Visualização de leitura

What is sovereign AI? Strategic control of your AI future

Ask IT leaders what sovereign AI is, and you’ll get a wide range of answers. Some will even struggle to define the term.

Sovereign AI is an emerging concept focusing on giving organizations — or countries —control over how they develop, deploy, and govern the technology, often using in-house talent, data, and infrastructure.

But only 13% of respondents in a survey from AI platform provider Cohere and IDC say sovereign AI is widely understood across their organizations, and one in three IT leaders had difficulty describing sovereign AI in their own words.

It’s important for IT leaders to understand the concept, because it can help them control costs, keep internal data private, and avoid vendor lock-in, advocates say.

A solid sovereign AI plan can help organizations avoid disruptions caused by forces outside their control, says Joelle Pineau, chief AI officer at Cohere, which offers an AI platform that enables customers to host AI models on premises.

“Over the past year, enterprises and governments have confronted a hard truth: AI systems that rely on external infrastructure can be disrupted without warning by decisions and actions outside their control,” Cohere says in a recent report. “Recent model access restrictions and several high-profile cybersecurity incidents have become a global wake-up call, exposing how fragile technological dependencies can be.”

Sovereign AI is about giving organizations as much autonomy, choice, and control as possible as they deploy and run AI systems, Pineau says.

“The notion of sovereignty really is about giving users control over their tech stack, the ability to choose how it’s deployed, how it works, what data is fed into the system, and how employees are exposed to the technology,” she adds.

Pineau wasn’t particularly surprised about the lack of understanding about sovereign AI reflected in the survey. Cohere’s accompanying report is an attempt to bring more clarity to the issue, she says.

Many goals under one umbrella

Confusion about sovereign AI in part reflects practitioners’ varying goals. Some users want to maximize their AI model options, some want better control over data ingested into AI systems, some want data to reside within country borders, some want to control costs, and others may want to run AI models optimized to their native language or culture.

For Berk Yilmaz, co-founder and CTO at AI integrated development environment provider Noah Labs, sovereign AI encompasses five characteristics: data sovereignty, legal jurisdiction, model provenance, operational control, and supply chain independence.

“Fulfilling one of those does not mean fulfilling all the others, so two executives can agree with sovereign AI and have little in common,” he says.

Freedom of choice doesn’t always mean a company has to host an AI model on premises or data must reside within a certain country, advocates suggest. Sovereign AI is more about preserving options when something unexpected happens.

“The sovereignty model performs well even in a situation where the vendor breaks off the contract, your model is added to the list of models that are banned for exports, and the connection is off,” Yilmaz says. “Each of these three scenarios has already played out somewhere in the last year.”

Others have different definitions. Confusion over sovereign AI isn’t surprising because it is four separate concepts that were collapsed into one, says Jeet Pattanaik, founder and CTO of AI solutions provider Glokal AI. Those four concepts: where a company’s data physically sits, what country’s law can compel access to it, who controls the AI model, and whether a company could still operate if the relationship with the model provider ends.

“Vendors usually sell you the first and call it sovereignty, because data residency is easy to demonstrate and makes a good diagram,” says Pattanaik, author of the book Sovereign AI: The Enterprise Guide to AI That Is Private by Design, Compliant by Default, and Yours Forever. “The hard one is the second, and it’s a legal question rather than a technical one. A server in Frankfurt owned by a US company is still reachable under US law.”

While the concept is largely about control, few companies want full control of their AI stack, he notes.

“Building your own models is expensive and usually worse,” Pattanaik says. “What CIOs actually want is bounded dependency: knowing exactly what you depend on, what happens if it changes, and having an exit that doesn’t take three years.”

Future impact

But the benefits aren’t always immediate, Pattanaik notes.

“The value arrives in specific moments, not continuously — when a regulator asks who processes this data and under whose jurisdiction, or when a vendor changes terms at renewal,” he says. “Organizations that thought about sovereignty already have an answer. Everyone else discovers the question and the crisis at the same time.”

