Data sovereignty is emerging as a natural extension of the enterprise conversation around data privacy, cybersecurity and control. At Everpure’s September Pure Accelerate event in Singapore, its tech leaders rationalise that organisations need to make data discoverable, contextualised and governed if they are to use it securely across changing AI models, applications and workloads.

What Everpure calls data primacy also provides a way to approach sovereignty. Rather than tying critical information to a particular AI model, cloud platform or application, organisations can establish a governed, model-independent data foundation that maintains control.

Everpure defines data primacy as an architecture in which information is separated from individual applications and becomes a shared, governed system of record. Par Botes, Everpure’s VP of AI Infrastructure, said the industry needs to move beyond explainable data.
The longer-term objective, he said, is self-describing data. “I like self-describing a little bit better. That also comes with full audit semantics around what the data means. The semantic layer is the most under-tapped layer right now.”
Par is reported as sharing that Everpure was seeking to make storage layers self-describing, including storage from other providers, so organisations could query and use enterprise information through AI without continually making full copies of it.
I like self-describing a little bit better. That also comes with full audit semantics around what the data means. The semantic layer is the most under-tapped layer right now.
Par Botes
Ashish Gupta, Everpure’s GM of Data Management, framed the topic in terms of model flexibility. “You can make your data ready so that you can have any kind of model” and application working with it. He described data primacy as a “true north” for organisations regardless of the AI models they choose to use.
The implication is that companies should not have to wait before building governance capability. Ashish said manual tagging risks overlooking useful context, flagging that discovery and contextualisation that is automated can make governance more effective.
For enterprise AI and AI agents, that capability has direct sovereignty implications. Organisations need more than a clear understanding of the data they hold. They also need to establish where it is stored and processed, who can access or administer it, which jurisdictions may assert authority over it, and which cloud, SaaS and AI services can use it.
Recognition without readiness
Everpure’s Global Data Sovereignty Report 2026 suggests that many enterprises recognise the strategic importance of sovereignty but have not converted that concern into operational preparedness.
The company surveyed 2,100 technical and C-suite leaders across the UK, France, Germany, Australia, Japan, South Korea, India and Singapore. The research found that 90-percent of organisations considered data sovereignty a business concern.

Yet 64-percent of organisations reported having no formal data sovereignty strategy. Sixty-two percent lacked full visibility into where sensitive data resided or who could access, control or manage it.
The survey points to a clear “sovereignty gap” between executive recognition of risk and actual operational readiness.
Provider choice is beginning to reflect that concern.
Eighty-five percent of respondents said they would give up advanced features to work with a local or sovereign provider, while 40-percent said they were already limiting their use of SaaS providers that depend on non-domestic infrastructure. Everpure also found that 87-percent prioritised local or sovereign environments for high-risk AI workloads.
Sovereignty by design
Everpure’s response is a framework it calls “sovereignty by design.” The approach recommends applying sovereignty controls and governance according to the risk associated with each dataset, application and workload, rather than requiring every workload to sit in a sovereign environment.
The company says that this allows organisations to protect strategically important or highly regulated data while retaining the flexibility, innovation and scale offered by global cloud and SaaS providers.
Everpure positions its Data Intelligence platform as an enabling layer for this approach. The company says the platform can discover, classify and contextualise enterprise data at source across the Everpure Platform, public clouds, SaaS applications and third-party storage.
Such visibility is an important starting point, but it is not sovereignty on its own. Organisations also need enforceable access controls, clear ownership, encryption, data lineage, and tested resilience plans in the event of foreign legal access requests.
A model-independent data foundation can potentially help organisations adopt new AI tools without surrendering visibility, control or accountability over the information that those systems use.
For enterprises deploying AI, the most durable strategy may be to treat governance and privacy as foundational and constant, rather than any individual model or platform. As Ashish reiterated during Pure Accelerate in Singapore, “You can start building the Lego plate (foundation) and put the right Lego blocks. You don’t have to wait.”









