Why AI Is Pushing UK Businesses to Take Back Control of Their Data

IDC research commissioned by Expereo shows UK technology leaders are linking AI risk, data control, and network visibility more closely.

9
Tower Bridge in London with secure data connections representing AI, digital sovereignty, and data control for UK businesses
AI & Automation in CXNews

Published: September 23, 2026

Sophie Wilson

AI may have shifted from experiment to enterprise priority, but many UK businesses now face a difficult follow-up question: who controls the data that makes those systems work?

New IDC research, commissioned by Expereo, suggests that digital sovereignty is becoming a more prominent concern for organizations managing AI, cloud, and connectivity across increasingly complex environments. According to the UK findings, 50% of UK enterprises want greater control over sensitive and strategic data, while 56% of UK technology leaders worry that AI could create new security risks.

The findings do not suggest that organizations are retreating from AI. Instead, they point to a shift in how technology leaders view the foundations required to scale it. Data location, cross-border transfers, network resilience, security controls, and visibility into traffic flows now sit closer together in enterprise decision-making.

TL;DR

  • Data control is rising: Half of UK enterprises surveyed want greater control over sensitive and strategic data.
  • AI adds urgency: Security concerns remain a major barrier to adoption, and 56% of UK technology leaders say AI may create new security risks.
  • Infrastructure matters: IDC’s global research links AI outcomes to data quality, skills, governance, and network performance, not models alone.

Why Is Digital Sovereignty Becoming an AI Issue for UK Businesses?

Digital sovereignty is becoming an AI issue because organizations need to know how sensitive data moves through cloud, network, and AI environments before they can manage its security, compliance, and operational risk. For UK businesses, that challenge extends beyond where data is stored. It also includes the providers, jurisdictions, and connections involved in processing and moving it.

IDC’s research frames digital sovereignty as a global priority shaped by the need to retain control over sensitive data amid regulatory complexity and geopolitical risk. Across the global respondent base, 33% of organizations described digital sovereignty as a high or top priority.

The UK findings supplied by Expereo show a similar direction of travel. Alongside the 50% of enterprises seeking greater control over sensitive and strategic data, 29% of UK organizations now view digital sovereignty as a top or high priority. A further 27% rank it among the leading drivers of technology investment.

That matters for customer experience leaders because AI programs increasingly depend on data drawn from multiple business systems. Customer interaction data may move between contact center platforms, CRM tools, knowledge bases, cloud infrastructure, analytics environments, and AI services. Each connection can create a governance question.

In practice, sovereignty does not require every organization to keep all data within one country or avoid cloud services. It requires leaders to understand their obligations, map data flows, and decide which controls fit the information, services, and jurisdictions involved.

WHAT IS DIGITAL SOVEREIGNTY?

  • Control: The ability to understand and govern how data, applications, and infrastructure operate.
  • Compliance: Meeting regulatory and contractual obligations across the jurisdictions where an organization operates.
  • Resilience: Reducing exposure to disruptions, provider dependencies, and risks associated with complex cross-border operations.

What Is Driving the UK’s Push for Greater Data Control?

UK organizations are placing greater emphasis on data control because AI introduces new security, compliance, and operational questions at the same time as cloud environments become more distributed. The research points to a combination of internal risk management and external pressure from customers, partners, and regulators.

Security and privacy concerns remain a substantial obstacle to AI adoption. In IDC’s global Technology Leaders Survey, 58% of organizations cited security concerns as a barrier to AI adoption, just behind cost at 59%. The UK release adds that 56% of technology leaders worry AI could create new security risks for their business.

Those concerns reflect a real enterprise tension. AI can improve productivity, quality of work, and customer experience, but it can also broaden the volume of data in motion, introduce new dependencies, and create additional routes for sensitive information to be exposed or misused.

The commercial dimension is also growing. Expereo’s UK findings show that 26% of businesses say customer or partner demands to localize data are influencing their approach to digital sovereignty. That suggests the issue is no longer confined to internal legal and technology teams. It can affect supplier selection, customer trust, and the ability to win or retain business.

