Sovereign AI Is Now a Buying Decision. Here's the Checklist.

Posted Sep 01, 2026

Updated

Lindsay MacDonald
Lindsay MacDonald

Enterprises are about to spend roughly $80 billion on sovereign cloud in 2026

That’s a 35.6% jump in a single year, according to Gartner.  North America alone accounts for about $16 billion of that spend, making it the second-largest sovereign spender in the world, behind only China. And in the EU and Middle East, more than 75% of organizations are expected to shift workloads specifically to cut geopolitical risk by 2030. 

One thing is clear: the market is headed toward controllable AI infrastructure. 

When three-quarters of a region reorganizes its infrastructure around who can reach its data, sovereignty has officially become a design constraint. For anyone building conversational agents, the question is no longer whether to think about sovereignty, but how to build for it from the start. 

Let’s dive into what that means.

What is AI sovereignty?

According to McKinsey, AI sovereignty is freedom from three things: someone else's reach, someone else's roadmap, and someone else's rewrite of your system.

That freedom breaks down into three pillars, each with a simple test.

Data: Who can be compelled to access it? If the honest answer involves a third party's jurisdiction, you don't have custody. Agents built to deploy inside your own infrastructure keep the answer short.

Operational: How do you explain to a regulator why the agent did what it did? Regulators on both sides of the Atlantic increasingly require the logic behind a decision, not just the logs. "Too complex to explain" is not a defense. When every dialogue decision is logged and inspectable, explainable AI actually ships faster, because approval stops being a bottleneck.

Technological: What survives a major vendor change? A deprecated model, a price hike, an acquisition: each should be a config change, not a rebuild. Continuity comes from being model-independent and standards-based, not from hoping your vendor stays put.

Sovereignty is a question of control, not geography

It’s easy to assume that keeping data in-region solves the problem. It doesn't. Sovereignty is the ability to build, run, and govern AI under your own rules. It’s a question of who has control, not only where the data sits.

The EU has GDPR, yet under the US CLOUD Act you might be compelled to hand over your data even from an EU-based server. Location can end up giving organizations a false sense of safety when jurisdiction is what will actually determine the regulatory outcome. 

Control speeds teams up, it doesn't slow them down

The common objection is that owning more of the stack means moving slower. Our customers keep proving the opposite.

Swisscom migrated and piloted its SAM assistant on Rasa in eight weeks and has since doubled its automation rate. A major American bank runs 20 agents across 80 data sources on Rasa inside a high-risk trading environment. 

These are not teams that traded speed for control. They got both, because sovereign design removed the dependencies that usually stall a launch.

Accept it, diversify it, or own it

You don't have to own everything. In fact you can't. According to Brookings, roughly 70% of national sovereign AI projects still involve a foreign partner. The realistic goal is managed interdependence: making a deliberate choice at each layer of the stack rather than inheriting one by default. 

For every layer, you have exactly three options: accept the dependency, diversify it, or own it. Here is how we see the layers sorting out:

  • Frontier LLM: diversify. Building a frontier model yourself is hard and rarely worth it. Optimize the terms instead: a local provider such as Mistral in the EU, or a self-hosted open-weights model.
  • Orchestration and business logic: own. If the model is your business logic, every model update is an untested change to how your agent behaves. Own the logic that defines how your agent converses.
  • Conversation data and memory: own. Transcripts are regulated records and incident evidence, full of PII. They belong in your database, under your retention and access policies.
  • Hosting and infrastructure: diversify or own. Your private cloud, or on-prem. You can't verify controls on infrastructure you don't operate.

Bring the checklist to your next vendor

The fastest way to turn this from theory into a decision is to ask every vendor the same questions. You can use the checklist below as a framework: 

  1. Walk me through a turn of conversation and outline which legal entity operates each part of that turn. Even if your agent sits in a server in Frankfurt, if the official owner of that service sits outside of the EU you have only solved for data residency, not data sovereignty. 
  2. Do the same exercise for a few turns in a voice call. Once you move to the voice modality there are even more parties in play within the system. In addition to language models and tools and servers, you now have telephony players, voice gateways, speech to text/text to speech, etc. Remember to check the difference between data residency and true sovereignty. 
  3. Can we swap the model? If you needed to, could you run a sovereign model or a self-hosted one? Would it require you to rebuild the whole solution or just tweak it? 
  4. Who can read the transcripts and access memory? Some of your customers' most private information is temporarily housed within the memory of your agent, or shared within the transcript of the conversation. Usually vendors have tools to redact and remove this, but you still need to know where this data is housed, even if temporarily, and how you can set limits and boundaries for recall of this memory. Make sure as well that no one in the access group can use your conversations for training or evaluation, and be sure that that is an architectural fact instead of a line item in a contract. 
  5. Show us how to trace a conversation that went wrong?
    Make sure you are able to get access and own the observability layer that is key to how your agent works, and how you can audit and improve it over time. 
  6. If the contract ends tomorrow, what would you have left?
    Some vendors house all the files that define the agent’s logic inside of their systems. Skills, prompts, test cases, guardrails, memory schema, and more. If this is the case then you are renting your agent behavior rather than owning it. 

If you’re working with us at Rasa, ask us those questions too. Because we’re sovereign-by-design, we're built to answer them. We’re here to help you get quickly into production while you keep control of what matters.  Talk to Rasa about your AI sovereignty strategy.

AI that adapts to your business, not the other way around

Build your next AI

agent with Rasa

Power every conversation with enterprise-grade tools that keep your teams in control.