AI Strategy8 min read

AI Deployment and Data Sovereignty: Why Most Multinationals Know the Risk But Have Not Redesigned for It

NTT DATA research finds most multinationals know AI deployment must change for data sovereignty, yet few have redesigned for it. Here is what that redesign involves.

Mark MillerBy Mark Miller
AI Deployment and Data Sovereignty: Why Most Multinationals Have Not Redesigned Their Architecture Yet

NTT DATA's 2026 Global AI Report, based on responses from nearly 5,000 senior decision-makers across more than 30 markets, found that 95 percent of organisations consider private or sovereign AI important to their strategy, yet only around 29 percent are actually prioritising sovereign AI implementation in the near term. That gap between intention and execution is the real story. It is a meaningful share of the world's largest organisations concluding that the AI architecture they already built will not survive the sovereignty requirements now emerging across the markets they operate in, while still struggling to act on that conclusion.

What "Redesigning for Sovereignty" Actually Involves

Sovereignty requirements go well beyond choosing which region a cloud provider's data centre sits in. A genuine redesign has to account for where models are hosted and where inference actually runs, where training and fine tuning data physically resides, where logs and audit trails are stored and who can access them, and what contractual control an organisation actually has over a vendor's global infrastructure decisions. An architecture built without those questions in mind at the outset often cannot simply be reconfigured. It has to be rebuilt.

Why Retrofitting Sovereignty Is Harder Than Designing for It

This is the pattern NTT DATA's execution gap is really describing. Organisations that treated sovereignty as a future consideration, reasonable enough when their AI systems were still pilots, are discovering that a production system built on infrastructure that assumed no sovereignty constraint is expensive and slow to unwind. Data residency, once baked into how a system stores and processes information, is not a configuration toggle. It is an architectural decision made early, whether deliberately or by default.

The Architecture Decisions That Determine Whether Redesign Is Even Possible

Some components of an AI deployment can be swapped for a local or sovereign equivalent relatively cleanly, the hosting layer in particular, if the system was built with reasonable abstraction between the application and the infrastructure underneath it. Others are considerably harder, particularly where an organisation has built deep dependencies on a specific vendor's proprietary model access, fine tuning tools or agent orchestration platform, none of which necessarily have a sovereign equivalent available in every market. Knowing which category each component falls into before starting a redesign is the difference between a manageable project and a multi-year one.

What This Means for Organisations Operating in or Selling Into Australia

Australian financial services and healthcare organisations have largely already internalised this lesson, not by choice but by regulation. APRA's prudential standards on operational risk and information security already require regulated entities to demonstrate control over where data resides and how third parties access it, and equivalent obligations apply to healthcare providers handling data under the Privacy Act. NTT DATA's execution gap suggests the rest of the world is now arriving at the same conclusion Australian regulated sectors were pushed toward earlier by their regulators. Organisations building AI deployments intended to operate in or sell into the Australian market should treat sovereignty as a starting assumption, not a later redesign, because the market they are entering has already normalised the requirement.

Building AI Deployment That Does Not Need a Redesign Later

The practical lesson from the organisations currently mid redesign is straightforward, even if it arrives too late for them to apply retroactively. Build with clean separation between the AI application logic and the underlying infrastructure from the start, know explicitly which components carry sovereignty exposure, and avoid vendor dependencies that lock a system into infrastructure with no sovereign equivalent, unless that dependency has been consciously accepted rather than defaulted into.

What This Means for Your Organisation

What we see across implementation engagements in Australia is that the organisations avoiding a costly future redesign are the ones that treated data sovereignty as a design constraint from the first architecture decision, not as a compliance requirement to satisfy once the system was already built. Retrofitting sovereignty is always more expensive than designing for it, and the large share of multinationals NTT DATA found still stuck between recognising the requirement and acting on it are learning that the hard way.

Key Takeaways

  • NTT DATA's 2026 Global AI Report found 95 percent of organisations consider private or sovereign AI important to their strategy, but only around 29 percent are actively prioritising sovereign AI implementation in the near term, a wide gap between intention and execution.
  • Genuine sovereignty redesign covers model hosting location, training and inference data residency, audit trail storage and contractual control over vendor infrastructure, not just choosing a data centre region.
  • Retrofitting sovereignty into an existing AI deployment is considerably harder and more expensive than designing for it from the outset, because data residency is an architectural decision, not a configuration setting.
  • Australian financial services and healthcare organisations already treat sovereign cloud and on-shore hosting as effectively non-negotiable, driven by APRA prudential standards and Privacy Act obligations rather than by choice, putting the sector ahead of where NTT DATA's global research suggests most multinationals currently sit.
  • Organisations should build with clean separation between application logic and infrastructure, and consciously assess vendor dependencies for sovereignty exposure before committing to them.

How Trusenta Can Help

AI Integration Services builds clean separation between AI application logic and infrastructure so sovereignty requirements can be met without a future rebuild.

Custom AI Development builds AI systems around an organisation's actual data residency and hosting requirements from the first design decision.

Enterprise Architecture documents which components of an AI deployment carry sovereignty exposure before a redesign becomes necessary rather than after.

Conclusion

The multinationals NTT DATA found stuck between recognising sovereignty as important and actually acting on it are not failing at implementation. They are paying the cost of a design decision, or a default, made before sovereignty was treated as a first order requirement. Organisations building AI deployments now have the chance to make that decision deliberately, before it becomes an expensive redesign project of their own.

Mark Miller

Written by

Mark Miller

Mark brings a rare blend of C-suite leadership and hands-on consulting experience to Trusenta. As former SVP of Services, SVP of Business Operations, Managing Director and CIO he brings a breadth of experience in his specialty in guiding organisations through AI strategy, governance and adoption; bridging ambition with practical execution. His focus is on helping clients embed AI responsibly, at scale and in service of real business outcomes.

Connect on LinkedIn

Ready to transform your AI strategy?

Partner with Australia's AI strategy and governance specialists. From adoption roadmaps to ISO 42001 audit readiness.