Still, Pattanaik sees momentum building for the concept, with regulated industries such as banking, healthcare, and the public sector paving the way, treating it as a requirement.

“Most others are still at the stage of asking during vendor selection and accepting whatever answer comes back,” he says. “From where I sit it’s moved from philosophy to a procurement line item over roughly the last 18 months, but unevenly.”

David Wang, COO at enterprise AI gateway provider Tetrate, sees similar adoption trends with regulated industries and defense contractors leading the charge.

Other organizations should focus on a handful of questions to decide whether to investigate sovereign AI, he recommends. Companies that can most benefit include those with more than one regulator or legal entity, including recent acquisitions; those with a huge developer population running coding agents; and those with one AI model vendor that commands more than half of their AI spending.

“At that size, a supplier price change becomes a budget event,” Wang says.

Like Pattanaik, Wang suggests that sovereign AI is part of a long-game strategy rather than immediate gains. A good plan enables organizations to quickly shift to open AI models when a frontier model gets too expensive, he says.

“This work mostly prevents a loss rather than creating a gain, which is why it rarely wins the budget on its own,” he adds.

Cohere’s Pineau sees benefits for a broad range of organizations. With token costs a major concern for many companies, a sovereign AI plan can explore alternatives to current AI vendors, she notes.

“A lot of companies care about it, but they care about different aspects,” she says. “In regulated sectors, they care about the compliance aspects, and in some sectors with tight profit margins, they care a lot about the cost control. The manufacturing, the telecoms, and the energy sectors care about the ability to control their costs.”

Mars consolidates complex data infrastructure in hybrid cloud

Brands like Snickers, M&M’s, and Twix are familiar to most consumers, but Mars Inc. doesn’t just produce snacks. The family-owned company, with a revenue of approximately $65 billion, is also one of the largest manufacturers of pet food and ready meals, and its more than 100 production facilities operate around the clock. Of course, this places considerable demands on its IT.

“Our team must ensure that every system, including production lines, runs at maximum performance so we can continuously deliver the products and services our customers value,” says Luciano Batista, the company’s VP of enterprise services delivery.

However, Batista and his team realized that the existing data infrastructure could no longer reliably support operations, especially during peak periods such as Halloween and the pre-Christmas shopping season. So with the support of hybrid, multi-cloud data storage service Everpure, Mars is rebuilding its data and IT infrastructure.

“The Everpure platform met all our requirements,” says Batista. “It’s a scalable platform that futureproofs our operations and integrates seamlessly with our hybrid cloud infrastructure.”

Unified storage environment 

Mars initially consolidated its complex network of storage systems for business-critical databases like Oracle and applications like SAP onto a single Everpure Flash Array system. These software-defined, all-flash storage arrays are available in versions for different workloads, and typical use cases include databases, virtualized environments, SAP applications, and AI and analytics applications. 

Mars has since expanded its flash array infrastructure and now supports mixed workloads, including VMware, Windows, and Linux in areas of production, development, and quality assurance. It also uses Everpure Flash Blade as the basis for the global SAP file system. And while Flash Array is optimized for structured data, the scale-out systems of the Flash Blade series are designed for unstructured information.

“At peak times, Everpure supports up to 300,000 IOPS without any performance degradation,” says Lincoln Silva, product owner for Linux and on-prem storage at Mars. From his perspective, another point speaks favorably of the new platform in that he estimates his team saves approximately three months of planning time thanks to the Evergreen subscription model. This is because the vendor provides regular updates for the storage platform’s hardware and software. As a result, Mars’ IT professionals can focus on more critical tasks. 

Basis for hybrid cloud strategy

Mars also works with choice vendors to implement its approach to cloud. Dedicated local storage capabilities, for instance, are being integrated into Microsoft Azure cloud workloads, which simplifies restore processes and increases resilience.

