THE NEXT FIVE
THE NEXT FIVE - EPISODE 46
Code and Conscience: Intelligence Within and Without Borders
Can global enterprise innovation really survive in a world of digital borders?






































The Next Five is the FT’s partner-supported podcast, exploring the future of industries through expert insights and thought-provoking discussions with host, Tom Parker. Each episode brings together leading voices to analyse the trends, innovations, challenges and opportunities shaping the next five years in business, geo politics, technology, health and lifestyle.
Featured in this episode:
Tom Parker
Executive Producer & Presenter
Stéphane Israël
Managing Director of the AWS European Sovereign Cloud and Digital Sovereignty, AWS
Ali Ustun
Senior Partner and Global Co-Leader for Global Data and AI Foundations, McKinsey & Company
Dr. Catherine di Lorenzo
Partner, A&O Shearman
Sovereignty, by definition, is being updated. Sovereignty 2.0.
Under geopolitical tensions, supply chain dependencies and competing regional regulations, the discussion around digital sovereignty is shaping where you're allowed to build, what models you’re allowed to train on, and who's allowed to see the results.
Competing lines are being drawn. On one side there are those calling for the democratisation of AI and opening the global doors to innovation. On another is a fragmented map of regional regulations, like the strict mandates of the EU AI Act.
Bubbling underneath is the geopolitical chess match, primarily between the US and China, turning data, frontier models and the infrastructure behind them into a matter of national security.
All of this offers up some big questions for governments and businesses. One no bigger than this: Can global enterprise innovation really survive in a world of digital borders?
Joining host Tom Parker is Stéphane Israël, Managing Director of the AWS European Sovereign Cloud and Digital Sovereignty at AWS, alongside Ali Ustun, Senior Partner from McKinsey’s Middle East Office and co-leader of their global Data and AI Foundations Service Line and Dr. Catherine di Lorenzo, Partner at A&O Shearman.
Sources: FT Resources, McKinsey, NASA
This content is paid for by AWS and is produced in partnership with the Financial Times' Commercial Department. The views and claims expressed are those of the guests alone and have not been independently verified by The Financial Times.
READ TRANSCRIPT
- Tech
Transcript
Code and Conscience: Intelligence Within and Without Borders
Ali (00:03):
We estimate that 30 to 40% of all AI spending could be somehow influenced by sovereign requirements, which is basically a market of some 500 to $600 billion by 2030.
Catherine (00:15):
Where does true control sit? Well, really it's fragmented. The data might sit in Frankfurt, the model might have been trained on compute in Virginia, and the legal obligation might be triggered by an end user in a yard.
Stefan (00:26):
You will not have a worldwide regulation. It will not exist because you have specificities in different countries and regions. These specificities are linked to a geopolitical context. However, digital borders shall not become digital worlds which are not interconnected.
Tom (00:51):
Power systems today have evolved from days of old. Nations and their industrial complexes are no longer just flexing their energy, financial, or military strength. The real tug of war has quietly and quickly shifted to who controls the algorithms, the servers, and the data infrastructure. Sovereignty by definition is being updated. Sovereignty 2.0, if you will. Under geopolitical tension, supply chain dependencies, and competing regional regulations, the discussion around digital sovereignty is shaping where you're allowed to build, what models you're allowed to train on, and who's allowed to see the results. Competing lines are being drawn. On one side, there are those calling for the democratisation of AI and opening the global doors to innovation. On another is a fragmented map of regional regulations like the strict mandates of the EU AI Act, and bubbling underneath is the geopolitical chess match, primarily between the US and China, turning data frontier models and the infrastructure behind them into a matter of national security.
(02:05):
For the leaders in this AI board game who are commanding their digital pieces with confidence, it's a fearsome campaign map. For those surveying the board, not quite sure where to focus their pieces and what strengths they have when they do, it's a very different outlook over the next few years. All of this offers up some big questions for governments and businesses. One no bigger than this, can global enterprise innovation really survive in a world of digital borders? Welcome to the Next five podcast and the final instalment of our three-part special, code and conscience. Today, we're exploring intelligence within and without borders. We are stepping onto the global chess board to examine sovereign clouds, geopolitical trade-offs, and what happens when the promise of open technology meets the hard reality of national borders. Joining me to navigate this global landscape are three experts. First, we have Stefan Israel, managing director of the AWS European Sovereign Cloud and Digital Sovereignty.
