
Loading summary
A
This is an iHeart podcast. Guaranteed Human.
B
I'm Malcolm Gladwell and you're listening to Smart Talks with IBM. Imagine your business depends on a system you didn't build and don't fully control for years. It works perfectly. It's fast, reliable, affordable. So over time, more and more of your operations rely on it. Then one day, the terms change. What once felt flexible now feels difficult to leave. Moving to another provider or bringing those capabilities back under your own control could take years, cost millions, and disrupt the business in the process. That's the challenge of digital sovereignty. Businesses today rely on all sorts of third party systems. Cloud platforms, data pipelines, AI models, software tools. Most days these systems operate quietly in the background. But when something changes like costs go up or rules shift, organizations are forced to confront how much control and flexibility they actually have. This is why digital sovereignty has shifted from policy concept to board level priority. So to understand the challenge up close, I traveled to Paris to attend VivaTech, Europe's largest technology conference, to speak with two people who think about these questions every day. Ana Paula Asis, IBM's senior vice president and chair for IBM, EMEA and APAC, and Giovanni Daniello, group chief information officer at AXA. Hello everyone. Welcome to a live taping of the podcast Smart Talks with IBM. I was downstairs in the IBM booth chatting with the people who were doing the data sovereignty presentation and they were discussing the thing and I said, oh, it sounds like you're solving a headache. And the guy I was talking to said, that's what we do at IBM, we solve headaches and cure headaches. And I wanted to start out with the two of you, what is the headache in this instance?
C
So the topic of sovereignty gained a lot of traction over the past few years. And even though I would say it really became a buzzword this year, I, I think that this actually started during COVID when all the supply chains became extremely stressed and companies and governments started to understand that there were a lot of choke points in the world. Right? So how can I do more near shoring? How can I guarantee that I have autonomy of key elements of my supply chain? I think was really the wake up call. And then we entered in a period of unfortunately many wars happening, constraining for example, energy security. So all these disruptions in the world led companies and governments to think what is really that I need to consider as critical for me and how do I have better control of those capabilities? And now technology being at the core of the operations, I think that actually increased the need for companies to focus on sovereignty. So that is the headache. Given that there are so many dependencies, given that we are living in a world that is so interconnected, how do you gain autonomy? How do you get back control? Making sure that you continue to operate in a collaborative ecosystem.
A
It's a difficult equilibrium in reality because we have to take all those dimensions into consideration, making sure that at the same time we can continue to access innovation. And that's where the paradigm is really very complicated to solve. So the headache we have in axa, and I think probably many large organizations in the world is exactly the topic in Europe at least it's about sovereignty exactly in the terms you are talking about. And that's becoming a topic that has a lot of visibility, very high in the agenda at very top executive level since probably. Yeah, it started with COVID I agree. But the last two years there has been an acceleration, clearly.
C
Yeah. And I really have a few data points. Today we announced a study through our IBM Institute of Business Value where basically we asked companies around the world, so do you have visibility of your dependencies? Right. Do you know exactly where are your exposures? And only 9% of the companies said that they have that level of visibility. And 71% of the companies said that if they needed to switch a provider today, it would be very difficult to do so. So I think the headache, this actually shows in numbers, the size of the headache.
B
Yeah, I want to. Giovanni, you're in the insurance business, speak to the specifics of your own business. Why would this be an issue that. Am I right in thinking that this is an issue that is of specific and special concern to an insurer?
A
No, I don't think so. No, you don't? No, I don't think so. Because in reality it's an issue for organizations using technology, data and AI as an important driver within the activities they manage. Insurance, of course, insurance is about data, it's about people, it's about technology, of course. So it's very, very central. But it's absolutely not limited to insurance. Because at the end, if we want to talk a little bit more into details, what is sovereignty? Because everybody talks about sovereignty, but what is it about? And very often people believe that once you know where your data are located and if you are European company, if you have the certainty that data are located in Europe, many people believe I'm safe, I'm sovereign compatible. Well, it's absolutely not enough. So there are models that not only we are using in axa, but that are also very, very public on the market very often we refer to four dimensions, of course, data location is number one. If you don't know where your data are, you don't know anything. But it's not only that. How do you operate? Who is operating the system, who is patching, who is creating new versions of whatever the feature that becomes available? That's the second one. The third one is contracts, legal terms, who is in charge, legally speaking of the activities we talk about. And the last one is the technicality itself. Who is really mastering the technical details, the underlying stack? Is it something that is European, us, China, you know, and I mean, it's known by everybody. Most of the large European companies and US Companies are using US technologies. So the difficulty in sovereignty is to scan on a permanent basis the four dimensions, making sure that, as you were saying, Anna, that you know exactly what is exactly the situation on your business on those four dimensions.
