IT Trends & Tips for Users

Sovereign AI Is Becoming a Strategic Necessity, But Few Companies Actually Understand It

Sep 7, 2026 6 min read
All articles

Digital sovereignty has long been a boardroom topic, but when it comes to artificial intelligence, it remains mostly a statement of intent. That's the core finding of the IDC study "The State of Sovereign AI Adoption," commissioned by AI provider Cohere. The analysts surveyed more than 500 IT and business decision-makers at large enterprises with more than a billion US dollars in annual revenue across Germany, the UK, the US, and Canada.

A wide gap between ambition and understanding

IDC defines sovereign AI as the free choice and control over the design, development, deployment, accessibility, operation, maintenance, and governance of AI systems, as well as over their underlying technological foundations. The companies surveyed are far from that level of clarity: only 13 percent say the concept is broadly understood within their own organization. Around a third of respondents even struggled to explain sovereign AI in their own words. That leaves a clear gap between the strategic importance assigned to the topic and the actual understanding within companies.

The knowledge gap is even bigger when it comes to the risks sovereign AI is actually meant to address: 78 percent of respondents admit that risk understanding within their company is nonexistent, minimal, or only partial. The specific concerns, though, are clearly outlined: companies name data leaks and privacy violations as the biggest challenge when deploying generative and agentic AI, followed by compliance, regulatory, and legal risks. Hallucinations or faulty AI output, along with missing governance, follow at a considerable distance. The study also reveals a difference in perspective: business units view sovereign AI more through the lens of business risk management, while IT focuses more on regulatory compliance and national or regional requirements.

Germany leads on understanding, but lacks clear governance

In the country comparison, Germany performs comparatively well on understanding the concept: 29 percent of German respondents report high awareness of sovereign AI, notably more than in the UK, US, and Canada. Organizational ownership also differs by country: in Germany, responsibility for sovereign AI sits much more firmly with IT, while in North America a chief AI officer or head of AI is more often in charge. Overall, though, roles and responsibilities are rarely clearly defined, even where the topic is better understood, that hasn't yet translated into a resilient governance structure.

The agent wave raises the pressure

Time pressure is mounting because the next AI generation is already on the horizon. Generative AI is in near-universal use at 99 percent, while the next development step is already looming: the expanded use of AI agents. While only 13 percent of companies currently use prebuilt or third-party agents, that share is expected to rise to 67 percent within twelve months. For internally developed agents, usage is set to grow from 5 to 44 percent over the same period.

This development makes the sovereignty question more urgent. Agents don't just work with information, they increasingly execute tasks independently, interact with systems, and trigger processes on their own. That raises the bar for data control, access rights, governance, and control over the underlying infrastructure. IDC sees this agentic wave as a potential trigger that could turn sovereign AI from a side topic into a strategic corporate initiative, warning that existing approaches and insufficient preparation could otherwise expose companies to new risks.

Infrastructure and skills are holding back implementation

When it comes to implementation, the necessary prerequisites are largely missing. Respondents name infrastructure as the single biggest hurdle, followed by cost and budget, organizational questions, and a lack of skilled staff. Sovereign AI, then, isn't just a matter of picking the right AI model: you also need to clarify where models and data run, who holds access and control, how governance works, and what internal skills are needed for it. German respondents in particular see a need for corresponding capabilities on the vendor side, especially transparent model governance, clear data ownership, and regional hosting guarantees.

Sovereignty becomes a business argument

Sovereign AI is also no longer viewed purely as a security or compliance topic, it's increasingly seen as a potential competitive advantage. Companies associate greater control over their AI systems not just with fewer dependencies, but also with more resilience and the ability to run critical AI applications more independently of external conditions. That shifts the perspective: sovereignty moves from a niche technical topic to a question of business model and strategic freedom to act.

Pressure to act is likely to keep rising: 75 percent of German respondents expect the focus on sovereign AI to grow over the next two to three years, while 62 percent want to bring sensitive AI workloads or data under direct control within a year. IDC therefore recommends that companies build a strategic vision with measurable goals, assign clear responsibility to a CAIO or CIO/CTO, strengthen alignment between IT and business units, and invest in platforms and skills, both internally and externally. Companies that only start addressing sovereign AI once agents are already deeply embedded in business processes risk being too late, since the technical development is outpacing organizational preparation.