(03:18):
Stefan, welcome.
Stefan (03:19):
Thank you, Tom.
Tom (03:20):
Next is Ali Ustun, senior partner from McKinsey's Middle East office and co-leader of their Global Data and AI Foundations service line.
Ali (03:29):
It's a pleasure, Tom. Glad to be here.
Tom (03:31):
Ali, great to have you. And finally, Dr. Catherine DiLorenzo, partner at A&O Sherman and one of Europe's leading legal minds on strategic data protection and AI. Catherine, welcome.
Catherine (03:43):
Hi, Tom. Nice to join the discussion.
Tom (03:45):
It's lovely to have you all. Catherine, let's start with you. You are on the front lines of corporate compliance. Let's say a global enterprise wants to deploy an advanced unified AI model across its offices in New York, London, Riyadh, and Paris. How do you harness the borderless power of global AI models when intensifying geopolitical rivalries are forcing digital walls to go up? And where does true control sit when data resides in one country, the AI model is trained in another, and the legal jurisdiction belongs to a third? Is data sovereignty just simply a costly legal headache in that case?
Catherine (04:28):
Yeah, Tom, I think the short answer is no. I would say data sovereignty is not a simple costly legal headache. For me, I would qualify it as a strategic imperative and it's also becoming a competitive differentiator, I would say. So if we paint a picture saying when you deploy AI model across New York, London, Riyadh, and Paris, you're not just navigating four cities, you are navigating at least three or four entirely distinct legal ecosystems. So Saudi Arabia, for instance, has its own personal data protection law and a rapidly maturing data governance framework. In the US, it's the patchwork. You have not really a comprehensive federal privacy law yet, but a growing web of state laws and sector specific rules, and on top of that export control that can change quite quickly. And in the EU, you have the GDPR and now the EU AI Act, which imposes risk-based obligations on certain AI systems and restricts some others outright.
(05:34):
And since June this year, tax sovereignty is no longer a political aspiration in Europe, but it's a concrete draught legislation. So we have the proposal for a EU-wide cloud and AI development act, which we call CADA, and that includes now some measurable criteria for cloud sovereignty. And those criteria include, for instance, EU-based processing, the independence from third country control, supply chain transparency, and also ownership. In that sense, one could say that by making sovereignty more measurable or auditable, the European regulators want to turn the aspirational policy debate into an operational question that businesses will increasingly have to deal with. But your question was where does true control sit? Well, really it's fragmented. As I mentioned, the data might sit in Frankfurt, the model might have been trained on compute in Virginia, and the legal obligation might be triggered by an end user in a yard.
(06:37):
So what this means and practises that companies need, what I would call a sovereignty by design approach. So you have to architect your data flows, your model governance, and your contractual frameworks from day one with jurisdictional boundaries in mind and not do bold compliance on after the fact. The good news is that this is solvable. Smart companies are already building modular AI architectures with federated learning, regional model fine-tuning, data localization where it's required, and that will allow them to capture global scale while respecting the local rules. It costs more, yes, but done well. It will build trust with regulators, customers, and partners. And beyond trust, for me, it also creates an economic sovereignty, the ability to keep operating when a provider or legal regime change.
Tom (07:29):
Brilliant. Thank you. Stefan, Catherine said that and mentioned the Cataract about cloud sovereignty, transparency ownership. When European enterprises and public institutions that rely on foreign providers want confidence that their cloud infrastructure will have uninterrupted access, free from sudden remote lockouts, especially given the geopolitical environment, how can you provide assurances that day-to-day operations, data residency, system access remain entirely under local operational control, even if international diplomatic relations experience extreme friction, let's say?
Stefan (08:11):
Yes. So thank you, Katherine, for this first introductory word, and thank you, Tom, for your question. And Katherine, you have also mentioned that we all need to be sovereign by design, and this is what is a starting point of all what we are offering in the cloud, which is to be sovereign by design. When we say sovereign by design, it's about where are the data, who has access to the data, how I can control that what the cloud service provider is saying true, and what is overall resiliency, survivability, and transparency of the cloud service provider. And this is really what is at the foundation of what AWS has always offered in its diverse regions with cloud. And we know that sovereignty is not a frozen landscape. This landscape is evolving and we are evolving with this evolution. We see, for instance, in certain region more tension between data resiliency and data resiliency, and we see as well in other regions an increased willingness to have assurance against, for instance, geopolitical changes or extraterritorial.
