Your Data’s Not Where You Think. Your AI Isn’t, Either
- By Winston Thomas
- April 28, 2026

Ask a roomful of Asia-Pacific CEOs whether they control their data. Listen carefully, and you won’t hear a “yes.”
“In almost every leadership conversation across ASEAN, I often hear silence — followed by a qualifier,” says Patrick Bruinsma, ASEAN technology leader and regional chief technology officer at IBM Technology. The silence isn’t ignorance; it’s pattern recognition.
For three decades, enterprises bolted together CRMs, ERPs, data warehouses, and whatever a consultant was pitching that quarter. The result: data sprawled across dozens of environments with no unified layer to govern any of it.
Now regulators want to know where it lives. Attackers want to take it. AI models want to feed on it. And Bruinsma is watching C-suites realize, live, that the honest answer to “do you control your data?” is “not really.”
That’s the setup. Here’s why it’s existential.
Geopolitics ate up architecture
Asia-Pacific absorbs 34% of the world’s cyberattacks, according to “Sovereign Technology Capabilities: Why CEOs Must Act Now to Secure the Future,” the IBM whitepaper. In the whitepaper, Gartner estimates that by 2028, 65% of governments globally will enforce some form of technological sovereignty.
India’s Digital Personal Data Protection Act is in force. China’s trifecta — Cybersecurity Law, Data Security Law, Personal Information Protection Law — locks critical data inside its borders. Indonesia is moving the same way. The sovereign cloud market is projected to grow from USD37 billion in 2023 to USD169 billion by 2028.
The old playbook of standing up a centralized cloud estate, optimizing for scale, and then putting out compliance fires is dead. Bruinsma calls local residency “a live requirement that is reshaping procurement decisions today.”
Then he asks the question most AI leaders haven’t thought hard enough about.
Looking to learn how companies are using IBM to close AI-data infrastructure gaps? Join the upcoming Executive Roundtable "Building AI Ready Data Foundations: Turning Data Strategy into Scalable Outcomes" on May 13, 2026 to hear IBM executives and practitioners. To register and find more details, click here.
The question everyone should be asking
“Where is the AI actually running?”
That’s the blind spot. You can host your data inside Jakarta or Mumbai or Manila and still have a sovereignty problem, because when a model scores a credit application or flags a fraudulent transaction, that computation happens somewhere. If “somewhere” is infrastructure you don’t govern, in a jurisdiction that isn’t yours, your data sovereignty is fiction.
“If the inferencing is happening outside your jurisdiction, or on infrastructure you don’t govern, your data sovereignty is incomplete — even if the data itself sits in-country,” Bruinsma warns.
For chief AI officers — a role Bruinsma notes is still emerging in the region (“I haven’t met a Chief AI Officer yet in my client conversations across ASEAN”) — this is a major challenge. Mandates built around speed, ROI, and deployment velocity push sovereignty questions to the end of the process, where they arrive as a legal review, a checkbox, or a blocker on a project already sold to the board.
His remedy: sovereign-by-design acceleration. “Move fast, but build on ground that won’t shift under you.”
The harder conversation is with chief data officers, whipsawed between AI innovation mandates and tightening residency rules. Bruinsma’s reframe is sharp: “Sovereignty isn’t what’s slowing your AI down — ungoverned, untrusted data is.”
Most stalled AI projects, he argues, don’t die because the model was weak. They die because the data feeding it was inconsistent, un-lineaged, or distrusted by the humans meant to act on its outputs. Sovereignty frameworks force you to answer the unglamorous questions — where did this data come from, who owns it, is it fit for purpose — that AI needed answered anyway.
Twenty years of data swamps
Which brings us to the retrofit trap. Bruinsma has watched the enterprise data industry cycle through consolidation promises for two decades, including data warehouses and data lakes, which he says “often became what people started calling data swamps.” Each wave burned budgets. Each left the silos intact. “The architecture changed; the fragmentation didn’t.”
His prescription isn’t another consolidation exercise. It’s a lakehouse architecture with data lineage and a knowledge catalog as its spine — IBM’s watsonx.data being his preferred example. Lineage traces every piece of data: origin, transformations, access, movement. The catalog governs how assets can be used, by whom, under what conditions. Governance travels with the data, wherever it goes.
Hyperscalers will tell you they offer the same thing. Bruinsma’s counter is pointed: “Governance bolted on after the fact is governance that serves the platform, not the organization.” The real test, he says, is what happens when the goalposts move. Can you respond in weeks, or does every policy shift trigger a months-long re-engineering cycle your business can’t absorb?
Playing offense with sovereignty
The payoff for getting this right isn’t defensive. Here’s where Bruinsma flips the script: “Sovereignty done right is an offensive capability, not a defensive one.”
Fine-tuned, domain-specific models trained on your proprietary data, including transaction records, customer interactions, and operational vernacular, outperform generic frontier models on your actual business problems. They run on less compute, burn fewer tokens, and cost less to scale. “That’s not doing more with less-capable AI,” Bruinsma says. “That’s doing better with the right AI — built for your context, not borrowed from someone else’s.”
IBM’s own proof point: USD4.5 billion in internal productivity gains across more than 70 reinvented workflows. Bruinsma says the company didn’t rip out its systems of record. It layered AI agents on top, targeted the “most cumbersome, most repetitive, most draining” tasks first, and let employees interact with agents rather than navigate five screens for an HR task. “Once you remove that, productivity moves fast.”
The warning label: this isn’t one-and-done. “Each domain opened up new questions, new workflow candidates, and new governance considerations.”
The 2030 floor
So what are you actually racing toward? By 2027, Gartner projects 80% of multinationals will run sovereign data strategies. At that point, sovereignty stops being a differentiator. It becomes the floor.
Bruinsma’s answer to what comes next is unsentimental. By 2030, he expects agentic AI embedded across procurement, finance, HR, and customer operations — at scale, not in pilots. The winners will be the organizations whose data foundations are already trusted enough to let agents operate inside compliant boundaries. That work is happening now.
The losers won’t collapse dramatically. They’ll experience what Bruinsma calls “a gradual narrowing of options.” AI initiatives that stall because of vendor dependencies that don’t align with their interests will lead to a slow erosion of trust from regulators, customers, and investors. And that’s brutally hard to rebuild.
So ask the question again. Do you control your data? Do you know where your AI is running?
The silence is the answer you can’t afford.
Image credit: iStockphoto/Atstock Productions
Stay ahead with CDO Nexus
Join an exclusive community of CDOs and data leaders
- Access curated trends and thought leadership from IBM and industry experts.
- Participate in private roundtables and webinars to solve regional CDO challenges.
- Connect with a network of like-minded leaders navigating the same data landscape.
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.