AI leadership increasingly depends on control. Organizations are moving AI into their core business processes, public services, industrial systems, and regulated workloads, and they need confidence that they can determine who has access to their data, which models they use, and how their AI systems are operated. This raises practical questions for leaders: Who can access your data? Can you choose and change the models you rely on? Who controls the infrastructure and operations behind your AI? In simple terms: your data, your models, your decisions.
These questions are especially important in Europe and around the world. Organizations want access to leading AI capabilities while maintaining confidence in how sensitive data, security, infrastructure, and operations are governed. Microsoft’s goal is to enable organizations to adopt AI while helping them maintain the level of control each workload requires to give leaders the confidence to move forward with AI.
Microsoft defines sovereign AI as the design, deployment, and operation of AI workloads under defined controls for data, access, governance, infrastructure, and operations. The right controls depend on the workload, which is why our framework is built around four principles: control, choice, flexibility, and resilience.
This framework is the focus of a new white paper we developed in collaboration with NVIDIA. It helps leaders translate the four principles into practical decisions; from the level of control each workload needs to the operating model that best supports it.
Begin with the workload
We see digital sovereignty as a risk-management principle. Start with the workload and ask: What data will it use or generate, and where can that data be processed? Who needs access to the system, including administrative access? What must keep working if connectivity is interrupted? And how easily must the organization be able to change models or infrastructure as its needs evolve? Consider these questions alongside the workload’s mission, regulatory obligations, and threat profile.
For many workloads, those requirements can be met in the public cloud. Others need greater operational control or infrastructure that remains under the organization’s authority. Some need to operate with limited or no connectivity. Microsoft Sovereign Cloud gives organizations options across the spectrum. Sovereign Public Cloud and Sovereign Private Cloud support different operating models based on the level of control a workload demands.

Sovereignty at every layer
Data location still matters, but an AI workload goes beyond stored data. It can include prompts, models, agents, outputs, and the systems that operate them. Leaders need visibility into which models are being used, the power to switch models if the need arises, where they run, who can administer them, and what happens when connectivity or operating conditions change.
Sovereignty can’t be applied at just one layer. Organizations need control over what an AI system can access and do, which models it can use, and where data and processing can occur. Microsoft provides capabilities across identity, governance, encryption, monitoring, confidential computing, and operational control to help organizations apply and maintain workload-specific controls. Building those requirements into the architecture from the outset, while preserving flexibility in model choice, can make it easier to adapt as workloads, technologies, and regulatory expectations evolve.
Microsoft and NVIDIA bring complementary capabilities across the AI stack. NVIDIA accelerated computing provides the performance required for advanced AI workloads, while NVIDIA Confidential Computing helps protect sensitive data, models, and AI workloads during processing. Together, Microsoft and NVIDIA provide security and control across the AI stack, from the underlying cloud infrastructure to the applications running on top of it.
That shared approach also informed the development of the Microsoft Sovereign AI white paper, created with contributions from NVIDIA to provide organizations with a practical framework for evaluating control, choice, flexibility, and resilience across their AI environments.
Learn more about Sovereign AI
Explore how Microsoft helps governments and regulated industries adopt advanced AI with NVIDIA technologies.
Accelerating innovation with model and infrastructure choice
Model choice should start with the flexibility to use the best models available and adopt new models as capabilities, quality, availability, and access evolve, without having to redesign the underlying AI platform. AI is moving too quickly to assume that one model will remain the right answer for every workload. Decoupling the platform from the model gives organizations the freedom to evaluate and change models as technology advances and requirements evolve.
Microsoft Foundry and Foundry Local support development and deployment across a broad model ecosystem, so organizations can evaluate models against the requirements of the workload while maintaining consistent approaches to governance and operations. NVIDIA extends that choice across models, AI software, and accelerated infrastructure. NVIDIA AI Enterprise provides software, frameworks, and inference capabilities for production AI. NVIDIA’s model ecosystem, including Nemotron and physical AI models, gives organizations additional options for building and deploying AI. NVIDIA RTX PRO infrastructure extends that choice to the compute layer, supporting demanding inference, agentic, and reasoning workloads.
AI workloads will continue to become more capable and more distributed. Organizations need accelerated computing, software, and model choice that can follow those workloads across cloud, data center, and edge environments. Our work with Microsoft is focused on giving them that foundation with security and control built in.
Dave Salvator, Director, Accelerated Computing Product Marketing, NVIDIA
Model choice is only part of the equation. Organizations also need flexibility in the infrastructure, software, and environments that support those models. An organization may decide to adopt a different model, move processing closer to its data, or change where a workload runs as its requirements evolve.
Scaling from cloud to edge
Where AI runs is becoming as important as the models an organization chooses. For many workloads, the public cloud will remain the right environment, with access to scale and advanced AI services. Others need AI closer to sensitive data or physical operations. An industrial system may need low-latency inference on site. A government or critical infrastructure workload may need to continue operating during a network disruption.
Organizations should not have to reinvent their AI operating model for every environment. Sovereign Private Cloud, built on Azure Local and Foundry Local, extends AI capabilities into environments that remain under the organization’s authority, including connected, intermittently connected, and disconnected deployments. NVIDIA accelerated computing and AI software stack provides a common foundation across these deployment models. With NVIDIA infrastructure and AI stack available across Azure and Azure Local, organizations can bring AI training, inference and increasingly demanding agentic, industrial, and physical AI workloads closer to the data and operations they depend on.
The real test of deployment flexibility is when conditions change. Identify which functions must continue during a connectivity disruption, which can pause, and what data or services each depends on. Then test those assumptions under the conditions the workload may actually face. As AI expands into agentic, industrial, and physical systems, more critical decisions will happen close to data, equipment, and users. The infrastructure needs to follow.
Building for inevitable change
No one can predict exactly what AI requirements will look like five years from now. Models will improve, infrastructure will change, and regulations won’t remain static. New workloads will create requirements that are difficult to anticipate today. IT architecture choices should account for this.
Organizations benefit from a consistent foundation that allows workloads to move across sovereign environments while maintaining common approaches to identity, security, governance, and AI development.
Durable AI strategies will be built for change. Organizations need enough control to use AI confidently, paired with enough choice to keep adopting better technology, and an architecture that can adapt when requirements change.
Learn more about digital sovereignty at Microsoft
- Read the Microsoft Sovereign AI white paper to explore a practical framework for building AI around control, choice, flexibility, and resilience.
- Explore Microsoft Sovereign Cloud resources for your region.
- Read the Microsoft Sovereign Cloud in Europe white paper.
- Watch the Sovereignty Sessions webinar.
- Read why sovereign AI starts with sovereign data, and how Sovereign Private Cloud puts AI to work on sensitive data without giving up control from Douglas Phillips.
Learn more about Sovereign AI
Explore how Microsoft helps governments and regulated industries adopt advanced AI with NVIDIA technologies.