AI Business Strategy

Hosted is not Sovereign

By John Harms, Vice President, Government Solutions at Quantexa

You can host public sector data on British soil, within state-of-the-art facilities, and still lack operational sovereignty. If an organisation cannot decide how its data is processed, cannot explain how an artificial intelligence model reached a specific output, or cannot migrate away from a primary technology vendor without causing operations to halt, it does not possess sovereignty. It possesses hosted dependency.  

True sovereignty is not defined by static location. It is defined by operational authority: an organisation’s permanent ability to retain control over its data, its software, and its strategic decisions.  

The principle of control under distress  

The clearest test of sovereignty is control under distress: the ability to maintain operations and authority during periods of geopolitical, regulatory, commercial, or technical disruption. A sovereign system enables organisations to govern their data, adapt operational processes, reconfigure technology, and maintain continuity regardless of external pressures. If changes in export controls, vendor commercial terms, or system outages can cripple essential services, sovereignty has been compromised.  

Modern infrastructure inevitably relies on specialist providers, but outsourcing technology should never mean outsourcing control. When an organisation can no longer audit its AI models or extract its data without prohibitive costs, it sacrifices long-term resilience for short-term convenience.  

The data foundation failure in the public sector  

The primary obstacle facing public sector modernisation is not a lack of available software or advanced algorithms. It is the condition of the underlying data.  

Across departments, local authorities, and public agencies, operational data remains fragmented across disconnected systems. This fragmentation limits efforts to detect organised fraud, coordinate health-care services, streamline administration, and safely deploy AI.  

Recent public sector initiatives have focused heavily on adopting top-tier AI capabilities, yet AI is only as reliable as the data that supports it. Without a unified, verified data foundation, AI models produce unreliable outputs. Poor-quality or incomplete data creates errors that are difficult to trace, making decisions harder to audit or explain and ultimately weakening public trust. The effectiveness of public sector AI will not be determined by the complexity of the algorithms selected. It will be determined by the integrity, accessibility, and governance of the data beneath them.  

It will be determined by the integrity, accessibility, and governance of the data foundations beneath them.  

The structural risk of vendor lock-in  

A core requirement of data sovereignty is the practical ability to adopt new technologies when circumstances require it. Vendor lock-in therefore represents a direct threat to long-term resilience.  

Replacing one dominant, proprietary supplier with another simply shifts the point of dependency.  When public bodies build their operational workflows around closed, proprietary standards, switching providers becomes increasingly costly and complex, reducing their ability to negotiate, innovate, or adapt.   

Governments can and should adopt best-in-class technology, but it must be deployed within open, interoperable architectures that preserve choice. Technology ecosystems built on open standards and portable data ensure software components can be replaced or upgraded without disrupting essential services.  

A healthy public sector technology market also depends on supplier diversity.  Procurement approaches that favour large, monolithic contracts restrict competition to a small number of global providers, increasing operational and commercial risk. In critical national infrastructure, competition is not simply an economic objective; it is an essential component of resilience.   

Building citizen trust through transparency  

Public sector technology operates under a different mandate than commercial software. While commercial applications often prioritise conversion and retention, government systems must prioritise lawfulness, equity, and public trust.  

If citizens believe that decisions regarding health-care eligibility, tax assessments, or legal entitlements are being made by unexplainable systems controlled by third parties, trust in public institutions will erode.  

Transparency must be designed into AI systems from the outset, not added after deployment. Public bodies need clear decision pathways that allow them to explain the data, logic, and parameters behind automated decisions. Human oversight, supported by robust audit trails, ensures decisions can be challenged where necessary while maintaining accountability and control over data throughout the process.  

Accountability cannot be outsourced  

Governments can outsource infrastructure management, database administration, and software development. They cannot outsource public accountability.  

Private vendors provide platforms and software tools, but elected governments remain solely responsible for the decisions made using those technologies. If a government department loses the ability to govern its data, understand its AI systems, or alter its supplier relationships during a crisis, it has yielded its authority.

Achieving true UK data sovereignty does not require isolating public services from global technology or forcing every system onto domestic infrastructure. It requires secure data foundations, strong governance, open architectures, supplier competition, and AI that remains transparent, explainable, and auditable.  Ultimately, sovereignty is not about where technology resides. There is a single question that exposes the gap: how long would it take, and what would it cost, to leave your largest technology supplier? If nobody in the department can answer, you do not have sovereignty. You have hosted dependency.  

Related Articles

Back to top button