Cohere’s Joëlle Pineau on Sovereign AI and Enterprise Security
![Joëlle Pineau, Chief AI Officer at Cohere]()
IDC research commissioned by Cohere explores sovereign AI, with Chief AI Officer Joëlle Pineau outlining essential strategies for enterprise cloud security and data governance.
According to IDC’s report, The State of Sovereign AI Adoption in 2026, commissioned by AI firm Cohere, one in three business leaders struggles to define sovereign AI in their own words.
Canadian AI company Cohere develops large language models (LLMs) and natural language processing tools tailored for enterprise use. Between 2021 and 2024, the company secured four major funding rounds (Series A through D), raising nearly US$1 billion.
The company has previously argued in a blog post that the growing trend of nations controlling their own AI infrastructure, models, and data—known as “sovereign AI”—could introduce new competitive dynamics through regionally focused AI innovation.
The IDC research defines sovereign AI as "the ability for an organisation to have free choice and control over the design, development, deployment, accessibility, operation, maintenance and governance of its AI systems and applications, as well as the underlying technology foundations they depend on".
Among surveyed leaders who could define sovereign AI, 52% explicitly describe it in terms of location or national control, while 35% emphasize digital independence.
The biggest blind spot is security dependency
Joëlle Pineau, Chief AI Officer at Cohere

Key findings
- One in three leaders cannot describe sovereign AI, with only 13% reporting high familiarity.
- Over 80% of UK decision-makers rely on public or private third-party clouds for regulated AI processes.
- Data leakage and compliance are top adoption risks, cited by 82% of financial services and 77% of manufacturing leaders.
- Among informed leaders, 52% define sovereign AI by geographic/national control, while 35% cite digital independence.
- 37% of telecoms companies and 35% of Canadian enterprises pursue sovereign AI primarily for market differentiation.
The security blind spot
Despite high privacy concerns, over 80% of UK decision-makers report relying on public or private clouds for regulated AI processes, raising questions about whether true sovereignty is possible on third-party cloud infrastructure or if firms are operating under a false sense of security.
Joëlle Pineau, Chief AI Officer at Cohere, highlighted: "The biggest blind spot is security dependency.
"If critical AI runs through an external provider, you’re relying on their security as well as your own. Recent incidents with Anthropic and OpenAI have shown that vulnerabilities or failures at the model-provider level can create risks downstream for customers.
"We deploy inside the customer's own environment, behind their secured firewalls - that is a more secure environment to mitigate and reduce risk of a cyber breach."
Cohere helps enterprises to own their own AI. Credit: Cohere
'True AI sovereignty'
The research identified data leakage and compliance as the top two concerns of sovereign AI adoption across industries and geographies. For AI practitioners building and deploying these systems, understanding these priorities could be crucial for architecture decisions and implementation strategies.
Even without an agreed-upon definition of sovereign AI, the consensus on the importance of privacy and security is clear with 82% of financial services professionals most concerned about data leakage and privacy, closely followed by 77% of manufacturing, 75% of telco, 74% of healthcare and 70% of energy representatives.
There's so much sovereignty washing, where solutions that are not at all contributing to diversification or resilience are being marketed as 'sovereign' and painted in that light.
Joëlle Pineau, Chief AI Officer at Cohere
Many enterprises also see sovereignty as a path to stronger security, reduced dependence on external providers and market differentiation. In Canada particularly, 35% of those surveyed said competitive advantage is what drives sovereign AI. Meanwhile, telco providers lead the competitive advantage story with 37%, closely followed by 32% of manufacturing representatives.
Joëlle is quick to defend sovereign AI as not a false sense of security, but rather a spectrum that depends on strict technical guarantees.
"True sovereignty can include cloud infrastructure, but simply hosting data in a particular region or private cloud doesn't automatically make an AI system sovereign," she says.
"It also requires a set of technical guarantees about who controls the model, data, access, updates and deployment and what dependencies remain on an external API.
"There's so much sovereignty washing, where solutions that are not at all contributing to diversification or resilience are being marketed as 'sovereign' and painted in that light.
"The more important question is whether sovereignty is engineered into an enterprise environment rather than added as a label."
Adoption remains uneven because enterprises lack a clear plan for operationalising sovereignty. Also, only 13% of leaders are "very widely" aware of sovereign AI, revealing a fragmented and inconsistent grasp of the concept across global organisations. This means buyers or influencers may be making AI investment decisions without proper context, potentially complicating implementation for technical teams.
To help with this, Cohere says "organisations must bridge the awareness-to-action gap by creating a strategic vision and plan to achieve ownership over their AI systems".

