A sovereign AI system is only as sovereign as the person using it
A compliance officer at a regional bank can tell you which country every customer record sits in, which certified provider hosts it, and which clause in the contract guarantees it stays there. That answer took two years and a considerable budget to arrive at. Regulators set out where data could be held and who could process it, and enterprises across the region responded by moving workloads onto certified local infrastructure, reopening cloud agreements, redrawing architecture around jurisdiction, and hiring the people needed to prove all of it on demand. In banking, healthcare and government, that work is largely done, and it did what it was meant to do.
The same compliance officer cannot tell you what the bank's analysts typed into a chat window last week. Nothing in the architecture was built to know. A residency control governs where a file lives and which border it may not cross, and it has nothing to say about an employee pasting an unreleased figure into a prompt to get help with the phrasing, or about whether the answer that comes back is worth acting on. The controls hold right up to the point where a person starts typing, which is also the point where most of the risk now sits.
Organisations have generally answered that with training. What sits inside the training, and whether it prepares anyone for the judgment calls the architecture cannot make on their behalf, is a separate question, and the answer is uncomfortable.
Philippe Jarre, CEO and President of Mindware Group, said most of what is on offer does not qualify. "The uncomfortable truth is that most of what passes for AI training today is closer to product onboarding than genuine capability building," he said. "Teaching someone how to write a better prompt is not the same as preparing them to work alongside AI systems responsibly, and even we at Mindware have had to challenge ourselves on this."
Employees do not need the mathematics behind these systems, according to Jarre, though they do need to understand that a model predicts what sounds right without knowing what is right. That single point governs how a person reads an output and whether it occurs to them to check it.
The regulations are specific about infrastructure and silent about behaviour
Walid Natour, Director of Security Engineering at Tenable, said the obligations leave little room for interpretation. "Under the UAE’s Federal Personal Data Protection Law and Cybersecurity Council regulations, organisations must maintain strict data sovereignty," he said. "This dictates that all sensitive regulated authorities, corporate, financial, government, healthcare, and classified data be securely hosted and processed within certified cloud environments." Dubai’s Information Security Regulation, managed by the DESC, extends the requirement to government workloads, regulated sectors and critical infrastructure, all of which must sit with certified local providers.
For companies operating in more than one market, the rules do not line up. There is no single regional block, and each country sets its own residency policy, with public sector entities legally prevented from moving data outside domestic infrastructure unless an exception is formally granted. Natour said this rules out any single deployment model, and companies now run local on-premises systems for the most restricted entities alongside hybrid and localised cloud elsewhere. The investment behind that is real, and the certified domestic cloud capacity now available in the UAE exists because of it.
None of that architecture has any view of what an employee intends to do with it. Jarre said the concern raised with him most often by regional leaders is the one no residency control catches. "When employees interact with AI systems, they often share far more than they should, including confidential data, internal financials, and sensitive operational details," he said. "It goes into prompts without a second thought, often because no one told them not to, or because the training they received covered the tool without covering the responsibility attached to using it."
Delegation turns a training problem into a border problem
The exposure widens once staff stop asking AI for help and start handing it work to finish alone. "We are entering what I would call the delegation era of AI," Jarre said. "Employees are no longer just using AI as a tool. They are assigning it tasks and trusting it to complete them, and that is a fundamentally different risk posture."
An agent cannot complete anything useful without reaching into operational data, and operational data is what the residency rules fence in. Natour said the question this raises is ownership. "When teams span multiple borders, the absolute ownership of the data remains strictly with the local entity or sovereign organisation that generated it, rather than the cross-country team managing the technology," he said. "Sovereignty fragments the workflow because automated AI agents cannot freely aggregate or process data across borders due to rigid, country-specific residency rules."
His answer is to give each agent only the access its task requires, inside boundaries the system enforces rather than boundaries it is asked to respect, so that risk assessment and automated remediation happen inside the country where the data belongs. Jarre applies the same logic to people. "Not every employee should have access to every AI capability, and access should be tiered to match role, risk level, and demonstrated competency," he said. "It is about matching capability with accountability." A security engineer looking at machine permissions and a distribution executive looking at staff permissions have reached the same operating rule.
Safe usage has to be written job by job
A company-wide AI policy has to cover people whose work has almost nothing in common, and the phrase loses its meaning the moment anyone applies it to a specific desk. Jarre said the guidance has to be written by role. "The responsibilities of a marketing manager using AI are not the same as those of a financial analyst or an operations lead, and the guidelines they are given should reflect that," he said.
In marketing, that means anything the system produces goes through review before an audience sees it. In finance, every figure gets verified independently, because these systems generate numbers that look completely plausible and are completely invented. For an operations lead the risk sits in what an automated process does when it meets a situation nobody anticipated, and that needs answering before the system goes live.
Three requirements run across every role. Staff need to know where their tool is reliable and where it fails, they need a written policy on what data they can share rather than being left to work it out, and they need a route to raise a concern. Jarre said the last of those depends on culture more than documentation. "Employees should not be scared to escalate," he said. "In an AI-enabled organisation, raising a concern about an output is exactly the kind of human judgment that makes AI safe to deploy at scale."
Nobody has written the playbook for the day it goes wrong
Natour said fragmented regulation becomes manageable once a company establishes what he described as absolute ground truth, pulling security data out of disconnected local silos so teams can audit AI interactions continuously and hold to several sets of national law at once. That produces a record of what an agent did. It stops short of establishing who answers for it.
Jarre said almost nobody has closed that gap. "Something that almost no organisation has built yet, but every organisation needs, is an incident response playbook for AI failures," he said. "What happens when an AI agent makes an error at scale? Who owns it? How is it detected? How is it contained?" Most leaders have not noticed the omission yet, in his view, and will notice it at the point they need the document.
A residency rule settles which country is accountable for the data. An incident playbook settles which person is accountable for the decision. Companies across the region have spent heavily on the first and barely started the second, which leaves a chain of controls that holds until the last link, where it depends on whether one employee understood what they were doing. Jarre said that is why sequence matters more than speed. "At Mindware, when we think about deploying AI across our own operations or advising partners on adoption, we start by asking one question, which is whether our people know enough," he said. "If the answer is no, the deployment is not ready."