For years, Australian organisations have had serious conversations about data sovereignty.

Where is our data stored? Which jurisdiction does it sit within? Who can access it? What happens if regulations change? What happens if a critical technology provider is acquired, restructures its services or changes its commercial terms?

The shift to cloud computing forced boards, executives and technology leaders to think more carefully about these questions. Organisations gradually realised that moving infrastructure and data to the cloud was not simply an IT decision. It introduced questions around security, resilience, concentration risk, regulatory obligations and strategic dependency.

Artificial intelligence is about to take that conversation considerably further.

Because with AI, sovereignty isn’t simply about where data is stored.

It’s about what AI systems know about your organisation, what information they’re connected to, which decisions they influence, what actions they’re authorised to take and, ultimately, how dependent your business becomes on the organisations providing the underlying technology.

As AI moves from experimentation into core business operations, AI sovereignty is quickly becoming more than a technology issue.

It’s becoming a boardroom issue.

AI is moving from tool to infrastructure

Most organisations began their generative AI journey relatively simply.

Employees experimented with ChatGPT. Microsoft Copilot appeared in the workplace. Development teams started using AI coding assistants. Marketing teams generated content. Customer service teams experimented with chatbots.

The risk was relatively contained because AI largely sat at the edge of the organisation.

That’s changing.

We’re now seeing AI integrated with CRMs, document management systems, customer records, financial platforms, source code repositories, enterprise search, email, knowledge bases and operational workflows.

The next stage goes further again.

Agentic AI promises systems that don’t simply generate an answer, but can take action.

An AI system might review a customer request, retrieve information from several internal systems, make a recommendation, update the CRM, generate correspondence and initiate the next step in a workflow.

That creates enormous opportunities for productivity and better customer experiences.

It also fundamentally changes the relationship between an organisation and its AI providers.

An AI platform can quickly become much more than another piece of software.

It can become part of the operational fabric of the organisation.

Data sovereignty was only the beginning

Traditional conversations about technology sovereignty have largely centred on data.

Australian organisations have rightly asked where sensitive information is physically stored and processed.

AI introduces a broader set of questions.

An enterprise AI system may be given access to years of organisational knowledge. It could interact with internal policies, proposals, contracts, source code, customer histories, financial information, product documentation and commercially sensitive intellectual property.

That creates a distinction between storing information and understanding it.

An AI platform connected deeply enough into an organisation can potentially develop access to an extraordinary amount of business context.

The question therefore becomes much bigger than:

“Where is our data?”

Boards should increasingly be asking:

“What does our AI environment know about our organisation?”

And then:

“What is it allowed to do with that knowledge?”

Those are significantly more complex governance questions.

The strategic risk is dependency

There is nothing inherently wrong with relying on global technology providers.

Modern businesses already depend heavily on cloud platforms, SaaS products, payment networks, telecommunications infrastructure and countless other external services.

The major AI platforms are also producing extraordinary technology that would be prohibitively expensive for most organisations to develop independently.

Building your own frontier AI model is not a realistic sovereignty strategy for the average Australian business.

The more important issue is understanding dependency.

Consider an organisation that gradually integrates one AI platform across customer service, software development, internal knowledge management, sales, operations and finance.

Over time, hundreds of workflows could be designed around the capabilities and interfaces of that provider.

Employees become familiar with it.

Applications are built around its APIs.

Prompts and processes are optimised for its models.

Internal knowledge repositories are connected to it.

Agents are created to perform specific business functions.

Suddenly, changing AI providers isn’t the equivalent of cancelling a SaaS subscription.

It could mean redesigning a significant part of the organisation’s digital operating model.

That’s where AI sovereignty becomes a strategic issue.

What happens when your provider changes?

Technology providers change.

Products are discontinued. Pricing models evolve. Features are removed. APIs change. Companies are acquired. Regulatory environments shift. Commercial strategies change.

AI is developing particularly quickly.

The model considered market-leading today may not be the model organisations want to use in two years.

That’s why businesses should be cautious about designing an entire AI strategy around whichever platform happens to be leading the market at a particular moment.

Boards and technology leaders should consider scenarios such as:

What happens if our preferred model is retired?

What happens if API pricing increases significantly?

What happens if the provider changes how our data is handled?

What happens if regulatory requirements prevent us from using a particular service for certain workloads?

What happens if another provider produces substantially better technology?

How difficult would it be to move?

These aren’t predictions that something will go wrong.

They’re sensible architecture and risk questions.

The same thinking should apply to AI that organisations already apply to other business-critical infrastructure.

Sovereignty doesn’t mean building everything yourself

One danger in the sovereignty discussion is assuming that maintaining control means avoiding external technology.

It doesn’t.

For most organisations, attempting to develop everything internally would be expensive, slow and counterproductive.

The better objective is to design for choice.

Businesses should be able to take advantage of the best AI technology available while maintaining reasonable control over their data, business logic, intellectual property and architecture.

That requires thinking about AI as an architectural capability rather than simply buying individual AI products.

Where practical, proprietary organisational knowledge should remain under the organisation’s control.

Business logic should not unnecessarily become inseparable from a particular model.

Integration layers should be designed thoughtfully.

AI services should interact with enterprise systems through controlled interfaces rather than receiving unrestricted access simply because it’s technically convenient.

And businesses should understand which parts of their AI environment could realistically be moved to another provider.

Perfect portability probably isn’t achievable or even desirable.

But unnecessary lock-in should still be avoided.

Identity and access become critical

AI sovereignty also intersects with another fundamental technology discipline: identity.

For decades, enterprise cybersecurity has largely been designed around people and applications.