B
Give me an example of how, a specific example of what difference it would make where your data was being held. In other words, in what sense are regulatory requirements, for example, different from one country to another or from the EU to North America, or is there a practical way to kind of express those differences?
C
Yeah, there are very clear regulations in many of the countries regarding what type of data needs to reside inside the country. Right. So particularly financial data, health data, those are really, really controlled and they have to follow those regulatory requirements. So the way that we approach that in our architecture, in our platform, is to enforce those regulatory requirements within the platform so that this is not just relied from a contractual standpoint, but that you ensure with governance tools and with capabilities that the platform is securing that data in compliance with those regulatory aspects. And when you think about sovereignty, it has to go beyond just the regulatory and compliance requirements. It's really understanding your business requirements, what are the applications that are truly mission critical and that you need to ensure that have that level of control. Because also controlling everything is not necessarily viable, not from a technical standpoint and not from a business case standpoint. Right. So that is the, I think that is the challenge that many companies are going right now is to have the visibility of their application stake, how that matches the business strategy, and then making the decisions on what is the level of sovereignty that I need to apply.
B
Let's say I'm a naive company. I don't pay any attention to this. I have operations in many different countries. What's the worst case scenario? What happens if you don't act kind of prudently around data sovereignty?
C
So I think the first aspect is if something happens to your Your infrastructure that is sitting somewhere that you don't have, visibility goes out for some reason, a war, an energy blackout, any other cyber attack in your environment, if you don't have a fallback plan, if you don't have a way to move that application to operate from another place that has the backups, the real time data that you are accessing to, you're pretty much go out of, out of operations. Right. So it's, that's a very important question because I think it brings the sovereignty aspect to what I believe is the strategic role that it plays. It's about resiliency, it's not about necessarily just meeting regulatory requirements. And I think you need to do that from a risk management standpoint. And I think insurance company is the best position to do that. But it's, it's the, it's not just regulations, it's really making sure that you have continuous operation 24 by 7, which is pretty much all what businesses need
A
to achieve currently in some countries for insurance, for example, but not only for insurance in some countries there are obligations locally, for example, to store data in the country. So back to your question. There's a limit to how naive you can be if you want to develop a business because that's at the heart of getting the authorization to operate and to run your business in the countries where you would like to. But then once you are over this kind of MVP of requirements that are mandatory for you to open and operate, then of course, I mean, that's everything that. Anna, what you said is completely, completely relevant.
B
Yeah. How does one anticipate these issues changing over time? In other words, you said that people began to wake up to the importance of data sovereignty during COVID I'm just curious if we fast forward five years, do we imagine that the kind of landscape in which companies like huge money are operating is going to get more complex or less complex? What's the, what's the movement in this?
C
I think it's going to become more complex because AI is really accelerating all the trends.
B
Why I wanted you to, can you explain. I want you to kind of do a little deep dive on that.
C
Yes.
B
What specifically is it about AI that's complicating this?
C
That's a very good question. AI now moves from, you know, actions just being taken from, you know, somebody operating a system to the technology actually making decisions. Right. So you have to have a much better visibility of what systems AI is touching, what data it is accessing and where. Right. So you have to have that mapping much more clear because the stakes are higher now on how technology is actually operating your business. Right. So I do think that there is a, an acceleration. Because of that, the second element, AI, is going to increase the amount of vulnerabilities that are going to be either identified or created. So you have to have an ability to continuously monitor and scan what is happening in the cybersecurity landscape so that you can prevent and react in a much faster way. So there are more elements of disruption that are coming up as a result of the acceleration of technology.
