Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Sovereignty beyond residency: Why Gulf governments must rethink AI control | Computer Weekly

By Computer Weekly by By Computer Weekly
August 12, 2026
Home Uncategorized
Share on FacebookShare on Twitter


As Gulf governments accelerate their national artificial intelligence (AI) ambitions, data residency has become a central pillar of digital sovereignty strategies. Yet according to Haider Aziz, general manager for META at Vast Data, focusing solely on keeping data within national borders risks overlooking a more fundamental challenge: maintaining control over how data is accessed, shared, governed and used by increasingly autonomous AI systems.

According to Aziz, many organisations continue to equate sovereignty with residency, despite the growing complexity of modern AI environments.

“Data residency is an important first step, but it only answers one question: where is the data stored?” he said. “Residency provides location. Sovereignty requires control.”

The limits of data residency

Governments across the Gulf have invested heavily in sovereign cloud infrastructure, local datacentres and in-country hosting requirements to ensure sensitive information remains within national borders. However, Aziz argues that these measures alone do not guarantee sovereign AI.

A dataset may physically reside within a country yet remain difficult to govern if it is copied across ministries, exposed through unmanaged permissions, or consumed by multiple AI systems without clear oversight.

“Governments need to know not just that sensitive data remains in-country, but that it is being accessed, governed, used, recovered and audited according to policy across the full AI lifecycle,” he added.

This challenge becomes increasingly significant as governments seek to build cross-agency AI platforms to improve citizen services through data sharing and collaboration.

According to Aziz, one of the biggest obstacles to scaling government AI is not infrastructure, but the ability to support controlled collaboration between ministries and agencies.

Governments want AI systems capable of connecting information across public services, but they cannot allow unrestricted access to sensitive data.

“One ministry may need to share a limited dataset with another without exposing unrelated records,” Aziz explained. “A national AI platform may need to serve many departments, each with different users, data classifications, legal responsibilities and access policies.”

As a result, multi-tenancy and permissions management have become critical requirements for sovereign AI platforms. Ministries need to retain operational independence while participating in shared national AI capabilities.

This requires strong identity controls, tenant isolation, scoped access rights, clear data ownership and comprehensive audit trails capable of demonstrating who accessed data, when and under which authority.

Agentic AI creates a new sovereignty challenge

The rise of agentic AI introduces an entirely new dimension to governance and sovereignty.

Unlike traditional software applications, AI agents can autonomously retrieve information, interact with systems, trigger workflows and exchange context across multiple platforms without direct human intervention.

“Agentic AI changes the sovereignty equation because access is no longer limited to human users or traditional applications,” Aziz said.

He warned that without appropriate governance controls, organisations risk creating what he describes as “shadow data movement”, where sensitive information moves between systems faster than conventional governance processes can monitor or regulate.

Governments must therefore establish clear accountability mechanisms for AI agents, including identity management, permissions controls and detailed activity logging.

“The agent itself is not the sovereignty risk,” said Aziz. “The risk is an environment where agents operate with broad credentials, unclear identity, weak policy boundaries and insufficient audit evidence.”

For Aziz, sovereign control ultimately comes down to answering a series of practical questions. One of the most important is ownership of encryption keys.

“Who holds the keys?” determines who has the authority to decrypt sensitive information, revoke access and maintain control if infrastructure providers, tenants or service relationships change.

Equally important is understanding how data moves between clouds, applications, analytics platforms, AI systems and operational workflows. Governments need visibility not only into datasets, but also into AI-specific artefacts such as prompts, embeddings, retrieved context, inference logs and agent actions.

“Does policy control movement, or is it happening through uncontrolled copies and one-off integrations?” Aziz asked. For ministries deploying AI, sovereign control means enabling authorised access without unnecessarily exposing sensitive information, while retaining evidence that systems comply with policy.

As AI systems are deployed across healthcare, justice, public safety, citizen services and critical infrastructure, Aziz believes auditability is becoming just as important as residency.

“If a government cannot prove who accessed a sensitive dataset, which AI system used it, what context was retrieved or how an output was generated, then sovereignty becomes a statement rather than an operating model,” he said.

Comprehensive audit trails and AI lineage capabilities are therefore becoming essential for public sector AI governance. At the same time, governments must avoid becoming locked into individual infrastructure providers.

Aziz argues that portability is emerging as a critical component of sovereignty because organisations need the ability to move, recover or isolate workloads if regulations change, risks emerge, or strategic priorities evolve. “Without portability, cloud choice exists on paper but not in practice,” he said.

Building sovereign AI in the Gulf

Looking ahead, Aziz believes Gulf countries are uniquely positioned to establish global leadership in sovereign AI because many national AI programmes are being built from the ground up rather than retrofitted onto decades-old infrastructure.

However, success will depend on combining technical controls with governance frameworks that address classification, access management, key ownership, tenant isolation, recovery planning, auditability and portability.

He also cautioned against creating fragmented data architectures where every ministry or AI project builds its own isolated environment.

“The stronger model is shared infrastructure with clear policy boundaries, so governments can scale AI across public services without losing control.” Said Aziz.

“The countries that lead will not simply be those that buy the most compute or host the largest models. They will be the ones that can turn national data into trusted AI services while proving control over how that data is used. Compute creates AI capacity. Governed data creates sovereign AI advantage.”



Source link

By Computer Weekly

By Computer Weekly

Next Post
NBN Co passes fibre tipping point as speed uplift carries FY26 growth | Computer Weekly

NBN Co passes fibre tipping point as speed uplift carries FY26 growth | Computer Weekly

Recommended.

Truth Social’s New AI Chatbot Is Donald Trump’s Media Diet Incarnate

Truth Social’s New AI Chatbot Is Donald Trump’s Media Diet Incarnate

August 8, 2025
Palo Alto Networks y Deutsche Telekom aportan seguridad basada en IA

Palo Alto Networks y Deutsche Telekom aportan seguridad basada en IA

June 9, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio