{"id":168825,"date":"2026-05-05T15:18:45","date_gmt":"2026-05-05T14:18:45","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2026\/05\/05\/sovereign-by-design-architectures-building-transparency-and-traceability-into-your-data\/"},"modified":"2026-06-18T12:02:09","modified_gmt":"2026-06-18T11:02:09","slug":"sovereign-by-design-architectures-building-transparency-and-traceability-into-your-data","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2026\/05\/05\/sovereign-by-design-architectures-building-transparency-and-traceability-into-your-data\/","title":{"rendered":"Sovereign-by-design architectures: Building transparency and traceability into your data"},"content":{"rendered":"\n<p><em>As organisations accelerate AI adoption, the need for strong data governance and sovereignty has become critical to unlocking innovation while maintaining compliance and control. Michael Cade, Global Field CTO at Veeam Software, explains why clean, structured data and purpose-built architectures are essential to making AI both effective and secure.<\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"683\" height=\"1024\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2026\/05\/Michael-Cade-Field-CTO-Cloud-Native-Product-Strategy-and-Global-Technologist-Veeam-683x1024.webp\" alt=\"\" class=\"wp-image-168826\" style=\"width:175px;height:auto\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2026\/05\/Michael-Cade-Field-CTO-Cloud-Native-Product-Strategy-and-Global-Technologist-Veeam-683x1024.webp 683w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2026\/05\/Michael-Cade-Field-CTO-Cloud-Native-Product-Strategy-and-Global-Technologist-Veeam-200x300.webp 200w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2026\/05\/Michael-Cade-Field-CTO-Cloud-Native-Product-Strategy-and-Global-Technologist-Veeam-768x1152.webp 768w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2026\/05\/Michael-Cade-Field-CTO-Cloud-Native-Product-Strategy-and-Global-Technologist-Veeam-1024x1536.webp 1024w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2026\/05\/Michael-Cade-Field-CTO-Cloud-Native-Product-Strategy-and-Global-Technologist-Veeam-1366x2048.webp 1366w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2026\/05\/Michael-Cade-Field-CTO-Cloud-Native-Product-Strategy-and-Global-Technologist-Veeam.webp 1634w\" sizes=\"auto, (max-width: 683px) 100vw, 683px\" \/><\/figure><\/div>\n\n\n<p>So far, AI adoption has outpaced regulatory frameworks, leaving organisations largely to make up their own rules. But this lack of clarity hasn\u2019t slowed organisations down. In fact, McKinsey\u2019s latest survey found that 88% of organisations already report using AI in at least one business function. Despite this, innovation has slowed and it\u2019s become clear that organisations have overlooked a key enabler of safe and secure AI \u2013 data sovereignty.<\/p>\n\n\n\n<p>Simultaneously, regulation has begun to catch up and much of it points to the same principles of data sovereignty and AI visibility. Take the EU AI Act, for example, which sets strict, risk-based rules on both AI development and deployment within the EU to improve AI visibility.<\/p>\n\n\n\n<p>Rather than blindly charging ahead, organisations need to pause to develop transparent, traceable and sovereign-by-design data architectures. Otherwise, they won\u2019t just be unable to unlock the true potential of AI for their businesses; they\u2019ll also fall behind on regulatory compliance.<\/p>\n\n\n\n<p><strong>Not all data is good data<\/strong><\/p>\n\n\n\n<p>As you might expect, both digital sovereignty and AI innovation boil down to data. It\u2019s already well documented that AI needs a lot of data and we\u2019ve got plenty, with the IDC estimating that the global datasphere reached around 181 zettabytes annually in 2025. But, despite having plenty of data, Generative AI (Gen AI) pilots continue to fail widely. Some research suggests that as many as 95% of enterprise Gen AI pilots fail to reach production or even demonstrate measurable ROI. The reason? Long-standing data hygiene issues.<\/p>\n\n\n\n<p>Thanks in no small part to AI, data growth has become exponential, but organisations have largely failed to keep up. This influx has far outpaced storage processes and organisations have somewhat taken their eye off the ball, with \u2018junk\u2019 data being stored alongside the \u2018useful\u2019 data required for AI usage. And ultimately, AI systems inherit not just the bias but also the quality and structure of the data they are trained on. So, if the training sets are poorly structured and include \u2018junk\u2019 data, outputs and usability suffer.<\/p>\n\n\n\n<p>There\u2019s also a significant knock-on effect with compliance and regulation. While regulatory bodies are yet to agree on a unified approach to AI regulation, it\u2019s already becoming clear that visibility will be central to future requirements. In Europe alone, the EU AI Act and the NIS2 Directive are already signalling a broader push for stronger governance, transparency and control over operational and training data. And without strong sovereignty, organisations will remain unable to map and understand their data landscape to adhere to existing and future requirements.