A
I can give you a concrete example. So the way applications work today is pretty much deterministic. You have rules, you have data, you have processes very often embedded into the code, into the business logic, so they are executed. And very often if you have the same input, you have the same output. And so you have, I mean application with modules, you have APIs, you have data, you have beautiful mobile first front ends. All these fancy things that we run on the cloud or on prem in whatever. So let's project yourself into a couple of years from now where the architecture is going to be agentic, native with concepts such as headless applications. So you will interact with kind of prompt interface and you will start asking as a customer or as an employee or as a partner, you will ask, interacting and asking a certain number of problems to be solved. And this is going to be given through tokens and all these technologies into an ecosystem of digital agents orchestrated and orchestrating activities. Looking at what is in the rag, in terms of what is the process telling me about, how do I have to manage that, what kind of data do I have in my repository? And you enter into something which is going to become much more probabilistic and you have LLMs there in the meantime in the middle, trying to get answers, smart answers to queries that will come from specialized digital agents. So there's nothing to do with the way applications run today. And if you look at the flow of data today that we know, we know where the data located, I was saying a lot of things we know and how the data is going to flow in all the directions in this agentic native architecture. You understand that as you said, this is going to accelerate significantly. And the need to understand the underlying stack and architecture in the sovereignty ecosystem is going to be crucial. Data can suddenly become public, public in the way they can be used to train models and a little bit of your ip, step by step going to go into those models. If they learn, if you are not careful, that's what is going to happen. Of Course, there are ways to prevent that, but if you're not careful, you can suddenly see the world around you becoming more intelligent than you on your own business.
B
It seems like there's a. This is a very kind of crude way of putting it, but there's a race going on. The technology is running one race and then the other race is our ability to kind of make sense of it, have visibility in it, integrate the technology into the way we do our. Who's winning that race right now? Is it hard to keep up with the technology?
C
That's why I think you need the technology to govern the technology. Right. And to me, that is what our proposition with this platform that we launched a few weeks ago called Sovereign Core, is to provide that tooling and those capabilities to help organizations create those capabilities. Because what we learned already is that as Giovanni explained very well, the technology is going to accelerate exponentially. How do you map that with that same level of speed, only another technology that is going to operate at the same level of acceleration? And that is exactly the proposition that we have in supporting our clients. So that's the headache that we're trying to solve.
B
Giovanni, I'm assuming you've been in this field of technology for how many years?
A
30 years.
B
I'm curious to compare the moment we're in to any previous moments. So you've now lived through several technological upheavals. How does this one compare to the ones earlier in your career?
A
For me, this one is very clearly the one that has the highest potential. And in terms of speed, there's no precedent. Everything we've done in the past where we've been trying to modernize. Let's take a concrete exam. Modernizing business applications. We had this discussion a couple of months ago. So like all the companies in the world, we have legacy applications. All the companies have legacy applications that have been written, I don't know, 30, 50 years ago. And the journey to modernize those applications has been the last, let's say the last 15 years. Something like very often a five years ticket every time you want it to work, to modernize something, including migration and decommissioning. And every time we, even a year ago, every time we were thinking about there's technology out there, we can go much, much, much faster. We've always been blocked. And then we always came back to that unit of performance of the five years. And since this year, things are become potentially feasible because that's the agentic revolution. Because then you can specialize agents, like people in a team to split the process into subtasks, and everybody is going to be very smart and intelligent in solving a part of the problem. And then if you are good enough to orchestrate that towards an outcome which could be an application, modernization, ABC, whatsoever. Potentially, I'm saying potentially. But this is. Now, technologically, we see that it can work. You can do that. Not anymore in five years, but maybe, I don't know, a year and a half, two years, maybe a little bit less. Why not? I don't know. But you see, the difference is simply huge. I've never seen that before.
C
Yeah, yeah, I agree with that. I think the compression that you're seeing in project delivery, in new products, that we are releasing, updating versions of products, it's something that is absolutely unprecedented. So the pace of innovation is happening very fast. And if we think that AI has already created a tremendous impact, let's wait for Quantum, right, Which is going to even take this to another level.
