{"slug": "5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint", "title": "5 things CIOs must do as sovereignty becomes a design constraint", "summary": "CIOs must treat sovereignty as a permanent design constraint, reshaping enterprise architecture decisions around data residency, regulatory compliance, and geopolitical risk. The shift from global infrastructure to location-aware strategies is forcing organizations to reassess hyperscaler dependence, adopt sovereign cloud options, and prioritize resilience over efficiency.", "body_md": "For years, enterprise IT strategy operated on three assumptions: infrastructure could be global, vendors could be consolidated, and location had little impact on risk or compliance. That model is breaking down. As geopolitical tensions rise, AI regulation accelerates, and supply chains become more fragile, CIOs are being forced to rethink not just where technology runs, but how it’s sourced, governed, and secured.\n\n“Three years ago, sourcing decisions always started with total cost of ownership,” says Jochen Jaser, CIO of open-source software company SUSE. “But that’s not the dominant frame anymore. Now it starts more like a risk register.”\n\nSUSE\n\nThat shift is reshaping enterprise architecture decisions at multiple levels. CIOs are reassessing dependence on hyperscalers, evaluating sovereign cloud options, and paying closer attention to where data resides and how it moves across jurisdictions. According to Shannon Bell, EVP, CIO, and CDO at enterprise information management company OpenText, “geopolitical risk has become a core architecture and sourcing consideration.”\n\nThe result is a more fragmented and complex operating environment. Gartner analyst Luis Pinto says organizations increasingly view geography as an architectural constraint rather than a secondary deployment issue, while Ron Babin, IDC advisor and professor at Toronto Metropolitan University, says CIOs must now navigate a growing patchwork of regional regulatory requirements.\n\n[As AI becomes more deeply embedded in enterprise operations](https://www.cio.com/article/4168673/can-an-ai-be-a-competent-leader-lets-find-out.html?utm=hybrid_search), the strategic importance of data itself is also changing. CIOs are paying closer attention not only to where data is stored, but how it’s accessed, moved, and protected across borders.\n\n“The business transcends borders, but your data can’t always do the same,” says Matt Stern, CSO at Hypori, a secure mobile access provider.\n\nOrganizations aren’t abandoning global platforms, but they’re redesigning how they use them. As sovereignty becomes a permanent strategic constraint, here are five things CIOs must do in response.\n\nThe most fundamental change is conceptual since location is now a design variable rather than a deployment detail. For years, CIOs optimized for scale and efficiency, often centralizing workloads in a handful of hyperscale cloud environments. That approach assumed stable global access and predictable regulatory conditions. Today, those assumptions no longer hold.\n\n“Where technology is located and who has operational control over it is now a major business risk,” Pinto says. Organizations are responding by paying closer attention to data residency and access rights.\n\nGartner\n\nJaser adds that the shift is forcing organizations to rethink even [basic infrastructure assumptions](https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html?utm=hybrid_search). “Usually you’d just go with AWS, Google, and on-prem,” he says. “But now as digital sovereignty requirements are coming into space, we need to look for sovereign cloud offerings.”\n\nThat doesn’t mean abandoning hyperscalers entirely. SUSE itself operates a hybrid infrastructure spanning commercial clouds and its own data centers. Instead, Jaser says organizations are becoming more selective about workload placement, evaluating which systems require stronger sovereignty protections, and which can remain in global environments.\n\nThe shift is also reshaping operating models. According to Bell, workload placement strategies are increasingly driven by sensitivity of data, regulatory exposure, and operational risk. “We’re moving from a cloud-first mindset to more of a fit-for-purpose approach,” she says.\n\nAs geography becomes a constraint, resilience is replacing efficiency as the primary design goal. Enterprises are rethinking their dependence on a small number of global providers, particularly hyperscalers. While companies such as AWS, Microsoft, and Google remain central to most IT strategies, CIOs are increasingly wary of [concentration risk](https://www.cio.com/article/4146639/ai-is-coming-for-your-office-productivity-suite-too.html?utm=hybrid_search).\n\n“Vendor concentration is now treated as systemic risk, not strategic leverage,” Pinto says. Rather than abandoning hyperscalers, organizations are intentionally fragmenting their portfolios. Global providers are retained for standardized, low-risk workloads, while regional or sovereign alternatives are introduced for more sensitive applications.\n\nAccording to Jaser, many organizations are now discovering how deeply earlier cloud consolidation decisions constrained their flexibility. “A lot of companies optimized everything for a single cloud provider in terms of technology, skills, and planning,” he says. “Then they realized they had three- or five-year contracts with commitments, which limits the ability to choose something else.”\n\nBabin points to emerging risks that go beyond compliance. In some regions, even data centers are becoming potential targets in geopolitical conflicts. “CIOs now have to think about where their AI models are running and what risks exist in those locations,” he says.\n\nThe result is a more resilient, albeit splintered, sourcing model — one designed to preserve optionality if geopolitical, regulatory, or vendor conditions change.\n\nIf resilience requires diversification, it also requires precision. Not every workload needs the same level of protection. That’s where a more granular approach to sovereignty is emerging. Rather than treating it as a binary choice — sovereign or not — CIOs are increasingly thinking in terms of a spectrum.