The UK government has published a £1.1 billion AI sovereignty plan aiming to take greater control over the technology. As part of the plans, £750 million has been allocated to a national AI supercomputer and domestic chip capabilities.
It comes after MPs warned that the UK government “may not be able to count on its allies” for access to critical technologies and must set out an AI sovereignty strategy. Meanwhile, Prime Minister Andy Burnham has appointed a new AI minister as the UK strives to lead in AI and protect itself against the risks posed by the technology.
Experts say the AI sovereignty plan underscores a shift from abstract policy to practical considerations of national control over critical digital resources. What does the plan mean for UK businesses?
Control Over AI
The AI sovereignty plan is driven by geopolitical tensions as countries race to lead in AI. Today, much of the technology needed to build and run AI is controlled overseas, explains Neil Thacker, global privacy and data protection officer at Netskope. “As AI becomes more embedded in businesses and public services, that dependence becomes a bigger strategic consideration.”
Rather than trying to cut the UK off from international technology companies, the goal is to build enough capability at home to reduce dependence and “give the UK a stronger foundation for the AI era,” he says.
The AI sovereignty agenda reflects “a growing recognition that sovereign access to frontier intelligence matters,” says Alwin Magimay, global head of AI, PA Consulting. “We’re learning the hard way what strategic dependency on energy can cost. If the models powering our economies, critical infrastructure and public services sit entirely outside our control, we risk creating a strategic dependency at the heart of the AI age.”
Sovereignty has several layers, according to Magimay. “You need control over your data, compute, infrastructure, models and applications. Investment in domestic compute infrastructure and AI capability is ultimately about giving organisations and governments greater choice, resilience and control over the technologies that underpin economic growth and national security.”
Ultimately, AI sovereignty is “about control,” says Gary Watson, CEO of Stellanor Datacentres. “Countries that can secure the compute, infrastructure and skills needed to develop AI will have a significant economic and strategic advantage,” he says.
Challenges And Benefits
The plan offers multiple benefits. For UK businesses, the government's investment could provide more choice over where AI workloads are run and reduce dependency on overseas providers, says Thacker. It also places questions around who controls critical technology “firmly on the boardroom agenda,” he adds.
From a cybersecurity and resilience perspective, the objective of the plan is to remove single points of strategic dependency and failure, says Magimay. “Businesses can achieve considerable sovereignty through secure infrastructure, domestic hosting where appropriate, open-weight models, smaller specialist models and architectures designed to move between model providers. However, if the most capable intelligence layer remains controlled by companies in another jurisdiction, a strategic dependency remains. You may have operational sovereignty, but not strategic sovereignty.”
Greater domestic AI capability could give UK businesses more choice and resilience by reducing reliance on a small number of external providers, says Poliks. “It could also give organisations greater control over where critical workloads and data are hosted, and more flexibility over the models and technology they use,” he adds.
Yet there could also be issues. The biggest challenge is that “sovereignty doesn't automatically create capability,” points out Tristan Shortland, CTO, Infinity Group. “Access to infrastructure is important, but organisations still need the right data, governance, skills and security controls to generate value from AI. There is also a balance to strike between increasing national control and maintaining access to the global innovation ecosystem that AI depends on.”
From a practical perspective, capital and compute are major obstacles, followed closely by energy, according to Magimay. “Talent matters, but the UK and Europe already have world-class AI researchers and engineers. The challenge is providing organisations with access to the enormous quantities of compute needed to develop and deploy advanced AI capabilities at scale, while attracting the investment required to compete globally.”
Visibility and Governance
The AI plan shines a spotlight on visibility and control of AI within UK businesses. Taking this into account, CISOs should focus on visibility and governance first, advises Shortland. “That means understanding which AI tools are being used, what data they can access and whether appropriate controls are in place. The organisations that succeed with AI won't necessarily be those with the most advanced technology, but those with the strongest governance, security and data foundations."
Poliks believes CISOs should think about AI sovereignty at an organisational level: “Do they actually control the AI running inside their business, or are they merely observing it?,” asks Poliks. “That means understanding which models and providers they depend on, where data is hosted, and whether workloads can move if requirements change, with a defined exit or fallback.”
Firms also need visibility over which models and agents are deployed, what they can access, and the ability to limit, disable or roll back AI functionality quickly when needed, says Poliks. “They should also define what happens when a system behaves unexpectedly: who can intervene, what can be restricted or disabled, and how to return to a known, predefined state.”
Thacker concurs, highlighting the importance of controlling access. “AI systems should only be able to access the information they need, and security teams need to understand what happens to the data once access has been granted. This becomes even more important as AI agents act on behalf of employees and interact directly with company systems.”
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist