As AI adoption accelerates across Singapore, a question is surfacing at the board level that goes well beyond data residency: how much control do organisations have over the AI systems they are rapidly embedding into core operations?
“AI sovereignty” has long been shorthand for sovereign cloud and compliance checkboxes; that framing is starting to fall short. What’s emerging instead is a harder conversation — one that has shifted from technical policy to business risk, driven by geopolitical uncertainty and the rise of autonomous, agentic AI systems.
For Singapore organisations that rely heavily on a small set of global cloud and AI vendors, the exposure is real. But full-stack AI independence is a fantasy for most. The more practical path emerging is “operational sovereignty”: the ability to move across models, platforms, and environments without rebuilding from scratch.
That flexibility matters enormously for enterprises navigating tightening regulations, geopolitical tensions, and mounting pressure to operationalise AI safely at scale.
The layered reality of AI control
The confusion between data residency and AI sovereignty is one of the most significant blind spots in boardrooms today, according to Andrew Boyd, senior vice president and general manager for Asia Pacific and Japan at Dataiku.
“If I think about data sovereignty or data residency in its first instance, that’s the simplest thing. It’s really where the data that you have is stored, which geography it’s processed in, and under which legal regime,” Boyd explains.

“Then when I think about AI sovereignty, it adds layers to it. AI sovereignty can be about how the AI model processes your data. For example, depending on the regulation, if you said you want a sovereign AI system, again using Indonesia, you would need to make sure that your LLM is physically located in Indonesia, the data is not going offshore, and where the model runs is in Indonesia.” Andrew Boyd
This distinction became sharply visible recently when a major government placed an export ban on specific AI models.
As Boyd notes: “We’ve seen some of the ramifications of this come to light over the last few days in the media, if you’ve seen what’s happened with the US government and Anthropic. What we’ve seen is the US government placing an export ban on a couple of models for non-US citizens and non-US enterprises.”
Josephine Teo, Singapore’s Minister for Digital Development and Information, reinforces this layered view, noting that “sovereign AI” means different things to different stakeholders. “What matters is the ability to maintain meaningful control over your data, your decisions, and your AI workflows,” she told FutureCIO.
Sovereignty as a strategic priority
Interest in AI sovereignty has intensified dramatically. According to an IDC study commissioned by Dell Technologies, sovereign AI climbed from seventh to second in investment priority among Asia-Pacific governments within a year.
The research, which polled 360 government IT decision-makers across eight markets including Singapore, India, Indonesia, Japan, and South Korea, found that 46.1% are actively evaluating sovereign AI technologies, with 36.1% running initial proofs of concept.
Some 76.9% believe investing in sovereign AI enhances their agency’s resilience against geopolitical risks and supply chain disruptions. However, just 3.1% are currently investing significantly in it, highlighting a gap between intent and action.
Industry observers attribute this growing focus to an uncertain geopolitical environment and the perception of AI as both a competitive advantage and a valuable national capability, driving emphasis on sovereignty and the need to have control over the fundamental AI stack and value chain.
The board-level risk that demands a governance response
The stakes are high enough that governance is no longer optional. According to Boyd, this risk sits at the same level as cybersecurity threats. “It’s a board-level risk. It should be at the same level as cybersecurity risks,” he emphasises, citing a Deloitte study which found that 83% of boards see understanding AI sovereignty risks and requirements as critical.
The challenge is particularly acute for highly regulated sectors. “Highly regulated industries like FSI, healthcare and government are leading in that adoption, as you would expect, because they are required to. The reality is they are also slower in adoption in many areas because they are leading in regulation, control and governance.”
Boyd points to an emerging best practice: creating innovation hubs within controlled environments. “They control the data within a dedicated environment, learn quickly from that, and then apply it to their more traditional parts of the business in a more controlled way. That helps them manage governance across both data and AI.”
For enterprises, the governance framework must extend to the lifecycle management of AI agents. Boyd recounts a revealing example: “We’re working with a large company where we deployed our agent management system in a feedback phase. They told us they had developed 500 agents that week. We ran that basic visibility step and actually found 2,000.”
