And why it’s not just an IT problem
You’ve bought the AI tools. Your teams are using or experimenting with them. Productivity is up. But, does something feel a little uneasy about it all?
That unease has a name: digital sovereignty. It’s a term that sounds like it belongs in a government policy paper, not a partner meeting or a small practice office. But strip away the jargon and it begs one plain question, the same one any board, regulator, or client could be expected to ask:
“Who is actually in control here?”
Not who signed the contract. Not who pays the subscription. Who is actually in control of your data, your systems, your technology choices, and the decisions your AI is making on your behalf.
For accounting firms and finance professionals, this isn’t an abstract question. You hold client data under professional obligations that don’t disappear just because a machine touched it. You may sign off on numbers that a model helped produce. Your name, your licence, your reputation, sits behind the output. So it’s worth a few minutes at least to understand what digital sovereignty actually means, in language you’d use with a client, not a systems architect.
The four things you actually need to control
Digital sovereignty breaks down into four practical questions. None of them require you to become a technologist. All of them require you to stop assuming someone else has it handled.
1. Where does the data actually live, and who can touch it?
This is the most familiar one, and involves data residency, access controls, encryption. But the AI-specific twist is this, is when you paste any client’s financial data into the chat window, or add a connection for your AI Agent to your practice management system for example, you’ve just created a new place where your / their data lives, with a new set of people and other AI systems, who can access it. Most firms know where their server is. Fewer know where their AI tools have quietly extended that boundary.
The question to ask: If you had to map every place client data flows through your AI tools, could you produce that map today?
2. Where does the “thinking” actually happen, and who’s running the machine?
(Alright, admittedly there’s no thinking happening here, just computation), but most firms AI tools run on someone else’s infrastructure, a cloud region, a data centre, GPUs. That’s normal and fine. What matters is whether you know the terms: what happens if that provider has an outage, changes its policies, or is subject to a jurisdiction’s laws that conflict with yours. This isn’t far fetched either, a 10 second search will reveal numerous examples, including The US Cloud Act and export control orders.
The question to ask: If your AI provider went down tomorrow, or was acquired, or had a regulatory order placed on it, what happens to your workflows and your clients data, then?
3. Can you actually change your mind later?
This is about architecture, not ethics, but it has real teeth. If every process in your firm is built around one vendor’s specific AI product, with no ability to swap it out, you don’t have a tool. You have a dependency.
Think of it the way you’d think about a trust. Legal title and beneficial ownership aren’t the same thing. A trustee can hold legal title to an asset while the beneficiary, the person who actually benefits from it, has no say in how it’s managed day to day. You already apply this distinction professionally, every time you assess who really controls an asset versus who merely appears to on paper. Apply the same test to your own AI stack: does your firm hold beneficial control of its technology, or just legal title to a subscription? If you can’t switch providers, can’t extract your workflows, and can’t act independently of the vendor’s decisions, you’re the beneficiary of an arrangement someone else is trustee over, not the owner of it.
The question to ask: If you had 30 days’ notice, an outage, a policy change, a jurisdiction ruling, could you switch and run on an alternative, or would you be stuck?
4. Who’s actually accountable when the AI is wrong?
This is the one most talked about or around, and the one most firms probably haven’t answered yet. When an AI system drafts a report or email, flags a risk, or takes an action (submits a filing, sends a communication, updates a record), who is accountable if it’s wrong? “The AI did it” is not an answer a regulator, a client, or your professional body will accept. Someone with a name has to own that output.
But accountability assumes something else first: that you’re auditing a stable thing. Most firms think about AI sovereignty as governing usage – which tool, which model, how outputs are checked. Very few ever ask whether they understand or control what’s actually inside the tool. Vendors update and retrain models on their own schedule, often without notice. The same prompt can produce a materially different answer next quarter. You can have a watertight review process for AI-assisted work and still be auditing a moving target without knowing it, because the thing doing the deciding changed underneath you, without you ever knowing. And this applies whether you built it yourself or not.
The question to ask: For every AI tool touching client work in your firm, do you and the individuals concerned, know that they’re accountable for its output and what steps they’re taking to ensure this? And separately: would you even know if the model itself changed tomorrow?
Drowning in manual, repetitive work? Tell us the task and we’ll show you what to automate.
Why this matters in accounting
Some industries will treat AI governance as a technology risk issue. Accountants really can’t, because a firms’ value is built on licensed, personal accountability. A client doesn’t hire your firm because a model produced a number (the software does that already), they hire you because a qualified person stands behind that number. That’s the whole basis of trust in professional services.
AI platforms know this. The firms and platforms consolidating in this space aren’t trying to remove the licensed professional, they’re trying to retain just enough of them to keep that legal indispensability, while running everything else at machine scale. Sovereignty is what determines whether that consolidation happens to your firm or through your firm, on your terms.
If you don’t know where your data lives, who’s operating your infrastructure, whether you can switch providers, and who’s accountable for AI-assisted output — you don’t actually control your own client relationships anymore. You’re just the name on the door.
Firm Size and the stakes involved
If you’re a smaller firm or business, the temptation is to assume sovereignty is a big-firm problem, you don’t have the budget for elaborate governance. But smaller firms are often more exposed, not less. You’re more agile and can experiment more freely, but with fewer resources to notice a problem, tighter dependency on a single vendor and less capacity to run parallel systems. Sovereignty for an SME isn’t about building elaborate infrastructure, it’s about honestly answering the four questions above to know what you don’t know and how to proceed.
If you’re a larger firm or enterprise, the risk is different and where complexity hides the gaps. You likely have multiple AI tools, deployed by different teams, some of it is even “shadow AI” that nobody formally approved. The governance structures often exist on paper but haven’t been tested against how people are actually using these tools day to day. Scale doesn’t protect you from a sovereignty gap, it just makes the gap harder to see.
Either way, the same four questions apply. Only the effort of answering them changes.
Sovereignty is not the brake pedal
The instinct, once you start asking these questions, is to treat sovereignty as a constraint, and something that slows AI adoption down in the name of caution. That’s the wrong decision though.
A firm that knows where its data lives, understands its infrastructure dependencies, can change providers without rebuilding from scratch, and who’s people know they’re accountable for every AI-assisted decision. And that enables the firm to move faster and freer, not slower or constrained. You can adopt new tools with confidence instead of anxiety, because you already know how to answer the hard question when a client, a regulator, or a board asks it.
Digital sovereignty isn’t about controlling AI out of fear. It’s about being able to answer, plainly and immediately, the one question every stakeholder eventually asks:
Who is actually in control here?
If your firm can answer that today, you’re ahead of most of the market. If you can’t, that’s not a failure, it’s a wake-up call and it’s simply where the work starts.
Know you need to get to grips with this, but not sure where to start? Our Partner Services are built specifically to help firms with AI governance, awareness, learning, and fixing what’s already in place. Check out Partner Services → AI Academy | AI Governance | Fix & Scale
