Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Squaring the circle - digital sovereignty’s big picture versus its operational details

Дата публикации: 30-07-2026 07:30:02

In a world of stratospheric risk but persuasive promises, AI is both alluring and dangerous –there is mounting evidence for both. So how can organizations gain control, build guardrails, and establish trust?

Основное содержимое страницы с новостью.

When it comes to AI, we live in interesting times, in the words of the apocryphal Chinese proverb. Organizations want to be more resilient to risk, uncertainty, and upheaval, but that means quantifying the risks first. And in the real world, some of it falls squarely into the ‘big picture’ category. So, before we get to the nitty gritty, let’s look at that first.

Enterprise research findings that AI’s productivity uptick has failed to materialize have reached the ears of the mainstream business media. Take the headline in the Financial Times recently which asked,  ‘Is AI productivity growth in the room with us right now?’ Ouch.

Recent research from AI industrialization specialists Domino Lab finds that AI is “not delivering business value”: the ROI picture is unchanged from a year ago, according to its fifth annual enterprise report, with most organizations noting that returns merely match expenditure – or fail to. 

But four years on from ChatGPT, and a year after the notorious MIT report last year of 95% AI failure rates, surely adoption should have translated into measurable business value by now?

The financial picture is troubling too, from both user and vendor perspectives. Enterprise research to be published next week suggests emergency spending freezes due to AI, while other studies have documented the soaring costs of tokenomics. 

Meanwhile, the FT reported on 22 July that Google burned through $6 billion in cash on AI in Q2 alone, transforming it from “an asset-light business into a capital-intensive one”. Just four hyperscalers – Google, Microsoft, Meta, and Amazon – are on track to spend $725 billion between them in 2026 on AI infrastructure, it reported, a staggering outlay which far exceeds global revenues from AI software.

A lurking big-picture challenge is China, of course: its focus on dramatically lowering the cost of AI models and increasing their efficiency will look more and more attractive to the many enterprises whose sums don’t add up. 

Meanwhile layoffs in the sector are rising, with estimates ranging from 157,000 (widely reported) to 165,000 (Yahoo!tech) so far in 2026. At the current rate, by the end of this year the tech industry will have shed half a million well-paid workers since the beginning of 2025. Less well reported is the fact that some of those staff are being quietly rehired, as automation fails. 

Still happy? 

So, feeling confident? Arguably, our faith in AI is largely reflected in the trillion-dollar market capitalizations of just nine US companies, which are propping up the stock market: NVIDIA, Apple, Alphabet, Microsoft, Amazon, Broadcom, Meta Platforms, SpaceX, and Tesla. Factor in dramatically cheaper Chinese AI models and the whole edifice looks precarious.

With probable IPOs from OpenAI and Anthropic this year, the West, where political alliances are fracturing, is living in a belief-based economy of infinite jam tomorrow, not a dog’s dinner today. 

But one topic dominates, even in this febrile atmosphere. Not agentic AI – despite the hundreds of ‘announcements’ each week – but digital sovereignty, which is the sub-text of many enterprise conversations, conferences, and vendor events. 

Sometimes hot topics merge into one. As Economist Enterprise reported last month, though organizations want sovereignty over their infrastructure and data, they are handing it to agentic AIs instead, which are causing problems in 98% of implementations. Despite this, the rush to adopt continues, but is this yet more faith-based decision-making?

So, sovereignty is a big-picture, macro issue, but in practical terms it is very much a micro, granular one. What can organizations do about digital, data, and infrastructure sovereignty in a world where resilience is easy to say but harder to achieve? 

These are particular concerns for the EU, where the Cloud and AI Development Act will require governments to carry out sovereignty risk assessments across their entire technology estates, including their cloud applications and infrastructures. 

As previously noted  - see diginomica, passim -  the wider political context is a growing perception that Europe needs to reduce its reliance on US vendors. However, the day-to-day context is no less important. 

Nick Reed is Chief Strategy Officer at Bizzdesign, a Netherlands-headquartered company whose SaaS solutions aim to map technology to strategy, while offering detailed architectural insights into where data is held, where dependencies are critical, and what the risks may be in each location. 

Put simply, knowing where things are should be your organizational baseline; you can’t govern unless you know your boundaries. He explains:

There's a new sector called a digital twin of the organization, which we're present in. We help our customers transform faster and more effectively using connected architecture models of the enterprise, where they can know, plan, design, and govern transformation, and bridge silos of the enterprise, so they get a better view – and a better context – of the enterprise for decision making. It’s about bridging the strategy to execution gap.

Then unexpectedly, he adds:

You might want to look at who's holding the risk of current AI data center funding for the next ‘big one’ [financial crisis] when it comes along. There’s definitely some Enron-style double counting of revenues across multiple companies. And from what I'm seeing, there's a lot of pension funds are on the wrong end of this private credit risk. A lot of funding shifted into private credit outside of the typical bank lending and bond markets. That could be very bad news.

Noted. 

Sovereign thoughts

But back to sovereignty. I tell him about my experience at SUSECON in Prague in the Spring, where nearly every keynote, roundtable, and interview shared the same theme: taking back control from US hyperscalers. It was a theme that also rang out time and again at this year’s World Economic Forum meeting in Davos, and one that’s now a regular topic at vendor conferences everywhere, including in the US. 

Reed recognizes these themes from his own discussions:

We have sovereignty conversations day in day out with customers and prospects, and that's been going on for some time. Brexit triggered a number of conversations [Britain’s data adequacy agreements with Europe were a real concern]. And the Middle East today has strict requirements around where data is. A lot of on-premise software in the Middle East is a result of that.

