Data Sovereignty and AI: Understanding the Whole Chain, From Chips to Models

2026-09-24
Data Sovereignty and AI: Understanding the Whole Chain, From Chips to Models

In just a few years, data sovereignty has moved from the vocabulary of specialists to that of governments. Generative artificial intelligence has pushed the question to the forefront: before handing documents to a model, many public organizations first want to know where it comes from and where it runs. Without clear answers, that uncertainty often slows AI adoption rather than speeding it up.

But what exactly are we talking about? Sovereignty is not a switch you turn on or off. It is a chain, and every link raises its own questions.

A priority for governments

In the United States

For federal agencies, cloud services are assessed through the FedRAMP program, and many state and local governments set their own security and data residency requirements in procurement. With generative AI, a new layer of questions has appeared: which model processes public records, where it runs, and what it retains.

In Canada

Canada has made sovereignty an explicit policy goal. In 2024, the federal government launched the Canadian Sovereign AI Compute Strategy, with 2 billion Canadian dollars over five years for domestic AI compute, from private data centers to public supercomputing. In September 2026, Ottawa presented new investments in sovereign and affordable compute capacity.

In Europe

France has long relied on the SecNumCloud qualification from its national cybersecurity agency to identify trusted cloud services, and a bill would require it for local governments of more than 30,000 residents for their sensitive data. On the model side, Mistral AI announced in September 2026 a 3 billion euro raise to build a European "sovereign AI layer", from open models to compute capacity.

Sovereignty plays out along a whole chain

1. Chips

It all starts with hardware. In 2025, Taiwanese manufacturer TSMC held 69.9% of the global semiconductor foundry market, according to TrendForce. No public organization controls this link, but it is a reminder that total sovereignty does not exist: the goal is to reduce dependencies where it is possible.

2. Data centers

Where is the data stored, and under which jurisdiction does the company running the data centre operate? A server located in one country but operated by a company subject to another country's laws does not offer the same guarantees as a local host. This is at the heart of data residency and sovereign hosting policies.

3. AI models

Large models are mostly developed in the United States and China. According to Stanford's 2026 AI Index, US organizations released 50 notable models in 2025, and China is closing the gap quickly. Europe is betting on players such as Mistral AI. Using a model means sending it data: knowing where it runs and what it keeps becomes essential.

4. Open models and local deployment

Alongside closed models, more and more open weight models can be installed on infrastructure the organization controls. They are often combined with a RAG approach (retrieval-augmented generation): the model answers based on the organization's own documents, indexed locally, without those documents leaving the chosen environment.

5. Software and its subprocessors

Finally, every cloud application relies on other providers: hosting, email, support, analytics, and now AI model providers. The real question becomes: which data is shared with which third parties, and why?

Large models or local models: a trade-off

There is no single right answer. Large cloud models are usually more capable and easier to use, but data leaves the organization's environment. Open models deployed locally offer more control, but they require infrastructure and expertise, and they often perform less well on complex tasks.

The right choice depends on the sensitivity of the data and the use case. Translating a progress note does not carry the same requirements as analyzing confidential documents. This is the kind of more local deployment we explored for Planivore's compliance module, developed through a Scale AI-funded initiative: a RAG that draws on an organization's documentation to validate strategic content. It is a good example of what a more local deployment makes possible, and of the trade-offs it involves.

Six questions to find your way

  • Where is our data hosted, and under which jurisdiction?
  • Which third parties receive our data, and which data?
  • Which AI model is used, who develops it and where does it run?
  • Is our data used to train a model?
  • Can AI features be turned on or off depending on data sensitivity?
  • Can we get our data back in a usable format if we change providers?

In short

Data sovereignty is not a state you reach once and for all. It is a series of informed choices, link by link, between control, performance and cost. For a local government or public agency, the starting point is simple: know where your data goes, who sees it, and be able to decide.

Call to action

To structure the governance of your strategic plan, explore our guides.

Sources

More on this topic
How local government staff can choose performance indicators they will keep current all year long: three families of measures and five practical tests
AI can speed up public sector reporting without replacing judgment. 3 practical uses and 4 rules to keep accountability in human hands.
New elected officials, shifting priorities: how local governments and public agencies can realign their strategic plan without starting over.

See Planivore at work in your organization

Book a demo: we'll show you, based on your own challenges, how Planivore structures your plans, tracks your KPIs and simplifies your reporting.