True sovereignty can include cloud infrastructure, but simply hosting data in a particular region or private cloud doesn't automatically make an AI system sovereign
Joëlle Pineau, Chief AI Officer at Cohere
Beyond compliance
While 'sovereignty' often evokes thoughts of strict government compliance, Cohere points to its work with high-performance commercial clients like the Aston Martin F1 team as an example of how the architecture delivers practical value beyond simple data protection or standard public cloud deployments.
"True sovereignty gives enterprises invaluable levels of control, customisation and secure deployment – resilience is the foundational benefit that underlines what accessing AI from an external API can't give, but its value goes beyond simply protecting data," says Joëlle.
"A sovereign architecture can help organisations unearth and make sense of information wherever it sits, integrate AI directly into existing workflows and turn that data into faster, better decisions.
"Formula One is a useful case study because it compresses many of the challenges enterprises face every day: huge volumes of telemetry, diagnostic and simulation data, specialist teams, high-pressure decisions and no tolerance for slow or insecure systems.
"The same principle applies in any high-stakes enterprise environment. AI creates the most value when it is close to the work, tailored to the organisation's context and secure enough to operate where its most sensitive IP and operational data already live."
Cohere joined the Aston Martin Aramco Formula One as its Generative AI partner in March 2026.
Strategic partners
On its website, Cohere claims to be trusted by industry leaders:
- McKinseyis a global management consulting firm advising private, public and social sector organisations on strategic management, operational performance, digital transformation, leadership and sustainable business growth across international markets.
- Salesforceis a global cloud software company specialising in customer relationship management tools. It provides cloud applications focused on sales, customer service, marketing automation, data analytics, artificial intelligence and system integration.
Salesforce is a key backer of Cohere. Credit: JasonDoiy/Getty Images
- Accenture is a multinational professional services company specialising in information technology services and management consulting. It provides digital transformation, cybersecurity, cloud computing, systems integration, operations management and business process outsourcing.
- Oracle is a global technology company specialising in database software, enterprise applications and cloud infrastructure. It develops software systems for corporate financial management, supply chain planning, human resources and business operations.
- Dell Technologies is a global technology company that designs, manufactures and sells personal computers, enterprise servers, data storage devices, network switches and hardware infrastructure. It also provides enterprise IT solutions.
Related article
How AI and Robotics Are Transforming bp’s Oil Production
Digital twin technology enables bp to simulate energy asset operations, identifying improvement opportunities and predicting failures before they occur. Credit: bpRicky Burns, Transformation & Technology Manager at bp, explains how digital tools help
Toyota’s $6.4bn robotics estimate puts physical AI in focus
Toyota Motor projects that rolling out automation across its manufacturing facilities, subsidiaries, and key suppliers may require approximately 400,000 robots and an annual expenditure of roughly 1 trillion yen ($6.4 billion) starting in 2028.Accord
Japan tackles labor shortage with AI model for 10 million robots
Japan’s AI robotics initiative has transitioned from a discussion topic into an official national strategy. The government recently validated widely cited projections: deploying 10 million AI-driven robots across 18 sectors by 2040, supported by publ
Related Special Topic Recommendations
Comments (0)
0/500
IDC research commissioned by Cohere explores sovereign AI, with Chief AI Officer Joëlle Pineau outlining essential strategies for enterprise cloud security and data governance.
According to IDC’s report, The State of Sovereign AI Adoption in 2026, commissioned by AI firm Cohere, one in three business leaders struggles to define sovereign AI in their own words.
Canadian AI company Cohere develops large language models (LLMs) and natural language processing tools tailored for enterprise use. Between 2021 and 2024, the company secured four major funding rounds (Series A through D), raising nearly US$1 billion.
The company has previously argued in a blog post that the growing trend of nations controlling their own AI infrastructure, models, and data—known as “sovereign AI”—could introduce new competitive dynamics through regionally focused AI innovation.
The IDC research defines sovereign AI as "the ability for an organisation to have free choice and control over the design, development, deployment, accessibility, operation, maintenance and governance of its AI systems and applications, as well as the underlying technology foundations they depend on".
Among surveyed leaders who could define sovereign AI, 52% explicitly describe it in terms of location or national control, while 35% emphasize digital independence.
The biggest blind spot is security dependency
Joëlle Pineau, Chief AI Officer at Cohere