(09:26):
And here I would mention the European Sovereign Cloud, which I know quite well because I'm responsible for it. And on top of this sovereign by design approach, we offer four leading assurances. The first one is the fact that we do not only have the data in our European cloud, which Germany in the region, it's also the customer created metadata which are remaining in the region. The sovereign assurance is the fact that this infrastructure has been sought to be, if necessary, disconnect from the overall AWS regions. We have no neither physical nor logical dependency with the other AWS regions. We are operated by European residents and we're transitioning towards European citizens. It means that in case of geopolitical disruption, and this was the art of your question, we can go on running the European sovereign cloud in full continuity. Some operator have a copy of the source code.
(10:35):
So all has been organised to be resilient to this kind of disruption. The third element is the fact that we are operating under European legal entity or German one. We have European duties, we must abide by European laws, and it is an additional protection against extraterritorial request. And last but not least, it's not only what we say, it is what we prove. We have a sovereign reference framework with all the rules we must abide by, which are verifiable by third party auditors and independent validation. So this is our answer to a moving sovereign landscape and we cope with this evolving request.
Tom (11:22):
Ali, you advise public sector and healthcare clients across the Middle East and globally introducing things like agentic workflow automations. These are sectors handling the most sensitive, intimate citizen data imaginable. How are these regions protecting this data and sovereignty?
Ali (11:39):
Tom, I think the way to look at this is that the sovereignty has become actually much broader than data residency, and that is true about beyond a single region. In our global work on sovereign AI, we break it into four components. Component one is territorial, which is where data and your compute physically sit. Second is operational, so who manages and secures them? Third is technological, which is who owns the underlying stack, who owns the IP, et cetera. And then the fourth is legal that we also have been talking in the last couple of minutes, so which jurisdiction can actually reach the data and the systems. So keeping health records or any type of citizen sensitive data, identity data physically inside the country only answers the first part of these four questions, which is territorial. You also have to ask, so who operates the infrastructure, who holds the encryption keys, where are the models running, and increasingly also who controls what an AI system is allowed to do.
(12:47):
What is interesting is that governments that we also closely work with everywhere are now working through those questions across the whole stack, but slightly through different models. So in the Gulf that we've been referring to and where I will separate from, you see countries building sovereignty infrastructure and capability at a considerable scale, domestic data centres, cloud, increasing the AI compute, et cetera, while by the way, is simultaneously bringing in the best technology through various partnerships, strategic partnerships, et cetera. In Europe, I think just the characteristics of Europe, the emphasis being first regulation, EDPR, the U Act, the European outdated space, et cetera, now basically increasing the match by infrastructure as well, similar to the Gulf you're seeing. India separately, Japan differently, Singapore differently. So the roots differ, but these are not attempts to create completely independent technology stacks in my view. They're actually different forms of controlled interdependence.
(13:51):
So the objective is basically not to eliminate the dependencies, and that's what we advise. It's actually to understand them, diversify them, and increasingly be able to choose among them. By the way, this is also where I would potentially push back a little bit on this image of a wall type of situation, because I think the more the sophisticated the frameworks are moving from localise everything, keep everything resident towards classify, govern and control intelligently, we are going to see more and more of that. The national security data centre, citizens, medical record, any government information should not be always treated or governed identically. If everything is treated as maximally sensitive as you can imagine, you destroy much of the value that comes from sharing data across government and using it for AI in the first place. And then there is also this layer where it becomes very critical with agentic AI because there you actually have sovereignty over decisions and AI system that helps a doctor retrieve information is one thing and an agent that can update a patient's record, schedule a treatment or reach across systems, pull an identity record here and there is quite a different thing.
(15:00):
And that is where the regulation actually is where we need to spend more time in designing because the question is no longer only where is my data? It becomes where is the model running? Who can modify it? Can I audit it? What authority have I given it? So I do think that the destination in the Middle East or in Europe or Asia in every single country is not like putting a wall around the data. It is like different models are emerging and they are all trying to solve the same fundamental question, which is how do you create enough control to generate trust, trust in the citizens above all, and then without cutting yourself from global innovation. And then that ultimately is what I think good digital sovereignty should look like.
Tom (15:41):
Catherine, Ali's discussed there about not cutting you away from international innovation, but I want to look at this geopolitical conversation a bit more because with intense competition between major superpowers and the tightening of export controls, are multinational companies increasingly finding themselves weaponized or perhaps trapped in the middle of a data trade war? I'm thinking specifically about earlier in June this year when the Trump administration forced Anthropic to block foreign users from its latest AI models. The White House cited national security concerns, which could be the first of many and not just for AI companies. Can a board legally insulate its technology stack from sudden geopolitical realignments?
Catherine (16:29):
Yeah, I think the anthropic example that you just mentioned was quite a wake-up call and in my view, it would be hard for a board to fully insulate its technology stack from geopolitical shocks. But I would say a well-prepared board can build an action plan. What we are seeing is what you rightfully call a weaponization of technology. So the export controls the sanctions, the national security orders can cut off access to models or chips or cloud services with very little warning. And the anthropic situation showed that even your AI provider's capabilities can be switched off overnight and not because you as the company did anything, but just because of where the provider happens to sit. So how can a board prepare? What can you do? As a board member, you've met the risks and consider the solutions or if there are no solutions, at least mitigation measures.
(17:25):
And I would say you should maybe consider two things. So first would be diversify your dependencies. If the entire AI strategy of a company sits on a single provider in a single jurisdiction, well, there is a concentration risk. And bots need to think about a multi-cloud, multi-model strategy and not just for technical resilience, but also for legal and political resilience actually. And I think Ali mentioned that it's not a one-fits-all approach that you should take. You should deliberately place the most sensitive workloads, data, and technology in the jurisdictions and operating structures that can protect them best. This may be costly, but at the same time for less critical IT and operations, you can definitely live with simpler, if I can call it, and less protective structures. I just mentioned earlier the CADA regulation, and it tries to attack this problem by providing a solution of classifying dependencies in the fourth-tier assurance framework.
(18:31):
So basically they give recommendations on what points you should consider for which criticality of service, if I could call it like that. And that looks at provider location, at portability, et cetera. So I think that is one way of looking at it, looking at identifying the IT, identifying your dependencies as Ali said, identifying what is critical to your business, where's the biggest exposure, and then make choices on that basis. I think that is from that part. And then the second angle I would look at is the contractual protections. For instance, what happens if the US-China tensions escalate or if there are new EU adequacy decisions that restrict transatlantic data flows, or even if there are new trade alliances which open new opportunities with India or Australia or whatever. So I think the contract that you have with your service providers should give you a certain flexibility to adjust to these evolutions.
(19:32):
And that means you should negotiate robust service continuity clauses, data portability commitments, exit rights in any company's cloud and AI vendor contracts. And as a client, you want to know if access is restricted to my data, what happens to my data? Can I migrate it? What is the notice period? And these contractual protections should become the rule and not the exception, and they belong in every technology procurement negotiation. So I would say just as you stress test your balance sheet, you also need to stress test your technology stack against plausible geopolitical and legislative changes. And the board that has gained these scenarios out in advance as much as they can, can respond much quicker than one that hasn't. And the time that can elapse until you figure out the right solution, some damage may be done in the meantime.
Tom (20:22):
Stefan, some reports estimate the global sovereign cloud market will climb towards $200 billion in 2026. AWS is investing heavily in things like the AWS European Sovereign Cloud. In well-drawing digital borders, some with potential trusted partner status. How do you actually scale without breaking the boundaries or upsetting partners?
Stefan (20:46):
Yes. And I would like to rebound on what Katrina said, the fact that the board members have to make decisions. And these decisions are really a trade-off between the assurances they need, the services they want, and at which price. And as a company and as all companies, we are here to offer the best trade-off because perfection does not exist, but good and better exist, and this is what we want to deliver. And when it comes to scaling, this is exactly the point. We need to scale because both cloud infrastructure and AI capabilities are requesting billions of investment. And this is why it is so important to scale. And the way we scale is by offering the same experience with our customers, same API, same services to avoid them having different experiences when they use us. Another way to scale is also what we did with the European Sovereign Cloud.
(21:49):
We have voluntarily decided not to make a French cloud, a German cloud, an Italian cloud. We have decided to make a pan-European infrastructure available for all European needs in EU 27 countries, abiding by European overall requirements after we know that there is a CADA regulation, there are some national regulation, but all in all, by listening to our customers or regulators, we have decided to make available a pan-European infrastructure, which is obviously a way to scale. After, I would say that when it comes also to AI sovereignty, we have the same requirements. The customers or the regulators, they want to have the choice in the chip they would use. They want to have the choice in the model they would select. They want to have the choice between the cloud and on-prem solutions, and they always want to have control. And here again, with our AI stack, which is available in our different regions and in our different solution, this is where we scan by offering this overall technology and abiding by these sovereign requirements when it comes to AI sovereignty.
(23:05):
So the way we scale is to offer as much as possible the same solution, the same technology, the same experience by adapting it also to more local, national, original requirements.
Tom (23:21):
Ali, let's look at the financial cold realities. McKinsey data suggests that sovereignty alone rarely drives an enterprise to switch tech vendors. They still care deeply about price, performance, and reliability, yet sovereign AI is a 10 to 30% more expensive. How do you sit down with a budget director or corporate board and justify that premium cost? Will boardrooms be able to pay up to 30% more for sovereign AI architectures and for how long?
Ali (23:53):
Thomson, that clearly can be a premium today and there's a premium today. Now I'm not going to argue with the number our own research as you mentioned shows sovereign AI offerings are pursued anywhere between 10 to 30% more expensive than the global alternatives. But there's one more thing in the same research that tells you something else in addition, which is around 70% of all enterprises that we surveyed would still switch an AI vendors for a better price and a performance. So sovereignty alone has almost never wins the decision. So the conversation with the board cannot start with the pay the premium. It has to start with where do you actually need it? We estimate that 30 to 40% of all AI spending could be somehow influenced by sovereignty requirements, which is basically a market of some 500 to $600 billion around by 2030. So for me and for us, the most important first question is the first discipline is the segmentation.
(24:55):
So not every workload needs the highest tier of sovereignty. And so a national security data set, the public website should not necessarily be treated the same way in the architecture. So as you classify the portfolio, apply what we call the minimum sufficient sovereignty to the genuinely sensitive segments, citizen data or patient records or whatever it is, and keep everything else on the most efficient environment available. So do that properly and you're typically paying the premium on a minority of the estate, not the whole of it. And that's completely different conversation for a CFO or for board. Then for the regulated core, which actually matter, I would ask three questions. I would ask one, does sovereignty unlock a workload that would otherwise stay off limits? Second question, does it materially reduce a legal security continued risk? And then third, can the provider deliver compliant performance without really degrading the service?
(25:48):
So because in many regulated sectors, what we see is the comparison is not sovereign AI versus cheaper AI, it's actually sovereign AI versus not being able to deploy AI at all, so not being eligible to operate in that market in the first place. And then not deploying is usually the most expensive option on the table if you think about it. So that's one. Second thing is basically aggregation. So as Stefan also mentioned, utilisation and scale matters. So sovereign compute built for a handful of workloads could always be expensive, but turned into a shared platform across governments, across industries, the economics change fundamentally. So the demand aggregation matters. So that your example in that sense is very important. So the multi-year committed demand gives providers a certainty to invest locally while driving unit costs down over time. So that's the second point. I also would like to mention that sovereignty, if done well, converts this topic into a productive asset.
(26:44):
What I mean by that is it unlocks AI adoption in regulated sectors that would otherwise stay on the sidelines. It anchors data centres, engineering and AI talent in the country. It seeds startups, research. It keeps a much larger share of the economic value of AI inside your borders rather than exporting it along with your data. So there's a little bit of that localization angle and economic value captured in the borders as well. So for Europe alone, our colleagues estimated roughly 400 to 500 billion euros in annual GDP at stake by end of the decade from building sovereign AI capabilities. So at that point, you're no longer defending a coastline, but you're actually describing an economic development strategy. So long story short, will boards pay 30% or 10 to 30% more forever? No. And then they should not have to. So scale improves, utilisation improves, competition increases, and then localised sovereign providers are already matching the global players in that sense from a service levels, et cetera.
(27:44):
So what I would tell the board is budget for a premium on your regulated core over the next three to five years because this is how these migrations typically take time, but treat it as an entry price during the build out phase and hold your providers accountable for closing the gap, design the investment so it pays you back in resilience adoption and domestic capabilities.
Tom (28:04):
Stefan, Ali mentioned localization there, so I would like to build out on that a little bit more because looking out over the next five years, do you see a world where data regulations align globally or is it a future where different regions operate on entirely separate digital realities?
