Leadership1 distinct publisher3 min readUpdated
A Forbes Tech Council column argues enterprise AI sovereignty clauses fix where data sits and say nothing about whose model gets smarter. The author also sells the remedy.
The Board Room · Leadership desk
Compiled by The Board RoomSomething wrong?How this is made
Writing in a Forbes Tech Council column, SymphonyAI chief executive Sanjay Dhawan argues that almost every enterprise AI vendor has a data sovereignty story built around on-premises options, residency agreements and private cloud configurations, and that almost every one of them answers the wrong question [1][2]. The question procurement skips is what happens to the intelligence: the model that acts on your data, trains on pooled inputs from across the vendor's customer base, and improves in an environment you do not control [4].
Dhawan's framing is that enterprise AI procurement treats sovereignty as a data-location problem, solved by negotiating the right contract, keeping data in the right jurisdiction and satisfying the legal team [3]. He argues the more consequential issue is competitive rather than compliance-driven [5]. Every process anomaly detected, transaction flagged and demand signal interpreted is a data point [6]. In most current deployments, according to Dhawan, that data point makes the vendor's shared model marginally better for every customer the vendor has, including your competitors, which means the buyer is contributing to an intelligence asset it does not own [7].
He also says, on his own observation, that the fine print in most enterprise AI agreements does not deliver the level of data control buyers assume they have, and that enterprises are connecting sensitive operational, financial and customer data to shared cloud infrastructure under terms offering less visibility than their own governance frameworks require [8][9]. The regulatory floor is moving underneath that gap. The EU AI Act's risk-tiered requirements and the Financial Conduct Authority's model risk management expectations have turned data governance from a planning exercise into a standing requirement [10]. In the United States, April 2026 interagency model risk management guidance from the Office of the Comptroller of the Currency, the Federal Reserve and the FDIC reset the baseline for how banks govern the models they rely on, while leaving generative and agentic AI outside its scope entirely [11]. So the fastest-moving category of deployment sits outside the reset baseline [12].
The structural point is the useful one. General-purpose vendors and hyperscalers are built cloud-first, which is what makes them capable at scale and also what shapes the sovereignty options they can sell [13]. Residency agreements and private deployments are available; a system designed to keep improving with no external data dependency at all is harder to source from that architecture, because the more isolated the deployment, the less the shared model gains [14]. Vendor economics and buyer interest therefore point in opposite directions on exactly this term [15].
The trade is real in both directions. Frontier models are powerful because they train on vast pooled data, so the more isolated the deployment, the fewer of those advantages carry over [16]. Dhawan proposes vertical AI as one answer, and discloses that his company builds it for industrial, financial services and retail organisations [17][18]. He concedes the limits: a platform built for financial crime detection will be unremarkable at everything else, leaving most buyers managing more than one AI relationship rather than fewer [19]. Isolated deployments also push infrastructure, monitoring and lifecycle responsibility back inside the enterprise [20].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The column 'Why Companies Don't Own Their AI' was published by Forbes (Forbes Tech Council) and written by Sanjay Dhawan, CEO at SymphonyAI, described as having 30 years leading global tech companies.
Dhawan discloses that his company builds vertical AI for industrial, financial services and retail organizations.
Dhawan poses the diligence question: what specifically changes about model performance when the external data pipeline is closed, and how is that measured?
Dhawan writes, based on what he has seen, that the fine print in most enterprise AI agreements does not deliver the level of data control that buyers assume they have.
Dhawan writes that enterprises are connecting sensitive operational, financial and customer data to shared cloud infrastructure under terms that provide far less visibility than their governance frameworks require.
The EU AI Act's risk-tiered compliance requirements and the Financial Conduct Authority's model risk management expectations have shifted data governance from a planning exercise to a standing requirement.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-authored column, no primary documents
The cluster contains exactly one source: a Forbes Tech Council contributed column. Its most consequential market-wide claims — that most enterprise AI agreements fail to deliver assumed data control and that customer data is making vendors' shared models better for competitors — are hedged as the author's own observation with no contract text, survey, sample or named vendor terms. The regulatory anchors (EU AI Act, FCA model risk expectations, an asserted April 2026 OCC/Fed/FDIC interagency guidance excluding generative and agentic AI) and the three named sovereign AI commitments are all uncited. What is firmly evidenced is provenance and the diligence question the piece poses; the substantive diagnosis is not.
No usable adoption signal
Nothing in the supplied material measures uptake of model-isolation or sovereign AI architectures. The only adjacent datapoints are a secondhand, uncited mention that H2O.ai, Palantir and IBM made sovereign AI commitments in the prior twelve months, and the author's disclosure that his own company sells vertical AI — neither with deployment counts, customer references, contract volumes, pricing or benchmark results. Inferring adoption from a vendor's own column would be guessing.
Sweeping market diagnosis outruns its evidence
The framing is universal — 'almost every' vendor answers the wrong question, 'most' enterprise agreements fall short of assumed control, buyers are feeding an intelligence asset they do not own — while support is one executive's stated experience. The column also omits the strongest counterweight, namely the no-training and opt-out contract commitments already common in enterprise AI deals, which would narrow the gap it describes. Two things hold the score down from the extreme: the piece discloses the author's commercial interest, and it genuinely concedes the costs of its own remedy (capability lag versus frontier models, more vendor relationships not fewer, in-house maintenance burden), plus it poses a falsifiable diligence test rather than claiming a solved problem.
Author sells the remedy he prescribes
The diagnosis (shared-model vendors capture your intelligence) and the prescription (vertical AI that improves on your data in your environment) come from the CEO of a vertical AI vendor serving industrial, financial services and retail buyers — including the financial crime detection use case the column singles out as exemplary. The channel compounds this: Forbes Tech Council is a contributed-column venue rather than reported journalism, so no editorial adversary tests the claims. Score is not maximal because the conflict is disclosed in-text and the piece concedes real drawbacks of its own product category.
Low — single conflicted source, no corroboration
Confidence in the story's substance is low: one publisher, one author with a direct commercial stake, no primary documents, no adoption measurement, and uncited regulatory and competitor references. Confidence is materially higher on two narrow points — the provenance and disclosure, and the fact that the column poses a specific closed-pipeline diligence question — which are visible on the face of the source. The underlying distinction between data residency and model-training rights is a legitimate procurement issue, but this cluster does not establish how widespread the gap actually is.
product
Washington's secret AI test is coming for open weights, and release dates go with it2 distinct publishers
invest
Treasury's stablecoin rule makes the listing venue liable, not just the issuer4 distinct publishers
invest
Palantir's 93% growth is now a procurement argument, not a manifesto1 distinct publisher
invest
The OCC has a third answer on fintech charters, and it does not announce it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026