IDC’s global analysis also shows regional differences. Enterprises in APAC place the highest priority on digital sovereignty globally at 38%, compared with 31% in Europe and 30% in the US. IDC characterizes Europe’s approach as predominantly regulation-led, with GDPR and data residency rules shaping infrastructure, cloud, and vendor decisions.

Can Businesses Scale AI Without Stronger Security and Governance?

Businesses can deploy AI without mature governance and security foundations, but IDC’s research suggests they are less likely to produce reliable value at scale. Organizations need clear ownership, high-quality data, appropriate skills, cost visibility, and resilient infrastructure if they want AI investments to move beyond isolated experiments.

IDC found that AI use is widespread, but maturity remains limited. Across the survey sample, 62% of organizations described their AI use as limited, while 25% reported extensive use and 5% described their use as transformative. The research does not establish causation, but it does show that more advanced adoption aligns with more optimistic business expectations.

The research also highlights a gap between activity and outcomes. Nearly 60% of organizations globally reported positive AI ROI, according to IDC’s Global AI & Network Performance Survey. However, the report warns that aggressive investment without the right foundations can amplify inefficiencies rather than close the ROI gap.

For organizations where AI underperformed expectations, poor data quality was the most commonly cited factor at 51%, followed by costs exceeding ROI at 47% and AI underperformance at 46%. Inadequate network performance affected 26% of respondents in this group.

By contrast, organizations where AI exceeded expectations cited AI performance, strong in-house skills, network performance, high-quality training data, and project management as contributing factors. The findings reinforce a familiar lesson for CX leaders: an AI experience is only as dependable as the data, workflows, people, and infrastructure behind it.

WHY AI ROI CAN STALL

  • Data quality: AI systems cannot deliver reliable output if the underlying data is incomplete, inconsistent, or poorly governed.
  • Skills and accountability: Enterprises need people who can manage data, security, implementation, and business outcomes.
  • Infrastructure readiness: Distributed AI workloads need dependable, secure connectivity and the visibility to identify potential weak points.

Why Does Network Visibility Matter for Digital Sovereignty?

Network visibility matters because it helps organizations understand how data travels between cloud services, users, applications, and jurisdictions. It cannot solve every sovereignty problem, but it can support informed decisions about routing, security, resilience, and compliance in complex enterprise environments.

Expereo argues that digital sovereignty increasingly depends on visibility into data movement, not only data storage. The company’s position reflects the growing importance of distributed infrastructure as enterprises combine public cloud services, private environments, SaaS platforms, remote workforces, and AI tools.

Ben Elms, CEO of Expereo, said:

“Digital sovereignty is increasingly being driven by a desire for greater control over how data moves across cloud, network and AI environments. As many UK businesses operate across multiple providers and jurisdictions, they are focusing not only on where data is stored, but also on how it moves between them.”

Elms added that network visibility and routing transparency are receiving more attention, while acknowledging that sovereignty extends beyond the network.

“This is placing greater emphasis on network visibility and routing transparency. But while digital sovereignty extends beyond the network, a sovereignty strategy without a network strategy is increasingly incomplete. Delivering on digital sovereignty requires network, cloud, security, governance and data management strategies to work together, helping organisations meet regulatory requirements while enabling innovation and growth.”

IDC’s global findings support the broader infrastructure argument, although the research does not assess Expereo’s services specifically. Networks ranked as the third technology priority for surveyed organizations, behind security and AI. Only 5% of respondents said their networks were fully ready for future needs.

The report also found that 46% of organizations with successful AI implementations attributed success to their networks. Among organizations where AI failed, one quarter identified underperforming networks as a main factor. These figures suggest that network strategy belongs in AI planning, but they do not mean connectivity alone determines success.

What Should CX and Technology Leaders Check Before Expanding AI?

CX and technology leaders should assess data flows, decision rights, security controls, infrastructure capacity, and supplier obligations before expanding AI into higher-value customer journeys. The aim is not to slow useful innovation. It is to ensure the organization can explain, govern, and sustain the experiences it puts in front of customers and employees.

A practical first step involves mapping the end-to-end data path for each priority AI use case. Leaders should identify what data enters the system, where it is processed, which third parties can access it, how long it is retained, and what happens when a model or connected service fails.