Who is this user?

What are they authorised to access?

What can this application do?

AI agents complicate that model.

If an autonomous system can retrieve customer information, analyse financial records, generate documents, communicate externally or initiate transactions, organisations need to understand exactly what authority it has.

The principle should be familiar: provide only the access required to perform the task.

But implementing that principle becomes more important when software can reason about information and initiate actions dynamically.

Organisations need visibility over which AI systems have access to which information, which tools they’re able to invoke and which actions require human approval.

The question isn’t simply whether an AI system is secure.

It’s whether the organisation remains in control of what that system is permitted to do.

Your organisational knowledge is an asset

One of the most interesting developments in enterprise AI is that the underlying foundation model may eventually become less strategically important than the proprietary context surrounding it.

Many organisations will use similar models.

The competitive advantage comes from combining those capabilities with information and processes unique to the business.

Customer knowledge.

Industry expertise.

Historical project information.

Operational processes.

Internal methodologies.

Product knowledge.

Commercial experience.

Intellectual property.

This is what makes enterprise AI useful.

It also means businesses should think carefully about how that knowledge is structured and controlled.

If years of organisational intelligence become embedded inside a proprietary platform in a way that is difficult to extract or transfer, the organisation may have unintentionally created a significant dependency.

The goal should be to maintain ownership and control of the knowledge layer wherever practical, while allowing different AI technologies to interact with it securely.

That creates optionality.

And optionality has strategic value.

Boards don’t need to become AI engineers

Board members don’t need to understand transformer architectures, embeddings, vector databases or model inference.

But they should understand the strategic dependencies being created.

There are several questions boards can reasonably ask management.

Which AI providers are becoming critical to our operations?

What sensitive organisational information can those platforms access?

Which business processes depend on them?

What decisions are AI systems making or influencing?

Which actions can AI systems perform autonomously?

How do we monitor and audit those actions?

How difficult would it be to change providers?

What happens to our business if a critical AI service becomes unavailable?

Do we retain control of our proprietary knowledge and business logic?

These are governance questions rather than engineering questions.

And as AI becomes more deeply embedded in businesses, they belong alongside existing discussions about cybersecurity, cloud risk, privacy and business continuity.

AI sovereignty is also an architecture decision

The organisations best positioned for the next stage of AI adoption may not necessarily be those implementing the most AI today.

They may be those building the right foundations.

A well-designed AI architecture should allow an organisation to evolve as the technology evolves.

That could mean creating abstraction layers between applications and AI providers.

It could mean separating enterprise knowledge from the models consuming it.

It could mean maintaining strong API governance.

It could mean implementing identity controls specifically for agents.

It could mean ensuring sensitive workloads can be directed to different models depending on security, regulatory or commercial requirements.

It could also mean accepting some provider dependency where the commercial benefits clearly outweigh the risks.

The objective isn’t technological purity.

It’s making those trade-offs deliberately rather than discovering them several years later.

Australia has particular reasons to think about this

For Australian organisations, sovereignty has always had an additional dimension.

Much of the technology powering Australian businesses is developed and operated by companies headquartered overseas.

That isn’t necessarily a problem. Australia benefits enormously from access to global technology platforms.

But AI could deepen those relationships substantially.

If AI becomes central to how Australian organisations develop software, serve customers, manage knowledge, analyse information and make operational decisions, our dependency on a relatively small number of global providers could become significant.

That makes questions of jurisdiction, resilience, competition, portability and strategic control increasingly important.

Australian businesses don’t need to retreat from global AI innovation.

Quite the opposite.

We should be adopting it enthusiastically where it produces meaningful business outcomes.

But adoption and dependency are not the same thing.

Strong technology strategy means being able to benefit from an ecosystem without unnecessarily surrendering control to it.

From AI adoption to AI strategy

The first phase of enterprise AI was understandably focused on experimentation.

What can this technology do?

Where can we use it?

How much productivity can we unlock?

Those remain important questions.

But as AI matures, organisations need to move from experimentation to strategy.

And strategy requires asking harder questions.

What role should AI play within our technology architecture?

Which information should it access?

Which decisions should it influence?

Which actions should it be allowed to perform?

Where are we comfortable accepting vendor dependency?

Where do we need greater portability or control?

And what capabilities are strategically important enough that we should maintain ownership of them?

These questions aren’t barriers to innovation.

They’re what allow organisations to innovate confidently.

Control without slowing down innovation

There will always be tension between moving quickly and building appropriate governance.

AI makes that tension particularly visible because the technology is developing so rapidly.

But sovereignty shouldn’t become an excuse for paralysis.

Organisations don’t need to wait until every possible AI risk has been resolved before implementing the technology.

They need an architecture and governance model that allows them to move quickly while understanding where their critical dependencies are forming.

Use the best technology available.

Experiment.

Build.

Automate.

Improve customer experiences.

Give employees better tools.

But know where your data is going.

Know what your AI systems can access.

Know what they’re authorised to do.

Understand which providers your business is becoming dependent on.

And maintain control over the organisational knowledge and capabilities that create your competitive advantage.

The boardroom question shouldn’t simply be:

“Are we using AI?”

It should increasingly be:

“How dependent are we becoming on AI providers, and do we understand the consequences of that dependency?”

AI sovereignty isn’t about rejecting global technology or trying to build everything locally.

It’s about maintaining control over the parts of your technology environment that matter most.

As AI becomes embedded deeper into Australian businesses, that distinction is going to become increasingly important.

Get our latest news
and insights delivered
to your inbox___

Contact Newpath Team Today
Back to top