Data sovereignty

From pilot to production: in July 2026, enterprise AI money moved to two places — the bridge to production and the data border

Last updated: 29 Jul 2026

Three people in business suits meeting around a white table in a bright office, one typing on a laptop, with notebooks and a phone on the table — illustrating an enterprise AI investment decision

Across four weeks in July 2026, three press releases from three different companies told one story. On 2 July, Cognizant partnered with Domyn to run large language models inside customer infrastructure. On 23 July, Atos launched a cloud platform designed and engineered in the EU. On 28 July, Cognizant stood up a dedicated AI unit for EMEA, with a subheading that named the problem outright: helping clients build the bridge from AI pilots to scalable outcomes. Three announcements, two themes: how to get AI out of the lab, and how to keep data inside a border. This piece unpacks each release in its own words, and reads them back for businesses in Vietnam, where the Personal Data Protection Law has just entered its first year in force. Figures checked on 29 July 2026.

TL;DR

  • What happened: three July 2026 releases — Cognizant × Domyn (2 Jul, sovereign AI on-premise), Atos Sovereign Cloud (23 Jul), Cognizant EMEA AI Unit (28 Jul, bridging pilot to production).
  • The bottleneck, named: not weak models, but the distance between experiment and daily operation. Cognizant calls it "the gap between experimentation and scaled business impact".
  • The number to remember: a Gartner forecast cited in the Cognizant release — by 2029, geopolitics will drive 50% of cloud AI workloads to sovereign deployment models, up from 5% in 2025.
  • The new product shape: LLMs delivered to run inside customer environments — "on-premise or in private cloud configurations" — then distilled into smaller domain-specific models (SLMs).
  • For businesses in Vietnam: same problem, different scale. Personal Data Protection Law No. 91/2025/QH15 has been in force since 1 January 2026.
Key facts (every line sourced at the end of this article)
  • 50% by 2029 — share of cloud AI workloads moving to sovereign deployment models, up from 5% in 2025 (Gartner, cited in the Cognizant release of 2 Jul 2026).
  • Over 50% of multinationals will have digital sovereign strategies by 2029, up from less than 10% today (Gartner, cited in the Atos release of 23 Jul 2026).
  • 3 service models — Foundation · Accelerate · Transform, the structure of the Frontier Deployed Engineering offering (Cognizant, 28 Jul 2026).
  • From months to days — the development-cycle compression Cognizant describes at a European online fashion retailer (28 Jul 2026).
  • 1 January 2026 — the date Personal Data Protection Law No. 91/2025/QH15 took effect in Vietnam (Ministry of Public Security).

What actually happened in July 2026

Three July 2026 releases show that large vendors have stopped selling "AI capability" and started selling two more concrete things: a service that carries a pilot into real operation, and infrastructure that runs models within a perimeter the customer controls. This is the shift from demo to construction work.

It opened on 2 July, when Cognizant and Domyn announced a strategic partnership. The line directly under the headline of Cognizant's release says the partnership enables "regulated organisations to deploy AI securely on-premise and within sovereign environments". The body is more specific about the division of labour: Domyn supplies the infrastructure layer, delivering "LLMs that can be deployed within client environments, on-premise or in private cloud configurations"; Cognizant is the application and integration layer, adapting Domyn's models into smaller, domain-specific models (SLMs) and building agents for particular use cases.

Three weeks later, on 23 July, Atos followed. The release from Paris introduces Atos Sovereign Cloud as "a next-generation application orchestration and modernization platform designed for governments, defense organizations, healthcare providers, critical infrastructure operators and other highly regulated organizations". The detail worth pausing on is not the adjectives but the terms: customers use "a platform entirely hosted, operated and contracted within the EU". "Contracted" is the expensive word in that sentence — data sovereignty usually breaks at the legal layer well before it breaks at the technical one.

Then on 28 July — a day before this article — Cognizant announced its EMEA AI Unit in London. The subheading of the 28 July release reads: "Unit will provide fit-for-purpose teams that can help clients build the bridge from AI pilots to scalable outcomes". When a global services firm builds an entire organisation just to construct that bridge, the bridge itself has become scarce enough to sell.

Table 1 — Three press releases, July 2026 (compiled from the original Cognizant and Atos releases; the "Verbatim" column is quoted directly)
DateAnnounced bySubstanceVerbatim
2 Jul 2026Cognizant × DomynPartnership to run LLMs and agents inside customer environments, aimed at regulated sectors in EMEA"deploy AI securely on-premise and within sovereign environments"
23 Jul 2026AtosLaunch of Atos Sovereign Cloud — an application modernization platform for government, defence, healthcare and critical infrastructure"a platform entirely hosted, operated and contracted within the EU"
28 Jul 2026CognizantEMEA AI Unit launched in London, with a three-tier Frontier Deployed Engineering offering"build the bridge from AI pilots to scalable outcomes"

Note: none of the three releases published pricing, contract values or customer counts. We do not speculate on those figures.

