Beyond sovereign AI

Beyond sovereign AI

Gabriele Obino, vice president for Southern Europe and the Middle East at Denodo, on what sovereignty really means for Saudi government.

As Saudi Arabia celebrates National Day, there is an opportunity not only to reflect on the Kingdom’s transformation, but to consider the capabilities that will shape its next chapter.

In 2026, that question is increasingly about Artificial Intelligence.

The Kingdom has designated 2026 as the Year of Artificial Intelligence, following Cabinet approval in March. The initiative reflects a broader shift from building AI foundations towards deploying the technology at scale and creating measurable impact across Saudi society and the economy.

Government is already central to that shift, and Saudi Arabia’s progress on digital government, with services increasingly integrated across institutions and platforms, is changing the sovereignty conversation.

Data residency, domestic infrastructure and national AI capabilities remain important foundations. But a system can be sovereign in location while still being dependent on technology, disconnected in information, blind to policy or uncontrolled in action.

Sovereignty cannot stop at localisation

Consider an AI-enabled government service assessing whether a citizen qualifies for a particular service or form of support.

The model might operate inside the Kingdom and provide strong Arabic-language capability. Yet an appropriate outcome could depend on information held across several systems, the latest eligibility rules, the purpose for which particular data may be used, which organisation owns that information and whether the AI is authorised to recommend an outcome or make a decision, none of which is settled simply by where the model and data sit.

For government, sovereignty therefore needs to be a continuing capability rather than a condition achieved at the point of procurement or deployment.

One useful way to assess that capability is through a developing perspective built around six connected dimensions of sovereignty, each addressing a different form of control.

The first is data sovereignty: who controls the information?

Saudi Arabia has already established substantial policies and regulation covering the protection, classification, sharing and management of data. The next challenge is operational.

Government information is inherently distributed across ministries, agencies, applications, cloud environments and legacy systems. Sovereignty therefore has to remain effective when information is discovered, accessed and combined, not only when it is stored. Ownership, classification, purpose and permissions need to remain visible at the point of use.

Centralising every dataset is not necessarily the solution, more copies can create more governance points and increase the potential for inconsistency. But keeping information isolated can also prevent government from creating value across organisational boundaries.

This becomes especially relevant as digital services become more integrated. At LEAP 26, SDAIA and the Digital Government Authority noted that Tawakkalna was averaging more than 4.4 billion transactions a month and serving over 13.3 million monthly active users. By June 2026, 40 government, private and non-profit entities had added a further 160 services to the platform, spanning education, health, housing, justice, transport and the economy. That scale of integration creates public value, but it also shows why data cannot simply be treated as a collection of isolated institutional assets.

Data sovereignty, then, is not control over where information rests. It is continuing control over how information is accessed, combined and used.

The second dimension is infrastructure sovereignty: who controls the foundations?

Domestic cloud, data centres, computers, networks and cybersecurity strengthen national capability. Yet infrastructure sovereignty is not necessarily about owning every component.

It is also about knowing where critical dependencies sit, deciding which workloads require the strongest domestic controls, maintaining resilience and ensuring that government has credible options if technologies, suppliers or circumstances change.

The Digital Government Authority is advancing both whole-of-government integration and cloud adoption across Saudi public institutions. Sovereignty in this context should preserve choice rather than replace one form of dependency with another.

The third dimension is AI sovereignty: who controls the intelligence?

Public institutions need control over which models are used, what information grounds them, how sensitive data is handled and how easily one model or platform can be replaced, control that goes well beyond simply knowing where a model is hosted.

Arabic-language capability and Saudi cultural relevance are essential elements of national AI capability. But public-sector AI also needs current institutional context: the right policy, appropriate permissions, citizen circumstances, service rules and relationships between government entities.

Language helps AI understand what is being said. Institutional context helps it understand what government means.

The fourth dimension is policy sovereignty: whose rules does AI follow?

Saudi government organisations operate within national regulation, data classifications, ministry mandates, service rules and defined decision rights.

These controls may exist across different systems, documents and organisational processes. The challenge is ensuring they remain authoritative when information is actually used by AI.

An AI application may need to know whether particular information may be accessed for a specific purpose, which organisation owns it, which version of a policy applies and where an issue needs to be escalated. Policy sovereignty therefore means ensuring Saudi rules remain effective at the point of use, rather than existing only as governance documentation around the technology.