Teams should also distinguish between customer-facing and internal use cases. An internal productivity assistant may carry a different risk profile from an AI tool that summarizes customer conversations, recommends next-best actions, or makes decisions that affect service eligibility and outcomes.

IDC recommends that enterprises move from fragmented experimentation to execution discipline. That includes selecting a focused set of use cases, defining ownership, setting ROI expectations, and strengthening governance, data readiness, and cost visibility before scaling.

BUYER CHECKLIST: AI, DATA, AND CONTROL

  • Map the data: Identify data sources, processing locations, transfers, retention periods, and third-party access.
  • Test the network: Assess bandwidth, resilience, security, and visibility for distributed AI workloads.
  • Set governance: Assign ownership for risk, security, performance, cost, and customer outcomes.
  • Review supplier commitments: Confirm contractual and technical assurances around data handling, residency, and incident response.

Will Digital Sovereignty Slow Down AI Innovation?

Digital sovereignty does not need to slow AI innovation, but it can expose whether an organization has built the controls needed to scale responsibly. The strongest programs are likely to treat governance, security, data quality, and infrastructure as enablers of sustained innovation rather than as late-stage compliance work.

The IDC report describes a three-way tension between AI-led innovation, cybersecurity and resilience, and sustainability. Organizations cannot assume that progress in one area automatically strengthens the others. They need to balance competing demands through clearer priorities and cross-functional collaboration.

That is particularly relevant for customer experience programs. A fast AI rollout may improve response times or agent productivity in the short term. Yet a poorly governed deployment can create risks around incorrect advice, insecure data handling, inconsistent service, and damaged customer trust.

The Expereo-commissioned findings add a timely UK perspective to that challenge. The growing focus on control reflects a recognition that AI strategy now reaches far beyond model selection. It touches the entire environment in which data is created, moved, secured, and used.

Final Takeaway: AI Control Depends on More Than the Model

The debate around AI readiness is often framed around use cases, models, and ROI. IDC’s research suggests the more durable question is whether enterprises have the operational foundations to support those ambitions. Data quality, skills, governance, cybersecurity, and network performance all influence whether AI delivers value or creates another source of risk.

For UK businesses, the push for greater digital sovereignty indicates that control is becoming a strategic requirement. The challenge is not simply to keep data in one place. It is to maintain a clear view of how critical information moves across an increasingly distributed technology estate.

Expereo’s emphasis on network visibility is one part of that wider strategy. The research supports the importance of resilient connectivity, while also making clear that enterprises need a coordinated approach across network, cloud, security, governance, and data management. AI may accelerate the pressure, but the response needs to be broader than AI itself.

What is digital sovereignty?

Digital sovereignty is an organization’s ability to maintain control over its data, digital infrastructure, and technology decisions. It often includes understanding where data is stored and processed, how it moves across jurisdictions, and whether arrangements meet regulatory, contractual, security, and resilience requirements.

Why does AI increase digital sovereignty concerns?

AI can increase sovereignty concerns because it often uses data across multiple systems, cloud environments, and third-party services. Organizations need to understand how sensitive information is accessed, processed, transferred, retained, and protected before they scale AI into important business or customer-facing processes.

What did IDC’s research find about UK business attitudes to data control?

According to UK findings released by Expereo from an IDC InfoBrief, 50% of UK enterprises want greater control over sensitive and strategic data. The release also states that 56% of UK technology leaders worry AI could create new security risks, while 26% say customer or partner demands to localize data influence their approach to digital sovereignty.

How does network visibility support digital sovereignty?

Network visibility can help organizations understand how data and traffic move between users, applications, cloud services, and jurisdictions. It does not replace data governance or security controls, but it can support routing transparency, resilience planning, incident response, and informed compliance decisions.

What should enterprises prioritize before scaling AI?

Before scaling AI, enterprises should prioritize data quality, security, governance, skills, cost visibility, and infrastructure readiness. They should map data flows, define decision ownership, assess supplier commitments, test network resilience, and establish measurable business and customer outcomes for each use case.

Agentic AIAI Governance Tools
Featured

Share This Post