Snapshots from the local environment can be replicated to the cloud, too. Recovery point objectives (RPEs) of four to 24 hours are available, depending on system priority. “Our success is also the success of our partners,” Batista says. “We embrace a spirit of reciprocity to get the most out of our collaboration.”

The hybrid cloud allows Mars to run VMware workloads and extend its IT infrastructure to the cloud as needed. And the company aims to expand its use of cloud-native applications via Microsoft Azure at a lower cost.

“We’re seeing a data reduction ratio of 18 to one. That’s nine times the expected compression rate,” Batista adds. “This puts us on track to save up to 50% on cloud storage costs. We can now work more efficiently and make better decisions thanks to intelligent solutions and automation.”

Fewer racks and lower power consumption

By consolidating on the flash platform, Mars has also reduced the space requirements and power consumption of its data centers so they only use one sixth of the power, and the number of racks has decreased significantly.

“We’re shaping a sustainable future by changing the way we work,” says Batista. “The decisions we make today will impact the world we leave behind, and Everpure aligns with our commitment to thinking in generations, not just business quarters.”

The vendor consolidation trap: When one throat to choke costs more than it saves

Vendor consolidation is sold as discipline. Fewer vendors, simpler architecture, better pricing through volume, one throat to choke when something breaks. Every one of those benefits is real on paper. The problem is that the biggest cost of consolidation rarely appears on the slide the procurement team uses to sell it internally, and it does not show up on the savings tracker until the first renewal cycle after the ink is dry.

Within CIO Mastermind’s topic-specific cohorts, which I sometimes facilitate, I hear a version of the same story often enough to recognize the pattern early. A consolidation program gets pitched against a strong multi-year savings target. The first year or two look good. Then a renewal arrives, the remaining vendor prices to the switching cost the company just built for itself, and a meaningful share of the projected savings quietly erodes. The company still ends up with fewer vendors. It does not always end up with the leverage the original business case promised.

What consolidation actually removes

What consolidation actually removes is competitive pressure on the vendor you keep.

That is the part most business cases leave out. Going from a dozen vendors in a category down to three or four feels like simplification, and it is. It is also a message to the vendors you kept about how expensive it would be for you to leave. The fewer live alternatives you maintain, the more accurately a vendor can price to your captivity rather than to the open market. A consolidation deck typically shows how many vendors are being reduced. It rarely shows how many of the remaining vendors could credibly be replaced inside a reasonable switching window. That second slide is the one worth building before the program starts. That capability is often missing.

Procurement teams are not being dishonest when they leave that slide out. Their incentive is to close the program and book the savings target, and the pain of a diminished market shows up two or three years later, on someone else’s dashboard. By the time the first hard renewal arrives, the people who built the original business case have often moved to a different project entirely, and the CIO who is still in the seat is the one negotiating from the position the program created.

The condition that decides the outcome

Consolidation programs succeed or fail on one question, and it has to be answered honestly before the program starts.

Can you walk from this vendor at renewal?

Not in theory. Not with twelve months of migration work. At renewal, inside the window the contract gives you, with a credible alternative that has been exercised recently enough to be real. If the answer is yes, the vendor will price to keep you. If the answer is no, the vendor will price to what you can absorb. Consolidation that leaves you unable to walk is a long-dated price increase with a celebratory kickoff meeting, dressed up as a savings program.

Contract language deserves particular scrutiny here, because it is where a lot of the false confidence comes from. Multi-year agreements often include price increase caps that look protective at signing. Those caps are usually written around the product as it exists at signing. Vendors may repackage functionality into new or higher-priced tiers, leaving the contractual cap covering less of what the company actually needs. A cap that looked airtight in the negotiation can end up covering a shrinking share of what the company actually pays for at renewal.

CIO.com has covered the leverage problem for years, including a piece on how to increase your renegotiation leverage with vendors that frames the handcuff problem directly. The advice in articles like that one is sound. The hard part is applying it in the middle of a consolidation program, when the procurement team is telling you that keeping alternatives warm is wasteful and the CFO is asking why the savings number is dropping.