<\/p>\n\n\n\n<p><strong>Sorting the wheat from the chaff<\/strong><\/p>\n\n\n\n<p>After the last few years of data growth, the sheer scale of the workloads most businesses now hold can seem daunting. Before organisations can improve their data hygiene, they first need to understand and classify their data. Not just for what it contains, but also according to how sensitive it is.<\/p>\n\n\n\n<p>A piece of data may be useful for a Gen AI pilot, but if it\u2019s too sensitive, it cannot be used. This level of understanding not only avoids mistakenly giving Gen AI programmes sensitive data, but could also be key to creating Gen AI that delivers on its potential. Instead of training it on a pile of \u2018useful\u2019 data peppered with \u2018junk\u2019 data, organisations will be able to feed AI only the information it needs.<\/p>\n\n\n\n<p>Once this is all in place and you know what you\u2019re working with, organisations can begin to define the sovereignty requirements for each data bucket, including both regulatory and locality rules.<\/p>\n\n\n\n<p>For some, the knee-jerk reaction is to restrict usage to meet the strongest requirements of data localisation laws. Still, the EU\u2019s GDPR, for example, doesn\u2019t mandate localisation within a specific EU country, just to the European Economic Area (EEA), although it does place strict restrictions on the transfer of personal data outside the EEA \u2013 creating a \u2018soft localisation\u2019 effect in practice.<\/p>\n\n\n\n<p>There\u2019s a lot of nuance within this, which is why many organisations are adopting hybrid or multi-cloud architectures to maintain flexibility over where workloads are processed and stored. With these, organisations can restrict data where needed to meet localisation requirements, while still maintaining data portability, which will be essential as regulations continue to change. This flexibility and transparency allow organisations not just to monitor where their data resides, but who can access it \u2013 essential knowledge not just for compliance, but for security too.<\/p>\n\n\n\n<p><strong>Not just a tickbox<\/strong><\/p>\n\n\n\n<p>Up until now, data sovereignty has been relegated to the bottom of the priority list, seen mostly as a compliance exercise. Organisations have ticked it off, but only as part of a longer list of regulatory requirements, rather than considering it as a vital part of their data strategy. But if fully understood and wielded correctly, aligned with the wider business strategy, it can do much more.<\/p>\n\n\n\n<p>Not only can it feed into the data governance frameworks that underpin operations, but it can also help inform and establish AI governance. With clean, structured and classified data, organisations can finally unlock the true potential of their Gen AI pilots.<\/p>\n\n\n\n<p>So far, data sovereignty has been underestimated, but with Gen AI innovation stalling and regulation catching up, organisations can\u2019t afford to do so any longer.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As organisations accelerate AI adoption, the need for strong data governance and sovereignty has become critical to unlocking innovation while maintaining compliance and control. Michael Cade, Global Field CTO at Veeam Software, explains why clean, structured data and purpose-built architectures are essential to making AI both effective and secure. So far, AI adoption has outpaced [&hellip;]<\/p>\n","protected":false},"author":4189,"featured_media":168827,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,18793,573,497,1489,29,93],"tags":[22362,577,7362,444,1336,2038,2109,1064,76,21622,2125,18593,367,3682],"class_list":["post-168825","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-europe","category-features","category-government","category-insights","category-software","category-top-stories","tag-ai-regulation","tag-artificial-intelligence","tag-compliance","tag-data-governance","tag-data-management","tag-data-privacy","tag-data-security","tag-data-sovereignty","tag-digital-transformation","tag-eu-ai-act","tag-gdpr","tag-generative-ai","tag-hybrid-cloud","tag-multi-cloud"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/168825","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/4189"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=168825"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/168825\/revisions"}],"predecessor-version":[{"id":169929,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/168825\/revisions\/169929"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/168827"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=168825"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=168825"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=168825"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}