This discovery points to shadow AI — the quiet erosion of sovereignty from within. “The first and most obvious, and probably the easiest to get visibility on, is that people will be using AI tools or creating AI agents in the organisation,” Boyd advises. “You need to, as a company, have an agreed, approved set of AI use cases and cover off the basics.”
Without visibility, there can be no sovereignty. As organisations move from experimenting to deploying agentic AI, agents acting autonomously across platforms introduce governance blindspots. Infrastructure is a critical governance layer because conversations need to move beyond LLMs and focus on how AI runs across fabrics.
Building for portability and optionality
With geopolitical tensions affecting access to leading AI models, enterprise resilience depends on architectural flexibility. Boyd advises: “For the most critical use cases and applications, one way to manage that dependency is to have multiple providers within your platform. This is similar to cloud, where many companies adopt a multi-cloud approach or combine on-premise with a cloud provider.”
Leading organisations are adopting a “mesh” approach. “What I advise customers, and what leading organisations are doing, is adopting a platform approach that provides optionality. They use multiple models, compare them, and A/B test them against the same use case repeatedly. This is important because model performance changes frequently.”
This optionality extends to geography. “I’m seeing companies and governments use models from different geographies, including the US, Europe and others, to manage geopolitical considerations.”
CIOs face critical decisions about model independence and long-term strategic choices to avoid being locked into the wrong technology several years down the road. However, these questions are difficult to answer in an evolving market, with no clear paths yet established.
Concentrating on concentration risk: The MAS perspective
The Monetary Authority of Singapore’s focus on concentration risk assessment is a direct challenge to enterprises that rely heavily on a small set of AI providers. Boyd contextualises this in familiar risk management terms:
“Dependency risk is in my mind a factor of two things. It’s, one, the number of systems that you’re dependent on, and two, the criticality of the use case.” Andrew Boyd
The architectural response is to design provider-agnostic AI platforms. “You must enable multiple LLM providers and data sources within your one system, and you should, in my opinion, allow seamless switching between models when needed without having to retrain users.”
This mirrors existing best practices. “I go back to MAS and what they do with cloud providers. You do not want all your applications and systems on one single cloud provider or tech provider. You need to balance between cloud providers and on-prem and similar,” continues Boyd.
A risk-based approach to AI sovereignty considers three vectors: whether the use case is highly sensitive, highly autonomous, or highly regulated. Based on that assessment, organisations determine their requirements for model, data, and infrastructure sovereignty.
A two-speed strategy for sustainable AI adoption
Boyd recommends a two-speed approach balancing controlled experimentation with robust governance.
“Think about it in two speeds. First, you want to be able to get users to experience it. We have to lift the overall education bar. To do that, as a company, you should provide access to these tools in a really controlled way for people to go and learn and experiment.”
“In parallel, the best people spend the most time getting the scaffolding right. And that scaffolding is not which LLM provider you choose. … It’s actually thinking about my governance, my risk and my control for it.”
Key components of this scaffolding include data sovereignty (knowing how data moves across borders and complies with regulations), model governance (clear understanding of which model is used and its risks), infrastructure sovereignty (running trusted cloud and security frameworks), and governance sovereignty (enforcing policies that reflect local laws and standards).
Minister Teo reinforces that many of the controls required are not new. Third-party risk management, data management obligations, access controls, and incident notification requirements are embedded in existing frameworks like CSA’s Code of Practice, which should be applied to AI deployments.
Control without constraint
The AI sovereignty challenge is not about rejecting global providers but about building governance capabilities that maintain optionality. “The best people spend the most time getting the scaffolding right,” Boyd summarises.
For Singapore’s CIOs and boards, the question is no longer whether to prioritise AI sovereignty, but whether they have the frameworks in place to act on it now. Enterprises that embed sovereignty and resilience into their AI strategy from the start will avoid the costly re-engineering that others will inevitably face.








