bg gradient

For years, “sovereign AI” was mostly a conversation about geography: where servers sit, whose cloud hosts the workload, which country’s electricity powers the data center. That conversation hasn’t gone away, but it’s no longer the whole story.

Increasingly, the sovereignty question governments are asking isn’t just “where does this run,” but “who controls what it learns, what it touches, and what it’s allowed to do with it.” That shift matters most in exactly the environments where AI adoption is accelerating fastest: policing, justice, defense, and other public services handling data that can’t simply be handed to a third party and trusted to behave.

Veritone’s recent selection to BlueLight Commercial’s National Open Framework for Digital Forensic Software and Tools, an eight-year framework with a potential value of up to £960 million, giving UK policing a vetted route to procure forensic AI tools, is a useful lens on this shift. It also offers a glimpse at a much larger story about what governments now expect from AI vendors before they’ll let them near sensitive evidence.

Infrastructure sovereignty was the easy part

The UK’s public sector has spent the last several years building the policy scaffolding for sovereign AI. A National Procurement Policy Statement took effect in February 2025 under the Procurement Act 2023, directing contracting authorities to mitigate supply chain and national security risk through defined controls. Cloud buyers across government are increasingly expected to demand that a “sovereign cloud” arrangement mean exactly what it says: data stored and managed entirely within the UK, governed by UK law—GDPR, the Data Protection Act 2018, and the newer Data (Use and Access) Act 2025—regardless of where the vendor is headquartered.

This isn’t a uniquely British phenomenon. Denmark switched on a sovereign AI platform atop its Gefion supercomputer at the end of 2025, explicitly framed around unlocking public-sector value while keeping national data under national control. Momentum toward domestic AI capability—sovereign chips, sovereign models, sovereign cloud—is now a fixture of public-sector technology strategy well beyond the UK.

That’s the infrastructure layer of sovereignty. It’s necessary. It’s also, increasingly, table stakes.

The harder question: sovereignty over data, not just data centers

What’s changing now is the layer above infrastructure. In our view, AI sovereignty includes where a system runs and whether an institution retains meaningful authority over how its data is accessed and used. Recent UK government guidance identifies data quality, governance, interoperability, legal clarity, and legacy systems as material constraints on safe, scalable AI adoption in the public sector. 

For policing, this is a critical distinction. Data location is one consideration, but agencies also need digital-forensics platforms that support evidential integrity, continuity, auditability, and secure operational control. In England and Wales, where a platform is used to perform forensic science activities within scope of the Forensic Science Regulator’s Code of Practice, it should support the forensic unit’s applicable quality-management, validation, accreditation, confidentiality, and reporting requirements. For sensitive material such as body-worn video, CCTV, and data obtained from seized devices, agencies also need appropriate controls over access, processing, retention, disclosure, and any use of that material for model training. 

The BlueLight Commercial Digital Forensic Software and Tools Framework was designed to give policing a route to procure tools that support compliance with the Forensic Science Regulator’s Code of Practice and uphold the integrity and reliability of digital-forensic processes. In Veritone’s view, those objectives also inform a practical approach to sovereign AI: agencies retain governance over evidential data and its use, systems provide explainable outputs and end-to-end auditability, and vendor relationships clearly allocate responsibility for data access, model training, intellectual property, and operational control. 

Why this is a preview, not a one-off

Frameworks like this one are becoming the standard route by which public bodies de-risk AI adoption—a pre-vetted shortlist rather than a one-off procurement, backed by a regulator’s code of practice rather than a vendor’s marketing claims. As more government functions such as tax, social services, immigration, defense face the same pressure to adopt AI without losing control of the data underneath it, the model being built out for UK policing is likely to be a preview of how sovereign AI gets adopted everywhere else in government: not as an infrastructure checkbox, but as an ongoing test of whether a vendor can prove, continuously, that the institution stays in charge.

That’s a higher bar than “hosted in-country.” We think that’s the right approach. 

Learn more about Veritone’s Public Sector offerings. 

 

Sources 

https://www.burges-salmon.com/articles/102lzhr/hot-topics-in-2026-for-uk-public-sector-cloud-contracts

https://securitybrief.co.uk/tag/digital-sovereignty?page=4

https://www.techuk.org/resource/trusted-data-as-the-foundation-of-ai-sovereignty-in-public-services.html

Meet the author.

Author image

Veritone

Veritone (NASDAQ: VERI) builds human-centered AI solutions. Veritone’s software and services empower individuals at many of the world’s largest and most recognizable brands to run more efficiently, accelerate decision making and increase profitability.

Related reading

.
22.09.2026
Police officer standing on the side of the street smiling.

How Veritone AI is Empowering Federal Law Enforcement with Searchable, Actionable Intelligence

.
10.09.2026
Man analyzing files on a laptop. Pop-up box shows results of gap analysis using Veritone Assess.

Modernizing Investigations with AI-Powered Document Analysis

.
10.06.2026
Body camera police footage for redaction

AI and Privacy: Balancing Technology and Compliance in Law Enforcement