SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Many leaders struggle to define sovereign AI, study finds

Many leaders struggle to define sovereign AI, study finds

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Cohere has published research suggesting many senior business and IT leaders struggle to define sovereign AI, highlighting a gap between interest in the concept and understanding of it within organisations.

The study, conducted by IDC for Cohere, surveyed more than 500 senior AI decision-makers in Canada, the US, the UK and Germany across financial services, healthcare, energy, manufacturing, telecoms and the public sector. It found that one in three respondents had difficulty describing sovereign AI in their own words, while only 13% said the concept was very widely understood across their organisations.

Awareness appeared especially limited in Canada, where 89% of respondents reported low awareness of sovereign AI concepts within their organisations.

The findings come as businesses and public bodies face growing scrutiny over data control, infrastructure location and reliance on external technology suppliers. Concerns about data residency, security, regulatory exposure and operational dependence are prompting organisations to review how they deploy and govern AI systems.

The study defines sovereign AI as "the ability for an organization to have free choice and control over the design, development, deployment, accessibility, operation, maintenance, and governance of its AI systems and applications, as well as the underlying technology foundations they depend on".

Even among respondents who said they could define the term, views varied. The findings showed that 52% described sovereign AI in terms of local or national control, while 35% associated it with digital independence.

Differences also emerged between management groups. Line-of-business leaders were more likely to frame sovereign AI around business risk, including data security, privacy and cost control. IT leaders, by contrast, tended to view it through the lens of regulatory compliance and alignment with national or regional rules. The research found that IT professionals showed twice the level of awareness recorded among line-of-business leaders.

Risk focus

Across the sectors surveyed, respondents ranked data leakage, privacy, compliance and regulatory risk among the main issues sovereign AI efforts could address. Concern was highest in financial services, where 82% cited those factors, followed by manufacturing at 77%, telecoms at 75%, healthcare at 74% and energy at 70%.

The findings also suggested larger companies are more sensitive to these risks than smaller businesses. Organisations with USD $20 billion in revenue showed higher levels of risk awareness.

Competitive positioning appeared to be a less established driver, though the research suggested it is gaining ground. Among Canadian respondents, 35% said competitive advantage was a factor in sovereign AI adoption, compared with 28% in the US, 23% in Germany and 18% in the UK.

By sector, telecoms recorded the highest share citing competitive advantage at 37%, followed by manufacturing at 32%, healthcare at 28%, and both financial services and energy at 21%.

Strategy gap

Cohere and IDC identified three main barriers to wider adoption. The first was the lack of a clear operating model for AI autonomy, despite concern over vendor lock-in, portability and geopolitical risk. The second was uneven understanding of sovereign AI within organisations. The third was the absence of a broader plan linking leadership ownership, measurable goals and implementation.

The report argued that organisations are making AI investment decisions without a shared understanding of the term or a clear framework for responsibility. It added that accountability for sovereign AI strategy may vary between countries and leadership structures.

IDC said in the research that "while more than half of executive leaders believe sovereign AI is a priority, there is little agreement on the definition, and many cannot define it."

It described the broader direction of travel in firmer terms: "Across regulated industries and geopolitically sensitive markets, enterprises are re-architecting their digital operating models - shifting from a global-by-default posture to a deliberately sovereign-by-design approach."

The report also cited an IDC forecast on technology spending patterns: "By 2028, CIOs at multinational organizations will boost investments in modular, sovereign-ready cloud and data localization environments by 65% to future-proof operations against rising sovereignty demands."

The findings highlight a growing debate over who controls the infrastructure behind AI systems, where sensitive data resides and how dependent organisations should be on third-party platforms for critical operations. They also suggest that while sovereign AI is becoming more prominent in boardroom discussions, many companies remain at an early stage of turning the idea into policy and execution.