Who controls the data controls the future
In March, Iranian drones targeted three Amazon Web Services (AWS) facilities in Bahrain and the United Arab Emirates (UAE), striking two directly and almost hitting the third. It was the first time a commercial data center had been a military target, yet almost nobody outside specialist circles noticed. They should have. The servers holding a country’s data, and the chips running the artificial intelligence (AI) models on which its economy increasingly leans, are no longer background infrastructure. They are as strategic as ports or power grids — and just as exposed.
For most of the past decade, data was something companies mined, and AI was something companies sold — regulated at the margins through privacy law, if they were regulated at all. This framing no longer works. AI now sits inside finance, defense, healthcare and public administration, and it runs on two things most governments do not actually control: the data that train it and the compute that processes it. Countries that ignore this would find their futures being decided in boardrooms where they have no seat.
Many governments have taken note. Global spending on “sovereign AI” would reportedly surpass US$100 billion this year. Over the past few months, Canada, France, Saudi Arabia and the UAE have rolled out national compute funds and GPU allocations. The EU has gone further, treating sovereign AI infrastructure almost as doctrine, which has meant backing Gaia-X to build out European data infrastructure and financing projects such as Mistral AI’s new data center outside Paris.
Illustration: Mountain People
On paper, this looks like sensible diversification away from a handful of US and Chinese firms. In practice, it risks creating something more brittle: a patchwork of national fortresses, each self-sufficient and none capable of talking to the others. Part of the problem is that “AI sovereignty” encompasses at least three things, and most governments are only working on one.
Data residency — keeping citizens’ data within national borders — is the oldest of the three, the easiest to legislate, and the one most policy actually addresses. Compute sovereignty — who owns the chips and data centers doing the processing — is more difficult: a country can wall off its data, but it loses control if those data are processed on infrastructure someone else owns. Governance sovereignty — the ability to set the rules AI systems have to follow, rather than importing whatever standard the country hosting the dominant developers happens to set — is the one almost nobody talks about.
A fragmented regulatory landscape does not help any of this. Roughly 90 countries have some kind of national AI strategy; at least 33 have passed binding legislation. The approaches often clash. The EU’s AI Act, whose main provisions became applicable last month, carries penalties of up to 35 million euros (US$40.6 million) or 7 percent of the offender’s global annual turnover. The US’ AI Action Plan takes the opposite approach, treating deregulation itself as a competitive edge. China’s Global AI Governance Action Plan offers cooperation on AI governance with developing economies, but on Chinese terms.
The Council of Europe’s Framework Convention on AI — the first binding international AI treaty — represents real progress, but its enforcement is modest next to the scale of what it is meant to govern. Coordination beyond that has barely started. The UN’s Independent International Scientific Panel on AI has warned of a “race to the bottom,” with jurisdictions competing to offer the most permissive rules rather than the safest ones. Companies running high-risk AI deployments are already shopping for the softest jurisdiction.
Genuine AI sovereignty requires four things, none of which is complicated in concept. Start by putting AI data infrastructure in the same legal category as power grids, with someone clearly on the hook for physical and digital security.
Next, countries building sovereign compute need shared interoperability standards, not just national champions — Gaia-X’s work on data portability is a useful template. A hospital in Lagos or a ministry in Warsaw ought to be able to verify that a system meets baseline safety requirements, regardless of whose infrastructure it is running on.
Oversight needs teeth: audit rights, mandatory incident reporting, and licensing for the handful of frontier models capable of touching critical infrastructure or financial stability. These models should be treated more like nuclear material than ordinary software.
The world needs a real mechanism to stop AI sovereignty from turning into just another axis of inequality. That US$100 billion investment in sovereign compute is happening almost entirely in rich countries. Pooled regional compute, financed and governed jointly by smaller countries, would deliver better results than each of them trying to go it alone.
None of this requires a grand global treaty. The components of a governance framework — including the EU AI Act, the Council of Europe convention, Gaia-X, and the UN’s scientific panel — already exist. The scaffolding connecting them is missing, and building that takes deliberate work. Every year it is delayed, the infrastructure gets bigger and harder to reconfigure. Nobody pouring billions of dollars into data centers and GPUs is waiting around for governance to catch up.
The strikes on those AWS facilities in the Gulf sent a message (whether or not anyone intended it): The infrastructure underpinning a growing share of consequential decisions — who gets a loan, which patients get flagged for treatment, which factories keep running — sits in buildings most governments do not control and cannot fully protect. Data sovereignty, compute sovereignty and governance sovereignty are not conference-room abstractions. They are the precondition for a future shaped by countries’ own citizens — not whoever happens to own the servers.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.