Stefan (28:20):
I think it will be both, and it's not totally contradictory. You will not have a worldwide regulation. It will not exist because you have specificities in different countries and regions. These specificities are linked to a geopolitical context. They are linked to the size of the country. They are linked to the aspiration of the country. As Ali rightly said, one country may put the emphasis on the local priority, which is an AI model for instance. Another country will have another priority and it has an influence on the sovereign requirements. When you are in Singapore, you are not in the same context as India to go to countries for which we are delivering some services. So I do not see a unification of the regulatory landscape. However, regulators speak a lot to each other. They influence each other. What is done now in Europe as an influence outside Europe.
(29:22):
We know that because we speak to regulators and we speak to our customers and we see that, for instance, the CADA regulation is known in other regions and all that creates a sort of dynamism of regulation, if I may. And in this context for us, what is very important is to work with the different regulators and to have the trust of the different regulators. And I would just quote one example, AWS has a unique relationship with the German regulators. The name of the German regulator is BSI. We have been working with a German regulator for now more than a decade. We have been the first hyperscaler to have the C5 certificate. Recently, we have had an agreement around the sovereign and AI best practise. When the regulator has made its national framework, which is called the C3A, and this framework is influenced by the European framework.
(30:27):
When this regulator has decided to go for its national framework, it has launched a discussion with the different cloud service providers, and we have been part of this discussion. So what I want to highlight is the fact that in a context where you will have a mix of different regulations and some common trends, what is important for us as a cloud service provider is really to be a trusted partner of the regulators and to have an open dialogue. We must say, okay, here we think you are going in a direction which will not help the customers in your country, the organisation to be competitive or here maybe we could have another idea. All that must be a very open and very front dialogue. And all in all, knowing that again, there will be some differences, there is a trend and this trend is to have on the one side a commercial cloud.
(31:27):
And as Katherine and Ali said, you do not need to put all your data in sovereign cloud and another trend which is to have sovereign cloud and we are here to cope with these requirements.
Tom (31:41):
Well, Katherine, coming to you, how do we keep compliance from completely suffocating the small innovator? If building a compliant sovereign AI system requires a massive legal and financial premium, do we risk creating a world where only the massive mega corporations can afford to innovate legally?
Catherine (32:01):
Yeah, I think at first this sounds like a big challenge, but I don't think that this means that only the mega companies can innovate in legally compliant way. First, when the tech sovereignty package in Europe came out, there was a reaction immediately of several European actors to also consider partnerships, either partnerships between themselves. So for instance, there's one which post Luxembourg and OBH in France entered into in order to provide certain services to the European Commission in line with the requirements. So this is one option or others teamed up with big mega companies for certain projects. So there are these partnerships evolving. But to your question, is from a legal perspective possible? Yes, the European legislator has already taken this into account. So as we mentioned already several times, I think today, not everything has to be on the highest stake of the sovereign cloud requirements.
(33:01):
And basically under CADA for instance, the assessment is that 70% of the public sector cloud services covered there would actually not need the highest level of safeguard. So this is just to give a little bit of an idea on that front. But even when you need certain safeguards or the full stack, the legislation has also smaller mid-sized enterprises, SMEs in mind. And so they've introduced in the legislation a concept of proportionality. So what means that in practise that not all the rules will to the full extent apply to the smaller and mid-sized enterprises.That's one way of handling it. Another way of handling it is that recently we had this simplification wave, which is called a digital omnibus, and there is an attempt to consolidate part of the data arche and reduce overlapping obligations, which again reduces a little bit the number of rules applicable to smaller but also bigger companies.
(33:59):
And while we remain to see whether this bears fruit, of course European Europe, it could not resist fostering innovation through another regulation and that's the upcoming EU Innovation Act. And that's expected to be presented I think later this month and it should improve access to testing, help research, reach the market and make it easier for startups to protect and scale ideas across the single European market. So I think that's coming up. And then I think from an industry perspective, we are already also seeing the emergence of shared compliance toolkits, open source governance frameworks, and AI as a service platforms that bake in compliance by default and which will also, in my view, help smaller companies tackle the compliance challenge. And I think there we have companies like AWS who will also help on that front. So all in all, I'd say the answer isn't lower, but proportionate standards, shared capability and the market that stays open.
Tom (35:02):
Well, as we conclude this final chapter of our series, we have a few quick fire questions. Stefan, coming to you first, I asked at the top of the show, can global enterprise innovation truly survive in a world of digital borders?
