For years, the cloud conversation was mostly about speed, scale, and cost.
Now, for many companies it’s about something else too: control.
And not just in the abstract, “we take security seriously” way. I mean the very practical questions customers are asking when they move core ERP to the cloud:
- Where does our data actually live?
- Who can access it?
- Under whose laws and jurisdiction does it fall?
- Who operates the environment?
- And what happens when our regulatory, national or economic requirements go beyond standard cloud assurances?
Today, these are board-level questions—especially for organizations in the public sector, defense, critical infrastructure, and regulated industries. And if you’re running your business on ERP, they matter even more.
Why “cloud” and “control” are no longer opposites
A few years ago, many organizations still saw sovereignty and cloud as trade-offs. You could modernize and innovate, or you could stay in control. That assumption doesn’t hold up anymore.
The reality is that many organizations need both. They want the agility, resilience, and innovation that come with modern cloud ERP, but they also need to satisfy strict requirements around data residency, legal jurisdiction, operational control, and technical separation.
And increasingly, they need to satisfy requirements that go beyond IT policy. Several countries have introduced or are actively preparing economic security legislation that directly affects where critical systems can be hosted, who can operate them, and what dependencies are acceptable. For organizations running ERP on infrastructure that touches national supply chains, defence, or critical services, this is no longer a compliance footnote. It is a strategic constraint.
This is where the conversation often starts to blur—because in the market today, many offerings are described as “sovereign,” but not all of them mean the same thing.
The real problem: sovereignty is often oversimplified
One of the biggest issues in this space is that digital sovereignty is often reduced to data location. If the data sits in-country, the assumption is: problem solved.
But that’s not how most organizations, security leaders and regulators look at it anymore. Because sovereignty is broader than geography. It includes questions like:
- Is the environment operated locally?
- Are access and administration tightly controlled?
- Is there separation at the technical and operational level?
- Is there exposure to foreign ownership, foreign legal reach, or external dependencies?
- Can the organization meet industry or national security-grade requirements—not just generic compliance checkboxes?
That’s why more companies are looking beyond the terminology and starting to ask questions about the actual control model. And they should.
The market is full of broad ‘sovereign’ claims. The key is matching the control model to your requirements—data-only, data+operational, or full sovereignty—and verifying it stands up to scrutiny.
What customers actually need from a sovereign cloud ERP
When customers talk about sovereignty, they’re usually not asking for one thing. They’re trying to solve for a set of very real business and risk requirements. In my experience, these usually fall into a few capabilities:
1. Data sovereignty
This is the most visible one. Customers need confidence that data is stored, processed, and governed in line with local or regional requirements. That includes not only data residency, but also clarity around data flows, access, and regulatory alignment. For many enterprises, this level, when coupled with strong operational controls, is sufficient.
2. Operational sovereignty
This is where things become practical: who operates, who administers, and how it’s audited. Often the decisive factor for regulated workloads. Are administration and maintenance handled only by approved personnel—such as local nationals or individuals from trusted countries—with the required security clearances? For some organizations, especially in sensitive sectors, these are often not optional design preferences. They are mandatory operating conditions.
3. Technical sovereignty
This is about the architecture itself. Customers need to understand how environments are isolated, how the control plane is managed, and how tenant separation works. For customers with elevated requirements, technical sovereignty includes an independent, locally managed control plane with no operational dependencies outside the country. Many others meet obligations with data and operational sovereignty without requiring a fully independent control plane. This is not a subtle distinction. It is the difference between an environment that is locally operated in name, and one that is structurally independent in practice.
This dimension is also where AI enters the picture — and where the stakes are rising fast. As organizations begin to run AI-powered capabilities on their ERP — automating processes, surfacing insights, driving decisions — the sovereignty question extends naturally to those workloads. A fully sovereign environment needs to ensure that AI models, data, and inference remain within the same controlled boundary as the rest of the system. For regulated industries in particular, sovereign AI is not an add-on. It is part of the architecture from the start.
4. Legal sovereignty
This dimension addresses the question of who ultimately has legal influence over the environment. Are service providers based locally or in approved countries? Are there extraterritorial legal implications? Could foreign jurisdictions exert influence or control over systems or data? This is no longer just a concern for public institutions — it is increasingly relevant for enterprises in regulated sectors, critical infrastructure, and geopolitically sensitive environments.
