Leadership1 publisher3 min readPublished
Data residency is not model isolation, and your contract probably only covers the first
A Forbes Tech Council column argues enterprise AI sovereignty clauses fix where data sits and say nothing about whose model gets smarter. The author also sells the remedy.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- The column 'Why Companies Don't Own Their AI' was published by Forbes (Forbes Tech Council) and written by Sanjay Dhawan, CEO at SymphonyAI, described as having 30 years leading global tech companies.
- Dhawan writes that most AI vendors have a data sovereignty story that explains on-premises options, residency agreements and private cloud configurations, but almost every one of them is answering the wrong question.
- Dhawan writes that enterprise AI procurement generally treats sovereignty as a data-location problem: negotiate the right contract, keep the data in the right jurisdiction and satisfy the legal team.
- Dhawan writes that such agreements rarely address the intelligence itself: the model that acts on your data, trains on pooled inputs from across the AI vendor's customer base and improves in an environment you don't control.
- Dhawan writes that while the concern also matters for compliance reasons, the more consequential issue is competitive.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
Writing in a Forbes Tech Council column, SymphonyAI chief executive Sanjay Dhawan argues that almost every enterprise AI vendor has a data sovereignty story built around on-premises options, residency agreements and private cloud configurations, and that almost every one of them answers the wrong question [1][2]. The question procurement skips is what happens to the intelligence: the model that acts on your data, trains on pooled inputs from across the vendor's customer base, and improves in an environment you do not control [4].
Dhawan's framing is that enterprise AI procurement treats sovereignty as a data-location problem, solved by negotiating the right contract, keeping data in the right jurisdiction and satisfying the legal team [3]. He argues the more consequential issue is competitive rather than compliance-driven [5]. Every process anomaly detected, transaction flagged and demand signal interpreted is a data point [6]. In most current deployments, according to Dhawan, that data point makes the vendor's shared model marginally better for every customer the vendor has, including your competitors, which means the buyer is contributing to an intelligence asset it does not own [7].
He also says, on his own observation, that the fine print in most enterprise AI agreements does not deliver the level of data control buyers assume they have, and that enterprises are connecting sensitive operational, financial and customer data to shared cloud infrastructure under terms offering less visibility than their own governance frameworks require [8][9]. The regulatory floor is moving underneath that gap. The EU AI Act's risk-tiered requirements and the Financial Conduct Authority's model risk management expectations have turned data governance from a planning exercise into a standing requirement [10]. In the United States, April 2026 interagency model risk management guidance from the Office of the Comptroller of the Currency, the Federal Reserve and the FDIC reset the baseline for how banks govern the models they rely on, while leaving generative and agentic AI outside its scope entirely [11]. So the fastest-moving category of deployment sits outside the reset baseline [12].
The structural point is the useful one. General-purpose vendors and hyperscalers are built cloud-first, which is what makes them capable at scale and also what shapes the sovereignty options they can sell [13]. Residency agreements and private deployments are available; a system designed to keep improving with no external data dependency at all is harder to source from that architecture, because the more isolated the deployment, the less the shared model gains [14]. Vendor economics and buyer interest therefore point in opposite directions on exactly this term [15].
The trade is real in both directions. Frontier models are powerful because they train on vast pooled data, so the more isolated the deployment, the fewer of those advantages carry over [16]. Dhawan proposes vertical AI as one answer, and discloses that his company builds it for industrial, financial services and retail organisations [17][18]. He concedes the limits: a platform built for financial crime detection will be unremarkable at everything else, leaving most buyers managing more than one AI relationship rather than fewer [19]. Isolated deployments also push infrastructure, monitoring and lifecycle responsibility back inside the enterprise [20].