Terry Gerton As countries race to adopt artificial intelligence, the challenge is building capability they actually control without falling behind or over relying on outside providers. You saw some of that in the Anthropic and Fable 5 conversation over the weekend. Alan Weber, Program Vice President for National Security, Defense and Intelligence at IDC, tells us what it takes to get that right. Mr. Weber, thank you so much for joining me today.

Alan Webber Thank you for having me. I appreciate it.

Terry Gerton We have been talking a lot about AI in terms of pilots and experimentation, but this new research suggests that something is changing. Where do you see governments now on the AI development and deployment curve?

Alan Webber Wow, they’re really finally beginning now. Let me start with the fact that it’s highly dependent upon levels of government, maturity of the government organization, civilian versus defense, things like that. So overall, if I had to say generally, it’s really towards the fact that it is moving from pilot to actual implementation in certain places. I would still call it spotty, is how I might refer to it. I wouldn’t say it’s broad. I think there’s still a lot of experimentation going on. There’s still a lot of issues with data that we’re dealing with, what the actual models produce, things like that within government, how we actually tune what it is we’re using model-wise and data-wise to the actual needs of government. So I think we’re at a great starting point generally, but we still have a long ways to go. We still have maturity around policies that need to be put in place. We still have significant cybersecurity issues that need to be addressed. We still have to address exactly what and how we actually audit and check what’s coming from an AI. So it’s, like I said, we’re really at the beginning, but given the unique aspects and constraints of government, we still a lot of work to do.

Terry Gerton And this report tosses a specific term into that AI soup that you just described. And it talks about sovereign AI. Define that term for us and tell us how it would play out.

Alan Webber So sovereign AI, as we use it here at IDC, just at a high level, is really around where the model and where the data actually come from and where they actually get used. So for example, right now, if you’re using Claude, if you’re using ChatGPT, things like that. Those are pretty much what I might refer to as global models. They’re pulling data from all over the world. Primarily U.S., European, places like that, but they’re actually pulling data from all over the world. The models are built primarily in the U.S., so there’s a bias that comes with this. That’s the United States bias. And, you know, if you’re over in Europe and you’re trying to use, say, ChatGPT, all your data and everything, all the commands are flowing back and forth to the United states. Sovereignty, by definition, says everything’s constrained within, generally, a politically defined geographical area, whether that’s actually digitally or actually physically. So sovereign AI would have a model that’s developed, say some of the stuff we’re seeing out of China right now, I would almost call sovereign AI. They’re developing the models there, they’re developing data sets there, they’re deploying them there. We’re seeing the same thing begin to come up in Europe with some of work that, for example, Leonardo’s doing over in Italy, some of the places there. Now there are US companies, primarily on the hyperscalers, who are actually trying to deploy and actually create sovereign boundaries within places, such as over in Europe. But sovereign AI is really those factors that say, okay, this is ours, it’s created by us, it’s controlled by us. The output that we get is unique to us.

Terry Gerton So it sounds like you’re not talking about something that is necessarily suited for commercial market, but specifically for government decision-making using government data.

Alan Webber You might see sovereign AI used in healthcare, in financial services, what I would call the highly regulated industries, but it is primarily government, but there are places, there are commercial applications out there.

Terry Gerton And is it designed by people who are government employees or is it defined in partnership with the commercial developers?

Alan Webber It’s very much commercial. So if you remember the old term, COTS, custom COTS and GOTS, okay, a lot of this is actually either custom COTS or specifically designed for government depending upon the application. So for example, Myspace, you will see it in national security in the IC where it’s actually designed specifically for that application by government employees and things like that. Not a whole lot of that yet, but there’s more and more of that every day. In most cases, though, it’s either customized specifically for government or we’re buying commercial. And what actually changes that is the deployment model and the data source model.

]]>

Terry Gerton I’m speaking with Alan Weber. He’s the program vice president for national security, defense, and intelligence at IDC. Alan, let’s go further down with this. We talked about government data, sovereign data. What does that look like?

Alan Webber Well, that’s government. That’s generally data that’s held by the government that is not, for whatever regulatory reason or lawful reason, is not exported outside certain boundaries. So, for example, you know, here in the United States, we have PII and CUI types of information, and we might not want those to go overseas. So we’d want to keep those sovereign to the United states. Again, you see more of this within Europe right now. But it’s, you know, Europeans don’t want their data coming over to the United States, then Answers coming back. So they try to keep all the data protected. And it’s one of the things a lot of people go to is, oh you must mean like an air-gapped environment or something like that. No, that’s really not what we’re talking about. It is, there are both physical and digital walls that essentially get built that keep the data within that specific area. It’s a broad range of data. It can be economic data, it can be personal data, it can health data, all kinds of different data.

Terry Gerton You mentioned the highly regulated areas, financial services, healthcare services. Are those predominantly the places where you are seeing government organizations deploy sovereign AI or are there other uses?

Alan Webber It’s highly deployed in the national security, defense, and intelligence space globally. It is deployed in a number of social services areas that would cover such as health care, financial services to citizens, things like that. So if you think through some of the social programs and stuff that actually require the transfer of funds, that’s a place where you would that just to protect the data of the citizen.

Terry Gerton And what are the biggest challenges that governments are facing as they’re considering development and deployment of these sovereign AI tools? Is it money? Is it regulatory capacity?

Alan Webber No, honestly, the biggest problem number one is data. They don’t know what data they have. They don’t know the quality of that data. They haven’t actually gone through and said, okay, how well does this align with what it is we need an AI to actually do? For example, within any department in the U.S. federal government, you have reams and reams of data. And it’s all great if an AI goes through that, but then how do you block out what you don’t want it to use and how do you make sure that what it’s using is actually right and up to date? You know, back to something like the U.S. Department of the Interior who has records around land use and things like that, going back to 1876. You know, the amount of data that is and actually getting those all within the AI might not seem that critical until you start to talk about mineral rights, water rights, things like that where you actually need to know the whole history there. How do you get the right information? So data is the number one. Two is the whole regulatory regime we have around it. What’s the proper use? How can we use that? Who gets to use it? Not everybody should have access to everything that’s within a sovereign AI. Even within government, there has to be levels of access to that. Third is how do we actually give people the skills? This new technology is moving so fast. You know, when you talk about getting on, for example, say, ChatGPT and you need to run a query through ChatGPT and what does that actually look like, that’s all great and good because it’s really simple, similar to like a Google search. But when you say, okay, I need to build a skill in there that’s going to allow me to do this on a regular basis, that’s a whole different level. And honestly, most people in the world, most people on government have not been trained around those. So those are the three big things. The fourth one I’m going to put out there is we really do not have the cyber security regime set up to be able to deal with this yet. We’re literally building the airplane as we’re flying when it comes to this stuff.

Terry Gerton The president has just signed out a new executive order related to AI. How close would you say we are to at least setting up the framework to tackle this challenge?

Alan Webber I think the whole cybersecurity clearinghouse that’s tasked out, I believe it’s to the Treasury Secretary to review vulnerabilities and stuff around the advanced AI models and stuff, I think is actually the beginning of this. I think you see some of the things that are coming out of NIST and other places are the beginning to this. I think these are the cornerstones for what we’ll build out, but it’s still just the basic foundation that we’ve got. And the fact of the matter is that these tools are moving so fast, do we really have the ability to actually maintain and keep up with where this stuff is at?

Terry Gerton What if the answer to your last question is no?

]]>

Alan Webber I don’t think it can be no, because then the response to that immediately becomes, but we have no choice. I mean, let’s just be honest, if you’ve read the Wall Street Journal yesterday, there was an article in there talking about how the CEOs of the major AI companies are actually asking for constraints around the use of AI around biotechnology and the vulnerabilities that that brings out. You hardly ever see a tech CEO asking for constraints. These guys are because they understand that now you can buy a gene editing system for about $1,500 that you can set up in your garage to actually create all kinds of, you know, biological mayhem for lack of a better term. So it’s not, we can’t answer no, we have to figure out a way and it has to be a priority.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.