AI Strategy
-29 June 2026
-6 min read
By Patrick Rechsteiner, Founder rechsteiner.io
McKinsey says sovereign AI has moved from policy debate to commercial priority. For retail leaders, the practical question is simpler: which AI workloads need to stay under your control, and which can ride on the public stack?
Sovereign AI has moved from policy debate to commercial priority. A recent McKinsey interview with three of their partners - Ali Ustun, Luca Bennici, and Melanie Krawina - lays out the case clearly. For retail leaders, the question to answer is simpler: when you're buying AI for your business, which workloads need to stay under your control, and which can ride on the public stack?
The McKinsey piece draws a sharp distinction between data sovereignty and sovereign AI. Data sovereignty is about where your data lives and which jurisdiction's laws apply to it. Sovereign AI goes further. It is about who controls the intelligence layer built on top of your data - the infrastructure, the models, the operational switches, and the legal jurisdiction.
The practical translation: you can have data sovereignty (your data sits in an Australian data centre) and still not have sovereign AI (because the model processing that data is run by a US hyperscaler under US jurisdiction).
For most retailers, this distinction has been academic. It is becoming material.
McKinsey's three partners give three reasons it has become strategic. Each lands harder in retail than the source article spells out.
First, liability. Courts are increasingly holding deployers of AI - not vendors - responsible when AI systems produce biased or wrong outputs. If your loyalty programme uses a vendor's recommendation engine and that engine starts denying offers to specific customer segments, you are the one explaining it. Vendor contracts cap their liability. Yours does not have a cap.
Second, geopolitical resilience. Retail businesses run on third-party tech: cloud platforms, payment processors, AI services, ad networks. A service denial or geopolitical shock that turns off any of those is operational risk that was not on most boards' registers five years ago.
Third, economic value. If your data trains a foreign vendor's model, the long-term value of that data flows offshore. For mid-market retailers and ASX-listed businesses, that is a real conversation about what intellectual property gets created on whose stack.
Here is where the McKinsey piece is genuinely useful: not all AI workloads need sovereignty.
The practical move is to segment the portfolio. Use public hyperscaler AI for generic tasks - drafting product descriptions, summarising customer reviews, classifying support tickets. Reserve sovereign infrastructure for the things where control matters: customer data analysis, pricing models, loyalty algorithms, anything that touches proprietary commercial data or generates IP worth defending.
This sounds obvious. The discipline is in the doing. Segment the portfolio, decide which workloads warrant control, and vendor accordingly. The value compounds because every future AI decision gets made against an already-tested framework.
A pragmatic sequence:
Map the existing AI footprint by data sensitivity. Which models touch the most proprietary data? Which touch only generic content? This is usually a one-day exercise.
Tier the future AI roadmap the same way. For each planned use case, ask whether the data and the IP being generated warrants control. Most use cases will not. Some will.
Build vendor contracts around the tiering. Standard hyperscaler agreements for the generic stuff. More structured arrangements - with clear data boundaries, exit clauses, and IP ownership - for the workloads that matter commercially.
Stay flexible. The sovereign AI vendor market is fragmented and immature. The right move for a mid-market retailer today is not to pick a sovereign stack and commit forever. It is to build optionality into the architecture so workloads can move as the market matures.
Sovereign AI is not a binary choice. It is a workload-tiering discipline. The McKinsey piece is right that the question is moving from "shall we do it?" to "how do we implement it?" The retail-specific translation is more practical: look at the AI roadmap, identify the two or three workloads where control actually matters commercially, and design accordingly. Everything else can stay on the public stack.
Source: McKinsey, What is sovereign AI? (March 2026).
Frequently Asked Questions
Keep exploring
Work With Patrick
If this resonates with where your organisation is, start a conversation. Patrick works directly with leadership teams navigating AI strategy, digital retail, and commercial growth.
Get in Touch