So, different countries and jurisdictions have different approaches to what sovereignty means or how much sovereignty is enough. And in many ways, that's the key question: how much sovereignty do you need? It's like risk management. What is your acceptable risk appetite? You then tailor how you control risks in line with your appetite, and that can vary depending on the circumstances.

Citing defence and aerospace as examples, he continues:

Sovereignty is an extremely strong factor in decision-making at that level. But if it's your public website, there's probably no sensitive information there. So, there's a contextual element to sovereignty as well, depending on the sensitivity and the business criticality of the data, and everything that sits beneath that.

So, it does require a holistic approach, which is what's good about the whole EU tech sovereignty package and the cloud sovereignty framework. I think having a principles-based approach is much better than a prescriptive, control-based one.

But is it? Under President Biden, the US had a voluntary code: the AI Bill of Rights, and there were countless voluntary commitments made in the wake of the UK’s Bletchley Park AI Safety Summit, all which look naïve and antiquated today. The rising tide of legislation and regulation, particularly in Europe can be read as a response to the realization that principles, while admirable, don’t amount to a hill of beans in this crazy world (to mis-use a line from Casablanca); what you need are rules

Reed replies:

Well, regulation is coming. The EU Cloud and AI Development Act is at proposal stage now. That must go through a process to turn into binding legislation in the respective countries, but it takes an assurance-level approach and has sovereignty objectives, with a principle-based approach underpinning it.

It's not clear how that will manifest in legislation yet. But it looks like it's not going to be left up to states, agencies, and private organizations that are related to critical infrastructure and services to decide if they want to do it themselves. There will probably be an element of compulsion to at least report on it, and to demonstrate that they have governance in place. 

It’s similar in principle to the approach to operational resilience, which is a bit more prescriptive. But the first step is demonstrating that you can report on your resilience. Such as financial institutions reporting on the resilience of their critical business services and demonstrating that they understand the dependencies. The approach to sovereignty is similar, but it has additional aspects to it.

But what then about the paradox seen in many enterprises, the desire, on the one hand, to establish sovereignty over data and infrastructure, but on the other, to hand control to agentic AIs, which in many cases are undermining control over business processes. 

The problem is similar to the Jevons Paradox, Reed observes, where making a resource more efficient increases the demand for it, which then outweighs the initial savings:

In many ways, that’s at the heart of what you describe. When the cost of producing software and new solutions comes down, what's going to happen? We're going to solve a lot more business problems through software, which is great. But the flipside is, does that mean that problem of not knowing what's running where, and where the data is, gets multiplied tenfold? That would make the IT landscapes of large organizations ten times more complex, which makes it even harder to transform and achieve business goals.”

And more expensive to fix, of course. Indeed, there is hard evidence of this phenomenon in a  recent report from Freshworks, which says that 88% of IT decision-makers admit that managing AI complexity has increased their team's workload. IT teams now spend around a quarter of their time troubleshooting integrations, governance and other operational headaches.

Bizzdesign’s Reed continues:

Allowing agents to run riot through business processes and break everything is another manifestation of the Jevons Paradox, where the efficiency and cost of automating work through agents makes it attractive, but the risk is bad things happen without governance.

So, I think it's all a governance challenge. But when you get into agentic AI, you can't have human-speed governance for agents operating at machine speed. Governance must now become automated too, establishing and running the guardrails for agents in real time as they operate. In turn, that means agentic AI governance must be architected and deployed as something machine readable by agents.

My take

One can argue whether that counts as rules or a set of principles, but at a wider scale, society also needs laws, regulations, and a clear path towards responsibility and liability. 

Another challenge of the AI age, I suggest, is that some AI vendors appear to be creating a world in which they can claim credit and responsibility for anything good that an AI achieves, while denying all responsibility for anything bad. In the latter case, some seek to blame the user or the AI itself, as my two-part interview with author and consultant Kate O’Neill explains.

In any case, you need to know where your data is, where your infrastructure is, and under which jurisdiction, before you can govern any of this effectively, which is what Bizzdesign seeks to do for its clients.

Reed explains:

We have to architect trust into the new, autonomous world, and that means clear rules around what decisions can be made using what data by any given agent. It means a decentralized model of that governance and trust, and being very explicit about where human accountability lies for the work being done by agents. 

Any agency of those agents, as it were, must result in human accountability at some level, and being very clear and explicit about that accountability. So, you're effectively leveraging and multiplying human accountability rather than abdicating it, avoiding it, or giving it away to agents.

And on the notion of sovereign clouds in Europe and elsewhere, he adds:

The fundamental issue here is trust, and control. Do you have control over your entire supply chain and operations for your digital capabilities? And how much do you trust all aspects of that supply chain, including how much legal and jurisdictional sovereignty you have over it?

In the uncertain world I describe at the top of this article, those are vital questions enterprises need to ask – and to find answers to. 

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1AI governance: Building trust in the age of AI video creation05.5216-12-2025
2Responsible AI governance in 2026: Frameworks and failures0512-01-2026
3AI and a gathering storm of unchecked power-3703-05-2026
4What is digital sovereignty and why does it matter?0502-01-2026
5 How should bosses talk about AI? 0528-05-2026
6 Navigating uncertain times with the help of artificial intelligence 5721-04-2026
7 AI and the danger of cognitive surrender 0530-04-2026
8Power politics in the age of AI-2621-06-2026
9How AI is shaping the future of diplomacy0717-07-2025

Классификация: . Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 8.68. Источник: diginomica.com.