Why this matters specifically for ERP
This conversation is important for collaboration tools or peripheral workloads, but it becomes even more serious when we’re talking about ERP.
ERP holds and orchestrates some of the most sensitive and operationally critical processes in the enterprise:
- Financial records
- Procurement and supplier relationships
- Production and manufacturing flows
- Workforce and payroll dependencies
- Inventory and logistics operations
- Compliance and reporting data
That means the sovereignty discussion can’t sit outside the ERP conversation for regulated industries and the public sector. It has to be built into it. Because once ERP is in the cloud, the question isn’t just whether the system works. It’s whether it works within the boundaries your business, regulators, and risk teams actually require.
The Autonomous Enterprise and the sovereignty imperative
The Autonomous Enterprise is SAP's model for AI agents embedded across finance, procurement, supply chain, HR, and other core processes, moving ERP beyond systems of record into systems of execution. They are agents embedded directly into business processes, capable of running workflows end to end.
For organizations in regulated or sensitive environments, this raises a number of questions: where do those AI workloads actually run? Under whose jurisdiction does inference happen? Who has access to the prompts, the outputs, and the data that feeds them?
SAP is investing in AI capabilities that operate within the same sovereign boundaries as its cloud environments—with the ambition to deliver full sovereignty across AI offerings, powered by locally deployed large language models, governed by local rules:
- EU AI Cloud and sovereign AI partnerships: Applied AI with sovereign capabilities through the EU AI Cloud, in partnership with Cohere and Mistral AI.
- Industrial AI Cloud: Advanced AI models on SAP's secure cloud platform with NVIDIA GPU acceleration, deployed in T-Systems' data center.
- Sovereign OpenAI for Germany: AI solutions built in Germany, in partnership with OpenAI.
This is what sovereign AI means in practice: the same autonomous capabilities, aligned to your required sovereignty level, from data and operational‑sovereign AI to fully sovereign AI, running within boundaries your organization controls.
What SAP Sovereign Cloud does
SAP Sovereign Cloud addresses this directly by focusing on how cloud environments can be operated with greater levels of control across data, operations, infrastructure, and compliance—aligned with local laws and regulatory expectations.
This is not treated as a one-dimensional problem. The same dimensions that typically emerge as requirements—data, operational, technical, and legal sovereignty—are reflected here as capabilities. That distinction matters because it follows how organizations actually work—from defining risk to operationalizing control.
For those moving ERP to the cloud as part of the RISE with SAP journey, this becomes particularly relevant when sovereignty requirements extend beyond what standard cloud models are designed to support. SAP has explicitly linked the Autonomous Enterprise vision to RISE with SAP as the vehicle through which customers put AI innovation to productive use—making clear that the transformation journey and AI value creation are designed to go hand in hand.
As AI becomes part of how ERP runs—automating decisions, surfacing insights, driving processes—SAP extends this commitment to include sovereign AI capabilities, ensuring control doesn't stop at the data and infrastructure layer but extends across the full stack.
This is further reinforced through partnerships with European AI providers such as Mistral AI, giving customers in regulated environments greater control over where AI workloads run and how model access is governed.
Moving ERP to the cloud without losing the sovereignty your business still needs
Organizations want to modernize — with faster innovation, stronger resilience, more automation, and better ways to run the business. But they want to do it on a foundation they can defend: to regulators, boards, security teams, and increasingly, to countries and customers too.
That’s why sovereign cloud is becoming a much more important part of the ERP conversation. And for organizations navigating modernization in regulated or sensitive environments, the real objective is not simply to move ERP to the cloud. It is to modernize without giving up the control the business still needs.
That’s where RISE with SAP and SAP Sovereign Cloud come together—not as a trade‑off between innovation and control, but as a progression. Choosing the minimum sovereignty level that satisfies your obligations, with a path to full sovereignty when required: move to the cloud, activate AI at scale, and do both without compromising the sovereignty your business still needs.
Explore what digital sovereignty really means for your organization and how SAP helps you calibrate control, whether data-only, data+operational, or full sovereignty—while maintaining compliance and innovation.
Digital Sovereignty Across All Four Pillars
Explore how SAP Sovereign Cloud helps you maintain control, compliance, and innovation without compromise.