The CIOs who hold their leverage tend to do one thing differently. They keep one credible alternative warm in every major category they consolidate, even after the primary vendor is chosen. Warm means more than a name on a shortlist. It means a live relationship with the alternative’s account team, some recent proof of concept, and at least one internal team that has actually touched the alternative’s platform. That readiness carries a real cost. Maintaining it may cost far less than an uncontested renewal can quietly take away.

The number that actually matters to the CFO

Most consolidation programs get measured against a single number: the savings projected in year one of the business case. That number rewards aggressive consolidation and quietly punishes the CIO who keeps an alternative warm, because the carrying cost of that alternative shows up immediately while the protection it buys only shows up at the next renewal, two or three years later. Judged against a one-year number, the cautious approach always looks worse.

The number worth tracking instead is the savings figure three years out, measured against what the business case originally promised. That is the number an aggressive consolidation program tends to miss once a full renewal cycle has run its course, and it is a fairer test of whether the program actually worked. It also reframes the conversation with the CFO. A carrying cost presented as insurance against a specific, quantifiable renewal risk is a different ask than a carrying cost presented as overhead, and it tends to get a different answer.

What to do if you inherited the problem

Most of the CIOs I talk to are not starting a consolidation program. They inherited one. They sit down in a seat where the leverage is already gone and the next renewal cliff is six or nine months out.

If that is where you are, the fastest way back to a real negotiating position is not to rebuild leverage everywhere at once. That approach takes years and asks the CFO to fund carrying costs across the entire portfolio before there is any evidence it will pay off. Pick one category instead, ideally not the largest one but the one where a credible alternative can be stood up fastest, and rebuild it inside twelve months. Speed matters more than scale here. A live proof of concept in a smaller category, exercised recently enough to be real, does more for your negotiating position than a partially built case in a larger one.

One proof that you can still move part of the portfolio changes the conversation at every other renewal table. A vendor who knows you have already done it once treats the next renewal differently than a vendor who has only heard you claim you could.

The second you cannot walk, the price stops being yours to negotiate. Most consolidation programs remove your ability to walk as their first move, and most CIOs do not realize they have given it up until the next renewal arrives and reminds them.

What the San Diego Padres CIO does to deliver major league IT experiences

Petco Park consistently ranks among MLB’s top ballparks for fan experience. That doesn’t happen by accident, and it didn’t wait for a star-studded roster or a deep postseason run.

According to Padres CIO Ray Chan, the club made a deliberate choice more than a decade ago to run its tech organization as if every seat were full and the team was playing in October every year. The philosophy was simple — build a World Series-level digital foundation so when the on-field product caught up, the elite fan experience would already be there.

More than a ballpark

Most people know Petco Park as the home of the San Diego Padres, which it is, but the venue was designed to be more than that. In a typical year, it hosts 81 regular-season home games, plus potential postseason contests, and then adds concerts and private events in renovated premium spaces.

By Chan’s count, that totals to nearly 400 annual events, often with more than one on the property in a single day. Different parts of the venue may host different audiences simultaneously, with IT expected to turn spaces quickly and support the unique digital requirements of each event.

The multi-use model puts a premium on flexibility and speed. Spaces are designed to be reconfigured quickly, and the underlying technology stack must adapt just as quick.

An always‑on network

When Chan arrived 15 seasons ago, Petco Park looked very different from a connectivity standpoint. On sellout nights, fans often couldn’t place a call or send a text once they were inside the building. There was no real concept of a digital fan journey.

The first major shift came with deploying a full-venue managed distributed antenna system (DAS) from Verizon, and an Extreme Networks Wi-Fi solution, providing fans, staff, and baseball operations with reliable connectivity throughout the ballpark. That network has since become the converged backbone for almost everything that happens at Petco, including digital ticket entry via the MLB Ballpark app, security and operations, tech like instant replay and dugout tablets used by coaches and players, and in‑venue IPTV and signage, all riding on the same IP infrastructure.

