Speaking at the Global Fintech Fest 2026 panel on "Building Sovereign AI for a Digital Economy," Bharti Airtel's Group CRO and Director - Corporate Affairs Rahul Vatts argued that true sovereignty goes well beyond storing data within Indian borders. He outlined the defining pillars — data, digital, operational and jurisdictional sovereignty — stressing that only end-to-end control over infrastructure, operations and technology can secure India's data and AI ecosystem as consumption scales rapidly and geopolitical pressure over data control intensifies.
As India rapidly evolves into a digital superpower, adopting AI at breakneck speed, what the country needs critically are secure guardrails for safe growth. What rapid AI adoption, deployment and leverage critically need is a strong foundation — one built with sovereignty, keeping data, operations, and technology under Indian jurisdiction to ensure security, compliance, and control at scale.
True sovereignty cannot be treated as a simple data-residency checkbox; it is a systemic architecture.
Redefining Sovereignty Beyond Data Residency
Detailing true sovereignty, Rahul Vatts, Group CRO and Director - Corporate Affairs, Bharti Airtel, said, "I think what is really happening on sovereignty is that we seem to have created sort of a mishmash that sovereignty is something in data sense, and is more about having data residence. So, if your data is in India, you tend to say I am sovereign. But I don't think that's the correct way to define sovereignty. Sovereignty is really about how you are controlling the end-to-end stack of what you are trying to create in an AI. Are you able to create the infrastructure? Are you able to create the control? Are you also able to have the influence happening in your control? At Airtel, we are quite proud to have created at least four direct principles, which we feel are important to define sovereignty. For us, first is data residency and this comes very naturally. The data has to be in India. We are generating the largest data in the world, as you are aware. And so, the protection of data should be in the country. The second part is really about digital sovereignty, which is about having the control systems controlling that data within the sovereign stack. Then, it is about operational sovereignty. We talked about control play being very important. We have seen what is happening across the world. So increasingly now, because of the geopolitical world we are living in, there's huge pressure on who really controls the data. And so, for us, the third big pillar is about operational sovereignty. This is then followed by jurisdictional sovereignty that your local laws are able to protect the data which you are creating and are you subject to some other laws. A lot of people also add up a fifth piece into it sometimes which is about technological sovereignty also. So for us, it's not just about residency, it is really having an end-to-end control of how you are able to control this entire sovereign stack."
Given Airtel's telco-native cloud capability, it is structurally aligned to the five pillars. Data sovereignty is delivered through in-country data centers, network points of presence, and clear rules on replication, backup, and cross-border flows.
Why India's Data Scale Demands Control, Not Just Storage
Detailing the critical need for sovereign cloud in India, he added, "India is already generating the largest data per consumer. We are already hitting around 38 to 40 GBs per month per customer. And if a lot of predictions now take us towards 70-75 GB per customer in next 3-4 years. So you are already generating humongous amount of data. Also, increasingly all our systems are getting digitized. We are already seeing more than 2.4 billion UPI transactions happening in the country. So you are today generating huge amount of data for yourself. Our financial system is getting robust. So, today we need to have a clear control on what's really happening around in our own universe. If you look at the world, the world is also trying to look at it differently. If you go to Germany, you go to France, increasingly now, because of the geopolitical world you are living in, you are having a need to be able to control your data. And I think all people who answered, you know, one unanimity was that we need to have control. Why do we need to have control? Today your data is susceptible for anything. Your identity, your health record, your financial reports are all critical data sets. Why should any other country have access to that data? The universe has to be that we have to have the laws which control the data which we have and we also have a control plane which we are able to manage in terms of sovereignty. So that is the real need for sovereignty and that's why at Airtel, we don't do a data residency checkbox alone but an end-to-end control of the stack."
Detailing the government policy on sovereignty, he said, "The government has again taken a lead out here. As early as 20th March, the government came up with the first circular talking about sovereignty, which is actually quite path breaking and the government has had very detailed discussions over the last 30 to 45 days as to what should we be really looking at. While the government remains proactive, two areas which should always be important for us to keep - one is to have a clear discussion on where the control plane is and how are we going to manage it."
He added, "The second part, which is a larger part, is that we need to get away from this fragmented policy approach. For example, government today says that critical government data sets should be under sovereign ground. But why not for the energy data of the country? Why not the health record of the country? Why not the identities of people? So, I think this policy approach has to get consistent so that we cover the entire universe of what is critical to us. Why? Because we need to have a control on safety, to have control on trust and the financial system."
Measuring What Sovereignty Success Actually Looks Like
Detailing the success metric for sovereignty, he added, "Two important things - one parameter of success is that we are actually deploying at scale. Second is about what percentage of this deployment is really going to be sovereign in terms of the four pillars we discussed which includes residency and control. So whatever percentage we are able to do in next 2 or 3 years, that is really the parameter of sovereignty success for me."
As sectoral regulators begin issuing their own enabling guidelines, the question for critical workloads is no longer just about the selection of any cloud, but a careful evaluation of which cloud architecture guarantees end-to-end control under Indian law. For critical sectors like banking, health, public finance, and digital public infrastructure, the answer will increasingly be sovereign cloud built and operated within India's jurisdiction.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