Close-up of blade servers seated in a rack chassis with green status lights, tinted teal
What the three releases share: models delivered onto hardware the organisation controls, rather than reached only through an API. Photo: Pexels (Pexels License).

The bridge from pilot to production — and why it sells

The bridge sells because most of the cost of an AI project is not in making the model work once, but in making it work every day, on the right data, for the right people, with someone accountable when it is wrong. That is exactly the part a demo never touches.

Cognizant packages this as Frontier Deployed Engineering, described as "a delivery model designed to help clients close the gap between experimentation and scaled business impact". Manoj Mehta, President EMEA at Cognizant, is quoted in the release: "Across EMEA, many organizations are enthusiastic about AI but are still working out how to turn that momentum into real business value."

The three-tier structure repays a close reading, because it is a fairly candid description of what organisations are actually missing at each stage.

Table 2 — The three Frontier Deployed Engineering service models (quoted verbatim from the Cognizant release of 28 Jul 2026; the right-hand column is Namtech's reading)
TierVerbatimThe bottleneck it addresses
Foundation"helps organizations establish the strategy, governance, technology choices and early prototypes needed to begin their agentic AI journey"No strategy, governance or technology decision — every effort stays half-finished
Accelerate"focuses on rapidly identifying, building and deploying high-value use cases into production"Prototypes exist but never ship
Transform"supports broader reinvention through multi-agent delivery squads that help redesign and automate workflows end to end"Shipped, but the surrounding process never changed, so value does not compound

The release gives two client examples, and both sit in the middle tier. Cognizant says it is helping "one of Europe's leading online fashion retailers move proven AI use cases into production through an AI factory model that can compress development cycles from months to days". Note the phrase "proven use cases": the problem is not a shortage of ideas, it is that known-good ideas do not ship. The second example is a global pharmaceutical company using multi-agent systems across drug discovery, clinical trial design and regulatory preparation.

For a small or mid-sized company, the lesson is not "hire a global consultancy". The lesson is sequence: settle process and access control first, run the model second. We have described that layering in departmental access control for internal AI and the architecture diagram of an internal AI system — same logic, different budget.

The data border: from 5% to 50% in four years

Data sovereignty has stopped being a policy topic and become an architecture parameter: two independent releases in the same month both cite Gartner forecasts that most AI workloads and most multinationals will operate under sovereign models by 2029.

The first figure sits in the Cognizant × Domyn release: "By 2029, geopolitics will drive 50% of cloud AI workloads to sovereign cloud AI deployment models, up from 5% in 2025." The release names its source in a footnote: the Gartner report "AI Vendor Race: True Sovereign AI Will Define Winners and Losers in the Cloud AI Race" by Rene Buest and Fernando Pereiro, dated 24 February 2026. The same release also quotes Gartner's view that "Geopolitics is the key driver behind the demand for true sovereign AI solutions and services".

The second figure sits in the Atos release: "Gartner predicts over 50% of multinational organizations will have digital sovereign strategies by 2029, up from less than 10% today." The two numbers measure different things — workloads versus organisations — but point the same way and land on the same year.

Table 3 — Two Gartner forecasts on digital sovereignty, cited in two different July 2026 releases
MetricToday2029 forecastCited in
Cloud AI workloads on sovereign deployment models5% (2025)50%Cognizant × Domyn release, 2 Jul 2026 (original source: Gartner, 24 Feb 2026)
Multinational organisations with digital sovereign strategiesunder 10%over 50%Atos release, 23 Jul 2026 (marked "Source: Gartner")

Note: these are forecasts, not measurements; and we quote them as they appear in two corporate press releases — we could not access the underlying Gartner reports, so the citation trail is stated explicitly for you to check.

The trend is not confined to the EU. On 9 June 2026, Civo and Era4 announced at London Tech Week a "UK-sovereign, full-stack AI partnership", with the entire stack "strictly hosted on UK-governed land, with UK-based control planes". Mark Boost, CEO of Civo, framed the trade-off in a line worth keeping: "Sovereignty without developer accessibility is a bottleneck, and accessibility without green power is unsustainable." That is a warning for every on-premise project: safe but unusable ends up unused.

A technician standing and typing at a monitor on a white desk inside a blue-lit server room, with network cabinets and cable bundles behind
Sovereignty only means something if someone can operate it day to day — the cost line most often left out of the on-premise calculation. Photo: Pexels (Pexels License).

The easy misreading: the bottleneck is not model quality

None of the three releases says the models are not good enough — all three talk about deployment, governance, contracts and process. That detail is easy to miss, because most AI headlines still revolve around benchmark scores.

Re-read the list of things actually named: strategy, governance, technology choices, legacy data pipelines, data cleaning, model alignment, human-in-the-loop compliance frameworks, where infrastructure sits, where the contract is signed. Not one line says "we need a smarter model". The Cognizant × Domyn release is explicit that the heavy lifting is "legacy data pipeline construction, data cleaning, and model-alignment work required for enterprise deployment".

