Data sovereignty becomes an infrastructure strategy in the AI era

For most of the past decade, data governance was treated as a legal issue. IT built networks and bought tools, while regulators were someone else’s problem. That division no longer holds. Cloud adoption and AI have turned data sovereignty into a core infrastructure and strategy question.

Regulatory frameworks such as GDPR, NIS2, and DORA are expanding and being enforced more strictly. Governments are also scrutinising foreign cloud providers and cross-border access. Local data storage no longer ensures absolute data sovereignty if critical control layers remain outside national jurisdiction.

Traditional SASE and SSE models were not built for this environment. Many still separate outbound cloud traffic from inbound controls. That split creates blind spots in distributed architectures and complicates consistent policy enforcement.

AI workloads intensify the pressure. Retailers, banks, and manufacturers are deploying models locally, not just in hyperscale clouds. Securing east-west traffic across systems and APIs without undermining data sovereignty is becoming a central architectural challenge.

Managed sovereign infrastructure is one response. It reduces reliance on external cloud paths while preserving operational scale. Ultimately, organisations must align security, AI deployment, and governance with long-term resilience goals.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

European businesses gain AI-powered contract tools with local data hosting

Workday has rolled out its Contract Lifecycle Management (CLM) platform with EU-hosted data in Frankfurt, allowing European organisations to use AI contract tools while keeping all data within the EU.

German, French, and Spanish language support is live, with more languages planned. The update is part of Workday’s EU Sovereign Cloud strategy, targeting the CLM market, which is set to grow to $1.9 billion by 2033.

The platform uses AI agents to automate contracts. The Contract Intelligence Agent extracts terms, obligations, and renewal dates to create a searchable repository, while the Contract Negotiation Agent flags deviations, drafts redlines, and speeds approvals.

Multilingual support ensures smooth workflows across Europe’s largest commercial languages, improving compliance and efficiency.

GDPR compliance remains critical, with fines up to €20 million or 4% of global turnover. EU-hosted CLM removes offshore data risks, which are crucial for the finance, healthcare, and defence sectors. Workday combines AI efficiency with full legal compliance.

Decision-makers should focus on three priorities: EU data residency, leveraging AI agents to accelerate contracts, and integrating CLM with HR and finance systems to maximise value. Workday aims to capture market share in Europe against competitors such as Icertis and DocuSign.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Agentic AI network slicing launches in 5G Advanced with Nokia and AWS

Nokia and Amazon Web Services have introduced what they describe as the first agentic AI-powered network slicing solution operating in commercial 5G-Advanced networks. Early pilot projects with du and Orange are already underway, marking the transition from laboratory testing to commercial deployment.

For an extended period, network slicing has been presented as a way to tailor connectivity to the needs of enterprises and end users, yet static configurations have until now limited its commercial impact. A more autonomous approach is now being tested, designed to convert operational intent directly into concrete network actions.

The joint system combines Nokia’s network slicing portfolio with AI services delivered via the Amazon Web Services (AWS) Bedrock platform. Software agents analyse real-time data, including traffic levels, location information, and significant events, and automatically adjust radio access network policies. However, this enables capacity to be prioritised in response to congestion, emergencies, or large gatherings.

Enterprise use is central to the deployment. Campuses, factories, and urban areas can receive connectivity aligned with predefined service level targets (SLAs), while public safety teams can activate dedicated network slices during critical incidents. Premium consumer services, such as gaming and streaming, may also benefit from more stable performance during peak demand periods.

The solution spans the radio, transport, and core networks and will be showcased at the Mobile World Congress 2026. Commercial success will depend on whether intent-based slicing can transform what has long been a promised feature into a sustainable and scalable revenue source for operators.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Google API keys exposed after Gemini privilege expansion

Security researchers warn that exposed Google API keys in public client-side code could be used to authenticate with the Gemini AI assistant and access private data. The issue arose after developers enabled the Generative Language API in existing projects without updating key permissions.

Truffle Security scanned the November 2025 Common Crawl dataset and identified more than 2,800 live Google API keys publicly exposed in website source code. Some belonged to financial institutions, security firms, recruitment companies, and Google infrastructure.

Before Gemini’s launch, Google Cloud API keys were widely treated as non-sensitive identifiers for services such as Maps, YouTube embeds, analytics, and Firebase. After Gemini was introduced, those duplicate Google API keys also acted as authentication credentials for the AI assistant, expanding their privileges.

Researchers demonstrated the risk by using one exposed key to query the Gemini API models endpoint and list available models. They warned that attackers could exploit such access to extract private data or generate substantial API charges on victim accounts.

Google was notified in November 2025 and later classified the issue as a single-service privilege escalation. The company said it has introduced controls to block leaked keys, limit new AI Studio keys to Gemini-only scope, and notify developers of detected exposure.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

Japan probes Microsoft cloud licensing

Japan’s Fair Trade Commission has launched an investigation into Microsoft in Tokyo over suspected antitrust violations. Authorities conducted an on-site inspection of Microsoft’s Japanese subsidiary in Tokyo on Wednesday, according to sources.

Regulators are examining whether Microsoft charged higher licensing fees to customers running Microsoft 365 and Windows on rival cloud platforms rather than on Microsoft Azure. The inquiry centres on concerns that software dominance may have restricted competition in Japan’s cloud market.

Microsoft’s Japanese unit said it would cooperate fully with the Fair Trade Commission in Tokyo. The watchdog is assessing whether pricing practices unfairly hindered rivals such as Amazon and Google, which also compete in Japan’s expanding cloud sector.

Japan’s Fair Trade Commission has intensified oversight of major technology firms in recent years. Previous actions in Japan include investigations into Amazon Japan and a 2025 order requiring Google to end certain preinstallation practices.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

Microsoft backs Australia’s next phase of digital government with new AI and cloud agreement

Australia’s rise to second place in the OECD Digital Government Index signals renewed momentum for national digital transformation.

A shift that comes as Microsoft signs a new five-year Volume Sourcing Arrangement with the Federal Government, designed to underpin modernisation across public services and create a secure, future-ready foundation for responsible AI adoption.

The agreement led by the Digital Transformation Agency gives agencies access to Microsoft Copilot, Azure, Microsoft 365, Dynamics 365 and a strengthened security and compliance framework instead of continuing reliance on ageing systems.

The arrangement sets clearer strategic pathways for innovation, procurement and skills development through an enhanced governance structure.

It recommits both sides to national security requirements, including the Security of Critical Infrastructure legislation, the Cloud Hosting Certification Framework and IRAP.

These measures allow agencies to expand AI use while retaining control of data and meeting the expectations placed on government institutions.

A successful Copilot trial in 2024 already demonstrated personal productivity gains of around one hour per day for participating staff.

Microsoft is also establishing a $1.55 million training fund for the Australian Public Service to support capability building in ethical AI use and modern cloud operations.

The company emphasises that Australia’s partner ecosystem will gain new opportunities because the agreement simplifies how local firms engage with government agencies. Such an approach forms an important part of the wider public sector reform agenda announced last year.

The new deal aligns with national priorities set out in the Whole-of-Government Cloud Computing Policy and the National AI Plan.

Australia now enters a pivotal period in which digital transformation is guided not only by technological capacity but by the frameworks of trust, resilience and public benefit that shape how government services evolve.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

Massive chip agreement signals shift in Meta strategy

Meta has committed to purchasing $60bn worth of AI chips from Advanced Micro Devices over five years, signalling one of the largest infrastructure bets in the sector despite ongoing concerns about an AI investment bubble.

The agreement includes a 10% stake in the chipmaker and large-scale deployment of next-generation hardware beginning later this year.

Analysts say the move signals a shift to secure compute capacity and cut reliance on Nvidia amid supply constraints. Talks with Google and ongoing in-house chip work signal a multi-vendor strategy to support expanding data centre operations.

