Future-Ready AI: Navigating Sovereign AI Infrastructure Choices
Sovereign AI has moved from a compliance question to a matter of national autonomy, and enterprise leaders are now navigating it as a board-level infrastructure decision. Tom Shields and Russell Fishman of NetApp join Nick Patience of Futurum to unpack what's driving that shift, how sovereign strategy differs by region, and what data infrastructure requirements regulated organizations can no longer treat as optional.
Sovereign AI has moved from a compliance issue to a strategic imperative. As governments and highly regulated enterprises determine who controls the compute, data, and AI models supporting critical infrastructure, the conversation has moved from the IT department to the boardroom.
Nick Patience, Vice President and AI Platforms Practice Lead at Futurum, brings the question of sovereign AI strategy to Tom Shields, Senior Director of Marketing at NetApp, and Russell Fishman, Senior Director of Field Advocacy and Solutions Technology at NetApp. Together they break down why sovereign AI has moved to the forefront and what enterprise leaders need to understand before making critical decisions.
The conversation walks through the layers hiding inside the term "sovereign AI," from data sovereignty to operational and technological sovereignty, and traces the events pushing this to the board level: the U.S. Cloud Act, the EU's new Cloud and AI Development Act, and the U.S. government's intervention blocking use of Anthropic's frontier models. Shields and Fishman also map how sovereign strategy diverges by region, from state-funded builds in the Middle East to ecosystem-led national labs in Asia, and detail the data infrastructure requirements, a unified control plane, security by design, and governance at the source that regulated industries can no longer treat as optional.
They unpack the layers hiding inside the term "sovereign AI," from data sovereignty to operational and technological sovereignty, while examining the policy and geopolitical forces pushing this to the board level: the U.S. Cloud Act, the EU's new Cloud and AI Development Act, and the U.S. government's intervention blocking use of Anthropic's frontier models. Shields and Fishman also compare how sovereign AI strategies differ across regions, from state-backed infrastructure investments in the Middle East to ecosystem-driven national initiatives in Asia. and detail the data infrastructure requirements, security, and governance that regulated industries can no longer treat as optional.
Key Takeaways:
🔹 Sovereignty splits into three distinct layers. Data sovereignty covers jurisdictional law, operational sovereignty covers provider transparency, and technological sovereignty covers control of the stack itself. Shields frames sovereign AI as the umbrella tying all three to national security, cultural preservation, and economic competitiveness.
🔹 Geopolitical flashpoints are compressing the timeline to board-level urgency. Shields points to the U.S. Cloud Act, frontier model capabilities accelerating month over month, and the U.S. government blocking access to Anthropic's models as the data points that are forcing enterprises to act now rather than plan for later.
🔹 Regional sovereign AI strategy has no single template. The U.S. approach is market-driven and enterprise-funded while the EU's is risk-based and state-funded around the AI Act, and the Middle East is building sovereign capability from scratch through direct state investment.
🔹 Data infrastructure carries the real weight of a sovereign strategy. Fishman identifies a unified control plane, security built in rather than bolted on, and governance applied at the data layer as the requirements regulated organizations can't skip, particularly as legal frameworks now enforce what used to be best practice.
🔹 Regulatory clarity is giving organizations room to invest. Fishman argues that the uncertainty enterprises faced before these frameworks existed, not knowing what was acceptable, was the real barrier holding back sovereign AI investment.
The infrastructure decisions enterprises make now around sovereign AI will shape how much control they hold over their own AI future, and that calculus now sits squarely with the board, not just the technology team.
Be sure to check out our extended coverage in The Sovereign AI Series, including Episode 2 with Russell Fishman and Tom Shields.
Watch the full video at sixfivemedia.com, and be sure to subscribe to our YouTube channel so you never miss an episode.
Learn more about NetApp's approach to data sovereignty at: https://www.netapp.com/data-storage/data-sovereignty/
Disclaimer: Six Five Media is for information and entertainment purposes only. Over the course of this webcast, we may talk about companies that are publicly traded, and we may even reference that fact and their equity share price, but please do not take anything that we say as a recommendation about what you should do with your investment dollars. We are not investment advisors, and we ask that you do not treat us as such.
