Skip to main content
August 3, 2026

Digital sovereignty in the age of AI

Are you in control of your digital destiny? In this episode, Alan Pringle and Sarah O’Keefe define digital sovereignty. They break down what organizations need to consider as they bring AI into content operations, from data leakage and competitive intelligence to shifting international regulations.

Sarah O’Keefe: The working definition that I’m using is that digital sovereignty is control over your own digital assets, digital destiny. That could be you personally, it could be you as an organization, or it could be you as a country or as a group of nations. And when I say group of nations, probably 98% of the time I’m talking about the EU, which has some laws in this regard. Digital sovereignty is your ability to control, own, and manage your digital assets and how they are used, reused, processed, resold, repurposed, and all the rest of it.

Related links:

LinkedIn:

Transcript:

Disclaimer: This is a machine-generated transcript with edits.

Introduction with ambient background music

Christine Cuellar: From Scriptorium, this is Content Operations, a show that delivers industry-leading insights for global organizations.

Bill Swallow: In the end, you have a unified experience so that people aren’t relearning how to engage with your content in every context you produce it.

Sarah O’Keefe: Change is perceived as being risky; you have to convince me that making the change is less risky than not making the change.

Alan Pringle: And at some point, you are going to have tools, technology, and processes that no longer support your needs, so if you think about that ahead of time, you’re going to be much better off.

End of introduction

AP: Hey everybody, I’m Alan Pringle.

SO: And I’m Sarah O’Keefe, hello.

AP: Hey there. And today Sarah and I want to talk about something that’s really starting to come to the forefront with all of the AI things that are going on in our world. And that is digital sovereignty. And before we get too deep in that, I need to throw up many, many disclaimers. Sarah and I are not lawyers, nor do we play them on television.

And we are absolutely not lawyers or experts on anything in regard to international intellectual property. So with those disclaimers out there, Sarah, if you would, would you define what digital sovereignty is?

SO: The working definition that I’m using is that digital sovereignty is control over your own digital assets, digital destiny. That could be you personally, it could be you, the organization, or it could be you as a country or as a group of nations. And when I say group of nations, probably 98% of the time I’m talking about the EU, which has some laws in this regard. So it is your ability to control, own, and manage your digital assets and how they are used, reused, processed, resold, repurposed, and all the rest of it.

AP: And I’m going to give a very basic example from my personal life in regard to email. Years ago, actually decades ago, when I got set up with an internet service provider, they provided me with an email address. It had their company name in the domain.com. And I used it for years. But when I switched my ISP, guess what? I had to make a decision.

Do I continue to pay that old ISP, basically rent, to maintain that old email address? Or should I move to one of maybe the free email providers? So I did a little research, and my ultimate decision was I created my own domain with my name, and I kind of just decided not to ever use again the email provided by an ISP because if you switch it, you’re going to possibly lose control of that email address. And at the time that I made the switch, a lot of the free providers, they would scan your email to provide targeted ads and some other things that was kind of unsavory to me. 

So I ultimately made the decision I was going to own the domain and set that up myself and pick my own software that I hooked up to it to use to to read it. And I did not use a third-party email provider to basically pull in or reference my account. I am using an open-source standalone email client to kind of minimize who can poke into my email. So that’s one very basic example of how I kind of took control of my digital life as it were.

SO: Right. And if we apply that to content ops, again, staying pretty general, you think about cloud systems, like the cloud universe versus on-prem.

AP: Yes.

SO: And when you talk about, let’s say, a CCMS, a component content management system that is on-premises, the the argument was always, well, that way all of our content lives on our servers, in our organization, we have complete control over it.

Along come the cloud services, the cloud-based CCMSs and everything else. And they say, well, yes, but it’s much cheaper for you to put this into the cloud on our systems, which are shared. And you know, there’s advantages of upgrading, and there’s all sorts of advantages to cloud systems, mostly around IT overhead. from a digital sovereignty point of view.

You are delegating to that cloud system and you have some sort of a contract or a service level agreement. And again, we are not lawyers, but you have this agreement that says we the cloud provider promise to not scan your information or not use it for evil or not, you know, there’s a bunch of stuff in that contract that governs how cloud provider is or is not allowed to handle your content, your personal information, your credit card information that you might be putting in there and all the rest of it. And with software as a service, with cloud systems, we have for the most part cut over into cloud. You know, that’s that’s kind of the default these days. There’s hardly anybody that is still putting their content, their content and their content management systems on their own proprietary in-house servers.

AP: Yes, correct.

SO: So we have decided that for cloud, you know, cloud writ large generally, that the advantages of cloud outweigh the disadvantages. Now, moving this a little bit more towards content and slowly towards AI, where things get really interesting with digital sovereignty, if we talk about machine translation for a minute.

There are a couple of different ways of doing machine translation, obviously, but big picture, you can have your in-house machine translation system and database, and you can control that and govern it and do things with it. Or you can take your content and you can throw it at a public-facing machine translation system. And the risk that you run when you throw something at a public system is that they will take your proprietary confidential content.

And use it. So I throw at it a sentence that says, the XYZ company has developed a special new thing, right? And I need that translated into various languages and I get it translated. But as a result of that, I am leaking information. I am leaking my confidential, potentially information into the machine translation services. And there are some really interesting security issues around that and how you might be able to.

As a competitor, extract that back out. But just dialing it back for a for a minute, we understand the concept of leaking information by using public-facing machine translation, right? Publicly available machine translation. But one thing that I think is very often overlooked is that machine translation, the fact that I ask for a specific language, never mind the content,

But the fact that I am now asking for a new language provides competitive intelligence in the sense that that means that I or my organization now cares about that locale, that that language. So let’s say that I’ve been consistently submitting European languages for machine translation, right? If you but if you look at my record of what I’m asking for, you will see that all of a sudden, about three months ago, I started adding a bunch of Asian languages.

Well, what does that tell you about what I’m up to? Either I’ve decided that Asian languages are interesting and fun, or my organization, I mean, presumably I’m doing this for work and not fun, or my organization is launching into Asia. And I don’t actually need to see the content to sort of get that piece of competitive intelligence out of it. So essentially.

The way that I’m using the machine translation, even if we protect or have a contract that says you you are not allowed to look at what I’m processing, but if you can look at the parameters of what I’m processing, that might give you enough information to tell you something about what I’m up to.

AP: Yeah, so basically what you request or don’t request, as the case may be, can give away clues that you may not want floating out in the world.

SO: Right, exactly. So now we take this to AI and we think about digital sovereignty for AI, and it gets very much more complicated. So t first, taking this example of machine translation, if you think about AI chatbots and prompting and public-facing models, then in the same way that requesting a particular language so well, let’s back up. 

Let’s say that we have a contract with XYZ model provider and it says we will not use your input as training data. We will not use your output as training data. Cool. But are you going to use my prompts as competitive intelligence? Because think about what I’m prompting on. Hey, tell me about the intellectual property laws in Vietnam.

Tell me about how to go to market in a particular country. Tell me about strategy for pricing tiers, right? If I’m doing those kinds of prompts, then you, as my competitor or adversary or whatever we’re dealing with here, can get an awful lot of information out of what I’m up to, right? You can figure out what I’m up to just by looking at my prompts. So we have to worry not just about the protection of the input and the output, but also the actual prompting that I’m using to get the inputs and the outputs, because the prompting itself has competitive information in it. So then when we start thinking about digital sovereignty, you say, okay, well, then what we should probably do is have a restrictions on usage of input, output, or prompting data by the vendor, right? The vendor who’s providing the AI model should have a contract that says we are now not allowed to use this stuff.

But then we take that another step forward. Nearly every contract I’ve seen in the past, you know, whatever years, decades says we promise not to use this unless we’re required to by law. So in other words, if a government subpoenas us, we will cough up this information as we are legally obligated to do, that sends us right down the road to something called zero data retention. Which is the idea that you process your AI prompts in such a way that they are not retained, that the inputs and outputs are not retained by the provider, so that if they are subpoenaed, they cannot in fact cough up the information because they don’t have it.

And then if you’re more paranoid than that, and some of you, you know, depending on what industry you’re in, should be, you start thinking about bringing the model in-house. So instead of using public-facing with a an enterprise contract of some sort, you think about bringing the model onto again, in-house on premises in the same way. This is right back to cloud versus not cloud.

And then we have some questions about what model are you using and do you know what’s going on in the internals of that model, which points you maybe at using something open source or maybe not. It depends. But there’s all these layers of decisions that you have to make around how you’re going to use AI and how concerned you are about leakage from your use of AI to you know your competitors or something else. 

Now, over the top of that, we start thinking about nations rather than organizations. And we have some of this with just generalized cloud systems. GDPR, the European Data Protection Regulation, says a lot of things about how you process personal information and what the requirements are and what you are and are not allowed to do. Now

If you’re a European company inside the EU, you’re clearly subject to GDPR. But many non-European companies are also subject to GDPR because you have a server in the European Union, or you have customers in the European Union, or you operate in some way in the EU, which then that’s enough to have you sort of folded into GDPR.

On the AI side, we have something very similar going on where companies are looking at AI models and making decisions based on what jurisdiction does that model belong to. Now, the most prominent of these is that, for example, currently, as of right now, as we’re recording this, the American models, like a ChatGPT, a Claude, that kind of thing, are largely not available in China. and it’s a little bit tricky in terms of is it actually banned or is it just restricted, but broadly not available. The Chinese models are available in the US and are open source, but if I’m an American or actually, let’s say I’m a European company and I’m trying to figure out my AI strategy. Do I use an American model? Do I use a Chinese model? What happens if I’m using a Chinese model and then the US government bans that model in the US and I have operations in the US? And I’m suddenly now what? 

In reverse, if I’m a an American company and I’m using American US models, and I have, let’s say, a chatbot, and I go to market in the EU. I am now subject to the EU AI Act. And the EU AI Act, with some complications for when it goes into effect, et cetera, has rules that say things like: if you put up a chatbot, you have to disclose that it’s AI. You can’t pretend that people are talking to a human. You have to say this chatbot is AI. This image was generated by AI. there are disclosure requirements in the EU. That are much more stringent than the disclosure requirements, which are none in the in the US.

AP: Yeah. In the US. And again, if you were making decisions about what model to get, where you should place your servers, etc., we highly recommend that you speak to your intellectual property attorneys and do not take advice from the two of us. Thank you very much. 

SO: Right. This entire podcast is just an ad for IP lawyers. You’re welcome, IP lawyers.

AP To me, this whole thing is so interesting. You know, we talk about the digital world and globalization and you know, there’s no boundaries anymore. Guess what? They very much apply here because, like you said, if you have customers in the EU, and you may be a US-based company, but that does not give you clearance to absolutely ignore GDPR. So we still have to be aware of geographical boundaries and the laws of all the nations inside those boundaries.

SO: Yeah, the thing that keeps me awake at night is the question of what if I build out an entire thing on some model? It it kind of doesn’t matter which one, but I build an entire infrastructure based on some AI vendor and then and then that AI vendor gets banned by a government whose jurisdiction I or my operations are subject to. 

AP: But there are significant costs.

SO: Right. And I’m not picking on any particular country. It it could go every which way that you can imagine. So then as a as an organization, especially if you’re a big international organization, you start thinking about well, maybe we should bring all this stuff in house so that we can control it.

AP: And infrastructure involved with that decision.

SO: Right, because now we’re talking about you operating your own data center, and that makes you, you know, not so beloved by literally anybody. So I mean, this is a really hard problem. And what’s fascinating to me is that we generally in software, software as a service, generally cloud has pretty much won with some minor exceptions for air-gapped systems, high security systems, network operations centers, or you know, software that runs utilities, that kind of thing. Things where you really, really, really do not want it taken down by external things. So you have this idea of secure systems, air-gapped systems, systems down at the bottom of a mine that are cut off because they’re literally down at the bottom of a mine.

AP: Yes, inside the earth, correct.

SO: We used to talk about airplane help, but that’s much less of an issue anymore because now, for better or for worse, we have Wi Fi on the planes.

AP: Yes.

SO: Mostly for the worse. Anyway…

AP: At least I haven’t heard a meeting yet, an online meeting. I’m sure it will happen at some point, but I have yet to see that happen. Thank goodness. 

SO: On a plane? Yeah. Hmm.

AP: Yeah.

SO: So anyway. So cloud, the risk-reward for cloud versus on-prem has pretty much tilted towards the cloud systems in general, with you know, very specific kinds of exceptions for I would say unique use cases, but it’s kind of like a ninety ten or an eighty-twenty kind of split.

Back in the day, it was everything was on-prem and cloud was the exception, but it’s it’s very much shifted. And now with all this AI stuff, everybody’s using currently big picture. As everybody’s adopting AI, they’re using public-facing models, public-facing chatbots, maybe with like some sort of an enterprise license. But I just have this feeling that a lot of this stuff is going to be brought into in-house at least managed models. 

AP: Exactly. Yeah.

SO: So still sort of cloud software as a service, but with a big enterprise contract wrapped around it that says, here’s what you you, the vendor, the AI vendor, can and cannot do with our data. But it’s a it’s just a really interesting problem because we in content we don’t deal with these sort of national issues that much, like sovereignty at the national level. And I think that with AI systems, we’re seeing a lot of concern around, well, what does it mean that this might be regulated differently in different countries? And how do we manage that? I mean, how do you put together an AI content ops strategy if you are not sure whether your model will be available in that country over there next week.

AP: Yeah, and I’m just thinking, think about audits are often a component of a contract, and you add AI on top of this, and all of the jurisdictional things you’re talking about, all of the facets of those audits just got even more complicated with AI than they already are, which that is probably a whole other discussion. Again, not a lawyer, don’t want to be, but I can see that being a very contentious something that’s gonna have to be ironed out in the very near future.

SO: Yeah, so digital sovereignty, it’s it’s very hard to say and even harder to spell. but I think that it’s something that we should be thinking about as content people and we should at least understand the big picture of what’s going on so that when we go to our corporate legal team and say, Hey, we’re worried about this, we can at least have a reasonable conversation about where this is going.

AP: And again, we don’t know where it’s going, but it’s definitely something to keep an eye on. This is a great place to wrap up. Sarah, thank you very much for a conversation that I frankly haven’t heard a lot about in the content world.

SO: Well thank you. Not a lawyer.

AP: Nor am I. Until the next time everyone, thanks. Bye.

SO: Bye everybody.

Subscribe to our monthly newsletter for more insights on AI, content ops, and more!