Stefan (35:15):
Yes, we can. And we are able to adapt to different context. However, digital borders shall not become digital worlds which are not interconnected. So we are still evolving in one world. National requirements, regional requirements are legitimate, but for the sake of the whole communities, the nations, the customers, the providers, we need to go on operating in an open world.
Tom (35:43):
Ali, coming to you.
Ali (35:45):
Absolutely. We need to, however, define what global innovation actually looks like. So I think for 20 years or so, we built technology on the assumption of almost frictionless globalisation. So we build, deploy, identical everywhere. So to me, that model is gone and that's actually now we are turning into a federated model. And then which basically means globally connected technology with certain data infrastructure and controls anchored locally, digital borders acting as routing rules rather than walls, common control architectures that routes each workload to the right environment, et cetera, et cetera, and then the legal exposure and resilience that comes along with it. So you don't need a different product in every country, but you need one system that can respect many rule books. And also, I think one thing that people actually miss is sovereignty can actually expand innovation. That I really want to highlight because trust unlocks adoption.
(36:41):
The real risk is fragmentation. 100 incompatible standards would price small innovators out completely out. So the task for the next decade is for us to eliminate the borders, to make them interoperable, the way we did with financial systems, telecom, aviation, et cetera. And then so on to should determine where the boundaries are not to prevent innovation from crossing them.
Catherine (37:05):
Catherine? Well, the good thing, we all agree, my answer is also yes. So I think similar to what Ali and Stefan said, I think the companies that will win the game are those that treat sovereignty not as a war, but as an architecture challenge and that maybe even treated as a business opportunity and the sales argument. And the four trillion AI opportunity today, I think that Alien mentioned, I think it will go to those who move wisely, so fast enough to act disciplined enough to stay trusted and practical enough to work with the different rules in the different market.
Tom (37:37):
Throughout history, power has moved from the control of land to the control of machinery to control of energy and now to the control of data. If data is now the strategic resource nations and corporations fight over, what does the 21st century arms race actually look like in practise? Katherine?
Catherine (37:56):
I think it's looked like a race to write the rule book and not just a race to build the most powerful technology right now. So I think the US Cloud Act and China's National Intelligence Law reflect the computing answers to how one can control access to data. And the EUS CADA regulation is an attempt to define what trusted sovereignty would actually look like. The real battlefield for me therefore is standard setting. Whoever decides how a sovereign cloud is classified, certified, and audited would probably shape the market more or less globally. And I think the difference from historical races that we've seen earlier is this one is a bit quieter, more diffuse, deeply embedded in commercial relationships and every cloud contract, every I partnership, every data transfer agreement is in some sense a small move on the chessboard.
Tom (38:52):
Ali, let's come to you.
Ali (38:53):
So I would broaden it beyond data. What we are really seeing is I think a race across the entire stack, energy, advanced chips, compute data models, talent, whatever you name it. And then probably at the very front, most people still under rate is just basically the energy part. The binding constraint for us right now is not model capability, but it's actually basically gigawatts and how we basically think about even how we split them across influence versus research. So whoever can stand up those together, I think is going to be ahead of the curve, but there's a crucial distinction between accumulating resources and creating value from them. And I just want to highlight that because an organisation can sit on decades of incredibly valuable data and almost extract nothing out of it. So there's a big difference between processing it and then having it ready for AI.
(39:45):
The same is true for quantum compute, the same is true for adoption, the same is true for talent and the entire ecosystem that's around it. So in my view, there are actually two races. One race is actually around AI resources to actually capture as much as you can and not just necessarily data. And then another race is for diffusion. Basically how fast can you turn these into productivity, new companies, better public services? And then also worth saying that that is. So no sovereign system is truly independent and then everyone basically, most of them are dependency managed architectures built around everyone else's sort of capabilities. The decisive advantage is not purity. It is actually knowing which dependencies are acceptable, which to diversify, which control points to secure, et cetera, which I mentioned also earlier, and then being best at connecting everything into real economic and social capability.
(40:36):
I suspect that that diffusion race, I call it, is the one that ultimately matters beyond all the individual resources.
Tom (40:43):
And Stefan?
Stefan (40:45):
There is obviously a race to leverage data and to make the best usage of data to value data. But in the context of distress, I prefer the notion to a win-win dynamism in a three-party environment to the one of an armed race. This win-win dynamism, or we could also evoke a virtuous circle, is made of having the requirements of nations and region respected, the wishes of the customer accomplished and the customer want the best solutions. And for us as a trusted partner, the ability to deliver the best services possible to our customers abiding by this different regulation. And what is important as well in this race, it's not all about us. This race, we will win it with local partners. I give you the example of the European Sovereign Cloud. ASAP is a local partner. It's a German national champion. Atos is a local partner.