Tom Shields:
It's shifting from just sovereignty being a compliance issue to really being about national autonomy. Countries don't want to depend on foreign tech to maintain critical services for things like the power grid, hospitals, defense.
Nick Patience:
Hello, and welcome to another Six Five virtual webcast. I'm Nick Patience, the AI Platforms Practice Lead here at Futurum. AI conversations have evolved dramatically over the last year or so. The discussion is no longer just about building better models. It's increasingly about where AI operates, who controls it, and how organizations can maintain trust, governance, and resilience as AI becomes part of the critical infrastructure. Today, we're exploring sovereign AI with Tom Shields, Senior Director of Marketing at NetApp, and Russell Fishman, Senior Director of Field Advocacy and Solutions Technology, also NetApp. Welcome to The Six Five.
Tom Shields:
Happy to be here.
Russell Fishman:
Thanks for having us, Nick. Thank you.
Nick Patience:
The first question I'd like to put to you is, we hear terms like sovereign AI, sovereign cloud, data sovereignty, almost used interchangeably. How should enterprise leaders think about the differences? Maybe Tom, we'll start with you, and then Russell, I'd like to hear what you're seeing from customers.
Tom Shields:
Yeah, I'll take a shot at defining sovereign AI. I think what we're talking about here is really a nation state's ambition to develop and use AI without foreign assistance. And it's in support of sovereign objectives like national security, cybersecurity. cultural preservation, and of course, economic competitiveness. So access to the control of the compute data, the models, is really becoming the new basis for national and industrial competitiveness. So it's shifting from just sovereignty being a compliance issue to really being about national autonomy. Countries don't want to depend on foreign tech to maintain critical services for things like the power grid. hospitals, defense, and they also want to spur economic development, so they want to spur research and investment, and they want to build local skills. So these are both critical objectives. Now we get to the soup of different sovereignty terms. You think about AI, sovereign AI, as what I just described, but within it there's some other concepts. Data sovereignty. The data is governed by the laws of the originating jurisdiction. So for Europe, it would be the EU. Then there's operational sovereignty, which is transparency and control over the provider's operations, which usually are in clouds. And that's based on locality and people actually operating the cloud in those localities. Then there's tech sovereignty. That's about control over the AI tech stack, and that includes the models, the data, the tools. the infrastructure and even the power and energy. So just to net it out, Sovereign AI wraps all this together, and it's about developing and deploying AI systems within the jurisdictional boundaries so that people have control of data security and compliance to jurisdictional regulations. And who's it in fact, it's most relevant really for regulated industries. So we're talking finance, healthcare, government services, especially defense.
Russell Fishman:
I'd probably just add a few things to that. Right. So one of the things that we're seeing is in addition to all the things that Tom mentioned, Nick, we're also seeing just this interest in investing in the growth opportunities, economic advantages, that AI might bring on a regional basis. So you can think of this more like I'm a government in some way and I'm thinking, hey, how do I accelerate economic development in my country? One of the ways of doing that is making sure that AI is available on the terms that I want to my local economy. That could be through an investment where it's not essentially a commercial environment, where it's available for free, to local companies. It could be to spur investment in some foundational AI work, for example, foundational model training or frontier models for countries that may be not English-speaking, where we tend to think about LLMs and frontier models, but it's always through, or mostly through the lens of English-speaking, where we're replete with options. not so much when you're talking about other languages, especially non-Latin languages. There are some other things that I think are driving this sovereign AI boom, and I do see it that way. When we sit down with customers, I know that, Tom, you talked about technological sovereignty. Actually, it's funny, I think there's no doubt there's some concern around that, but I would say that more often than not, the use of technology that isn't local isn't so much of a problem as it is the service elements around it. As long as the equipment is run and operated and managed by folks within that jurisdiction, The belief is that you're isolated from any potential geopolitical issues out there. So at the end of the day, I think sovereign is something that I think is evolving pretty quickly. But to the points that Tom made, it is the regulatory environment that is going to drive organizations to have to consider sovereign AI and the data supporting it as well.
Nick Patience:
Yeah, so sovereignty is a multifaceted thing, but it feels like sovereign AI in particular has gone from being a niche discussion to being a strategic priority almost seemingly overnight. So, what's driving that shift and why is this now a conversation happening at the board level? Tom, maybe let's start with you and then Russell, bring in what you're hearing from customers.
Tom Shields:
Yeah, I think in general, just AI is a technology that amplifies the stakes. So it makes the control of data and models and infrastructure, you know, very much more consequential to the nation state's competitiveness, security and defense. And what we've seen in the last several months, you know, people reacting to the U.S. Cloud Act, U.S. access to data stored on clouds for law enforcement purposes, kind of there's a shadow of risk there since the major cloud providers are embedded everywhere in the world. So that's one thing. Then there's the speed of advancement of frontier model capability. Things are just moving at breakneck speed and, you know, intelligence thresholds are being shattered seemingly every couple months. And then there's the power of AI use in defense is becoming clearer And then most recently, things are starting to happen here in governments. The U.S. government has intervened to block the use of Anthropic's cutting edge frontier models. So we saw that recently. So all these things, all these data points, to me kind of explain the urgency and why things are percolating up to the board level. And of course, you know, these considerations are prompting nations to build sovereign AI stacks in response. And so we see the recent legislation from EMEA, the EU Cloud and AI Development Act, it just came out in June. And it really addresses two key vulnerabilities in Europe. One is the lack of data center capacity. And the second is that U.S. companies control more than 70% of the European cloud market. And clouds are where the scale is to do AI, right? The risks are reacting to, with that legislation, are the U.S. Cloud Act, and the possibility that there's a kill switch, right? That those clouds or access to data can be shut off. And so it's opening up new opportunities for other players besides the hyperscale cloud providers to offer sovereign AI services.
Russell Fishman:
Yeah, I mean, just to pile on to what Tom's saying, look, I think, you know, we're definitely seeing some differences in the way that customers are looking at this. I mean, you know, if you talk to the average US customer, it depends if they have international aspects to their business. Of course a US multinational is subject to the regulations and limitations of all the places it works in. So those folks are absolutely very aware. of the proliferation of these new regulations and limitations. You talked about a few of them, Tom, everywhere. It's not just the EU, of course, it's the Middle East, the United Arab Emirates with the Information Assurance Regulation. If you go to Singapore, you would look at the new frameworks they've put in place around generative AI. The point is that you're seeing these regulations pop up in lots of different places. It's becoming quite a complex landscape for a lot of these organizations to deal with. If you talk to a company that's not multinational, this isn't an issue. In the US, it's not something that's even top of mind. You look at Canada, though, just across the border, and it's absolutely top of mind. So the reality is that I think that vendors, and NetApp is not immune from this, are having to look at it through multiple lenses. Of course, we're working with the hyperscalers that Tom mentioned and organizations that maybe don't have quite the same limitations that these regulations and frameworks put on them, at the same time helping sovereign clouds and sovereign AI clouds in particular to meet those challenges and it really comes down to. Agility, that's the word that I would say here, because even if we have, you say, hey, this is the current situation today. The reality is, it's not going to stay that way. Right. Nick, I mean, we're not, this isn't a static environment. It's changing and it's changing really rapidly. So organizations are thinking, look, even if I don't know where I need to be. The idea that I'm building something that has that flexibility. For us, it's the data side of things, but it has that flexibility and agility to mean that I can adapt to whatever comes at me. That's the key thing. And the last thing I'll just add is that I know that it's maybe a slightly counterintuitive view, but I know that mostly people will think, hey, regulation tends to slow down or stifle innovation. I take a slightly different view to that. I think that the lack of certainty that organizations found themselves in, in terms of what is acceptable, what's the right way to do things, that actually was holding people back. That was holding organizations back. They were saying, look, it's quite risky to get involved now because the standards haven't been established. If I start investing and then it turns out that I'm, I'm off kilter in terms of what's needed from a regulation legal perspective, then that's going to be a problem. So having this in place actually is not a bad thing. Now, do people know exactly where our folks are going to land from an enforcement perspective? No, we don't know that yet, but actually starting to see these regulations, it's creating an environment where it feels a little bit more stable to organization.
Nick Patience:
Yeah, I think that's an interesting point. I mean, and that stability is a kind of, it may be a constraint, but constraints can drive innovations, can't they? So it's like now you know within which, yeah, the framework within which you can work. Let's see how much we can prize out of this AI stuff within those boundaries. So we've been discussing, obviously, various kinds of sovereign AI. There's no single blueprint for this. And as different regions pursue their own priorities, what should enterprise leaders understand about those differences? So maybe, Tom, we could start. We've talked a little bit about some of the various regions. Maybe dive into some of the ones we haven't touched on so much. And then, Russell, tell us what you're seeing in the market.
Tom Shields:
Yeah, I think this is a global thing that's happening. It's not just the EU. It's elements of it are touching even the US, right? I mean, we've seen some things I talked about with Anthropic and government is getting involved. EU for sure, it's kind of driven by the analysis of the risk and there's a lot of legislation happening around regulating this. In the Middle East, there's aggressive, you know, state-funded sovereign capability being built from scratch. So I would point to Humane there. In Asia, we're seeing kind of our equivalents of the national labs partnering up to provide sovereign infrastructure. I would point to a player like RIKEN in Japan, or FREI. Also, we see it in Australia. India has a huge emphasis on sovereign AI. So it's a pretty global phenomenon, and the trend is clear. People just want to control their destiny, their economic and defense and security destiny.
Nick Patience:
Yeah. And Russell, is that what you're seeing?
Russell Fishman:
Yeah. I mean, look, I think you touched on, Tom, the national critical infrastructures. with, you know, I talked a little bit earlier about this idea that there's almost an investment happening at a, at a nation state level. And the way that that's being factored is by a combination of public and private, right. The public side is exactly as Tom mentioned, those national labs, which typically came more from an HPC space to be honest with you, sort of moved into this sort of AI and HPC space. And he mentioned a couple, RIKEN for example, in Japan's a good one where, you know, they're making that transition and building, you know, something new that's going to help support these environments. There is a bit of an interesting difference between some of the early players and big Neo clouds you've heard in the Americas, for example, and the sovereign clouds. One of the big differences is that the sovereign clouds tend to be offering a more complete platform environment, which means that it will come with the tools and the platforms necessary for maybe a less sophisticated organization to take advantage of and go build something to a use case. And that's really very different from the more GPU as a service or infrastructure as a service players that you've heard a lot of in the news, and those were the ones, the NeoClouds. And the reason for that is that when you invest in an economy, you probably are assuming that the organizations that are going to take advantage and start innovating using AI might not have that deep data science experience, data engineering experience, and all this other stuff. So the more you can make that turnkey, the more accessible you make it to local players. So there's definitely quite a lot of variation, back to your original question, there's quite a lot of variation in how we see people addressing sovereign. It's more, as Tom mentioned, more of an umbrella concept. But I think that what's going to happen is sovereign is going to show up with a new raft of innovation that is gonna accelerate AI into use cases that we haven't even imagined yet. And that only happens, I've used this phrase before, maybe like an iPhone moment. It's when you start getting in the hands of folks that haven't traditionally come from a tech or an AI background and start to think about business problems in new ways where it isn't about AI, making something more AI is actually starting fundamentally from a use case that could never even have been considered.
Nick Patience:
Yeah, another one of those kind of constraints, isn't it, that drives innovation. Yeah, it's a good kind of metaphor. So we've talked about the regional differences quite a bit, so let's talk a bit more about the actual technology and the product. So once organizations have concluded that sovereign AI is a strategic priority, so what are the kind of capabilities that become non-negotiable in the underlying infrastructure? So Russell, maybe start with the data management perspective, and then Tom, your thoughts on this as well.