That matches what we see at a far smaller scale. An internal assistant rarely fails because the model answers poorly; it fails because the source documents are a mess, because nobody owns keeping them current, or because access was opened too wide and had to be switched off. We unpacked how an internal assistant actually reasons in how internal AI reasons, and broke down the real cost of self-hosting in the true cost of running an LLM on-premise. Both land on the same conclusion as the vendor releases: the hard part is the unglamorous part.

How to read this from Vietnam

For a business in Vietnam, the value of these three releases is not in buying from Cognizant or Atos, but in the priority order they confirm: decide which data must stay inside the organisation first, then choose where the model runs.

The domestic legal basis is settled. Per the Ministry of Public Security portal, in the original Vietnamese: "Ngày 01/01/2026, Luật Bảo vệ dữ liệu cá nhân (Luật số 91/2025/QH15) chính thức có hiệu lực thi hành" — on 1 January 2026, Personal Data Protection Law No. 91/2025/QH15 took effect, establishing citizens' basic data rights including the right to be informed, to consent, to access, to rectify and to request erasure (translation ours). The erasure right carries the heaviest technical weight: if you do not know where a person's personal data sits across your systems, you cannot delete it — and an AI assistant loaded with documents indiscriminately is one of those places.

The opposite caution is worth stating too, because a "sovereign" wave is easily turned into a hardware sales pitch. Not every workload needs to run locally. The real cost of on-premise includes hardware, power, staff on call, patching responsibility and the risk of stranded technology — and as the Civo CEO put it above, a sovereign system your engineers cannot use is just an investment sitting still.

Table 4 — Mapping to a business in Vietnam (this is Namtech's recommendation, not content from the releases quoted above)
What to doWhyTypical cost
Inventory the personal data you processWithout an inventory you cannot honour access, rectification or erasure rights under Law No. 91/2025/QH15A few working sessions, no capital outlay
Classify workloads: sensitive vs non-sensitiveOnly the sensitive set warrants local execution; for the rest, an API call is usually cheaper and safer given a clear data processing agreementA few working sessions
Read the hosting and contracting terms closelyThe lesson of the word "contracted" in the Atos release: jurisdiction decides, not just server locationVendor contract review
Fix access control and document ownershipThis is the most common failure mode of an internal assistant, ahead of anything model-relatedProcess work, not hardware
Only invest in infrastructure once the four above are doneBuying hardware before defining process is the fastest route to a cluster nobody usesThe largest outlay — deliberately last

The common message of the three July 2026 releases is not "AI is finally good enough", but "AI has been good enough for a while; what is still missing is the path from experiment to a system that runs for real, and a clear border for the data travelling along that path".

Frequently asked questions

What does "sovereign AI" mean in these releases?

As the releases describe it, a deployment model that keeps data and control within an organisation or within a defined jurisdiction. The Cognizant × Domyn release refers to LLMs delivered "on-premise or in private cloud configurations"; the Atos release refers to a platform "entirely hosted, operated and contracted within the EU". The common elements are three: where it is stored, who operates it, and which law governs the contract.

Do these announcements affect businesses in Vietnam directly?

Not directly — this is commercial activity by foreign vendors in EMEA. The indirect effect runs through the market: as on-premise and private cloud delivery become standardised products, price and availability of comparable options in Vietnam tend to improve. Your legal obligations still come from domestic law, in particular Law No. 91/2025/QH15, in force since 1 January 2026.

Does running AI locally automatically mean compliance with the Personal Data Protection Law?

No. Local execution keeps data inside the organisation, but the law imposes obligations around data subject rights — to be informed, to consent, to access, to rectify and to request erasure — and those must be exercisable wherever the model runs. The data inventory and access control mechanism are what satisfy the obligation; server location is only a supporting condition.

Did the releases disclose pricing or contract size?

No. None of the three releases we checked on 29 July 2026 states pricing, contract value or the number of signed customers, and we do not speculate on those figures. Atos does state that its platform is "becoming available for customers in 2026".

Where should a 50-person company start?

With the data inventory and access control, not with hardware. The first four items in Table 4 are process work, achievable in weeks with almost no capital outlay; only the fifth is an investment decision. That order is precisely the one Cognizant's Foundation tier describes: strategy and governance first, prototypes after.

Review your path from experiment to real operation

Namtech helps businesses build a personal data inventory, classify sensitive workloads, design access control for an AI assistant, and judge when running models locally is genuinely necessary — starting from process, not from a hardware invoice.

Book a free consultation

Note: This article draws on public sources, checked on 29 July 2026. Quoted passages are verbatim from press releases by Cognizant, Atos and Civo. The two Gartner forecasts are quoted as they appear in corporate releases, not from the underlying reports. Table 4 is Namtech's recommendation. Informational only, not legal advice.

Get started

Start with a free assessment

To determine the right package and detailed scope, Namtech offers a short assessment session at no charge.

We respond within one business day. No spam, and we never share your details.