(41:45):
DWS is a local partner. Atos is French. The Datos is Italian. We need to shape an ecosystem with our different local partners in a race, which is a virtual circle and not antagonist.
Tom (41:58):
The last question here is all about hope. What is your one hope as to where we will be when it comes to data sovereignty in five years time? Stefan, you just mentioned a win-win scenario. What's the dream everyone win scenario for each of you? Ali, let's come to you first.
Ali (42:14):
Sure. So my hope that in five years we talk much less about sovereignty as a defensive concept, so it stops being a fight, but starts being an infrastructure the way that is today. Simply there, trusted, built on without anyone having to think about who controls the grid. So the critical workloads get genuinely strong protection, then everything else actually stays open to the world's best innovation. So that's the goal. And then the trusted corridors allow data, models, services to move between compatible jurisdictions with auditable controls without saying. So a hospital in one country are working can run the same model as the hospital in another and each fully accountable to its own regulators. If you get that right, I think countries protect what is strategically theirs and capture more of the economic value of AI at home, and then also in jobs and talent and companies, et cetera, and citizens gain a real confidence in half of their data is being used.
(43:18):
So for me, the ideal outcome or five years down the line, ideal situations as follows. There's enough autonomy to create trust, enough openness to create innovation, and enough interoperability to keep the global digital economy still connected.
Tom (43:34):
Stefan, to you.
Stefan (43:35):
First, what would be the worst? The world would be complex regulations leading customers and organisation to a wait and see strategy, which is never a strategy. And the best of the hope would be to have regulations as consistent as possible, as compatible as possible between different regions and fully compatible with the best services possible. Again, abiding by your national and regional request, but regulations agile and clever enough to allow customers and organisation to leverage their data.
Tom (44:12):
And finally, Katherine.
Catherine (44:14):
It would be an irrealistic dream to expect harmonised legislation. So I think what we can hope for and what would be a good outcome is interoperability and collaboration. And for that, it would be good to see data sovereignty as a foundation for global collaboration and not a barrier to it. I guess that's the best I would hope for.
Tom (44:35):
Well, it's been a truly monumental conversation to close out this series. Many thanks to Stefan Israel.
Stefan (44:42):
Yes. So thank you, Tom. Thank you, Katherine, and thank you, Ali. I really enjoyed this conversation.
Tom (44:47):
Ali Ustun.
Ali (44:48):
Thank you very much, Tom and everyone. It was a pleasure.
Tom (44:51):
And Dr. Katherine DiLorenzo.
Catherine (44:53):
Agreed. It was really a nice conversation and enjoyed it a lot and a really interesting exchange. Thanks to everybody.
Tom (45:03):
And so we come to the end of this episode and the Code and Conscience series. Today, we've stood on the front line and in the commander's situation room, surveying the lines of code that are colliding and crossing the physical, political, and legal borders of a world in constant flux. Digital sovereignty is a core consideration for all businesses and governments who want to redraw the blueprints of the next five years and beyond. It isn't just a first line of defence. It's not purely isolationist. It's also an attack, an attack on legacy thinking, on those that ignore innovation and those that pull up the drawbridge rather than negotiate a peaceful collaborative treaty. Those that thrive will be those that are bridge builders delivering the borderless potential of AI while upholding the sanctity of local law, privacy, and control. And let's not forget, AI for all its dazzling power, is ultimately just a mirror.
(46:08):
It reflects the ambitions, the anxieties, and the values of the culture that builds it. Perhaps that is what scares us the most than in our human history of people, politics, and power, there have been times of great conflict and great pain. But in our moments of selfless shared endeavour, we found some of our greatest victories. 250 miles above earth sits one of them. The International Space Station is built with a single surviving fully integrated mantra. Via NASA's solar arrays, it's powered by the US, yet propelled by Russia's Ros Cosmos boosters. Neither segment nor nation can operate without the other. It was intentionally designed to be interdependent no matter what happens geopolitically below it. We now have the opportunity to be on the right side of history again and create a final frontier on earth, to create code with courage, with compassion, with conscience. I'm Tom Parker, and this has been the next five podcasts.
(47:21):
Thanks for listening.