For fans, the network is invisible. For Chan’s team, it’s non‑negotiable. “None of this stuff works without the infrastructure in place,” he says.

Consolidated convenience

The Padres have leaned heavily into the league-standard MLB Ballpark app, which provides a consistent digital experience across all 30 venues, while allowing clubs to customize the local section. At Petco specifically, that app becomes the fan’s control center for digital ticketing, ballpark navigation, and a built-in payments and discount wallets tied to offers like Padres Pay and contactless options.

The result is a highly digitized journey, and for many fans, their first and last interaction with the ballpark occurs on their mobile device, and that’s by design.

Toward frictionlessness

Chan and his team are already looking beyond digital barcodes to facial-authentication-based entry, leveraging MLB’s Go Ahead Entry program rolling out at several parks. In that model, fans enroll once in the app with a selfie, then simply walk through a designated lane while overhead cameras verify identity and automatically scan tickets.

The promise is a hands-free, eyes-up experience where fans no longer need to take out their phones at the gate. Chan says this is the most frictionless way to enter a ballpark, and it even enables personalized greetings by name at the turnstile, another small but memorable touch to create a World Series-caliber experience.

Concessions are another example of how Petco’s IT modernization seamlessly enhances the fan journey. Petco is now a fully cashless venue, so fans pay with credit cards, mobile wallets, or the dedicated Padres Pay capability integrated into the Ballpark app. This reduces transaction friction, speeds lines, and improves security by minimizing cash handling.

IPTV everywhere

The expanding IP television footprint is another hallmark of Petco’s fan experience strategy. New screens throughout the venue serve multiple roles to ensure game coverage is never lost, even when fans leave their seats.

They also show real-time updates and wayfinding, an L-bar format that combines live video with adjacent ad inventory and informational content, and full-screen takeovers during concerts or special events, letting the venue transform its look and feel to match what’s happening on the field or stage.

Because it’s all IP-based, game-day operations and marketing teams can reskin the park on the fly, turning screens into a flexible engagement and monetization channel rather than relying on fixed signage.

Constant modernization

Despite opening in 2004, Petco Park doesn’t feel like a 22-year-old venue. Chan says that’s intentional and points to a continuous program of infrastructure upgrades and capital projects to redo suites, unify premium spaces such as the Western Metal rooftop and loft, and find areas to transform into new experiences.

Beneath those visible changes lies ongoing modernization of the network and systems in terms of upgrading switches, faster Wi-Fi, and backend platforms to support the latest apps and services. As Chan puts it, the goal is to make the park look and feel no older than a couple of years, which requires consistent ownership commitment and alignment between IT and operations.

Perhaps the most important part of Chan’s playbook, however, is cultural rather than technical. He describes the Padres as a listening organization that actively solicits and incorporates fan feedback to refine the experience across seasons.

That mindset is shaping the club’s approach to AI, so instead of chasing it for its own sake, Chan is focused on use cases that improve customer service by using chatbots or AI-assisted voice lines to free staff for higher-value interactions, and solve specific operational problems such as using AI to match lost-and-found queries with a database of found items.

The bigger IT picture

The way Petco Park manages its technology operations offers patterns that can apply beyond sports venues, starting with establishing a converged, resilient backbone. Connectivity is a shared utility layer that everything else depends on, rather than a series of isolated projects. That makes it easier to add new capabilities later without rearchitecting every time.

Chan’s philosophy of building as if every seat were filled also applies across all e-commerce peaks, clinical surges, and manufacturing seasonality. Capacity planning, observability, and failover should be set at Black Friday, not an average Tuesday. And treat your environment as a multiuse and continuously modernizing platform. Petco’s “more than a ballpark” mindset reflects the shift toward mixed-use destinations or campuses that blend learning and events, and offices that evolve into collaboration hubs that chip away at legacy infrastructure. IT leaders across sectors can apply the same rolling-renovation model to networks, identity, observability, and edge infrastructure, keeping technical debt manageable.

❌