What digital sovereignty really means for government data
By IBM
Sovereignty is less about which vendor to pick and more about a habit worth building, by asking who holds the keys, whether that can be proven, and what happens the day you need to walk away, says Eddy Liew, Chief Technology Officer at IBM Malaysia.
-1785333665043.jpg)
Eddy Liew, Chief Technology Officer at IBM Malaysia, speaking at a recent executive roundtable event co-organised by GovInsider and IBM Malaysia. Image: GovInsider
Would you hand your house key to a stranger? Or toss your car key to a valet and hope for the best? Most people wouldn't and if they had to, they would feel a certain kind of unease.
That, said Eddy Liew, Chief Technology Officer at IBM Malaysia, is exactly the feeling agencies should have whenever they hand their data to someone else's infrastructure.
Presenting on digital sovereignty at a recent executive roundtable event co-organised by GovInsider and IBM Malaysia, Liew used the above two analogies to illustrate what "digital sovereignty", which is one of government technology's biggest words, mean in practice.
Strip away the jargon, he told the room, and digital sovereignty comes down to one question: who holds the keys to your data, your applications and your artificial intelligence (AI)?
Who really controls your digital future?
Liew's opening test was simple: ask any agency how many databases it runs, and "a lot" is a safe answer, but most may not really know the answer.
That blind spot, he highlighted, goes deeper than storage counts. It extends to who is in control: the data itself, the applications running on it, and the encryption keys locking it all down.
Move workloads onto someone else's infrastructure, he warned, and an agency can lose sight of who holds those keys and lose the ability to prove it.
The uncertainty is where digital sovereignty starts. But a case study in Saudi Arabia shows that control and scale don't have to be a trade-off.
The country's Vision 2030 shows what closing that gap can look like in practice.
The kingdom requires data from regulated industries such as finance, healthcare, government, oil and gas, education and insurance to reside in data centers within the
Local ICT and data-center firm Edarat Group met that requirement without giving up hyperscaler-grade capability, deploying IBM Cloud Satellite across three data centers in just two weeks to run hybrid workloads on Saudi's soil.
Jihad Nehme, the firm's Principal Consultant and Head of Cloud Services, said the setup gave clients the experience of the public cloud while maintaining data sovereignty as a local provider.
Sovereignty is bigger than where the server sits
Liew broke digital sovereignty into four areas agencies need to control.
- Data sovereignty means knowing which data can and cannot sit with a hyperscaler.
- Operational sovereignty means visibility over who is using a system and how.
- Technology sovereignty is the ability to switch providers without being trapped.
- AI sovereignty means understanding how a model was trained, how it behaves, and who has the ability to update it, which is a particular concern with open-source models.
Once an agency builds deeply on one cloud platform or AI model, he warned, walking away later is nearly impossible, since large language models (LLMs) from different vendors don't simply plug into one another.
Gartner research, he said, projects that three-quarters of enterprises will have adopted a digital sovereignty strategy by 2030.
IBM's own Institute for Business Value has found that 58 per cent of businesses point to technology supply chain issues as a source of disruption. Over a third expect tighter regulatory scrutiny of AI risk management by 2027.
67 per cent of executives see AI governance itself, not the technology, as the main barrier to scaling AI.
Sovereignty as a platform?
IBM's answer to sovereignty is Sovereign Core, which Liew described as its first attempt to put control over data, operations, technology and AI under a single control plane.
Regardless of which hyperscaler, hardware vendor or AI model an agency runs on, the platform is baked in with 235 compliance standards, so public agencies can demonstrate compliance rather than simply assert it.
The bigger picture is also national. A few days before the event, Malaysia's National Cyber
Security Agency and the Malaysian Communications and Multimedia Commission signed a memorandum of understanding with IBM Malaysia at the National Cybersecurity Summit 2026 to explore setting up a National Quantum and Artificial Intelligence Centre of Excellence.
The proposed centre is envisioned as a platform linking government, academia, industry and international partners around trusted AI governance, quantum readiness and talent development, aligned with Malaysia's national interests.
Hans Dekkers, General Manager, IBM Asia Pacific, framed the collaboration as being about more than adopting technology, highlighting trust, sovereignty, and local capability will matter more than ever as AI and quantum reshape economies.
For public officers watching Malaysia's sovereignty push, Liew said that it was less about which vendor to pick and more about a habit worth building.
Agencies should be asking who holds the keys, whether that can be proven, and what happens on the day an agency needs to walk away, before any contract is signed.
-1783304403050.jpg)