Data sovereignty has always been a slightly challenging topic in telecommunications, as it is seemingly contradictory to the original vision of the internet: open, free, and designed without borders. The internet was built with more emphasis on qualities like efficiency, reach, and resiliency. After all, political boundaries don’t matter very much to data packets. This “borderless” design has served companies well amid the connectivity industry’s many evolutions. Content, cloud workloads, and applications must all move freely across networks to maximize their business benefits and technological capabilities. But AI is bringing longstanding data sovereignty tensions back into focus.

Shifting the sovereignty conversation

Many data sovereignty conversations have traditionally revolved around sensitive data, like health care records or banking information. Now that sensitive data includes AI. As AI adoption expands, organizations are paying closer attention to where training, inference, and application traffic moves across their networks. Whether they are hospitals subject to stringent health care regulations or software companies seeking to protect proprietary training data and institutional knowledge, organizations want more visibility into where the data centers housing their data are located, and which geographies their data is being routed through. Ultimately, AI data sovereignty is introducing new constraints into an ecosystem that was originally designed to be open and minimize those constraints. So, as AI is integrated into more business processes, sovereignty is evolving even more from a specialized compliance concern into a broader infrastructure consideration.

The role of global operators

As the providers of the underlying connectivity supporting this ecosystem, global internet carriers play a central role in supporting changing sovereignty needs. The market already reflects this shift. We’re seeing an increase in sovereign cloud initiatives like the Amazon Web Service (AWS) European Sovereign Cloud. These market and technological developments suggest that data sovereignty is already influencing infrastructure investment decisions. As government bodies pass more data residency and privacy laws, heightened sovereignty requirements become more crucial to enterprises. So, where do operators fit?

Supporting enterprise data sovereignty

Historically, many customers of global operators focused primarily on purchasing bandwidth. Now, many of them also want geographical certainty with their bandwidth. Some customers may ask operators to keep traffic inside certain regions or avoid routing through certain transit paths or jurisdictions. But what exactly is sovereign routing, and how is it different from more traditional routing methods?

Sovereign routing uses specific routing policies and network paths to keep traffic within defined geographic or jurisdictional boundaries. Operationally, it entails more routing constraints and policy controls, requiring greater visibility into network paths. The challenge is that every routing constraint reduces some of the flexibility networks traditionally used to optimize performance and resiliency.

As a result, sovereignty requirements introduce additional considerations alongside latency, redundancy, and efficiency. For example, the lowest latency path or most redundant path may now not always be the most compliant path. Operators must help their customers meet these sovereignty requirements without losing the resiliency, efficiency and reach that global connectivity provides.

Practical steps for enterprises

As modern enterprise networks increasingly span multiple public cloud providers, third-party network domains, distributed data centers, AI platforms, and other digital infrastructure, they need more visibility, scalability, and regulatory clarity. Operators can support these needs by reducing unnecessary network hops, thereby lowering third-party exposure and providing better insights into traffic flows.

Enterprises should also understand where AI-related data originates, where it is processed, and how it moves between cloud environments, applications, and users. Enterprises can then evaluate the varying sensitivities between their data sets. Not all data is equally critical, so organizations must align data criticality with risk tolerance, helping define acceptable levels of exposure for different types of data while they are in transit.

Enterprises should also design for provability. Organizations need to understand not only where data is stored, but which networks it traverses in transit. Operators may need to demonstrate how they offer visibility into routing behavior, minimize intermediaries, and validate how traffic enters and exits their networks. Over time, we may also see more specialized, premium connectivity offerings emerge around these requirements. Instead of just providing bandwidth, these services could give customers a clearer picture of how their traffic moves across the network.

The new frontier of enterprise risk

The future is unlikely to be only global or only sovereign. Enterprises will continue to depend on global cloud platforms, global applications, and global connectivity, all while demanding greater control over where data resides and how it moves. Operators will be tasked with delivering local outcomes within a global ecosystem, providing the visibility, routing control, and flexibility needed to support both objectives. These qualities will help enterprises not only know what endpoints their data is traveling to, but which paths their data is traveling between. As data sovereignty requirements evolve, sovereignty and connectivity are not mutually exclusive. The challenge will be supporting sovereignty needs without sacrificing the resiliency and efficiency that global connectivity has always provided.