FPT Americas’ Niranjan Krishnan on AI Sovereignty with 7 Critical AI Sovereignty Observations Every Enterprise Must Confront: A Serious Insights Interview

AI sovereignty is moving from policy rhetoric to an urgent question of operating models. As enterprises embed foundation models, agents, vector databases, and automated decision workflows into core processes, they must decide which assets they truly control—and which dependencies could expose valuable knowledge, constrain strategic choices, or create costly compliance risk. The interview argues that sovereignty is not synonymous with owning every layer of the stack; it is the ability to direct, modify, move, monitor, and, when necessary, stop AI operations without being trapped by external dependencies
In this Serious Insights interview, FPT Americas’ Head of AI Solutions Niranjan Krishnan explores what meaningful AI sovereignty looks like in practice. He explains why proprietary data, decision rules, and operational flexibility matter more than building every model or data center in-house; why “unseeing” data in embeddings or model weights is a growing concern; and why the organizations that can orchestrate data, models, infrastructure, and governance together will gain the durable advantage.
Top takeaways from our Niranjan Krishnan interview:
- Sovereignty is operational control, not infrastructure ownership. Enterprises can use public cloud and commercial models if they retain control of data flows, protections, governance, portability, and the ability to change providers.
- Proprietary knowledge is the highest-value asset—and the hardest to recover once embedded. Sensitive data can persist in vector embeddings, fine-tuned weights, caches, and agent workflows, creating both persistence and exfiltration risks.
- The future is federated, modular, and governed. Regional rules will drive more localized AI operations, while competitive advantage will go to organizations that can coordinate models, infrastructure, proprietary data, and guardrails at speed and scale.
The Niranjan Krishnan interview
What does AI sovereignty mean operationally? Does it require ownership of infrastructure and models, or can an enterprise achieve sovereignty while relying on cloud providers and commercial foundation models?
AI sovereignty is a catch-all term used to represent the level of control and autonomy an organization has over its AI estate and its operations. This includes physical and digital infrastructure, intellectual property, business capabilities, and decision-making. Operationally, AI sovereignty means having the ability to build, run, monitor, control, modify, transfer, and pause AI processes at will, without external dependencies or constraints standing in the way.Â
Sovereignty does not necessarily mean doing away with cloud providers and commercial foundation models. It does not always require building a fully vertically integrated AI supply chain, complete with physical data centers and self-trained foundational models. Enterprises can achieve operational sovereignty with cloud providers and commercial foundation models as long as they put in place the requisite controls end-to-end. This includes having strong intermediate layers to manage the inflow and outflow of data into frontier models, thoughtfully designed and located data infrastructure, and modular and flexible AI operations that do not have one-way doors with hard third-party lock-ins.
Which assets must a company control to claim meaningful AI sovereignty: data, model weights, training pipelines, inference environments, intellectual property, decision rules, or all of them? What else?
“Sovereignty” is a catch-all term, as I mentioned earlier. It has a broad scope. It includes all of the above, but at different levels of criticality.
Data, IP, and decision rules are the most critical assets that must be controlled directly and from the inside. Datasets, transformations, vector embeddings, knowledge bases, prompts, policy engines, guardrails, validations/evaluations, agent workflows, agent boundaries, logs, telemetry and monitoring systems – these are non-negotiable internal controls to establish.
Model weights and training pipelines can be externalized with intermediate layers to mediate data flows with security, IP protections and vendor contracts on permissible use of data. Likewise, sovereign infrastructure can be achieved by leasing virtual private clouds or regional sovereign cloud zones.
One thing I’d add is retaining the ability to swap one vendor for another without disrupting business as usual, especially given the pace at which the AI space is evolving. That’s going to be super-critical to future-proof sovereignty.
Where are multinational companies discovering the greatest sovereignty risks today: vendor dependency, cross-border data flows, regulatory exposure, model behavior, or loss of proprietary knowledge?
For the clients I work closely with, it’s a toss-up between loss of proprietary knowledge and vendor dependency.
Companies have invested a lot of capital over decades in creating their internal knowledge assets and expertise that give them the competitive edge. These include formalized IP and trade secrets as well as captured datasets, documentation, business processes and workflows, and other forms of tribal knowledge. They are very protective of these assets and have a genuine concern about the risk of their proprietary data often used in the context layer, leaking out in some form or the other.Â
The AI space is evolving rapidly, and new models keep getting released. It is not always clear which model vendor would perform well for which use case in terms of the key parameters like accuracy, speed, and cost economics. Companies see a clear risk with locking themselves in with a particular vendor or model that may not be the best option for the long term.Â
How should companies distinguish AI sovereignty from data sovereignty? What new risks emerge when proprietary data becomes embedded in models, agents, vector databases, and automated workflows?