A
And the mix, the combination between, the combination of both.
C
Yes.
B
There's a very interesting contradiction at the core of all this, which is that intuitively we know that innovation thrives on openness, interconnectedness, you know, no borders whatever. But data sovereignty makes us think very specifically and often, I would imagine, painfully about the reality of borders. How do you manage that contradiction?
C
I think that is really the challenge that we are all facing right now. Right. I don't think we have 100% clear answer yet. There are certain elements of the stack that clearly, I mean, trying to reinvent is actually going to be a reinvention of the wheel. Like, I mean, I'm not going to develop chips from the scratch, from scratch, for example, infrastructure from scratch. But there are other elements of the stack that I can get much better control. Right. So, for example, to the point that Giovanni made before, where my data is sitting, what is the orchestration layer that I can implement so that I can bring the right player at the right time? So look at the stack of technology that you are implementing and see what are the elements where, number one, it's feasible to achieve control, and number two, I know that it's something that I actually have to do to make my business resilient and focus on those. Right? Because if you try to address the entire stack or if you try to create a model that basically build a fortress, that's not going to be even feasible for you to achieve. Right. I normally say that sovereignty is not about building walls, it's about building bridges. Right. Is how you really create those connections.
A
I like the way you phrase it. That's exactly that. Because at the end, if you put sovereignty as an architecture requirement when you do design, I don't say it's the key to this very difficult paradigm, but at least it's making choices easier. So for example, if you don't put sovereignty as a business requirement and you want to develop your business in the cloud, what you are going to do is probably look at the available features, native features from the cloud provider, you're going to use those features full speed to go as fast as possible, as efficient as possible and get access to all the stack innovation and everything else. And the day you have a problem, you cannot switch, or it will take you five years and 500 million to switch if you take the sovereignty as a requirement by design, when you want to start the configuration of your stack, you ask yourself what do I have to concretely put here as a configuration item if I want to be for example, multi cloud compatible or multi cloud and on prem compatible, what kind of additional technologies maybe I have to use in order to be able to, I mean do some portability of some workload from one platform to another. Not because I want to do that every day because it makes no sense, but if, if tomorrow I have a problem, I want to be sure that by design I know what the process I'm going to use, what's the process I'm going to use to do that portability. So these are elements that again, if you don't design your architecture using those elements, you wake up in the morning, you have a problem and you have no solution except spending half a billion euro. So that's the first point I wanted to make. Now the second point is if you want to turn technology into a business outcome, at the end you need to be very precisely activating a technology. So at the end you have to make a choice. Yes, I activate this feature and yes I use this tech provider, this solution, at the end you don't escape. And what it also allows to do is making sure that in this architecture based design you also make explicit what you buy from a tech provider and what you do yourself. And also what you do yourself for how long as you can try a certain number of things because you are not convinced that a certain number of technology providers out there are sufficiently cross, you know, cross cloud platforms, you know, and you don't want to end up into a lock in situation. So you can say I, I'm, I don't feel that it's mature enough so I start doing it. But it's not because you start doing it yourself, that you have to be stuck in that strategy of doing it yourself for 15 years again. Even if you start doing it yourself in the design of the way you do it yourself, you plan an exit door to be able to move into a solution from a tech provider when the strategy is mature enough. So that's the difficulty. And this is everyday discussions with discipline. What I always recommend the teams is make the things explicit. There's no right or wrong answer in a limited time frame. There is something that is best today for the company and may not be the case tomorrow. So let's make it explicit and don't miss that. I mean, that extra work, because it's extra work. This is not something that is coming, really. It's not falling from the sky. This is extra work. But it's worth doing this job to be sure that at least we are always in this equilibrium, difficult equilibrium, between accessing technologies and being sovereign, compatible by design.
B
Yeah.
C
Just to stress, you saw that Jovan used the word by design all the time. Right. Because I think that intentionality is probably what's different from what we saw in the past on how companies were adopting innovation. It was very much driven by convenience and speed. And now you have to have convenience, speed and intentionality and understand that you have to have visibility on the decisions you're making and you have to keep your choices more open.
B
I was curious, when you describe the kind of challenges that come along with data sovereignty, does this alter the way that two of you work together? So I can imagine, I mean, companies, insurers have been working with IBM, I imagine for as long as there have been insurers and as long as there have been IBM. Yeah, but I mean, in this particular iteration, are we altering the nature of the relationship?
C
Before I go specifically to the partnership with axa, I'm going to give an example of what we're doing with another company, which I think illustrates very well the intention, the objective and the challenge. We have a partnership with l' Oreal as well, which is the cosmetics company. And they were like, okay, foundational models, large language models are super powerful. But I invested 100 years in my company to build knowledge about building formula for cosmetics. Right. I don't want to give that expertise, that knowledge away. So I want to train my own, my own foundational model. They were not going to do the entire stack of training by themselves. So they partner with us. We provide research, we provide tooling that allows them to bring their data and create their own model based on an open Source pre trained model. So these are the types of challenges that companies are facing. And to my point prior, what is really critical to the point that you don't want a third party to have visibility or access to and when it comes to the relationship with AXA and many other of our clients, I think number one is transparency. Right. They totally understand how our technology operates. What are the, you know, what are the elements that are part of our architecture that are going to connect with their systems and trust becomes really a fundamental element. Giovanni said, there are things that I'm going to build, there are things that I'm going to buy. So who am I going to buy from? Does this company really understand sovereignty by design? It's part of the way that they architecture their solutions. I think those are the elements and I think that's why this discussion is so important right now because it also levels the playing field for us. Right? We at IBM, we have always been a company focused on technologies for the corporate world to really implement mission critical workloads. So I think now people understand why we approach things the way we approach and why hybrid cloud, you know, giving companies the ability to access multiple providers either on prem or in the public domain. Why we have approached our technologies in that characterization is because we are starting to see the challenges of not having a multi cloud hybrid cloud strategy can actually imply to your business. So I think that this is really what changes for us now. We are much more conscious on the risks and those have to be considered when you are making technical decisions.
A
Yeah, I think, I mean, can't agree more with what you said. That's, that's, that's at the heart of the relationship between company like AXA and a strategic partner, technology partner. If that understanding is not there, there is no way we are going to rely on that strategic partner to build whatever future strategic orientation. And it's true that today we have a large variety of technologies running in production. As an insurance company like banks, we have mainframes running a lot of business. But at the same time we are full speed in the AI transformation. We have finished the cloud migration and being able to understand the full stack again, that's what is absolutely critical.
B
I had asked you earlier about was there anything particular about the insurance business when it came to this question? I want to come back to that a little bit because you know, you've both of you have talked about trust and transparency. Aren't trust and transparency pretty core considerations for an insurer? I mean, much more so than someone that's making handkerchiefs talk a little bit about, can you revisit that question?
A
Yeah, of course. I think you have a very good point. If I look at the notion of trust, as you said, insurance is about trust, the noble purpose of an insurance company. That's what I repeat every time I have the opportunity. I'm so happy every morning when I wake up because I know what I'm waking up. AXA is there to help families, companies, individuals when they face real difficulties. You know why you wake up every morning, you know why it's difficult. And this implies, as you said, the notion of trust. So of course for us, what it means, it means one, we need to make sure you are talking about data, healthcare data in your initial intervention. We need to make sure indeed we know perfectly exactly where our data are stored and what kind of data we talk about, where is it sensitive data, health data, because we need to over protect that in order to make sure that data that we have for our customers are not going to be made public. It's our duty to do that. It's again a notion of trust. Our customers trust that we do that. Insurance companies are long term companies and if you don't have trust anymore, I mean we're simply out of business. So data is an important topic. But at the same time we talked about cyber. We have a very, very strong cyber team and cyber security practice that we use both of course to protect axa, like many organizations, I mean we all do that of course, but also to help our customers protect themselves. And we have also used our skills to develop insurance products for companies to protect them against cyber risks. So that's also our duty to say not only we develop those skills but we also give that skill back via an insurance product to our customers because we want to help them. And then there's of course back to the notion of trust itself if those elements are there at the end. What we believe as an insurance company, and I agree with you, this is valid for the insurance sector in general, is that if we continue to demonstrate that we do that very seriously, our customers continue to have a lot of trust in us. And probably with the AI revolution, the ones who will be able to be better, if I can use that word, will be the ones who will be able to continuously demonstrate that they always deserve the trust that they receive from their customers. So yes, of course this is specific. I mean the specific to the insurance sector probably things also such as pharmaceutical companies, things, activities where it's very sensitive. Yeah, that's clear.
