AI sovereignty through diversification | CIO

Since 2025, EU financial firms, for example, have been required under the Digital Operational Resilience Act (DORA) to maintain tested exit plans for any critical technology supplier. The UK has had a similar requirement with four US-owned cloud vendors designated as critical third parties: Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, AWS EMEA SARL, and Oracle Corporation UK Limited. These firms will be supervised jointly by the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority, and be required to undergo resilience testing and report major incidents. We can expect to see more vendors fall under this new regime, including AI frontier model providers.
Access is not control
As technology embeds further into enterprise workflows, government control extends into new realms, and points of failure multiply, so businesses need to adapt. Philosopher Luciano Floridi anticipated this six years ago when he said of digital sovereignty that control is the ability to influence something and its dynamics, and it comes in degrees and, above all, can be pooled and transferred.
The ability to pool and transfer AI control is being enabled by gateways and orchestrators, and we can expect to see power shift away from a small number of frontier model developers as customers spread their workflows across multiple models.