• Visibility Deficit: According to global research from the IBM Institute for Business Value (IBV), a striking 91% of executives do not fully understand their AI dependencies across vendors, models, and underlying infrastructure.
  • Vendor Lock-In Risk: 71% of business leaders acknowledge it would be difficult to switch AI providers or models if forced to do so today, leaving enterprises exposed to operational and regulatory shocks.
  • The Control Dividend: Embracing “selective sovereignty”, maintaining agile control over critical data, models, and infrastructure rather than trying to own the full stack, enables firms to protect 55% more operating profit from AI-driven disruptions compared to their peers.

For years, the default corporate baseline for technology sovereignty was simple: if you want sovereignty, you must own the infrastructure, own the models, and own the full stack. However, as artificial intelligence transitions from standalone pilot programs into hyper-connected agentic networks running core operations, the “own-everything” model has hit a wall of practical reality. Total ownership across rapidly shifting compute layers and foundation models is economically unviable and technically rigid.

New research published by the IBM Institute for Business Value (IBV), titled The Calculus of AI Sovereignty, highlights a dangerous structural shift in corporate tech stacks: a widening dependency gap. Companies are accelerating AI integration across business units without clear visibility into vendor ties, creating silent technical debt that compromises their operational agility.

Operational MetricCurrent Enterprise RealityImpact of Advanced AI Control
Dependency Understanding9% have complete clarity on their AI stackFull visibility across vendors, data, and infrastructure
Model/Vendor Switching71% find switching primary AI models difficultHigh portability and multi-provider optionality
Cross-Border Compliance68% struggle with regional data residency rulesStandardised governance across jurisdictions
Profitability ProtectionBaseline exposure to vendor outages and price shocks55% higher protection of operating profit from disruption

What it means for Malaysia

For Malaysia’s corporate ecosystem and policymakers, particularly agencies driving national digital transformation initiatives like MOSTI, MRANTI, and MDEC, IBM’s findings provide a strategic blueprint for tech adoption.

  1. Alignment with National AI Governance: Malaysia’s push toward establishing a robust National AI Framework relies heavily on local data sovereignty and security. Local enterprises that adopt a “selective sovereignty” stance can meet Bank Negara Malaysia (BNM) and regulatory data residency requirements without burdening themselves with the massive capital expenditure of building custom, end-to-end proprietary LLMs.
  2. Mitigating Vendor Concentration for GLCs: With major Malaysian public sector entities and Government-Linked Companies (GLCs) rapidly embedding third-party AI tools into internal operations, unmapped dependencies present a systemic risk. Focusing on governance and model portability ensures local institutions retain strategic freedom even if global cloud or SaaS providers shift pricing models or terms of service.

What it means for ASEAN

Across the wider regional economy, ASEAN is rapidly emerging as a multi-cloud, cross-border digital hub. However, disparate regulatory environments across member states create significant compliance friction.

  1. Navigating Digital Border Fragmentation: ASEAN businesses expanding across borders frequently clash with varying regional data residency, privacy, and sovereignty laws. A selective AI sovereignty framework allows regional conglomerates and high-growth scale-ups to maintain unified corporate logic while easily swapping underlying infrastructure to align with local jurisdictional laws.
  2. Supply Chain and Trade Resilience: As ASEAN positions itself as a critical node in global semiconductor and tech supply chains, operational continuity is paramount. IBM’s research indicates that companies with advanced control capabilities suffer fewer AI-related operational downtimes, shielding regional trade flows from vendor-induced outages.

Editor’s Take

The true currency of digital leadership is no longer asset ownership; it is strategic optionality. Trying to own every layer of the AI stack is a defensive, capital-intensive trap that slows innovation. True AI sovereignty isn’t about isolationism but maintaining the architectural flexibility to govern your critical data assets, swap out models when better alternatives emerge, and pivot without causing business-wide friction. For enterprise leaders across Malaysia and ASEAN, the immediate priority must shift from blind AI adoption to building dependency visibility.