I wouldn't describe myself as an AI expert, and I'm not convinced anyone really can yet. Over the past year I've been kicking the tyres of different models, developing internal policies and assessing how organisations can use AI responsibly.
I started out evaluating the technology itself, but quickly found myself thinking more about governance, dependency and long-term control.
Most organisations have moved beyond asking whether to use AI. The more useful question is how to adopt it without losing transparency, flexibility or control.
We're asking the wrong questions
Much of the current conversation around AI focuses on how to use it. Governments are publishing guidance on service delivery. Businesses are exploring productivity gains. Software vendors are racing to embed AI into existing products. But it tends to start from the same assumption: that the model itself has already been chosen.
Far less attention is given to the questions that come before implementation.
- How do we choose the right models?
- What criteria should we use beyond capability?
- How do we avoid creating new dependencies while trying to solve existing problems?
That's where I think digital sovereignty begins. Before we think about prompts, workflows or automation, we should be asking where our data goes, how much control we retain, and whether today's technology choices leave us with options tomorrow.
These aren't purely technical questions. They're questions of governance, procurement and long-term resilience.
Digital sovereignty is practical, not ideological
Digital sovereignty can sound like one of those policy phrases people like to put in strategy documents. For me, it's much simpler. It's the ability to control your own digital destiny.
In practice, that means understanding where your data is stored, who has access to it, and how easily you can adapt if circumstances change. It means avoiding unnecessary dependence on any single vendor, platform or proprietary ecosystem.
Most organisations already think this way about cloud infrastructure, hosting and critical business systems. It seems to me that AI deserves exactly the same level of scrutiny.
As AI becomes more deeply embedded in our organisations, I think there are a few practical questions every organisation should be asking.
- What happens if pricing changes significantly?
- What if licensing terms evolve?
- How easy would it be to switch providers?
- Can we audit the systems we're relying on, or are they effectively black boxes?
None of these questions suggest organisations should avoid commercial AI models. Many offer exceptional capabilities and will continue to play an important role. The challenge is making sure convenience today doesn't become dependency tomorrow.
Choice, transparency and adaptability have always been hallmarks of resilient technology. They should remain so as AI becomes part of everyday infrastructure.
Looking beyond capability
Capability is only one part of evaluating an AI model. Organisations also need to consider how those models are built, governed and sustained.
Questions around training data, labour practices, environmental impact and data ownership don't have simple answers. They shouldn't discourage organisations from adopting AI, but they do reinforce the need to look beyond benchmarks and feature lists when making technology decisions.
One of the ideas that resonated with me came from Pope Leo XIV's reflections on AI and the Tower of Babel. His argument wasn't simply about the risks of artificial intelligence. It was about the dangers of concentrating too much power in too few hands.
As someone who's spent most of my career working in Drupal, that feels familiar. Open source has spent decades demonstrating the value of transparency, interoperability and shared ownership. Drupal succeeded because it evolved through an open ecosystem rather than a single vendor's roadmap. That doesn't automatically produce better software, but it does create resilience, choice and accountability.
AI won't follow exactly the same path, nor should it. Commercial models will continue to play an important role. But those principles provide a useful way to think about responsible AI adoption: not just choosing the most capable model, but understanding the wider ecosystem you're choosing to depend on.
Avoiding lock-in starts with architecture
If digital sovereignty is the goal, the conversation quickly moves beyond individual AI models and towards the architecture that connects them.
It's easy to think of AI as choosing between ChatGPT, Claude, Gemini or another model. In practice, those choices don't have to be permanent. One of the encouraging developments is that AI models are already becoming increasingly interchangeable. Shared APIs and emerging standards mean organisations have more options than they might initially assume.
That flexibility matters for several reasons. Organisations may want to compare models, respond to changing pricing, meet data residency requirements or adopt new technologies as they emerge. Building around open interfaces rather than a single proprietary platform makes those decisions easier.
The same principle has shaped good software engineering for years. Loose coupling, well-defined interfaces and open standards reduce dependency and give organisations room to adapt. AI should be treated no differently.
What digital sovereignty looks like in practice
These aren't theoretical ideas for us. They're already shaping how we experiment with AI at Code Enigma. Rather than committing to a single provider or workflow, we've been exploring tools that give us greater flexibility over how AI is integrated into our day-to-day work.
LiteLLM is one example. It acts as a layer between applications and AI models, allowing organisations to connect multiple providers through a single interface. If requirements change, whether because of pricing, capability or governance, it's far easier to switch models without redesigning the applications that depend on them. That's important because I don't think anyone should assume today's preferred model will still be tomorrow's best option.
We're also experimenting with tools including OpenWebUI and OpenCode, but the underlying principle is the same: keeping the architecture flexible enough that organisations retain choice.
None of these tools is a complete solution. Their value lies in showing that AI can be integrated in ways that preserve transparency, flexibility and long-term control.
Looking ahead
AI isn't going away, whether we're entirely comfortable with that or not. If anything, it's becoming another layer of the technology stack that organisations rely on every day. That makes the decisions we make now about governance, interoperability and digital sovereignty increasingly important.
There are some straightforward places to start.
- Understand where AI is already being used across your organisation.
- Ask where your data goes and what safeguards are in place.
- Look for open standards and interoperable tooling that preserve flexibility.
- Evaluate models on governance, transparency and long-term sustainability, not capability alone.
None of this requires rejecting commercial AI. My hope is that we approach AI in the same spirit that has served open source so well: favouring transparency, interoperability and long-term resilience. If we do that, we'll be better placed to shape how AI develops rather than simply adapting to it.
This article is an edited version of a talk I gave at the LocalGov Drupal Conference. It focuses on the core arguments around digital sovereignty and responsible AI adoption. If you'd like the full context, including audience discussion and live demonstrations, you can listen to the complete recording here.