UK's Push for AI Sovereignty Starts with Knowing What It Owns
A former UK AI minister's move to regional government reveals why AI sovereignty matters for every leader - and how to map what your organisation truly owns.
Kanishka Narayan spent months as the UK's minister for artificial intelligence, warning that Britain's economic and security future runs through digital sovereignty. Now he has left central government and joined Andy Burnham's cabinet, working across the Cabinet Office and the business department, with a brief to push AI sovereignty and what Burnham calls "re-industrialising Britain". The interesting part is not the job title. It is that a former national AI minister has decided the real work happens closer to the ground, in the postcodes rather than in Whitehall.
That should make any leader pause, because it mirrors a decision most organisations are quietly getting wrong. We treat AI as a headquarters problem. A strategy deck, a central team, a big vendor contract. Narayan's move points the other way, towards moving power and economic focus away from the capital and into places with "industry and ambition at its heart". Translate that into a business and it reads: the value of AI shows up where the actual work is done, not where the strategy is written.
There is a harder lesson buried in the same story, and it is about who controls the ground you are standing on. Sovereignty sounds like a geopolitics word, something for governments. It is not. It is a question every leader should be asking about their own data. The report flagged the US Cloud Act, a law that lets US authorities request data held anywhere in the world by providers under US jurisdiction, with no requirement to tell the customer. When asked what assessment the government had made of that risk, the minister confirmed the department had made no central assessment of the Cloud Act's implications for UK government data. Read that as a leadership signal, not a partisan one. If the people responsible for national data have not mapped where their dependencies live, what are the odds your organisation has?
This is where I want to gently challenge the reflex I see in boardrooms. Most leaders think the thing blocking them is that they are behind on tooling. They are not. The block is that they have never made a clear, honest map of what they depend on, who owns it, and what happens if that owner changes the rules. You do not need to be a technologist to do that. You need to ask uncomfortable questions and refuse vague answers.
And the fear that "we have missed the boat" is largely misplaced. The Royal Academy of Engineering's president John Lazar noted that over half of UK engineering and technology firms have not yet adopted these potentially beneficial technologies. If more than half the field has not moved, the race is not lost. The advantage goes to whoever adopts with clarity of intent, not whoever bought the most licences first.
Here is the pattern I keep seeing in the work I do with leaders. The organisations that get measurable value from AI are not the ones with the biggest budgets. They are the ones who did the boring groundwork: they worked out what to eliminate before they automated anything, they knew where their data lived, and they built the confidence of the people using the tools. In one six-month programme for non-technical professionals, the outcomes that stuck were not "we bought a clever tool". They were an 86% daily use rate, two to four hours saved per person each week, and a jump in people's confidence to choose the right tool for the job. That confidence is the sovereignty that matters inside a business. It means your judgement, not a vendor's roadmap, decides what you do next.
Narayan put it plainly when he said AI could deliver a re-industrialised Britain and stronger security, while the risks to jobs and the pace of change are real and worth worrying about. Both things are true at once. That is the honest position, and it is the one leaders should model.
One thing to try this week: sit down and list every critical system your organisation runs on, and next to each one write who legally controls it and what happens if that relationship sours. If you cannot fill in a row, you have found your first priority. Sovereignty starts with knowing what you actually own.
Frequently Asked Questions
What does AI sovereignty actually mean for a business, not just a government?
AI sovereignty for a business means keeping meaningful control over your data, your systems, and the decisions AI makes on your behalf, rather than handing that control to a vendor or a foreign legal jurisdiction. In practice it is knowing where your data physically lives, who can legally access it, and whether you could switch providers without your operations collapsing.
Why did a former UK AI minister leave central government for a mayoral cabinet?
Kanishka Narayan left his role as national AI minister to join Andy Burnham's cabinet, working on AI sovereignty and re-industrialisation with a focus on moving economic power away from the capital. His move reflects a belief that AI's practical value is realised regionally, in places with existing industry, rather than solely through central government strategy.
What is the US Cloud Act and why should UK leaders care?
The US Cloud Act is a law that allows US authorities to request data held anywhere in the world by providers under US jurisdiction, with no legal requirement to inform the customer. UK leaders should care because much of their cloud and IT infrastructure runs on US-owned services, creating a dependency they may never have assessed or planned around.
Is it too late for my organisation to adopt AI usefully?
No, it is not too late. According to the Royal Academy of Engineering, over half of UK engineering and technology firms have not yet adopted these technologies, so the field is far from settled. The advantage now goes to organisations that adopt with clear intent and solid groundwork, not to whoever bought tools first.
What is the first practical step to take before rolling out AI?
Map every critical system your organisation depends on and, beside each one, record who legally controls it and what happens if that relationship changes. This exposes hidden dependencies and risks before you automate anything. Doing this groundwork first is what separates organisations that get measurable value from AI from those that simply buy tools and hope.

