The routing model
The central idea is straightforward: classify a request, then route it to a model estate whose residency and certification profile matches that classification. A customer-identifiable record goes to a sovereign deployment; an anonymised summarisation request goes to the highest-capability model available.
What makes this workable in practice is that classification happens at the data layer rather than being reimplemented inside each application. Policies apply organisation-wide and applications inherit them.
For a multinational insurer running dozens of internal tools, this replaces dozens of bespoke compliance conversations with one policy review.
Why regulated industries were stuck
Financial services, healthcare and public sector buyers have spent two years in a frustrating position: capable models existed but could not touch their most valuable data, while compliant deployments lagged the frontier by a generation.
The compromise most organisations reached was to deploy AI only against low-value data, which produced exactly the underwhelming pilot results that made executives sceptical of the whole category.
Routing changes the shape of that trade-off. Sensitive processing stays inside a certified boundary while everything else reaches for capability, and the split is a configuration decision rather than an architectural rewrite.
The new failure mode is policy
Every abstraction relocates complexity rather than removing it. Here, complexity lands in classification policy — and misclassification is now a compliance incident rather than a bug.
Organisations should treat routing policy as production code: version it, review changes, test with synthetic records representing each classification, and alert on unexpected routing distribution shifts.
A sudden increase in traffic routed to the global estate is a signal worth investigating within the hour, not at the next quarterly review.
Cost implications
Sovereign capacity is meaningfully more expensive per unit than shared global capacity, so routing decisions have direct budget consequences. Over-classification is safe from a compliance perspective and expensive from a finance perspective.
The organisations getting this right run a monthly review with legal, security and finance in the same room, examining the classification distribution and asking whether each tier is justified.
Competitive positioning
Every major cloud provider is converging on similar sovereign offerings, and differentiation is increasingly about the breadth of certification coverage and the maturity of governance tooling rather than the underlying models.
For buyers, the practical advice is unchanged: keep your application logic portable, negotiate on total cost at realistic volume, and treat certification coverage in your specific jurisdictions as the primary technical criterion.
Comments (0)
Discussion is opening soon. Be the first to comment.