Data sovereignty: how can the Executive Committee take concrete action?
29 July 2026
For a long time, data sovereignty was seen as an abstract concept, a matter for specialists, or simply another item on the CIO’s roadmap. Yet in the age of artificial intelligence and multicloud environments, reality is catching up with every organization. Sovereignty is no longer merely a security concern: it has become a strategic business issue and a cornerstone of entrepreneurial freedom.
During the 2026 edition of Viva Technology, I had the opportunity to share my vision on this topic during a panel discussion at the OVHcloud booth. Far from being a barrier designed to isolate organizations, sovereignty is what guarantees control over your critical processes and decision-making.
Here is why—and how—executive leadership should take ownership of this issue.
1. Sovereignty Is Not an IT Matter; It Is a Business and Decision-Making Matter
The first mistake is to delegate sovereignty solely to technical teams and ask them to choose a hosting solution. That is approaching the problem from the wrong angle.
Sovereignty is first and foremost about data, and data is the very essence of business: customer data, employee data, contracts, and financial processes. More importantly, it is a critical issue when it comes to decision-making.
Executive committees make decisions based on data transformed into dashboards and reports. If you do not control your data, you do not control your decisions.
With the rise of generative AI, executive teams are now requesting analyses in natural language, directly connected to their databases, without going through the IT department. If this strategic data is hosted or processed without sovereign guarantees, the company’s governance, confidentiality, and decision-making integrity are all at risk.
2. Building Awareness, Training Teams, and Tackling Shadow AI
Sovereignty cannot be achieved solely at the infrastructure level; it is also determined by the everyday practices of every employee.
We all exchange data through collaboration platforms such as Teams and corporate messaging services. Every user should understand that sovereignty starts with a simple question: "What am I sharing, where is it going, and who can access it?"
This challenge is amplified by the rise of Shadow AI—the uncontrolled use of public generative AI tools by employees. Sharing company data or meeting summaries with a non-sovereign third-party LLM is equivalent to relinquishing ownership of the company's intellectual property. Sovereignty must therefore become a daily habit, supported by a significant effort to educate and train teams across the organization, including consultants, managers, and sales professionals.
3. Where to Start: Mapping Risks and Dependencies
For organizations seeking to regain control, where should they begin? We recommend a pragmatic three-step approach.
Step 1: Categorize and Map Your Data
It is impossible to overprotect everything. Organizations must identify their critical data assets. A simple question should be asked at executive level: "Mr. CEO, if all your data disappeared tomorrow, which data would you absolutely need to continue operating?" The answer should form the foundation of your sovereignty strategy.
Step 2: Assess Vendor Dependency
In a world of hybrid architectures and multicloud environments, sovereignty raises a fundamental question: how much freedom do you really have from your technology providers? If a foreign cloud provider decides to increase its prices by 7% every year, or if a government requires it to restrict or suspend services in Europe, what alternatives do you have?
Managing sovereignty means managing software dependencies to avoid technological lock-in and maintain strategic flexibility.
Step 3: Integrate Sovereignty from the Start of Every Project
Sovereignty should not be an additional filter applied at the end of an IT project.
From the earliest stages of a new business initiative—particularly AI-related projects—organizations should assess the sensitivity of the data involved and select the appropriate architecture accordingly: on-premises infrastructure, public cloud, or sovereign cloud solutions certified under robust frameworks such as SecNumCloud in France or ENISA standards across Europe.
4. Audit Access Rights: Who, What, and Why?
Knowing where data is stored is one thing; knowing who can access it is another.
A best practice for maintaining sovereignty is to conduct regular access rights audits—at least once a year.
The objective is not simply to identify who has access to what, but to understand why that access exists. Too often, audits uncover major weaknesses in access-right management. Yet if audit findings are not followed by concrete corrective actions, the problem remains unresolved.
This is where management plays a crucial role. For sovereignty initiatives to be effective, they must be championed by an executive-level sponsor capable of making decisions, setting priorities, and allocating the necessary resources.
Sovereignty Means Trust and Efficiency
There is a common misconception that data sovereignty only creates constraints. In reality, the opposite is true.
Sovereignty should be viewed through the lens of trust: trust in your data, trust in your service providers, and trust in your strategic choices.
Proper data governance—knowing where your data resides, ensuring its integrity, and maintaining its quality—is precisely what enables algorithms and LLMs to perform effectively.
By combining sovereignty with modern principles such as Zero Trust and interoperability, organizations are not building walls around themselves. On the contrary, they are securing the freedom to choose the best tools on the market, switch providers whenever necessary, and remain fully in control of their digital future.
Contact us
Do you have any questions about an article? Do you need help solving your IT issues?
Contact an expertIs your data ready for AI?
Data sovereignty goes beyond where your data is stored. To ensure reliable decision-making and high-performing AI use cases, your data must be secure, accessible and properly governed. DEEP supports you in managing and administering your databases to ensure the availability, integrity and control of your strategic data.

Other articles in the category Trends
Technology Trends 2026: AI, Cybersecurity and Digital Trust
Explore the key technology trends shaping 2026: AI maturity, cybersecurity, data governance, digital sovereignty and enterprise resilience.
Published on
05 January 2026
Helping companies acquire a genuine data culture
Implementing a “Data Intelligence” approach within your organisation is a major project, which entails considering many aspects of the technology. If you want to adopt a data analysis process or, ultimately, use artificial intelligence or machine learning throughout your organisation, you first need to be familiar with your data and have full control over it.
Published on
12 September 2023
7 key technological trends and developments in 2023
Accompany us, and our partner Splunk, to find out about the trends and technological developments to watch out for in the coming months.
Published on
03 April 2023








Our experts answer your questions
Do you have any questions about an article? Do you need help solving your IT issues?