Everpure’s Global Data Sovereignty Report 2026, based on 2,100 enterprise organisations across eight markets, reveals a defining disconnect between strategic priority and operational readiness.

“We talk about data sovereignty a lot internally now, but nothing has really changed, to be honest.” A phrase attributed to a senior banking executive in Germany, offered to researchers conducting Everpure’s Global Data Sovereignty Report 2026 captures the current state of enterprise data sovereignty more honestly than any boardroom presentation.
90 percent of respondents of the report consider data sovereignty a business concern. 64 percent have no formal data sovereignty strategy in place. The gap between those two figures is where most enterprises currently live — aware of the risk, unable to translate that awareness into organised action.
Why does the gap exist
Data sovereignty — where data is stored, who can access it, and which legal jurisdictions govern it — has shifted from a compliance consideration to a board-level strategic question. Escalating geopolitical instability, new AI workloads that require knowing precisely where data lives before it can be used and expanding regulatory frameworks like India’s DPDPA have combined to make this question urgent in a way it was not three years ago.
Yet the report reveals that most organisational action is focused on immediate tactical measures rather than addressing long-term operational risk. The top three drivers of data sovereignty action are cybersecurity risk at 47 percent, new regulatory and compliance requirements at 39 percent, and AI adoption at 34 percent. Board-level strategic direction, listed by only 19 percent, ranks last. Organisations are responding to fires rather than designing fireproof buildings.
The tactical nature of current responses shows clearly in what enterprises have deployed. Encryption and access controls — implemented by 60 percent of respondents are the most widely used sovereignty measures. Sovereign or private cloud environments, which require deeper architectural commitment, are in place at only 53 percent. More tellingly, 56 percent maintain no mitigation strategy at all for data exfiltration or service disruption of geopolitical origin — despite identifying geopolitical instability as a concern.
“We’re in this interesting chasm between awareness and action. It’s one thing for a thought leader inside an organisation to be aware of this, but you need to educate and cascade that information across quite a depth of people to come on board. It’s not an initiative executed by an individual — it’s something done in collaboration.”
— Matthew Oostveen, CTO & VP Asia Pacific and Japan, Everpure
What AI has changed about the stakes
If there is one force accelerating the urgency of this conversation, it is AI. The report makes the connection explicit: 92 percent of respondents view data sovereignty as a critical part of their overall AI strategy. 87 percent will prioritise local or sovereign environments for AI initiatives or workloads considered high risk or sensitive in the next one to three years.
The reason is structural. AI systems, and agentic AI systems in particular, require knowing what data exists, where it lives, who has access to it, and whether it can legally be used in a given pipeline — before it is fed into a model. The data discovery and classification work that data sovereignty demands are not separate from AI readiness. It is the same work.
46 percent of respondents regard sovereignty to ensure confidence and trust in AI adoption. 45 percent agree that data sovereignty directly influences where AI models and data are hosted. And 39 percent acknowledge that sovereign AI introduces additional operational complexity — particularly the challenge of migrating legacy systems to sovereign clouds without downtime, closing the gap between compliance expertise and cloud architecture capability, and finding sovereign providers that match the feature depth of hyperscalers.
India’s contradictory position
India presents what is perhaps the most instructive case study in the report. Among all eight markets surveyed, Indian organisations lead in treating sovereignty as a significant consideration in vendor selection and RFP processes at 44 percent, compared to the global figure of 32 percent. India’s enterprises are the most procurement-aware in the study.
The report also reveals that 95 percent of Indian respondents believe sovereignty strategy is very critical — yet 57 percent of those same respondents have no idea how to embed sovereignty into their own organisation or lack a strategy to do so. 40 percent are actively limiting the use of SaaS platforms that rely on non-domestic hosting infrastructure. 9 percent in direct tension with the stated commitment — cite reducing dependency on global hyperscalers as a top priority.
“A lot of deployments are scaling, and people are taking the learnings from their pilot phase to the scaling phase right now. The difference you must understand is that the type of data which is getting used into these AI models is way too different from what was possibly existing five years ago. So, the sort of governance which you need to embed into these data formats is much different from what people have done in the past.”
— Matthew Oostveen, CTO & VP Asia Pacific and Japan, Everpure
He pushed back gently on the framing of hyperscaler dependency as a binary choice: “I don’t necessarily think people are walking away from the hyperscalers. I think people are putting contingency plans in place because we’re continuing to see wonderful growth on the hyperscale side. It is possible to have an A and a B option.”
The picture this draws of India’s sovereignty posture is one of high intent, active early-stage action, and significant execution gaps — particularly in formalising strategy and building the internal skills to implement it.
The execution problem is a skills problem
Across all eight markets, the implementation picture shares a common anatomy. 57 percent of respondents struggle to balance sovereignty with wider strategic priorities. 56 percent lack the internal skills and capacity to deliver data sovereignty initiatives. 55 percent cannot keep pace with changing regulatory requirements. Only 19 percent report that their data sovereignty strategy is being driven by the board.
The investments, however, are rising sharply. 86 percent of organisations increased their sovereignty investments in the past six to twelve months. The data repatriation trend is accelerating just 1 percent had moved the majority of their enterprise data to local or sovereign infrastructure twelve months ago. Today that figure is 28 percent. In the one-to-three-year projection window, 41 percent plan to host the majority or all their data in local or sovereign environments.
The pilot-to-production problem
On the question of what is stopping AI pilots from reaching enterprise scale, Oostveen identified data quality as the single largest constraint.
“There’s a really high failure rate taking an AI pilot to production. In my experience, it’s about 75 percent. It comes down to tokenomics and economics — we got something to work in a lab, and then we went to run it inside an environment, and the cost of doing so was prohibitive. The second point is trust issues. While we might get something working in a pilot, hallucination rates could be too high because we haven’t solved the data problem appropriately. We’ve got issues of concurrency — different versions and copies of data across an environment. One might be plus one day, minus two days. That adds complexity for AI to find out what the real data set is, so we’re starting to see poor outputs.”
— Matthew Oostveen, CTO & VP Asia Pacific and Japan, Everpure
The urgency is real
The Everpure report’s conclusion frames the next decade as a test of whether enterprises can close the execution gap while managing three simultaneous pressures: international regulatory demands, cloud scalability, and secure AI deployment.
Those three pressures are not in tension with each other in theory. In practice, they are in tension every day — in budget conversations where sovereignty competes with other priorities, in vendor selections where sovereign providers lag on features, and in skills markets where the combination of regulatory expertise and cloud architecture capability is genuinely scarce.
The organisations that resolve this tension first, move from the holding pen of awareness into the disciplined execution of a formal sovereignty strategy, will not just be more compliant. They will be more AI-ready, more trusted by their customers, and more resilient against the geopolitical volatility that shows no sign of diminishing.
