About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Data Firms Responding as AI Seen Driving Sovereignty Concern

Subscribe to our newsletter

While the criticality of data to financial institutions has made its security paramount, the internationalisation of that information has made it a strategic priority.

With ever greater volumes of data criss-crossing the world within and between organisations’ systems, data sovereignty has become a key component of governance policies required by regulators. Once considered relevant to how data is stored, who can access it and when, policies now routinely include the “where” dimension – or data residency – as modern data systems have become more widely distributed.

With regulators taking a firmer stance on sovereignty, multiple data and technology vendors have stressed the importance of such capabilities in their new products or product updates. When promoting its expanded tie-up with Microsoft Fabric, for instance, Informatica made explicit mention of sovereignty provisions. And in A-Team Group’s governance webinar in September last year, panellists put renewed emphasis on sovereignty as a major consideration in any policy draft.

The imperative to draft tighter sovereignty codes has been accelerated by a number of factors. Among them is increased geopolitical volatility, which has made data more vulnerable to attack from rogue actors, including nation states.

But many observers and practitioners say that the chief driver of heightened sovereignty awareness has been the increased deployment of artificial intelligence.

“Data sovereignty is not a new thing – it’s been obviously bubbling for a number of years, but AI has a lot to do with the big focus now,” said Russell Fishman, senior director of solutions, product management at NetApp.

Agentic Risks

AI has not only made the distribution and use of data more efficient and faster but it has also presented more risks.

The deployment of agents to automate AI-powered tasks has taken data processing another step away from human oversight, increasing the potential for misuse, especially as many models operate within black boxes. Agents also require much more data to work effectively, raising additional data volume risks.

Without sufficient guardrails, it’s possible that agents could leak or put data to wrong uses. The recent hacking of external companies by “rogue” agents associated with models owned by OpenAI and Anthropic has highlighted such dangers.

“Traditional access controls do not work for agents,” Fishman told Data Management Insight. “There is significant nation-state concern about the ability of organizations to take advantage of the rapidly expanding opportunities that AI offers while not inadvertently exposing themselves to a new threat.  A fundamental rethink of how data access is governed is needed in this new era of agents.”

Greater Security

Being able to control data is crucial to leveraging value from it. Secure guardrails foster trust among clients and regulators and protect against leakage of information that could pose a competitive or legal cost to an organisation. Importantly, it provides the framework for preventing fraudulent use of proprietary data.

Observers have stressed too that good data sovereignty practices are good business practices. As well as ensuring regulatory compliance and forfending against geopolitical uncertainty, well-designed sovereignty provisions also ensure data is properly marshalled, improve the quality of data-led decisions and accelerate innovation. They also make risk management more sustainable.

Recent research suggests companies are largely supportive of tougher restrictions. In a study of European, Middle Eastern and Canadian companies by Kiteworks, two-thirds of respondents said that compliance with sovereignty rules was beneficial to business performance, particularly with regard to data security.

Software giant SAP also found that while compliance with EU sovereignty regulations exacts a cost on business, a study of firms in Slovakia and the Czech Republic found they were so concerned about the risks to their data from external misuse that they would be willing to cough up more to ensure their data remained in the EU.

Data sovereignty is important for governments too. Many organisations’ data could pose a national security risk if leaked or hacked. And keeping data “local” helps inform authorities of the characteristics of the nation when drafting policy, Kumar told Data Management Insight.

“When data is exposed outside its borders, you increase the risk of manipulation and fraud – with real economic and financial consequences for that country,” said Aparna Kumar, founder of Nexora Tech Solutions, a technology advisory firm, and former chief information officer at State Bank of India and HSBC India.

Patchwork Quilt

For those reasons, regulators have been energetic in formulating localisation laws to protect not only consumers and investors but also national interests. However, that has given rise to a patchwork quilt of regulations across international jurisdictions that is imposing a compliance risk.

There are more than 100 regulatory codes worldwide that cover sovereignty, including the General Data Protection Regulation (GDPR) in Europe, all carrying the expectation of precise understanding of their frameworks. The European Union also recently released its proposed technology sovereignty package of measures, among which are its Cloud and AI Development Act that seeks to secure local data and the data centres that host it.