There may be some overlap between data and AI sovereignties, but they are distinct.
Data sovereignty is mostly about where data stored is located physically, who has access to it and for what purpose, who controls them, and which regional regulations govern its residency, usage, and protection.Â
AI sovereignty covers the full lifecycle of training, reasoning, and execution: what transformations are carried out on data, how models reason over data, where inferencing happens, who controls the algorithms, what automations and decisions are carried out and how, and who is to be held accountable for what.
Data sovereignty tends to be driven more by regulatory compliance, while AI sovereignty is more about having a winning AI operating model.
A key risk that’s emerging in this space is related to “unseeing” and “pulling out” data. Once data makes its way into a foundational layer as vector embeddings or model weights, it is often not possible for AI processes to selectively “unsee” parts of the data (Persistence Risk). Policies like the “Right to be Forgotten” can become very difficult to implement. The reason is that data goes through complex transformations as it becomes part of vector embeddings and fine-tuned model weights. Specific data elements cannot be culled out easily from those endpoints without rebuilding a large part of that system.Â
The “pulling out” risk is that once PII or sensitive IP leaks through the context layer, it can be implicitly cached or memorized by the model. Even if that information is removed in the future, the model could continue to have that available in memory. This carries a two-fold risk. One, the model continues to use sensitive information for inferencing (Persistence Risk). Two, it can be extracted by malicious players through targeted attacks (Exfiltration Risk). Net-net, a double whammy.
How should executives evaluate the economics of sovereign AI? Which costs tend to be underestimated when companies compare private infrastructure with public AI services?
AI is a software system at the end of the day, and executives should take a Total Cost of Operations (TCO) approach to managing it. This involves factoring in both trackable hardware and software costs, as well as hard-to-quantify risks related to business continuity, regulatory exposure and other liabilities.Â
That said, there are some cost components that need specific attention when it comes to AI.
Building and managing private AI infrastructure needs specialized skills, and building that team in-house tends to be more expensive than many companies anticipate. AI workloads are not even and tend to have peaks and lows with idle capacity. The cost of underutilized GPUs is another thing that tends to get underestimated when enterprises opt for the in-house route. The ongoing upkeep and upgrade work over the lifecycle of AI solutions tends to be underestimated too.
When it comes to public AI, token costs are often underestimated and need to be managed consciously. Large context windows and agent loops without circuit-breakers can lead to sticker shock.
Does the growing emphasis on sovereignty risk fragmenting enterprise AI into regional models, datasets, and platforms? What would that fragmentation mean for global operations and knowledge sharing?
Yes, fragmentation is inevitable when you need to respect requirements that vary by region or market. You need to move away from a top-heavy, centralized approach to more of a federated model when it comes to data hosting, model hosting, and inference processes.
We’re already seeing this in the data space with data mesh architecture where broader standards and frameworks come from the central level, but actual implementation is carried out locally with a lot of regional-level customization and control. I see decentralization of AI models and implementation to ensure sovereignty as a natural extension of this phenomenon. AI infrastructure, models, inferencing, and controls would need to sit closer to the end users, in their respective regions.
Federated operations will add overhead in terms of creating and managing multiple variations of architecture and AI processes. Plus, there will likely be knowledge silos that limit sharing of learnings and cross-pollination of ideas. But most large, global multi-market enterprises are already sufficiently modularized in their operations that I don’t see them needing to give up significant advantages they already have for the sake of AI sovereignty.Â
Over the next two years, where do you expect the competitive advantage to come from: proprietary models, proprietary data, infrastructure ownership, orchestration capabilities, or the organizational ability to govern all four?
This may not come as a surprise, but I’d say the ultimate competitive advantage comes from the ability to effectively bring together and operate all four pieces at speed and at scale, with no compromise on safety and security.
That said, if we look at the enabling layers, AI models and infrastructure are getting commoditized rapidly – accessing them is no longer a constraint. But proprietary data is different. It’s the secret sauce. Clean, well-organized internal data is the one asset that competitors can’t simply replicate.
About Niranjan Krishnan
Head of AI Solutions, FPT Americas

Niranjan Krishnan is a seasoned data and AI leader with two decades of experience in delivering on the promise of data. He has led large cross-functional teams and deployed dozens of AI/ML solutions across industries. Niranjan is the Head of AI Solutions at FPT Americas, FPT Corporation. A trusted ally to executives and business leaders, he is passionate about Responsible AI solutions that create measurable value for businesses and customers.
For more serious insights on AI, click here.
For more serious insights on learning, click here.
Did you enjoy the Niranjan Krishnan interview? If so, like, share or comment. Thank you!

Leave a Reply