On 23 April 2026, the UAE Cabinet approved a framework to move 50% of government sectors, services and operations onto agentic AI within 2 years, with ministers and directors-general to be assessed on how quickly their entities adopted it. 11 days later, Sheikh Hamdan bin Mohammed, Crown Prince of Dubai, set the emirate’s private sector the same 2-year window, backed by training tracks run through the Dubai Chamber, incubators and dedicated funds.
For the companies that host government data, the two announcements pushed a question that had belonged to procurement teams and cloud architects onto the desk of every department head: where does sovereignty hold once software agents, picked and used by employees, start acting on classified information?
Mohammed Retmi, Vice President Sovereign Clouds, Core42, the G42 company that operates a sovereign public cloud on Microsoft Azure alongside its own private cloud, answers the older version of that question for UAE government entities and regulated enterprises.
His answer to the newer one puts clear limits on what a provider can promise. Core42 can build the infrastructure, run inference inside the country and measure a customer’s compliance against national policy, yet it has no control over which outside platform a staff member opens in parallel.
Sovereignty claims fall apart when buyers check a single layer
Retmi placed the subject alongside food and military sovereignty as a matter of national interest. “Digital sovereignty is at the heart of any nation and economy,” he said. He divided it into 3 layers, which he named as data sovereignty, operational sovereignty and technology sovereignty, and argued that a customer has to reach the required level on all 3 before any claim to sovereignty holds.
Applied to cloud, his definition was specific about jurisdiction as well as location. He described sovereign cloud as “an infrastructure where the end customer has the data locally, under the governance and the jurisdiction only of that nation, so that no other nation can get access to this data, deal with this data or see this data.”
Vendors across the region now attach the word to data centre locations, encryption key custody, local operations staff and supply chain assurances, often promoting one of these as the whole answer. Asked which of them mattered most, Retmi declined to rank them.
“It’s everywhere. It’s an end-to-end journey,” he said. By his account, building a sovereign cloud for a nation begins with regulation, meaning what sovereignty means for that country and which policies must be respected, and then runs through the cloud service providers, the customer organisations and the employees inside them. “The whole chain must ensure sovereignty at each layer,” he said.
A workload’s data classification decides which cloud it runs on
His test for separating a genuine sovereign offering from a marketing label starts with the written policy a customer is bound by. Core42 works from three sources, which he listed as national policy, sectoral policy and custom policy. “We are driven by the policies defined by the country, either at the national level or at the sectoral level,” he said, adding that sectors such as energy and healthcare set their own sovereignty standards, and that some customers bring policies of their own that Core42 then builds to.
Those policies are organised around data classification, running from open data through sensitive and confidential to secret and top secret. The classification then determines the environment. For data that needs residency alongside policy controls, Retmi said a hyperscale platform such as Azure can serve, provided it runs with Core42’s Insight compliance layer on top. Secret and top secret workloads go to Core42’s private cloud, which he said covers all 3 layers of sovereignty, with the data in the country, in Core42’s data centres, running on its own technology stack and managed by its own operations staff, independent of foreign entities.
The practical consequence for a buyer is that a single “sovereign” label says little until it is matched against a classification level. A vendor that cannot say which classes of data its platform is approved to hold, under which national or sectoral policy, is selling a location.
The provider measures compliance, and the customer carries the obligation
The part of Retmi’s remit that outsiders tend to misread concerns ownership of compliance on the public cloud. Insight gives customers a live view of how far their environment meets the applicable policies. “We give them the tools, the platform, to check by themselves if they are compliant or not,” he said. He gave a worked example of a customer found to be 85% compliant and 15% non-compliant, in which case Core42 supplies guidance on closing the gap.
The customer then has to act on that guidance. “Still, the responsibility is with the customer,” Retmi said. Core42 provides visibility and direction, and the customer carries the obligation to comply. Core42 did not share figures on how many of its public cloud customers operate at full compliance, or how long a typical remediation takes.
That division of responsibility becomes harder to manage under the Cabinet’s 2-year timeline. “Once you deal with AI, the sovereignty challenge becomes bigger and bigger,” Retmi said. A conventional cloud audit checks a customer’s workloads inside a defined environment. AI adoption adds a population of users choosing their own tools, and each of those tools raises its own jurisdictional questions.
“Are those platforms sovereign? Are they in the country or outside the country? Are they subject to the policies of the country?” he asked.
Core42’s answer on its own side is Compass, its platform-as-a-service, which lets customers run inference on the model of their choice on infrastructure inside the UAE. Retmi acknowledged that it leaves a gap no provider can close alone. Nothing in the platform stops an employee from turning to shadow IT and shadow AI, using outside platforms in parallel with the sanctioned one. He described sovereignty in the AI era as a joint responsibility, shared between the provider and the organisation whose staff are making those choices.
The Cabinet framework will judge government entities on the speed of their agentic AI adoption. Retmi’s model of the chain means that the sovereignty of that adoption will rest heavily on controls each entity builds over its own users, because Core42’s reach ends at the platforms it hosts and the policies it can measure.


