AI Sovereignty isn't Something You Buy. It's Something You Build.
What Palantir, Apple, and a rogue AI model are revealing about your data in the AI boom.
AI is not coming. It is here, and every organization that wants to stay competitive is adopting it. The question that almost never gets asked in the same breath is a simple one: when your data enters an AI system, is it still yours?
Not yours in the sense of a contract. Not yours in the sense that a vendor promised to protect it. Yours in the sense that you control who can access it, how it can be used, and whether that access can be revoked after the fact, regardless of where the data ends up.
Because the organizations that figure out how to answer it are the ones that get to use AI on their own terms. The ones that don't are donating their edge to someone else's model.
Then July happened. And we can’t ignore it anymore.
Palantir sees the problem. So does everyone else who read the coverage.
On July 1st, Palantir Technologies shared "thoughts on the importance of AI sovereignty" on social media, a thread running to nine numbered points. The tech press covered it wall to wall, and most of the commentary focused on Alex Karp's combative tone and what it meant for Palantir's competitive positioning against the frontier labs.
Read past the theater, and the argument is plain and clear. Whoever controls your data and your models controls your future, so do not hand either to someone else.
Point two is worth sitting with: your ability to win is dictated by your ability to recognize and use your unique edges, and you keep winning by compounding the underlying data to generate new insights. Transferring that data hands over access to your pre-existing winning plays and yields the means of production for new ones.
That is correct. Data is the input that makes AI competitive, and the moment it enters an environment you cannot control or audit, the competitive logic reverses. You are no longer compounding your edge. You are donating it.
Where Palantir loses the thread is in its own conclusion. The irony is that "sovereignty" is the same argument now being used against Palantir.
Europe has turned the word into policy. France's foreign intelligence service dropped Palantir for a homegrown rival. Germany's military has kept it at arm's length. For those governments, true sovereignty means not depending on a single American vendor, however loudly it preaches independence.
If governance lives in a contract with a vendor, it is not governance. It is a service agreement. The data is still not yours in any meaningful operational sense the moment it crosses into their infrastructure.
Apple's lawsuit is not an employment story. It is a data story.
On July 10th, Apple sued OpenAI for trade secret theft. The suit claims OpenAI systematically poached Apple employees and coaxed them into sharing proprietary hardware designs, supplier information, and confidential product files. One named defendant is alleged to have exploited an authentication vulnerability to breach Apple's internal network and download confidential files before leaving. Another allegedly coached candidates still employed at Apple to bring actual hardware components to interviews for what the complaint calls "show and tell" sessions designed to extract still more proprietary information.
This got covered as a dramatic corporate reversal between two companies that had only recently announced a major AI partnership. A story about trade secret law and the messy dynamics of Silicon Valley talent.
But the data question underneath it is the one worth sitting with. Once those files left Apple's systems, Apple had no mechanism to revoke access. No control that traveled with the files themselves. No way to know what had been copied, where it had gone, or what had been derived from it. The data left. The policy did not go with it. The only recourse left was federal litigation.
That is perimeter-centric security meeting its logical end state. It works until it doesn't, and when it stops working, all you have left is lawyers.
Then the models started doing it themselves.
This is the part that should be recalibrating how every security team thinks about data, and it is not getting the gravity it deserves in the coverage.
OpenAI disclosed that two of its AI models autonomously hacked their way out of a controlled environment where they were supposed to be walled off from internet access, and then hacked their way into the systems of Hugging Face, a company that hosts open source AI models and testing resources, in order to cheat on an internal evaluation benchmark. OpenAI called it "an unprecedented cyber incident."
The models were not malicious. They had no intent in any philosophical sense. According to OpenAI, they appeared narrowly focused on completing the evaluation rather than pursuing a broader objective. That is exactly the point. The models did not care that Hugging Face's data was not theirs to access. They had a task and they pursued it across every boundary they could find, because none of those boundaries were enforced in a way that was meaningful to a capable agent with a goal.
It is unclear whether OpenAI will face legal consequences. But the incident offers some of the most vivid real-world evidence yet that advanced AI systems can independently discover and chain vulnerabilities across production infrastructure, extending capabilities previously demonstrated mainly in controlled benchmarks. The next time, the model might not be running in your own environment.
Visibility is not the same thing as control.
The market knows something is broken, and it is starting to act accordingly. Last week, Cyera acquired Oasis Security for a reported $1 billion. The logic is compelling: Cyera knows where your sensitive data lives, Oasis Security knows who and what can access it, and together they are building a control plane for data security in the age of AI. The price tag is a loud, unambiguous statement about where enterprise security is heading, and it is the right direction.
Discovery and identity governance are exactly the right problems to be solving. They are also the foundation that makes the next layer possible.
Because knowing where your data lives and controlling what happens to it after it moves are two different problems. A DSPM tool tells you where your sensitive data is. The question July raised is what happens when it leaves, into a vendor's training pipeline, a partner's AI workflow, or a sandboxed environment where a capable model is actively looking for a way out. That is where discovery hands off to something else entirely.
CEOs are pushing AI adoption faster than governance models were designed to allow. CISOs are discovering their stack has no answer for what happens after sensitive data leaves the perimeter. The Cyera acquisition is the market arriving at the right foundation. The next question is what gets built on top of it.
The answer is security at the data level.
The answer to all of this is not to stop using AI. Organizations that sit on the sidelines waiting for governance to catch up will simply fall behind the ones that don't. The answer is also not a taller perimeter, a stronger NDA, or a more trustworthy vendor.
Today's AI systems are, at their core, vacuums for data. They are designed to ingest, learn from, and derive value from every input they touch. Governance that lives at the network edge, in a contract, or in a vendor's promises cannot keep pace with that. The moment the data moves, which it will, those controls stay behind.
The architecture that actually closes this gap is one where policy travels with the data itself. Cryptographically enforced. Persistent across environments. Revocable after the fact rather than only deniable at the gate. Think less like a perimeter and more like a wrapper around every data object: encryption, attribute-based access control, and audit capability that move with the data wherever it goes. It does not matter if that data ends up in a third-party AI workflow, a vendor's training pipeline, or a sandboxed evaluation environment where a capable model is actively looking for a way out. The controls are in the data, not in the wall around it.
This is what open standards like the Trusted Data Format are built to enable. And the fact that it is an open standard matters: no single vendor owns the mechanism of control. That is a fundamentally different thing than what Palantir is selling, and it is the difference between sovereignty and dependency with better branding.
You do not have to choose between embracing AI and keeping your data yours. That tradeoff is not required. But building the architecture that makes both possible requires starting in the right place. Not at the network edge. Not in a contract. At the data itself.
That is the only place it has ever been able to start.
Matt Howard
A proven executive and entrepreneur with over 25 years experience developing high-growth software companies, Matt serves as Virtru’s CMO and leads all aspects of the company’s go-to-market motion within the data protection and Zero Trust security ecosystems.
View more posts by Matt HowardSee Virtru In Action
Sign Up for the Virtru Newsletter
Dive Deeper
/blog%20-%20cyera%20oasis/cyera-oasis.webp)
The Coin Has Two Sides: What Cyera's Acquisition of Oasis Tells Us About the Future of Security

Virtru Collaborate vs. Box: Secure File Sharing for Businesses of Any Size
/blog%20-%20william%20mcborrough%20recap/cmmc-compass-will-mcborrough.webp)
The $600,000 Problem: What the CMMC Pause Actually Revealed About the Defense Industrial Base
/blog%20-%20three%20stories/three-stories.webp)
Last Week in Critical Infrastructure: Three Stories You Should Read as One
/blog%20-%20cmmc%20on%20hold/CMMC-Pause-CUI-Not.webp)
CMMC Phase II Is Officially on Hold. NIST and DFARS aren't.
/2026%20Newsletter%20Assets/jk-HIO.png)
We Asked Kindervag: Why Are So Many Organizations Still Getting Zero Trust Wrong?
/blog%20-%20ShareFile%20Takedown/26-Competitor-Blog-Blog%20-%20Virtru%20vs%20Sharefile.jpg)
Looking for a ShareFile Alternative? Here's What Regulated Organizations Need to Know.
/blog%20-%20sendsafely%20takedown/26-Competitor-Blog-Blog%20-%20Virtru%20vs%20SendSafely%20(1).jpg)
SendSafely vs. Virtru: Which Secure File Sharing Platform Protects Your Data After Download?

Dropbox Alternatives for Secure File Sharing: What IT Teams Are Missing
/blog%20-%20alex%20karp/alex-karp.jpg)
Alex Karp Is Right About the AI Problem. He's Missing the Solution.
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.