Data sovereignty stopped being an infrastructure question in Australia some time ago. Most boards now understand that customer data belongs in an Australian region, and most vendors will happily tell you which region that is. The residency question is close to solved.
The question that has replaced it is harder, and it is the one Australian organisations are least able to answer: once an AI system has your data, what is it allowed to do with it afterwards?
The gap is not about where data sits
Research published by Fujitsu's Uvance Wayfinders team on 15 June 2026, from a survey of 400 senior business leaders across Australia, Japan, the UK and the United States run in February 2026, includes 100 Australian executives. Two findings from the Australian sample sit awkwardly together.
Eighty per cent of Australian leaders in that sample said strong data sovereignty is essential to scaling AI, and 63 per cent said it now features in board-level discussions. But only 7 per cent said they were confident they had effective controls over how AI systems continue to learn from or reuse data after deployment. Separately, 9 per cent said sovereignty is built into their platforms and AI lifecycles by design.
Those are three different numbers measuring three different things, and they are worth keeping apart. Conviction is high. Design maturity is low. Confidence in post-deployment control is lower still. The last one is the interesting number, because it is about the part of sovereignty that residency rules never covered.
What does data sovereignty actually require of an Australian business?
Four capabilities, and only the first is about geography. You need to know which jurisdiction holds the data at rest and in transit. You need a contractual and technical answer to whether the data is used for model training or improvement. You need visibility of every third party in the chain, including subprocessors your vendor uses. And you need the ability to move to a different model provider without losing the workflows and decision logic built around the old one. An organisation that can only answer the first has residency, not sovereignty.
That fourth capability is the one most often missing. If your automation logic lives inside one vendor's proprietary orchestration layer, changing providers means rebuilding, which is a commercial dependency dressed up as a technical one.
Why the gap persists
The same research points at three causes, and none of them are solved by buying an Australian region.
Skills. Sixty-nine per cent of the Australian leaders surveyed cited gaps in data and AI governance capability. A policy nobody is resourced to operate is a document, not a control.
Ecosystem pressure. Seventy per cent said AI is forcing them to share data more widely across partners and platforms than their existing sovereignty controls comfortably support, a higher figure than the US or Japan samples.
Split ownership. Accountability for sovereignty sits between technical and business functions in many organisations, which means it belongs to nobody when a decision has to be made quickly.
Add the Australian regulatory floor on top. The Privacy Act governs how personal information is handled and disclosed regardless of where the server is, and APRA-regulated entities carry information security obligations that extend to material service providers. Neither is discharged by picking a Sydney region.
The four questions that separate a claim from a control
When we review a vendor or an internal build for an Australian client, these are the questions we put in writing. The useful test is not whether the vendor says yes, but whether they can point at the artefact that proves it.
| The claim | The evidence to ask for |
|---|---|
| Our data stays in Australia | Named region for storage, processing and backup, plus the support model's location |
| Your data is not used for training | The contractual clause, not the marketing page, and the retention period after a request ends |
| We control who can access it | Subprocessor list, access logging you can read, and the notice period before that list changes |
| The system does not reuse data later | Written statement of what is retained from a session and for how long, covering caches and logs |
| We could switch providers | A described migration path for prompts, retrieval data and workflow logic, tested once |
The last row is the one people skip. A migration path nobody has ever tested is a hypothesis. Running it once against a small workload is a couple of days of work and it turns the hypothesis into a fact.
Where Claude fits, and where it does not
We build on Claude, and we tell Australian clients the same thing every time: a commercial model with clear contractual terms on training and retention will satisfy most sovereignty requirements a mid-market business actually has. Anthropic's enterprise terms address training use directly, which answers the second of the four capabilities above in writing rather than by assertion.
It does not answer all of them. If your obligation is that data must never leave equipment you control, no API satisfies that at any price, and a self-hosted open-weight model is the only option. That is a narrow case, and it carries a running cost most businesses underestimate. Our services page sets out how we scope the difference.
A sensible sequence for the next six months
Sovereignty work goes wrong when it starts with architecture. Start with the inventory instead, because it usually shows the exposure is smaller and more specific than expected.
List the AI systems already in use, including the ones staff signed up for without asking. That list is always longer than the one IT maintains.
For each, record what data it sees, which contract governs it, and whether training use is excluded in writing.
Rank by consequence, not volume. One system touching customer health or financial records outranks twenty touching internal meeting notes.
Fix the top two properly and document them as the pattern everything else follows.
Indicatively, a documented sovereignty review and controls uplift for a mid-market Australian business runs $40,000 to $90,000 depending on how many systems are in scope and how much of the inventory already exists. That is a planning range for budgeting, not a quote. If you want to sanity-check where the effort pays back, our ROI calculator handles the arithmetic, and our AI readiness assessment covers the data questions before the tooling ones.
The honest read
Australia is not behind on sovereignty ambition. The Fujitsu sample actually put a reasonable share of Australian organisations in the top two maturity tiers. What is thin is the operating layer underneath the ambition: the named owner, the tested migration path, the written answer about what happens to data after a session ends.
None of that is expensive compared with the cost of discovering the answer during an incident. You can read the Fujitsu research write-up for the full figures. If you want a second opinion on what your current AI vendors can actually demonstrate, book a time with us and we will go through the four questions with you.



