Search
A man holding a compass on blurred background

AI sovereignty: changing course without losing control

A guest article by Dr. Christian Krämer and Mahmoud Nahban, both Senior Managers at Detecon, the consulting arm of T-Systems

2026.07.29Mahmoud Nabhan

Asking the right questions

Today, the same question comes up in every boardroom meeting: How quickly can we scale AI? It is an understandable question. But it is also the wrong one. Because while you are focused on scaling, something quieter is happening in the background. AI is becoming embedded in your operations, software, security, supply chains, and the decisions that drive your business. With every integration, a new layer of dependency emerges—on data, models, platforms, vendors, and evolving regulations.

When a single point of control stops everything

Dependency is no longer merely a commercial issue. In June 2026, the U.S. government instructed Anthropic to block access to its most advanced models, Fable 5 and Mythos 5, for all foreign nationals. The order targeted non-U.S. citizens. Yet without a reliable way to identify and filter users in real time, Anthropic shut down the models for everyone. Worldwide. Overnight. Customers who had built systems around those models woke up to a simple notice: the service was gone.

The lesson from this case is not political. It is structural. The restriction was intended to be selective. The impact was absolute. The only way to enforce the distinction between domestic and foreign users was to switch off the entire product. That is the nature of centralized dependency: failures rarely occur in proportion to the original problem.

The lesson is not that a vendor failed or that a government overreached. The lesson is that there was only a single point of control—and that those who depended on it had neither influence nor alternatives.
 

A leadership issue, not a technical footnote

The more important question therefore becomes: How much control are we giving away while we scale? That single question transforms AI sovereignty from a technical consideration into a leadership responsibility. 

  • For CEOs and boards, it is about strategic control
  • For CIOs, CTOs, and data leaders, it is about platform choices and portability
  • For CISOs and risk and compliance leaders, it is about security, resilience, and accountability

Ultimately, everyone arrives at the same uncomfortable question: If the conditions around us change, do we still have the freedom to replace, supplement, or bring back critical AI capabilities without disrupting business operations?
 

What sovereignty really means

AI sovereignty is the ability to scale AI while retaining control over what matters most: critical data, models, infrastructure, decisions, and dependencies. The emphasis varies by region. In Europe, the discussion centers on trust, regulatory maturity, resilience, and strategic autonomy.

Across the Gulf region, AI sovereignty is closely tied to national transformation agendas, digital government, and infrastructure control. Yet the underlying business challenge remains the same everywhere: How can organizations scale AI while preserving control, trust, and strategic freedom of action?
 

The mistake almost everyone makes

This is precisely where most AI strategies fail—quietly. The sovereignty question arrives too late. After the use case has been selected. After the platform has been chosen. After the data flows have been designed. At that point, sovereignty is no longer a design decision. It becomes a remediation project, a constraint, or a compliance issue. The damage has already been done, and reversing it becomes expensive. The solution is easy to describe and much harder to implement: Shift sovereignty left.

But that raises a more difficult question. If the risk is so obvious, why do organizations postpone sovereignty discussions until the very end? Our view is that this is not negligence. It is a structural incentive problem. Speed is visible, measurable, and rewarded. A pilot that goes live within six weeks is a success story for the next board meeting. Sovereignty is the opposite. It is a cost today whose value becomes apparent only when something goes wrong—precisely when it is already too late to implement it cheaply.

Dependency rarely feels like risk at the beginning. It feels like convenience. As long as the provider continues to deliver, exit strategies remain theoretical. They become real only when someone else changes the rules—a government, a vendor, or a regulator. AI sovereignty is therefore a classic case of deferred costs: the effort is required today, while the benefits lie in a future most organizations prefer not to contemplate.

There is another force at work. Sovereignty is rarely anyone’s explicit responsibility. Speed has an owner: the product lead, the transformation sponsor, the delivery team. The downside of dependency is distributed across legal, security, procurement, and executive leadership. As a result, nobody truly owns it until it materializes. Diffuse risks almost always lose against concentrated incentives. 

Sovereign by Design means embedding sovereignty thinking into the earliest phases of AI transformation: defining business ambitions, selecting use cases, assessing risks, choosing platforms, designing data flows, selecting foundation models, defining deployment and operating models, and establishing governance principles.

It means asking the right questions before architecture, sourcing, and operational decisions solidify into commitments that cannot easily be undone.

IM-Nabhan-Mahmoud

Sovereignty does not mean owning every layer of the AI stack. It means understanding which layers must remain under your control, which can be entrusted to partners, and which must remain portable if the ground shifts beneath you.

Mahmoud Nabhan, Global Lead for cloud security und sovereign cloud at Detecon

A compass, not a checklist

At Detecon, we help organizations with a practical AI Sovereignty Compass. Rather than conducting a simple pass-or-fail audit, the framework evaluates how sovereignty-relevant each AI initiative is across seven dimensions:

  • Business criticality and decision impact
  • Data sensitivity, ownership, and jurisdiction
  • Model transparency, lifecycle governance, and accountability
  • Cloud, compute, and AI supply-chain dependencies
  • Deployment, operations, and runtime control
  • Portability, reversibility, and exit options
  • Security, resilience, and regulatory risk
     

The real cost: freedom of action

At its core, AI sovereignty is about preserving the freedom to change course without losing control. In practice, that means understanding exactly how dependent you are on specific foundation models, cloud and compute platforms, proprietary APIs, data flows, deployment models, and governance mechanisms. A sovereign strategy determines early which components must remain portable, replaceable, or independently manageable. The goal is not to avoid external providers. The goal is to avoid irreversible dependency.

In practical terms, that may mean building integrations against an abstraction layer rather than directly against a single vendor’s API, allowing models to be swapped without rewriting applications. It may mean keeping the most sensitive data and the most critical inference workloads within your own infrastructure while using external providers only where genuine substitutability exists. It may mean negotiating portability and exit clauses before signing contracts rather than during a crisis. 

None of these measures are free, and not all of them are justified in every scenario. That is exactly why they must be conscious decisions rather than silent defaults. The answer is never one-size-fits-all. Beyond a baseline level of governance, some use cases require only light sovereignty measures, while others demand strict control. A marketing content assistant, an industrial quality-control model, a clinical decision-support system, and a telecommunications network automation use case sit at very different points on the sovereignty spectrum. The discipline lies in classifying early, designing deliberately, and making trade-offs transparent—between speed of innovation, control, cost, compliance, and resilience.
 

Ask the question while you still can

Detecon helps organizations translate AI sovereignty from an abstract concern into concrete transformation decisions: identifying where sovereignty truly matters, which design options are available, and how scalable AI can be built, deployed, and operated without creating self-imposed lock-in. For organizations across Europe and the Middle East, the window of opportunity is now. Before platforms, architectures, operating models, and vendor dependencies become difficult—or impossible—to reverse. The shutdown of Fable 5 was a warning shot. The question is no longer whether a single point of control can be removed without your consent. The question is whether your business would survive it. 

AI sovereignty is not about slowing down AI adoption. It is about scaling AI with confidence, control, and trust.

You might also be interested in

Special

About the author
IM-Nabhan-Mahmoud

Mahmoud Nabhan

Global Lead for cloud security and sovereign cloud, Detecon International GmbH

Show profile and articles

We look forward to your opinion

Do you have any ideas, suggestions, or questions on this topic? We cordially invite you to exchange ideas with us. Get in touch with us!
Do you visit t-systems.com outside of India? Visit the local website for more information and offers for your country.