The fifth dimension is operational sovereignty: who controls the decision?

This becomes more significant as AI moves beyond generating answers and begins supporting recommendations, decisions and actions. The boundaries of authority then matter as much as the capabilities of the model.

Government needs to determine what may be automated, which actions require approval, when a public servant must intervene, what evidence should be retained and where accountability ultimately sits. An inaccurate AI answer is a problem. An inappropriate AI action can become a government event.

That is not a theoretical concern. Saudi Arabia is already seeing emerging uses of agentic AI in national data platforms. In July, the Ministry of Economy and Planning launched a beta version of INSAIGHTS within the Data Saudi platform, enabling users to interrogate more than 7,500 national economic and social indicators using agentic AI. As such capabilities evolve, the sovereignty question moves beyond where AI operates to what it is permitted to do.

The sixth dimension is the most nascent and perhaps the most difficult to define: who controls institutional understanding?

Sovereign understanding means retaining control over the institutional context through which AI interprets information. It extends sovereignty beyond data, infrastructure and models to the meaning that determines how government information is understood and applied.

Government knowledge does not sit in one database, model or application. It is distributed across policies, systems, institutions, relationships, events, responsibilities and the experience of public servants. A government could keep its data inside the Kingdom and run its models domestically, yet still use an AI system that does not understand how agencies relate, which policy is current, what a citizen may be entitled to, or which organisation has the authority to act.

Institutional meaning should not become locked inside a particular model or proprietary platform. If it does, government may retain physical control of its information while losing transparency over how that information is interpreted, or find it difficult to carry the same context to another model as technology changes. Keeping institutional context governed and portable protects choice, continuity and accountability. In this sense, control over meaning may become as important as control over the underlying data.

Sovereignty should enable integration, not fragmentation

The challenge is that stronger control can sometimes create unintended consequences.

If every organisation tightly isolates its information, citizen services that span several agencies become more difficult to deliver. If every new AI initiative creates another copy of government data, duplication and governance complexity increase. If information, models and applications become tightly coupled to a single technology environment, future choice may narrow.

The objective should therefore not be maximum isolation. It should be calibrated sovereignty: preserving ownership, policy, accountability and decision rights while enabling controlled interoperability across government.

Putting this approach into practice requires a data and context layer that connects distributed information while preserving source ownership. Governance must remain effective at the point of access, while AI receives current institutional context without requiring government information to be moved into another centralised platform.

Saudi Arabia’s own digital-government trajectory already points towards greater integration, the scale described above is not simply an architectural fact. It affects how efficiently government can serve citizens and residents, how consistently policies can be applied and how quickly agencies can respond to changing circumstances.

Sovereignty should therefore give government the confidence to participate in global innovation on Saudi terms, not force it to choose between innovation and control.

The real test is public value

Sovereignty matters because of what it enables.

Greater visibility over dependencies can improve national resilience. Portable information and institutional context can give government more technology choice. Stronger policy enforcement and traceability can support trusted AI adoption. Governed interoperability can allow ministries to collaborate while preserving ownership and accountability. Better context can enable government applications to respond to citizens based on their actual circumstances rather than fragmented information.

This is also where Saudi Arabia’s existing investment can generate greater long-term value. The Kingdom has already made significant progress across digital government, infrastructure, data governance and artificial intelligence. The next stage is ensuring that those foundations translate into sovereign government capability: the ability to use new technologies extensively while retaining control over the information, policies, institutional knowledge and decisions on which public services depend.

Enabling Sovereign Government Capability

No single technology, platform or organisation can deliver sovereignty on its own.

Sovereign government capability depends on a combination of secure infrastructure, effective data governance, trusted institutions, clear policy frameworks, accountable decision-making and the ability to apply AI within well-defined boundaries.

As governments increasingly adopt AI, the challenge is not simply to keep data or models within national borders. It is to ensure that information remains governed, policies remain enforceable, institutional knowledge remains accessible and decision-making remains accountable, even as technology evolves.

As Saudi Arabia marks National Day during its Year of Artificial Intelligence, the next phase of transformation may be defined not by the technologies government adopts, but by its ability to retain control, choice and trust while using those technologies to improve outcomes for citizens and residents.

Browse our latest issue

Intelligent CIO Middle East

View Magazine Archive