Jul 31, 2026
Policy

Forrester says sovereign AI requirements are moving into tech planning

Forrester says tech buyers now set data residency and AI control requirements early, with Europe facing the sharpest pressure.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Forrester says sovereign AI requirements are moving into tech planning
Photo: The Register

Technology buyers are putting sovereign AI requirements into new projects at the planning stage, according to Forrester, as geopolitics, regulation and risk concerns reshape procurement. The shift matters for cloud and AI vendors because buyers are asking for control over data, operations and legal exposure before systems are built, with Europe under the most pressure.

Forrester said organizations around the world are specifying data residency and sovereign AI architecture requirements earlier in technology programs. Dario Maisto, a principal analyst at Forrester, said sovereignty is becoming an imperative for buyers and argued that successful organizations will treat it as an architectural principle from the start, including governance, control across the AI stack and operating models that can adjust to regulatory and geopolitical changes.

What are sovereign AI requirements?

Sovereign AI requirements are controls that determine where AI systems and data are hosted, who can operate them, where models are trained, and which jurisdiction's laws apply. Forrester said buyers are no longer focused only on data location; they are also asking who manages encryption keys and who has operational access.

The issue is sharper in Europe because US technology companies dominate key parts of the market and Europe has fewer domestically developed hyperscale AI platforms, according to Forrester. Maisto described Europe as one of the main test beds for sovereign AI, saying organizations want assurance over how AI systems are built, governed and operated while still using global technology.

The European Union is trying to move that market through public funding. The bloc has launched a tender to establish as many as seven AI gigafactories across Europe, part of a broader push to strengthen technological sovereignty. The projects are set to receive up to €10 billion from EU and national funding, with at least another €20 billion expected from private investors.

The EU also introduced a Technological Sovereignty Package in June aimed at strengthening digital autonomy. One proposal is Union Assurance Levels, or UALs, an auditable four-level control system based on an organization's control over jurisdiction, data processing, supply chains and security.

Gartner said the UAL proposal is likely to create confusion for both providers and buyers because it adds another framework to an already crowded set of cloud sovereignty criteria. That warning matters for vendors selling into Europe: compliance language is becoming part of the product, and competing definitions can slow procurement or make contracts harder to compare.

The market structure gives the issue commercial weight. European providers account for only about 15% of the region's cloud infrastructure market, leaving dominant US suppliers subject to American jurisdiction. The risk is not theoretical: last year, International Criminal Court prosecutor Karim Khan lost access to work-based Microsoft services after the US government imposed sanctions on him.

Gartner forecasts that European spending on sovereign cloud infrastructure services will more than triple between 2025 and 2027 as geopolitical tensions push investment toward homegrown services. For startups and infrastructure vendors, the opening is specific: buyers want verifiable control, not broad claims about sovereignty or AI trust.

This story draws on original reporting from The Register.

More from Policy

All Policy →