Singapore government technology leaders overwhelmingly say secure data sovereignty shapes their AI investment decisions - 93.3% agree. But only 3.3% are investing significantly in it, according to Building a Sovereign AI Foundation for the Singapore Government, an IDC InfoBrief sponsored by Dell Technologies and NVIDIA. The December 2025 survey of 30 Singapore government IT decision-makers found 40% evaluating sovereign AI technologies and another 43.3% running proofs of concept with no spending plan attached. Nearly nine in 10 agencies are looking, and almost nobody has committed.
The stall is regional. Across eight Asia Pacific markets, the same research found sovereign AI climbed from the seventh to the second-highest government investment priority in a year. Priority moved; procurement did not.
What sovereignty actually means
Asked to define sovereign AI, 43.3% of Singapore government leaders picked strategic competitiveness and innovation capacity. Only 10% picked national control and autonomy. "Sovereignty is not about saying 'we own everything,'" one senior Singapore government official told IDC. "It is about whether the nation retains control over the data, the infrastructure, the models, and the decision-making process."
Andy Sim, vice president and managing director of Dell Technologies Singapore, says organizations making progress classify workloads before they buy anything. Three questions decide it: What are the consequences if this data is exposed? What happens if this system is manipulated? How much human judgment remains in the loop?
Score high on all three and the workload runs fully on-premises with no external dependencies at critical points. National security systems sit here. Score high on some, and partners can supply technology and elasticity while the institution keeps governance, residency and oversight. Healthcare analytics, tax systems and citizen services occupy that middle tier. Everything else runs in shared environments with sovereign controls switched on. Singapore's Government Commercial Cloud already works this way.
The gap in residency maps
Most residency programs track where data sits. Sim argues that is an incomplete picture. "A practical test is to assess not only where the data resides, but where prompts are processed and tokens are generated," he says. "In regulated environments, that matters because sovereignty risk can arise from the movement of context and inference, not just from where data is stored."
A customer record can sit in a Singapore data center all year and never move, while the prompt describing it, the retrieval context around it, and the model output about it are generated somewhere else. The map shows green but the exposure sits outside the frame. Autonomous agents make this worse - they generate far more tokens than humans do, and rising volume turns a governance question into a cost and latency question at once.
Why costs climb
Security leads Singapore's concerns at 50%, specifically vulnerabilities that leave sovereign AI models open to adversarial attack. Premium pricing follows at 40%, then technical complexity at 33.3%. Some of that price is self-inflicted. Applying full sovereign controls uniformly across every workload drives costs up and consumes capacity that is already short. "Access to compute is becoming a critical bottleneck for AI development," one Singapore official told IDC.
Some 76.7% of leaders agreed sovereign AI may inadvertently restrict innovation by limiting access to global technology ecosystems and advanced research. These are not skeptics - they are the people building sovereign AI systems, pricing in the cost of their own strategy.
Sim recommends standardizing against lock-in across three layers: open model frameworks so you can swap models as the field moves; a portable data layer built on open APIs and standard formats; and a governance and security layer owned independently of any vendor's control plane. "When you own governance, you can change technology partners without rebuilding your compliance posture from scratch," he says.
The failure mode is convenience. "The organizations that get locked in are those that standardize on a bundled solution that handles all three layers together conveniently," Sim says. "Convenient until the moment you need to change one component and discover everything is tightly coupled."
Data and skills lag
Half of Singapore agencies now document data definitions and lineage across multiple projects, up from 40% a year earlier. Only 6.7% manage data quality risk enterprise-wide with preventive measures, down from 10%. Investment in modernized data architecture dropped from 66.7% in 2024 to 30% in 2025, while investment in data abstraction layers nearly doubled from 26.7% to 46.7%. Fewer agencies are rebuilding the foundation; more are putting a governed layer over what they already have.
No Singapore agency reported a major skills shortage in 2025, yet only 3.3% said they can access the skills they need for all initiatives. The shortage did not deepen but spread. Cybersecurity specialists are hardest to hire at 50%, then data architecture and analytics at 43.3%, then sovereign data governance at 40%. "Customers plan for technology and underbudget for people," Sim says. A proof of concept runs on specialists. Production runs on 24/7 operations, incident response and model monitoring.
Almost every survey respondent expects agentic AI to accelerate adoption, and 76.2% attach a condition: strong guardrails and oversight first. Sim's list of what belongs in infrastructure rather than the application is short. Tamper-evident audit trails for every agent action; workload isolation so an agent cannot escalate privileges or move laterally; real-time observability with a hard stop that fires before the application registers a problem.
The payoff is the argument a CDO can take to the boardroom. Sovereign AI earns its cost when it unlocks data the organization already owns and cannot use. "Singapore's banks sit on extraordinary volumes of transaction data and risk signals," Sim says. Much is too sensitive for shared cloud under current rules, so it stays locked. "The bank that trains on its full data estate under its own governance moves faster than one constrained to the subset it's comfortable sending to a third party."
Four decisions to make this quarter
- Map inference, not just storage. For the top 10 AI use cases, record where prompts are processed and tokens are generated. If that differs from the residency map, there is work to do.
- Price the tiers. Identify which workloads justify full sovereign controls and which are paying for them by accident.
- Check who writes the audit trail. A record generated by the application rather than the platform can be bypassed by the application.
- Name the owner of the governance layer. If the infrastructure partner changed next year, would identity, encryption and audit frameworks survive the move?
"AI is now comparable to identity or payments infrastructure," another Singapore official told IDC. "Once you depend on it, you must govern it."
The 3.3% will rise. The organizations that move first will not be the ones with the largest compute contract. They will be the ones that knew which workloads truly deserved it.
Why this matters for government professionals
For public sector IT leaders, the gap between acknowledging sovereignty and funding it is not a budgeting delay - it is a risk position. Every month spent in proof-of-concept mode means AI workloads run without defined governance, audit trails, or residency controls. The survey's practical framework - classify workloads by exposure and manipulation risk, price sovereign controls by tier, and keep the governance layer portable - gives agencies a concrete starting point. Those who settle these questions now, before agentic AI scales token volumes and hardens routing choices, will avoid unwinding costly infrastructure decisions later. AI for Government training and an AI Learning Path for Policy Makers can help public sector teams build the internal capability the survey shows is missing.
Your membership also unlocks: