
Over the past year, I have noticed a subtle change in the way companies discuss artificial intelligence. The first question used to be: Which tool works best? Now, increasingly, it is followed by several less exciting but more consequential questions. Where will our data go? Who can access it? Will our prompts be retained? Can we use the same platform across Singapore, Malaysia and Indonesia? What happens if the provider changes its terms, raises its prices or restricts access to a particular market?
None of these questions makes for a particularly thrilling product demonstration. Yet they may ultimately matter more than whether one model produces a slightly better marketing plan, customer service response or meeting summary than another.
For the startups, SMEs and communications teams I work with, AI adoption rarely begins as an infrastructure strategy. It begins with a practical need. Someone wants to respond to customers faster, reduce repetitive work, generate content more efficiently or search internal documents without spending hours opening files. The team tests a tool, likes the result and gradually starts building it into everyday operations. That is usually when the simple software decision stops being simple.
Every AI tool comes with an infrastructure decision
The application a company sees is only the top layer. Beneath it sits a much larger stack of models, cloud providers, data centres, processors, jurisdictions and commercial relationships. By choosing an AI platform, a business may also be choosing where its information is processed, which country’s laws may affect that information and how dependent its workflows become on a particular technology ecosystem. This matters because data and AI infrastructure are becoming strategic assets for governments, not merely commercial services.
Singapore’s Economic Development Board has described data and AI sovereignty as increasingly important amid geopolitical tensions, noting the growing focus on storing, processing and securing critical data locally. Singapore has also introduced advisory guidelines encouraging cloud providers and data centre operators to improve the security and resilience of services on which businesses and society increasingly depend.
At the regional level, ASEAN’s expanded guide on AI governance recognises that generative AI introduces new questions around data, accountability, security and the models on which organisations rely. For business leaders, this means the provider behind a technology product can no longer be treated as invisible. A software subscription may look like a procurement decision. In reality, it can also be a decision about jurisdiction, dependence and future freedom.
Also Read: AI uncertainty is pushing companies from long leases to flexible offices
Sovereignty is not only a concern for governments
Much of the sovereign AI conversation focuses on whether countries should build national models, secure domestic computing capacity or retain strategically important datasets within their borders. These are important questions, but they can make sovereignty sound like something only governments, hyperscalers and large technology companies need to consider. Ordinary businesses face their own version of the same problem.
A company may never build a foundation model or operate a data centre. It still needs to know whether it can retrieve its data, move to another provider and continue serving customers if its preferred platform becomes unavailable or unsuitable. Consider an SME using an external AI system to answer customer questions. Over time, the tool may become connected to its product catalogue, customer records, service scripts and internal knowledge base.
The company has not simply adopted a chatbot. It has placed part of its customer experience inside another organisation’s infrastructure. That may be perfectly reasonable. Few SMEs have the money or expertise to build such systems independently. The danger begins when convenience turns into dependence without anyone noticing.
The same concern applies to content, HR, finance and internal productivity tools. A business may upload confidential plans, employee information or client material before deciding which types of data should ever leave its own systems.
The issue is not that global platforms are inherently unsafe or that local platforms are automatically better. The issue is whether the organisation understands the trade-off it is making.
Companies are beginning to separate experimentation from dependence
The most sensible response is not to reject foreign technology or attempt to build every capability locally. For most Southeast Asian businesses, that would be expensive, impractical and potentially counterproductive. Global platforms offer technical capabilities, security investment and scale that smaller providers may struggle to match.
Instead, organisations need to become more deliberate about where experimentation ends and operational dependence begins. A team may freely test several AI tools using public or non-sensitive information. It should apply a much higher standard before connecting one of those tools to customer data, proprietary documents or a business-critical process.
This requires companies to classify their information properly. Not every document needs the same protection. A public press release does not carry the same risk as an employee record, unreleased financial result or confidential client strategy. It also means looking beyond headline features when selecting vendors.
Businesses increasingly need to ask whether a provider offers clear data residency options, meaningful security controls, transparent policies on model training and a practical way to export information. Singapore’s government technology standards, for example, explicitly recognise that failure to enforce appropriate data residency can create legal, regulatory, privacy and security risks. These considerations should not be treated as legal fine print to examine after the contract is signed. They are part of the product.
Also Read: The AI-native economy: Southeast Asia’s once-in-a-generation opportunity
Multi-cloud does not automatically mean resilience
One popular response to infrastructure uncertainty is diversification. Companies assume that using several cloud or AI providers will protect them from becoming too dependent on one. In principle, this makes sense. In practice, adding vendors can also add complexity without creating genuine portability. A business may use three platforms but still depend on proprietary data formats, tightly integrated workflows or skills that apply to only one ecosystem.
Real resilience is not measured by the number of logos on an architecture diagram. It is measured by whether the company can continue operating when one component changes. Can it retrieve its information in a usable format? Can another system take over a critical function? Do employees understand the workflow without relying entirely on one vendor? Does the contract explain what happens when the relationship ends? A business that cannot answer these questions is not diversified. It has simply accumulated several forms of lock-in.
Better architecture may therefore be one unexpected benefit of geopolitical uncertainty. It is forcing organisations to confront questions they should arguably have asked even in a more stable world. Which systems are critical? Which data is sensitive? Which dependencies are acceptable? What must remain portable? Where should human judgement remain in the process? These are not only sovereignty questions. They are good management questions.
Southeast Asia should resist the pressure to choose one permanent side
Southeast Asia occupies a complicated position in the global technology landscape. The region benefits from investment, platforms and partnerships originating from several major technology ecosystems. Its markets also differ significantly in regulation, infrastructure maturity, languages and commercial needs. Choosing one permanent technological bloc may offer short-term simplicity, but it could reduce the region’s long-term room to manoeuvre.
At the same time, trying to remain neutral by accepting every platform without examining its dependencies is not a strategy either. The better approach is informed optionality. Countries need sufficient local talent, governance capacity, digital infrastructure and negotiating power to make meaningful choices. Companies need enough internal understanding to evaluate providers rather than outsourcing their entire technology strategy to them.
Singapore’s National AI Strategy 2.0 and the National AI Impact Programme reflect this broader emphasis on building domestic capabilities among enterprises and workers, rather than treating AI purely as technology to be imported and consumed.
That distinction matters. Technology sovereignty does not require a country or company to own every server, model and application it uses. Complete self-sufficiency is neither realistic nor necessarily desirable. It requires the ability to understand critical dependencies, protect sensitive assets and change direction without breaking the organisation.
For Southeast Asian businesses, the most important AI question is therefore no longer simply which platform produces the best result today. It is whether choosing that platform preserves the company’s ability to make a different choice tomorrow. Sovereignty will not come from selecting the supposedly correct side of the global technology divide. It will come from retaining the power to choose again.
—
Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.
The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.
Join us on WhatsApp, Instagram, Facebook, X, and LinkedIn to stay connected.
The post Why Southeast Asia cannot build sovereign AI on borrowed choices appeared first on e27.
