Data, not models, becoming the biggest hurdle to enterprise AI: Report
As AI matures, organisations are finding their data infrastructure isn't keeping pace.
AI adoption is stalling, and it’s not constrained by model performance alone. It’s outgrowing the architecture and infrastructure beneath it as data privacy and sovereignty requirements tighten, according to NTT DATA’s 2026 AI report.
At the same time, there’s a growing gap between understanding and execution, with 95 percent of organisations viewing private and sovereign AI as important, yet only around one-third are making sovereign AI a near-term priority, the report noted.
Data management may lead to rise of private and sovereign AI
Data jurisdiction has become a core design parameter, shifting away from globally integrated systems to regionally bounded architectures, according to the report, which draws on two studies engaging a total of nearly 5,000 senior decision-makers from more than a dozen industries, more than 30 markets and five regions.
As a result, private and sovereign AI have become critical considerations, although they serve different purposes. Private AI focuses on protecting sensitive enterprise data, controlling access and limiting exposure. Sovereign AI focuses on ensuring that AI systems, data and operating environments meet jurisdictional, regulatory or national and regional control requirements.
The report warned that organisations that try to layer AI into architectures not built for control, locality or data-flow constraints may struggle to turn their AI ambition into durable value.
Vito Rinaldi, MD, Blue Crystal Solutions, agrees, noting that uncertainty about how to build AI on top of existing environments is holding organisations back.
“We see private and sovereign AI as the final layer, not the first,” said Rinaldi.
Redesigning data platforms for AI
Together, private and sovereign AI are changing how AI systems are built, governed and scaled. However, the report identifies integration complexity as one of the biggest barriers to private and sovereign.
“Data integration remains the biggest challenge by far,” Rinaldi agreed.
“AI doesn't create value simply because you deploy a model. It creates value when it can securely access trusted enterprise knowledge – and the outputs from that trusted knowledge is where the gold is,” he said.
“Most customers already have the infrastructure available through public cloud, private cloud or on premises environments. The challenge is connecting fragmented data sources while maintaining governance, security and compliance,” he added.
Organisations that redesign early are better positioned in regulated, distributed and data-sensitive environments. Those that layer AI into architectures that were not built for control, locality or data-flow constraints may struggle to turn their AI ambition into durable value, the report said.
Rinaldi agrees, and the first step is to adopt a modern data platform that brings together governed, high-quality data before introducing AI. “Once that foundation exists, deploying secure AI becomes significantly more achievable with immediate ROI,” he said.
Organisations should then design AI architecture that separates models from business data, allowing different models to be introduced over time without rebuilding the underlying platform, according to Rinaldi.
“This also supports sovereign AI requirements by keeping sensitive data within approved environments while providing flexibility as AI technologies evolve,” he said.
Finally, organisations should avoid assuming every workload needs the most powerful model available. Different business tasks require different levels of capability.
“Matching the right model to the right workload, within a governed data platform, improves security, reduces operating costs and creates a far more sustainable path from proof of concept to enterprise deployment,” he added.