Key findings
- One in three leaders cannot describe sovereign AI, with only 13% reporting high familiarity.
- Over 80% of UK decision-makers rely on public or private third-party clouds for regulated AI processes.
- Data leakage and compliance are top adoption risks, cited by 82% of financial services and 77% of manufacturing leaders.
- Among informed leaders, 52% define sovereign AI by geographic/national control, while 35% cite digital independence.
- 37% of telecoms companies and 35% of Canadian enterprises pursue sovereign AI primarily for market differentiation.
The security blind spot
Despite high privacy concerns, over 80% of UK decision-makers report relying on public or private clouds for regulated AI processes, raising questions about whether true sovereignty is possible on third-party cloud infrastructure or if firms are operating under a false sense of security.
Joëlle Pineau, Chief AI Officer at Cohere, highlighted: "The biggest blind spot is security dependency.
"If critical AI runs through an external provider, you’re relying on their security as well as your own. Recent incidents with Anthropic and OpenAI have shown that vulnerabilities or failures at the model-provider level can create risks downstream for customers.
"We deploy inside the customer's own environment, behind their secured firewalls - that is a more secure environment to mitigate and reduce risk of a cyber breach."
Cohere helps enterprises to own their own AI. Credit: Cohere
'True AI sovereignty'
The research identified data leakage and compliance as the top two concerns of sovereign AI adoption across industries and geographies. For AI practitioners building and deploying these systems, understanding these priorities could be crucial for architecture decisions and implementation strategies.
Even without an agreed-upon definition of sovereign AI, the consensus on the importance of privacy and security is clear with 82% of financial services professionals most concerned about data leakage and privacy, closely followed by 77% of manufacturing, 75% of telco, 74% of healthcare and 70% of energy representatives.
There's so much sovereignty washing, where solutions that are not at all contributing to diversification or resilience are being marketed as 'sovereign' and painted in that light.
Joëlle Pineau, Chief AI Officer at Cohere
Many enterprises also see sovereignty as a path to stronger security, reduced dependence on external providers and market differentiation. In Canada particularly, 35% of those surveyed said competitive advantage is what drives sovereign AI. Meanwhile, telco providers lead the competitive advantage story with 37%, closely followed by 32% of manufacturing representatives.
Joëlle is quick to defend sovereign AI as not a false sense of security, but rather a spectrum that depends on strict technical guarantees.
"True sovereignty can include cloud infrastructure, but simply hosting data in a particular region or private cloud doesn't automatically make an AI system sovereign," she says.
"It also requires a set of technical guarantees about who controls the model, data, access, updates and deployment and what dependencies remain on an external API.
"There's so much sovereignty washing, where solutions that are not at all contributing to diversification or resilience are being marketed as 'sovereign' and painted in that light.
"The more important question is whether sovereignty is engineered into an enterprise environment rather than added as a label."
Adoption remains uneven because enterprises lack a clear plan for operationalising sovereignty. Also, only 13% of leaders are "very widely" aware of sovereign AI, revealing a fragmented and inconsistent grasp of the concept across global organisations. This means buyers or influencers may be making AI investment decisions without proper context, potentially complicating implementation for technical teams.
To help with this, Cohere says "organisations must bridge the awareness-to-action gap by creating a strategic vision and plan to achieve ownership over their AI systems".

True sovereignty can include cloud infrastructure, but simply hosting data in a particular region or private cloud doesn't automatically make an AI system sovereign
Joëlle Pineau, Chief AI Officer at Cohere
Beyond compliance
While 'sovereignty' often evokes thoughts of strict government compliance, Cohere points to its work with high-performance commercial clients like the Aston Martin F1 team as an example of how the architecture delivers practical value beyond simple data protection or standard public cloud deployments.
"True sovereignty gives enterprises invaluable levels of control, customisation and secure deployment – resilience is the foundational benefit that underlines what accessing AI from an external API can't give, but its value goes beyond simply protecting data," says Joëlle.
"A sovereign architecture can help organisations unearth and make sense of information wherever it sits, integrate AI directly into existing workflows and turn that data into faster, better decisions.
"Formula One is a useful case study because it compresses many of the challenges enterprises face every day: huge volumes of telemetry, diagnostic and simulation data, specialist teams, high-pressure decisions and no tolerance for slow or insecure systems.
"The same principle applies in any high-stakes enterprise environment. AI creates the most value when it is close to the work, tailored to the organisation's context and secure enough to operate where its most sensitive IP and operational data already live."
Cohere joined the Aston Martin Aramco Formula One as its Generative AI partner in March 2026.
Strategic partners
On its website, Cohere claims to be trusted by industry leaders:
- McKinseyis a global management consulting firm advising private, public and social sector organisations on strategic management, operational performance, digital transformation, leadership and sustainable business growth across international markets.
- Salesforceis a global cloud software company specialising in customer relationship management tools. It provides cloud applications focused on sales, customer service, marketing automation, data analytics, artificial intelligence and system integration.
Salesforce is a key backer of Cohere. Credit: JasonDoiy/Getty Images
- Accenture is a multinational professional services company specialising in information technology services and management consulting. It provides digital transformation, cybersecurity, cloud computing, systems integration, operations management and business process outsourcing.
- Oracle is a global technology company specialising in database software, enterprise applications and cloud infrastructure. It develops software systems for corporate financial management, supply chain planning, human resources and business operations.
- Dell Technologies is a global technology company that designs, manufactures and sells personal computers, enterprise servers, data storage devices, network switches and hardware infrastructure. It also provides enterprise IT solutions.
How AI and Robotics Are Transforming bp’s Oil Production
Digital twin technology enables bp to simulate energy asset operations, identifying improvement opportunities and predicting failures before they occur. Credit: bpRicky Burns, Transformation & Technology Manager at bp, explains how digital tools help
Toyota’s $6.4bn robotics estimate puts physical AI in focus
Toyota Motor projects that rolling out automation across its manufacturing facilities, subsidiaries, and key suppliers may require approximately 400,000 robots and an annual expenditure of roughly 1 trillion yen ($6.4 billion) starting in 2028.Accord
Japan tackles labor shortage with AI model for 10 million robots
Japan’s AI robotics initiative has transitioned from a discussion topic into an official national strategy. The government recently validated widely cited projections: deploying 10 million AI-driven robots across 18 sectors by 2040, supported by publ





Home






