Urgent.News

What's breaking now, across thousands of outlets.

AI

Why Southeast Asia cannot build sovereign AI on borrowed choices

Over the past year, I have noticed a subtle change in the way companies discuss artificial intelligence. The first question used to be: Which tool works best? Now, increasingly, it is followed by several less exciting but more consequential questions. Where will our data go? Who can access it? Will our prompts be retained? Can […] The post Why Southeast Asia cannot build sovereign AI on borrowed…

Why Southeast Asia cannot build sovereign AI on borrowed choices

In recent times, companies have been increasingly scrutinizing artificial intelligence (AI) tools beyond just their performance, focusing on critical questions such as data ownership, accessibility, retention, and the potential impact of provider changes. These considerations matter more than the marginal improvements in outcomes these tools may offer.

For startups, small and medium-sized enterprises (SMEs), and communication teams, AI adoption often starts with a practical need – wanting to respond to customers more swiftly, reduce repetitive tasks, generate content more efficiently, or search internal documents without spending excessive time on manual file retrieval. This initial enthusiasm for a tool soon evolves into a complex infrastructure decision.

Every AI tool is underpinned by a vast ecosystem of models, cloud providers, data centers, processors, jurisdictions, and commercial relationships. By selecting an AI platform, a business might also be deciding where its data is processed, which country's laws would apply, and how dependent its operations become on a specific technology ecosystem.

Data and AI infrastructure are increasingly becoming strategic assets for governments, not just commercial services. Singapore's Economic Development Board has recognized the growing importance of data and AI sovereignty amid geopolitical tensions and has introduced guidelines to enhance the security and resilience of services that businesses and society rely on.

Similarly, ASEAN's guide on AI governance acknowledges the new considerations around data, accountability, security, and the reliance on models by organizations.

While the conversation around sovereign AI often centers on national models, domestic computing, and preserving strategically important datasets, small businesses also grapple with similar concerns. An SME using an external AI system to answer customer inquiries could inadvertently embed part of its customer experience within another organization's infrastructure.

This convenience may be acceptable, but it can quickly turn into dependence without realizing the implications. The risk extends to various aspects of business operations, including content creation, human resources, finance, and internal productivity tools.

The issue isn't that global platforms are inherently unsafe, nor that local platforms are inherently superior. The critical question is whether the organization comprehends the trade-offs it is making. Global platforms bring technical capabilities, robust security measures, and scale that smaller providers might struggle to match.

Instead of rejecting foreign technology or attempting to build every capability locally—both of which would be costly, impractical, and potentially counterproductive—organizations need to be deliberate about where experimentation ends and operational dependence begins. Initially, teams can safely test multiple AI tools using public or non-sensitive information.

However, when connecting one of these tools to customer data, proprietary documents, or business-critical processes, a higher standard must be applied. This approach requires businesses to categorize their information appropriately. Not all documents require the same level of protection; for instance, a public press release poses less risk compared to sensitive employee records, unreleased financial results, or confidential client strategies.

Furthermore, businesses should look beyond the headline features of vendors and consider whether they offer clear data residency options, robust security controls, transparent policies on model training, and practical means to export data. Singapore's government technology standards highlight the legal, regulatory, privacy, and security risks associated with inadequate data residency enforcement. These considerations should not be viewed as mere legal formalities.

Written by urgent.news from e27's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at e27.co →

More in AI

More from Thursday 6 August →