For multinational organisations, keeping track of those various frameworks is a challenge and without full understanding of them, organisations can put their own data in jeopardy.

Mismatches between regulations and other jurisdictions’ data are fairly common. Data classifications vary from place to place and the increased use of multi-cloud strategies with their own guardrails adds to the complexity.

NetApp’s Fishman stresses that another challenge that organisations face is making sense of the myriad and quickly evolving regulatory landscapes emerging in different regions and nations, while the uneven availability of compliant and state-of-the-art AI models complicates things even further.

“It’s like an arms race in many ways,” he said. “Governments could be investing in creating capacity to help organisations take advantage of AI. But as you get further away from English and Chinese, many of the foundational frontier models that underpin widespread AI adoption don’t exist in the languages that organisations use.

That’s a problem that needs to be addressed first, he said, adding that the goal of widespread adoption of AI – and the economic benefits that come with that – inherently means more organisations that don’t have a deep data science background need to find ways to make their data work for AI.

“So all of this together means we now see nation states driving frontier model training, and along with that there’s an increased interest in making sure that the data, the fuel that feeds this AI fire, is being managed, controlled, protected and isn’t ending up being used in ways that were never intended in the first place,” Fishman said.

Dislocations between regulations have helped forge a trust gap across borders where organisations can’t be sure overseas security measures will live up to their own jurisdictional and corporate expectations.

It has also sparked diplomatic spats. The US and European Union recently scrapped an informal “safe harbour” agreement as Washington demanded that Brussels loosen the strict local privacy rules that American officials consider disadvantageous to their cloud providers, AI companies and wider digital trade.

“It’s less about them versus us as much as ‘can I trust you to manage the data in the way that I believe it is required to be managed’,” said Fishman.

Old Data

Regulations are good at ensuring processes are compliant in the present and future, but not so effective at mitigating the impacts of past breaches. Kumar argues that the absence of restrictions in the past has meant that large volumes of sensitive data from India are still in circulation.

That genie can’t be put back in its bottle, she said, despite the South Asian nation introducing localisation laws in 2018 and the Digital Personal Data Protection Act in 2023, which govern where data must be stored and how it may be transferred.

Challenges to achieving this include broken lineage within the data, which makes it impossible to “retrieve”.

“For that particular [challenge], I think nobody is able to have a very clear-cut answer,” she said, adding that even if that data could be repatriated, it would probably be unusable and challenging to integrate with new data sets because it would have been altered from its original state.

“It is not going to be the same as what you would have built with the new architecture while getting the data back in the respective countries,” she said.

“It’s not about getting data back. It’s about how you are going to use that data.”

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: The Data Office at a Crossroads — AI Governance, Organisational Design, and the Evolving Mandate of the CDO

Who owns AI governance in a capital markets firm – and is the Data Office structured to bear that weight? These questions sit at the heart of A-Team Research’s latest findings, presented here for the first time: the combined results of two landmark surveys examining the role of the Data Office in AI governance and...

BLOG

Governance to be Scrutinised at Inaugural AI in Data Management Summit NYC

Ensuring artificial intelligence deployments are securely governed without stymieing their potential is a delicate balancing act. It requires carefully drawn policies, frameworks and processes. As deployment of the technology expands and its capabilities and complexity multiply, the governance structure must adapt and evolve. How to get this right is among the most important topics swirling...

EVENT

RegTech Summit New York

Now in its 10th year, the RegTech Summit in New York will bring together the RegTech ecosystem to explore how the North American capital markets financial industry can leverage technology to drive innovation, cut costs and support regulatory change.

GUIDE

AI in Capital Markets Handbook 2026

AI adoption in capital markets has moved into a more disciplined phase. The priority is now controlled deployment: where AI can be used safely, where it can deliver measurable value, and how outputs can be governed, monitored and evidenced. The 2026 edition of the AI in Capital Markets Handbook examines how AI is being applied...