KEY TAKEAWAYS
  • A server’s location alone does not establish control over an AI system.
  • Map data, models and every party that can access them.
  • Ask for evidence and an owner for each control requirement.

Turn an ambition into requirements

Public discussions in Morocco about digital trust and AI infrastructure, including the ministerial intervention of 7 July 2026, provide context for technological control. They do not certify a supplier’s solutions. For an enterprise project, sovereignty must become technical, operational and contractual requirements matched to the need.

Start with the reason for the requirement. Do you want to control access to internal information, reduce dependency, choose processing locations or ensure an exit path? Several objectives may coexist, but they do not necessarily lead to the same architecture.

Map the full data journey

An assistant may use an application hosted in one country, a model running in another and logging elsewhere. Examine requests, documents, embeddings, outputs, caches, backups and technical traces. Include information sent to tools called by agents.

The diagram should identify who processes each data category, for what function and for how long under the applicable terms. Unknown points remain open questions. A complete diagram provides more value than a commercial label that is difficult to verify.

Compare cloud, private and hybrid options

A private environment can provide greater control over some components, but it requires operational capability: updates, monitoring, backups and incident handling. Cloud offerings may provide useful services under specific conditions and options that need careful examination. A hybrid architecture distributes processing and adds interfaces to manage.

The comparison should include performance on your tasks and required resources. A model suited to one document type may be less useful for another. Evaluation therefore concerns representative cases and the operation of the whole solution, not only the model’s name or size.

Specify access and responsibilities

Distinguish the rights of users, administrators, operators and subcontractors. Define authentication, secret management and operations requiring approval. Responsibility for model updates and permission changes should be explicit.

Ask how incidents are detected and handled, how backups are verified and who can restore service. An architecture that looks rigorous on paper may remain fragile if nobody owns daily operations. These questions belong in the assignment’s scope and cost.

Plan an exit before committing

An exit strategy covers data, configuration, evaluations and the knowledge required to take over the solution. Identify export formats and vendor-dependent components. Check relevant licences and terms with the appropriate specialists.

An exit exercise can be limited but concrete: export part of a corpus, rebuild an index and replay several cases on another configuration. It does not prove every migration will be easy. It identifies dependencies early enough for a technical or contractual response.

Prepare discovery with an evidence matrix

For every requirement, record the expected level, evidence to obtain and person responsible for validation. Separate non-negotiable points from trade-offs. Budget, available skills and timelines should be discussed alongside architecture.

Discovery should produce an explainable choice: why this option fits, what limitations remain and how they will be monitored. Legal classifications and compliance commitments need examination in their applicable context; they cannot be presumed from architecture alone.

DimensionQuestionExpected evidence
LocationWhere does each processing step occur?Complete data-flow map
AccessWho can view or administer?Roles, procedures and logs
OperationsWho maintains and restores?Responsibilities and restore exercise
ModelsWhat dependencies and terms apply?Architecture, licences and verified terms
ExitWhat can be transferred and exported?Formats and exit test

Sources & methodology

Ministère marocain de la Transition numérique — confiance numérique et infrastructures IA2026 · Source primaire / Primary source
Stanford AI Index 20262026 · Source primaire / Primary source

This insight combines cited publications with editorial analysis. Illustrative examples are not client results. Vendor features and terms may change.

i.
INKWAY

AI consulting, engineering and adoption. Perspectives connecting technology with business needs.

Our editorial approach
Explore how we can help with this topic