Russell Fishman:
Yeah, so it's one of the things that we've always noticed, Nick, is that organizations tend to get framed to the market as primarily a GPU problem, right? If I throw a bunch of GPU at it, you know, compute accelerated compute more, more generically, um, then, then good stuff will happen. And then it becomes a tooling issue. Do I have the right ML ops tools? Do I have the right platform? Environments in which, you know, and I wouldn't even say data scientists, data engineers, but even just AI practitioners can go do their thing. And now we see a lot more in the market from vendors who are creating. More business oriented AI platforms where you don't have to be any. You can just be a business person and it's all very easy. Maybe it's a version of vibe coding, if you will. So we see all that. And then what we see is the reality of where people get to and fail. And this is the reality. We're at a really interesting inflection point from our perspective in the adoption of AI. And that inflection point is that there's a huge amount of opportunity and a lot of investment. Organizations quite rightly start with POCs and then eventually the idea is to move to scale production. But so many of these projects never make it past POC. There's a whole variety of different reasons for that. But one thing we see very consistently is data, data management and, and people and organizations greatly underestimate the complexity and needs of getting your data right. to be successful at AI, not necessarily just in a POC, but when you actually get to production. Remember, production is where you get the ROI. So if you don't get to production, you never get the ROI. And then, of course, that next project is a much harder, tougher hill to climb to convince a board to give you some money. So from a data perspective, it really comes down to a few different things. Firstly, we've talked about sovereign AI and this new type of cloud. Reality is that for certain types of data, for certain types of workload, we may be talking about hyperscaler cloud as well. You're talking about organizations that have an existing data strategy and an existing data gravity that might not align to where those capabilities for AI sit today. That's a problem, right? That starts to create complexity. Right. And, you know, you want to be making it relatively easy to manage your data across all these different places. That's what we call it in the storage side is a kind of a unified control plane, which means that the data remains. visible, manageable, and portable across all of those different environments. And it has to be somewhat seamless. Remember, it's not just the data itself. It's all the stuff that sits around the data. So for example, security is the security and governance following that data as it moves through. And security is an important part of this as well. As we expand the boundaries of where data sits and start to introduce it to new environments, it opens up the chance of significant risk to that data. And let's be clear, the sort of data we're tending to use for AI is not limited to non-confidential data. It tends to be the crown jewels of any organization. So things like encryption, anti-exfiltration, autonomous ransomware. Things that are just inherently built into this data platform, wherever you need the data, you have the same features and capabilities. So it really becomes a single data plane rather than a series of individual data planes cobbled together, where it becomes super inconsistent. And then governance would be the third piece of it, where we're really thinking about things like traceability, data provenance, and really, really importantly, policy guardrails. Now, all of those things that I mentioned, they're all things that are best practices, but frankly, Nick, they're also things that are now being legally required by the regulatory frameworks. And this is not a, oh, if you don't do it, you get a slap on the wrist. No, we're talking about the same sorts of requirements that we first saw come to market with things like GDPR all that time ago, right? These are serious financial implications, but more than the financial implications, they are reputational impact implications, right? We've seen so many organizations who are controlling their data in a single location get caught out by ransomware gangs. Just imagine how more difficult and complex that becomes as you expand beyond the boundaries of your traditional networks, right? And then, you know, from a sovereign perspective, we're helping people build sovereign clouds. It's things like multi-tenancy. These are ultimately service providers, right? Right. So how do we start to isolate and guarantee control of data on a per tenant basis? Really important for managed service providers and sovereign cloud providers as well. And then probably the last piece I would just mention is, we talked about this agility and flexibility piece, right? Just as it's flexible and agile from a governance and regulatory framework perspective. It's also, we need the same from an AI perspective. What I mean by that is. the state of the art, the tools we're using, the use cases we're delivering, those are changing. They're changing, maybe slowed down very, very slightly, but not much. And what you have today, whatever you build in terms of a data foundation, you would want that to be suitable for whatever comes at you. Whether that's a year from now or three years from now, you don't want to fundamentally change that data foundation. So that flexibility, agility, that interoperability as well is super important.
Tom Shields:
So I'm just going to bring it up a level and close out here. So Russell explained what's important at the data layer under a variety of different sovereign AI solutions. I think if I'm an enterprise, I have to understand that what we're seeing is the AI supply chain is fragmenting. And people need to be, if you're in a regulated industry or serving those industries in your major markets, you have to align your AI strategy with the nation state's expectations. And you have to move from what we've enjoyed up to date, which is global standards, of clouds everywhere that are mainly hyperscaler clouds for prosecuting AI to more regional solutions. And so that involves, you know, probably planning to spend a little more. You know, the hyperscaler have scale. And some of these other players will not. So you also need to be considering your workloads, you know, and not everything needs to be in a sovereign cloud, even in regulated industries. So look at the sensitivity of the data and just tier your workloads and have a sovereignty tier rating. and expand your ecosystem options, start to understand those local players, be it hypers, neos, or MSPs, or telcos. Within those, like we said, look at security compliance control afforded at the data layer under any solution. And also look for the ways that it can afford you flexibility and optionability as the technology or regulations change.
Nick Patience:
So the headline is clear. Sovereign AI is not just a technology decision, as you've seen from this discussion. It's a strategic, it's a security and economic development doctrine as well. The infrastructure choices organizations make today will determine how much control they have over their AI-driven future. Thanks for tuning into this Six Five virtual podcast. Tom, Russell, thank you very much. See you next time.
MORE VIDEOS
NVIDIA’s $500B AI Bet, Anthropic’s Watermark Gamble & the Edge AI Debate | Ep. 315
NVIDIA mobilizes over $500 billion in third-party capital to finance AI infrastructure, Anthropic doubles down on data-center ownership and mandatory content watermarking, and Patrick Moorhead and Daniel Newman debate whether distributed AI at the edge is finally ready to accelerate, all on Ep. 315 of The Six Five Pod.
Modern Mainframes, Al, and Quantum: Rethinking Enterprise Infrastructure
AI keeps getting framed as the disruption that finally sidelines the mainframe. Tom McPherson, General Manager of IBM Z and LinuxONE, joins Daniel Newman and Greg Lotko on The Main Scoop to explain why the opposite is happening, and what platform-native modernization delivers that lift-and-shift migration can't.
Six Five Pod Ep. 314: TeraFab, Memory's Comeback, and the Custom Silicon Debate
Patrick Moorhead and Daniel Newman cover Tesla and SpaceX's $16.8 billion TerraFab chip factory, Samsung's zHBM debut at FMS 2026, a week of frontier model launches, and a simulated debate for “The Flip” over whether custom silicon will capture the majority of AI workload dollars by 2028. The episode closes with earnings from SpaceX, Palantir, AMD, Astera Labs, IonQ, and Lattice Semiconductor.
Other Categories
CYBERSECURITY

Threat Intelligence: Insights on Cybersecurity from Secureworks
Alex Rose from Secureworks joins Shira Rubinoff on the Cybersphere to share his insights on the critical role of threat intelligence in modern cybersecurity efforts, underscoring the importance of proactive, intelligence-driven defense mechanisms.
QUANTUM

Quantum in Action: Insights and Applications with Matt Kinsella
Quantum is no longer a technology of the future; the quantum opportunity is here now. During this keynote conversation, Infleqtion CEO, Matt Kinsella will explore the latest quantum developments and how organizations can best leverage quantum to their advantage.

Accelerating Breakthrough Quantum Applications with Neutral Atoms
Our planet needs major breakthroughs for a more sustainable future and quantum computing promises to provide a path to new solutions in a variety of industry segments. This talk will explore what it takes for quantum computers to be able to solve these significant computational challenges, and will show that the timeline to addressing valuable applications may be sooner than previously thought.

