Key Takeaways

  • Access to frontier AI has become a combined cybersecurity and digital sovereignty issue for European organizations.
  • Partnerships between global security providers and regional sovereign clouds are emerging to address data localization and operational resilience.
  • European buyers are increasingly evaluating technology across data location, operational control, resilience, and regulatory compliance.

Frontier AI is forcing European organizations to reconsider what digital sovereignty looks like in day-to-day operations. Zscaler’s position is that sovereignty cannot stop at data residency. It must also cover access to AI models, control over security policies, operational continuity, and the architecture connecting users, agents, applications, and data.

Worldwide sovereign cloud infrastructure-as-a-service (IaaS) spending is forecast to reach approximately $80 billion in 2026. European organizations are expected to nearly double their spend from roughly $7 billion in 2025 to more than $12 billion in 2026. By 2030, more than 75% of European and Middle Eastern enterprises will geopatriate workloads into sovereignty-focused solutions, up from less than 5% in 2025. Recent industry research indicates that by 2027, three in four organizations will restructure cloud and data strategies specifically in response to sovereignty risk.

Security leadership notes that the question isn't whether advanced models will impact security postures; it's whether defense teams will harness them securely before attackers do. Many capable AI models and the infrastructure supporting them remain under the control of foreign jurisdictions, creating dependencies around availability, data processing, and policy changes.

Europe is actively translating these concerns into strict procurement and assurance requirements. Vendors operating at this intersection of frontier AI and sovereignty include Orange Business and OVHcloud in sovereign cloud, alongside Thales and T-Systems in sovereign infrastructure and security services. Additionally, EU AI Act Article 10 places data-quality and governance obligations on high-risk AI systems, with requirements effective for general-purpose models from August 2025 and Annex III high-risk systems from August 2026. Forrester also identifies AI governance, governance-risk-compliance work, and third-party risk as top priorities among EMEA and APAC security leaders.

Data residency alone does not prevent excessive permissions, compromised identities, or lateral movement. An AI agent can possess valid credentials, operate inside its assigned scope, and still create systemic risks if its access is too broad or its activity is poorly monitored.

Zscaler applies a sovereignty model prioritizing choice, control, continuity, collaboration, and compliance to address this risk. The zero-trust architecture brokers billions of transactions daily and is being extended for frontier models and agentic AI. The goal is to reduce public exposure, connect identities directly to authorized resources, and restrict lateral movement rather than extending implicit network trust.

That model broadly complements the NIST AI Risk Management Framework, which provides a baseline for mapping AI governance, measurement, and risk controls. It also highlights why AI governance and cybersecurity architecture must be evaluated together.

A practical European application of this approach is the partnership with Schwarz Digits, the IT and digital division of Schwarz Group. The collaboration integrates zero-trust secure access with STACKIT, Schwarz Digits’ European sovereign cloud, hosted in STACKIT-operated data centers.

The arrangement does not remove every jurisdictional or third-party dependency. It does, however, demonstrate how an international security provider can localize service delivery, support EU data residency, and give customers clearer operational boundaries. As frontier AI compresses cyberattack and response timelines, combining local control with modern access architecture will remain a central test in European technology procurement.