a governance failure. 

Sovereignty, in practice, comes down to enforceable control across five layers: 

  • Data control: Where sensitive data resides and whether it is used to train third-party models 
  • Model control: Which models are permitted for which use cases and data classifications 
  • Infrastructure control: Where critical workloads run, and under which regulatory conditions 
  • Operational control: Whether AI-driven actions are logged, monitored, and reversible 
  • Vendor control: Whether organisations maintain portability, audit rights, and a viable exit strategy 

These layers form the real control plane of AI adoption. Without them, organisations may appear compliant while remaining operationally exposed. 

The Real Risk: Dependency, Not Nationality 

In UK and European discussions, “sovereign AI” is often framed around reducing reliance on US technology providers. While jurisdictional exposure is real, focusing solely on vendor nationality misses the more immediate risk: concentrated dependency without control.  

Recent history offers a clear lesson. A single faulty software update in a widely deployed security platform disrupted millions of systems globally, affecting airlines, healthcare providers, financial institutions, and government services. The issue was not geopolitical. It was architectural: a homogeneous dependency that failed everywhere at once. 

For CIOs, this reframes sovereignty as a resilience issue: Can you switch providers without operational disruption? Are you dependent on a single model, platform, or ecosystem? Do you retain access to logs, data, and decision records if a service is withdrawn?  

Vendor concentration, combined with limited portability, is the real exposure. 

Jurisdiction Still Matters 

That said, jurisdiction cannot be ignored, particularly in the UK’s position between US and EU regulatory frameworks. 

Data residency alone does not guarantee control. Legal obligations tied to a parent company’s jurisdiction may override where data is physically stored. This creates a complex risk model for highly sensitive workloads in financial services, defence, and critical infrastructure. 

For security leaders, the issue is not whether a specific provider is “trusted,” but whether the organisation retains auditability over data access and model behaviour, legal clarity on data control and disclosure requirements, and the ability to segment or isolate high-risk workloads. 

Sovereignty, in this context, is not about eliminating foreign providers, it’s about ensuring no single dependency can compromise operational control. 

Avoiding the “Build-It-Yourself” Trap 

The wrong response to these risks is blanket self-sufficiency. 

Few organisations (and few countries) can realistically build and maintain frontier AI models, infrastructure, and talent pipelines at scale. Attempting to mandate local-only solutions too early often leads to weaker capabilities, higher costs, and, critically, unintended consequences. 

One of those consequences is shadow AI. When sanctioned tools are slower, less capable, or overly restrictive, employees route around them, turning to external AI services without governance controls. This mirrors the rise of shadow IT in cloud adoption, but with greater risk due to the sensitivity of data and the opacity of model behaviour. 

For CIOs, the lesson is clear: sovereignty cannot come at the expense of usability. Controls that drive work outside governed environments reduce security rather than strengthening it. 

A More Effective Model: Risk-Tiered Sovereignty 

Leading organisations are converging on a more pragmatic approach: tier AI governance based on workload sensitivity. 

  • Low-risk applications (e.g., drafting, translation, summarisation) can utilise commercial AI services with appropriate safeguards 
  • Moderate-risk applications (e.g., internal analytics, operational decision support) require tighter controls around data handling and model selection 
  • High-risk applications (e.g., financial decisions, healthcare outcomes, public safety systems) demand strict oversight, auditability, and often controlled or segmented environments 

This model aligns sovereignty with risk, not ideology. It also allows organisations to benefit from global innovation while retaining control where it matters most. 

Auditability Is the New Trust 

As regulators in the UK and EU sharpen their focus on AI governance—through frameworks such as the UK’s AI regulation approach and the EU AI Act—the ability to explain AI-driven outcomes is becoming a baseline requirement. 

Public trust, corporate accountability, and regulatory compliance now hinge on a simple capability: Can you reconstruct and defend an AI-assisted decision? 

This requires comprehensive logging across the AI lifecycle, clear traceability between inputs, models, and outputs, and defined processes for human oversight and intervention. Without these, organisations may technically comply with policies but fail under scrutiny. 

Auditability in AI is not only about logging prompts and outputs. It reaches the composition of the system itself: which open-source components, libraries, and pretrained models sit inside the pipeline, where they came from, and whether any carry known vulnerabilities or license constraints. A software bill of materials, already standard practice for application code, applies with equal force to AI systems. If you cannot enumerate the model and data lineage behind a decision, you cannot fully reconstruct it, whatever your logs show.  

What CIOs and Security Leaders Should Ask Now 

Sovereign AI is not a future-state ambition. It’s an operational requirement that can be assessed today. 

CIOs and CISOs should be able to answer, with confidence: 

  • Can we classify AI workloads based on regulatory and business risk? 
  • Can we track where sensitive data flows across training, inference, and storage? 
  • Do we control which models are used for which use cases? 
  • Can we fully reconstruct an AI-assisted decision for audit or legal review? 
  • Can we change providers without losing data, capability, or continuity? 
  • Can we explain our AI systems clearly to regulators, customers, and boards? 

A “no” to any of these is not a sign of immaturity; rather, it’s a visibility gap. But closing that gap is what defines sovereignty in practice. 

Control Before Capability 

The UK does not need to win a race to build sovereign models to achieve sovereign outcomes. Most organisations will continue to rely on a mix of global providers, local infrastructure, and hybrid architectures. The differentiator will not be who owns the model. It will be who controls its use. 

For CIOs and security executives, the mandate is clear: focus on the control plane before the model layer. Because in AI, as in cloud before it, access without control is not sovereignty, it’s dependency by another name. 

 

Related Articles

Back to top button