\n\n“It’s not a black-and-white conversation,” Jaser says. “It depends on the workload, its relevance, and the specific sovereignty requirements attached to it.”\n\nIn practice, that means classifying workloads based on risk, sensitivity, and business impact. Highly sensitive data such as HR, security, or proprietary AI models may need to remain in tightly controlled environments, whether in sovereign clouds or on-prem infrastructure. Less sensitive applications like marketing systems or public-facing services can continue to run in global cloud environments.\n\nThis workload-based approach allows CIOs to balance competing priorities of cost, performance, regulatory compliance, and [UX](https://www.cio.com/article/4135922/what-ax-can-do-to-deliver-cohesion-and-uniformity-to-ai-agents.html?utm=hybrid_search). It also reflects a more mature understanding of sovereignty as a set of trade-offs rather than an absolute goal.\n\nJaser also argues that CIOs should avoid overcomplicating the process. “Don’t over-engineer it,” he says. “Just start classifying your workloads and move to relevant things.”\n\nBell argues that most enterprise data don’t require the same level of protection. “More than 90% of enterprise data can safely sit in the public domain,” she says. “There’s really a small percentage that represents the keys to the castle and needs to be protected.”\n\nAs organizations distribute workloads across multiple clouds, sovereign environments, and regional providers, the ability to move workloads becomes critical.\n\nDesigning for workload portability upfront is becoming increasingly important, Bell says, and that flexibility becomes a critical requirement, not just for optimization.”\n\nTechnically, this is driving greater adoption of open standards, containerization, and orchestration platforms such as Kubernetes. These technologies make it easier to shift workloads between environments, whether across cloud providers or between [cloud](https://www.cio.com/article/4159281/neglecting-the-cloud-good-luck-with-ai.html?utm=hybrid_search) and on-prem systems.\n\nContractually, CIOs are pushing for stronger exit clauses, price protections, and flexibility. According to Pinto, organizations are increasingly embedding exit by design into their sourcing strategies since if contracts don’t allow for rapid disengagement, they may find themselves locked into environments that no longer meet regulatory or operational requirements.\n\nOpenText\n\nThe goal isn’t constant movement, but optionality. CIOs want the ability to adapt as conditions change. “The mistake some CIOs make is trying to have an extreme amount of portability, or not enough portability,” Bell says. “The magic is in the middle.”\n\nWhile much of the sovereignty discussion focuses on cloud infrastructure, risk doesn’t stop at the data center but extends to how data is accessed, particularly in a world of remote work and mobile devices. That’s where a less visible but increasingly important dimension of the problem is emerging.\n\n“The business transcends borders, but your data can’t always do the same,” Stern says.\n\nAs employees travel and work remotely, sensitive data may be accessed across jurisdictions in ways that violate local regulations. Devices can also be inspected or seized at borders, creating additional exposure. As a result, some organizations are rethinking the model entirely, focusing less on securing devices and more on controlling access to data.\n\nStern argues that AI and distributed workforces are changing the nature of enterprise security itself. “Identity is now becoming the perimeter,” he says. “It’s not device-centric anymore but identity-centric.”\n\nHypori\n\nThis shift reflects a broader reality that sovereignty is more about who can access data, from where, and under what conditions rather than just about where it’s stored.\n\nTaken together, these changes point to a broader transformation in the [CIO role](https://www.cio.com/article/4126383/how-the-growing-ai-workforce-is-changing-the-cio-role.html?utm=hybrid_search). Technology strategy is about managing a dynamic set of risks for the long term that spans regulation, geopolitics, supply chains, and security, not just delivering capability at the lowest cost.\n\n“This isn’t solely the responsibility of the CIO,” says Babin. “The executive team and the board need to understand the trade-offs.” In many cases, achieving greater control and adaptability requires additional costs, slower deployment, or reduced access to cutting-edge features.\n\nToronto Metropolitan University\n\nAs organizations adapt, CIOs are building strategies that are more complex but also more resilient. According to Pinto, the organizations best positioned for this shift will be those that treat geopolitics as a permanent design constraint not a source of temporary disruption.\n\nThat requires a different mindset around operational readiness and risk management. “Being risk ready is about understanding, mitigating, and managing risk in real time,” says Bell.\n\nFor CIOs, sovereignty is no longer a niche compliance issue. It’s becoming a core design principle shaping how technology is sourced, deployed, governed, and secured.", "url": "https://wpnews.pro/news/5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint", "canonical_source": "https://www.cio.com/article/4178779/5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint.html", "published_at": "2026-06-17 10:00:00+00:00", "updated_at": "2026-06-17 10:30:35.545926+00:00", "lang": "en", "topics": ["ai-policy", "ai-infrastructure", "ai-safety"], "entities": ["SUSE", "OpenText", "Gartner", "IDC", "Hypori", "Jochen Jaser", "Shannon Bell", "Luis Pinto"], "alternates": {"html": "https://wpnews.pro/news/5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint", "markdown": "https://wpnews.pro/news/5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint.md", "text": "https://wpnews.pro/news/5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint.txt", "jsonld": "https://wpnews.pro/news/5-things-cios-must-do-as-sovereignty-becomes-a-design-constraint.jsonld"}}