By Sebastián García and Sebastián Laborde · Presented at Antel Summit 2026
Can organizations tap into the potential of artificial intelligence without handing over their data and their decisions to a third party? That was the question that opened our talk at Antel Summit 2026, and it’s also the question that structures everything that follows.
The short answer is: yes. But it requires design.
In 2026, technological sovereignty stopped being an abstract topic. This year, data centers became a target in armed conflict for the first time. AI providers can restrict access to their services for geopolitical reasons, and the world of artificial intelligence is increasingly organizing itself around two blocs: the U.S. and China. Uruguayan organizations — many without realizing it — send their data to one of those two blocs every time they use an AI tool.
That doesn’t mean they should stop. It means they need to do it with judgment.
When we talk about AI in organizational contexts, a tension usually comes up that’s actually a false dilemma: depend on external platforms to keep up with technological progress, or isolate yourself to keep control. As if those were the only two options.
They’re not.
AI sovereignty rests on three drivers, not two: security (protecting data, privacy, and resilience), productivity (innovating, being efficient and competitive), and values (rights, ethics, and autonomy — deciding by your own criteria). The false dilemma pitted security against productivity. Sovereignty pursues both, and anchors them in values.
And it’s not isolation. It doesn’t mean running everything on-premise, rejecting commercial models, or building from scratch. It means controlling which data goes where, being able to switch providers without rebuilding everything, being accountable for every automated decision, and keeping the service running even if a third party fails.
In a phrase that sums up the talk’s central thesis: sovereignty is designed, not bought.
That design rests on four pillars.
One of the most common mistakes is treating AI as if there were «one model.» There’s no such thing. What exists is a portfolio of options, and sovereignty starts with knowing which one to use for each case.
There are four relevant families:
A large share of organizational work doesn’t need the biggest available model. Summaries, drafting, internal document analysis, data extraction: all of that can be handled by local models, which are cheaper and keep data inside the perimeter.
The key is that this decision shouldn’t be left to each developer on a case-by-case basis. It should be an operating policy: a model gateway that routes each request based on data sensitivity, task complexity, and cost. Sensitive data runs locally. Routine tasks go to a lightweight model. Complex reasoning escalates to a frontier model. High-risk cases go through human review.
«The pilot proves value. The architecture proves scale.»
The second common mistake is connecting AI directly to systems — what we call «glued-on AI» — with no intermediate layer. The result is loss of control, scaling problems, and concrete risks: in the extreme case, an agent that deletes production data because no one defined what it could and couldn’t do.
The alternative is a layered architecture: input channels, intent classification and sensitive-data detection, an orchestration layer, a model gateway, and a data-and-tools layer built on a governed catalog. Running across that whole stack: identity, security, governance, and observability.
One concept worth underscoring here: it’s not enough to feed a model documents for it to work well. It needs structured context — entities, the relationships between them, business rules. An ontology that turns internal data into governable context for AI: less ambiguity, better answers, and more traceability.
The single most critical control point in the entire architecture is sensitive-data detection before anything reaches the cloud. That early filter is what makes everything else governable.
Sovereignty doesn’t mean building everything from scratch — that would be autarky, and autarky impoverishes. It means knowing what to build and what to adopt.
What’s worth building is what provides control and differentiation: business-specific tools, integrations with your own systems, agent orchestration with the organization’s own logic. What’s worth adopting is components that are already solved and mature, like a commercial model gateway.
And the insurance against lock-in is open standards: MCP (Model Context Protocol) for exchanging tools between agents, and OpenAI-compatible APIs for switching model providers without rebuilding the architecture. If a provider changes its terms tomorrow, an architecture built on standards can migrate. One that doesn’t use them, can’t.
Governance isn’t bureaucracy. It’s the ability to answer three simple questions: which model was used, what data went out, and why was it decided that way. If those can’t be answered, there’s no real control — just dependency with a good face on it.
That means clear usage policies (who can use which model, with what data, and for what purpose), personal information detection before processing, model contracts that define latency and cost guarantees, auditing of every routing decision, and traceability for compliance.
One of the most concrete risks we flagged in the talk: teams building their own AI solutions with personal accounts, uploading confidential data without anyone in the organization knowing, creating invisible exposure. Governance starts by taking inventory of what’s already happening today.
Sovereignty isn’t built all at once. The practical path has five steps: inventory the use cases with the highest potential value, classify which data can leave and which must stay, define the split between what runs locally and what goes to the cloud, set up a gateway with basic traceability, and measure to improve with evidence.
The minimum first component of sovereignty is the model gateway. Not the most expensive or the most visible piece, but the one that establishes the control point from which everything else can be governed. Switching from one architecture to another later is harder than it looks: it’s worth designing it well from the start.
The conclusion we brought to Antel Summit is also the simplest one: AI sovereignty isn’t a destination or a product you buy. It’s the result of design decisions — about architecture, governance, standards, and in-house capabilities. Decisions you can start making today, with what already exists, without waiting to have everything figured out.
Want to dig deeper into any of these topics, or explore how this applies to your organization? Get in touch.
With a 360° potential, our solutions matrix accompanies the lifecycle of any project, with skills and experience in Development, Design, Q&A, Devops, Operation & Deploy, and Architecture
We are here to help you!
You can leave us your query or recommendation through this form.
I accept the terms & conditions and I understand that my data will be hold securely in accordance with the privacy policy.