Executives say the investment reflects a shift towards hosting AI workloads and infrastructure services. Custom processors built for performance and efficiency will complement AMD GPUs, supporting capacity expansion as enterprise demand rises.

Enterprise AI competition intensifies as Anthropic and OpenAI expand integrations and tools. Significant platform investments are reshaping semiconductors and signalling strong long-term confidence in AI computing demand.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

Microsoft expands Sovereign Cloud with secure offline support for large AI models

Digital sovereignty is gaining urgency as organisations seek infrastructure that remains secure and reliable under strict regulatory conditions.

Microsoft is expanding its Sovereign Cloud to help public bodies, regulated industries and enterprises maintain control of data and operations even when environments must operate without external connectivity.

The updated portfolio allows customers to choose how each workload is governed, rather than relying on a single deployment model.

Azure Local now supports disconnected operations, keeping mission-critical systems running with full Azure governance within sovereign boundaries. Management, policies and workloads stay entirely on site, so services continue during periods of isolation.

Microsoft 365 Local extends the resilience to the productivity layer by enabling Exchange Server, SharePoint Server and Skype for Business Server to run locally, giving teams secure collaboration within the same protected boundary as their infrastructure.

Support for large multimodal AI models is delivered through Foundry Local, which enables advanced inference on customer-controlled hardware using technology from partners such as NVIDIA.

Such an approach helps organisations bring modern AI capabilities into highly restricted environments while preserving control over data, identities and operational procedures.

Microsoft positions it as a unified stack that works across connected, hybrid and fully disconnected modes without increasing operational complexity.

These additions create a framework designed for governments and regulated industries that regard sovereignty as a strategic priority.

With global availability for qualified customers, the Sovereign Cloud aims to preserve continuity, reinforce governance and expand AI capability while keeping every layer of the environment within local control.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

AI-powered electronic nose shows promise for early ovarian cancer screening

Researchers at Linköping University have developed an AI-powered electronic nose capable of detecting early signs of ovarian cancer in blood plasma samples. The pilot study, published in Advanced Intelligent Systems, reports 97 per cent accuracy using machine-learning models trained on biobank data.

Ovarian cancer is often diagnosed late because symptoms resemble those of more common conditions. In 2022, around 325,000 new cases and more than 200,000 deaths were recorded globally. Earlier detection could significantly improve survival rates and access to timely treatment.

The prototype device contains 32 commercially available sensors that detect volatile substances emitted by blood samples. Rather than targeting a single biomarker, the system analyses complex chemical patterns, with machine learning identifying signatures linked to ovarian cancer.

Unlike conventional blood tests, which can be slow and rely on specific biomarkers, the electronic nose evaluates a broad spectrum of compounds. Researchers say the approach offers greater precision and could reduce screening costs while improving accessibility.

Developers estimate the test takes around 10 minutes and could become part of cancer screening programmes within three years. Although currently focused on ovarian cancer, the team suggests the method could eventually be adapted to detect multiple cancer types.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

US tech giants eye Wales for major AI investment

American technology firms are increasingly looking to Wales as a destination for AI investment and data infrastructure. Strong inward investment figures and expanding growth zones are putting the nation firmly on the technology map.

Last year Wales secured £4.6bn in global investment across 65 foreign direct investment projects, marking a 23 per cent rise year on year. Thousands of jobs were created or safeguarded, outperforming many other UK regions.

Major projects underline the shift. US firm Vantage plans to transform the former Ford Bridgend plant into a large-scale data centre campus, while Microsoft is supporting another proposed scheme in Newport, both located within designated AI growth zones.

Beyond data centres, Wales offers land, connectivity and a supportive regulatory environment. Innovation clusters across Cardiff, Newport and North Wales, alongside strengths in life sciences, advanced manufacturing and renewable energy, are strengthening its appeal to global investors.

With expanding energy projects and a growing start-up pipeline, Wales is positioning itself as a competitive base for global business. Investors are increasingly encouraged to see it not as a regional outpost, but as an international platform rooted in strong economic foundations.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!