CASE STUDY
GDPR in Europe, for example, so organisations were already aware of the importance of protecting data. Data is what drives AI, Machine Learning and everything related to it, so the first question is: Can you protect that data?
Then we move into operations. You may be running in a public cloud located in Europe, but if the people running that operation belong to a different jurisdiction or have to comply with different laws, they could potentially be prevented from providing you with that service. That is the operational side of sovereignty and it is one of the reasons we have seen changes in how hyperscalers operate their services.
Technology also has a significant role to play. Today, for example, you can use technologies such as Confidential Computing to protect data so that even the people operating your systems cannot access it. With the appropriate key management and other controls, you can maintain much greater control over that information.
Then there is the question of what is actually inside the technology. When we talk about AI, this becomes even more important. Nobody fully understands how Generative AI reaches every decision it makes. We know that it works, but we don ' t always know exactly how those decisions are reached. We all talk about hallucinations and these are examples of the potential consequences of not having complete control and visibility.
The final area is assurance, particularly when you are operating in Europe. You need to understand the regulations and whether you are aligned with requirements such as the Cyber Resilience Act and the AI Act. These requirements are going to become increasingly important across different jurisdictions.
There is also a fifth element that we sometimes forget: people and talent. You can talk about these four pillars, but if you don ' t have people locally within your jurisdiction and sovereign environment who have the necessary skills, then potentially your most valuable asset is missing.
This is another advantage of open source. You don ' t need to be part of Red Hat to understand our technology. If Red Hat ceased to exist or had to change its business model, there would still be people with access to that technology who could continue operating and developing it.
That is critical to having the full picture: being able to maintain control of your data and your operations, having access to the technology and having the local talent capable of maintaining and developing that technology. Finally, there is the jurisdictional element and ensuring you can comply with local laws.
Highly regulated sectors can ' t rely on centralised public clouds due to strict risk boundaries. How does Red Hat’ s ' deploy anywhere ' model allow firms to run sovereign AI on local infrastructure without losing capability?
One of the key differentiators is making sure we provide technology that can run anywhere. When we talk about hybrid cloud, this isn ' t something new or something we ' ve started driving because of sovereign cloud. The idea has always been that our software can run equally well in a public cloud, with a sovereign provider or on your own premises.
We have also invested in technologies that allow you to run in a public cloud without the people operating that environment being able to access your data, such as Confidential Computing.
But there is still a risk around the availability of services. What happens if somebody says that a particular company can no longer provide that service to you? What happens if the contract changes and they decide they no longer want to provide that service? www. intelligentcio. com
INTELLIGENT CIO EUROPE
17