B
Let me ask the question another way. And maybe, Ana, you can jump in here. These considerations might differ from industry to industry, but can you. What about from big to small? Is this a more pressing issue for a multinational than it is for a startup?
C
I think that this applies to all the companies, right? Especially because the startups from today are not like the startups from the past, right? Everybody's scaling so fast, right? You're seeing companies going from zero to billion in like months in the current world. All the startups in general, they operate in a global, in a global footprint. So if I am a startup going into the, let's say, the healthcare, right. Industry, I'll need to follow the regulations, even if I'm a very small startup, right? So I do think that probably what is happening now is that this applies to different sizes, different industries, probably some more regulated than others. And going back to the point of Giovanni on insurance, I think insurance is probably the industry where this is much more visible because insurance is about pricing risk, right? And how do you price risk? Based on knowledge, based on probabilities. And that's all data, right? So data is their product, I would say. But every company now will have to be watching those aspects because as they scale, even if they are small, they'll need to be meeting those requirements.
B
If you were to chat with a founder who's just starting out, who came to you and said, what should I be doing about data sovereignty? What should I get right on day one, what would your advice be?
C
I think now it's much easier because when you're starting from scratch, you can really design your solutions and your applications already with all that in your mind, right? So all the points that Giovanni made before, by design, this is how you're going to design up front. Understand what industry you're operating in, understand what are the implications of the data that you are manipulating. Map the risk and the critical mission applications that you're going to develop, make sure that those are really like sovereign to the core and, you know, start the execution.
A
We have not been talking a lot about that, but if I look at Europe now, for example, encryption is very critical. When you talk sovereignty, everything you said is absolutely correct. But encrypt, that's an advice I would give, is make sure, for example, that the management of the keys is yours, is yours, and do that from day one. Don't do that, because when you do encryption, very often, that's what I was saying earlier. So you have native services, for example, coming from the cloud providers, and you can encrypt using the native Services and they store the keys, of course, that have been used to do this encryption. And it's very comfortable. You can go very, you can be very fast, but you lose control. And so that's a very simple trick that in the design very often now comes on a regular basis to say, pay attention. Of course you can use the services, but again, storing the keys, the keys are yours, then nobody can access your data.
B
This is a really interesting theme that I'd love to end on, which is it seemed like there was a moment in the evolution of technology where the trend was in the other direction, that you wanted to outsource as much as you could and just focus on a few things. But now you're talking about the importance of taking back control. Am I right? Is this a shift across a number of different dimensions when it comes to technology right now?
C
Yeah, I think technology now is so core to the business, is so central to the strategy that you really have to take it like any other major component of your supply chain. And to me that's the reason why we have this wake up moment where people understand that I need to put much more control, I need to have much more visibility.
A
The regulation itself is also creating in a way the obligation for us for certain activities to have those activities back under our control. For example, if I look at DORA regulation, what is DORA regulation telling you? Understand your key business processes, map those key business processes to your underlying technology. Check where you have concentration risks mapping again starting from your very critical business processes. And once you have identified the areas where you have concentration, which is normal, plan strategies. Right strategies, Test strategies on reversibility. And so this is a couple of years ago we were doing that on, I would say just when we were feeling that something in a specific area of the architecture was little bit strange, then we were doing a deep dive and we were very often arriving at the conclusion that probably there we need to change something. Let's change the technology, create more portability and bring the thing under control. But it was really sporadic, you know, it was not systematic with the regulation. Now it's mandatory. We are as an insurance company, we have to demonstrate every year we do the job. So you see, I think you are totally right in saying that we need to make sure we have a certain number of activities back under our control. But it's not only us deciding that. I think it's also regulation forcing us. And from that perspective, I to say this was a very good initiative.
B
Yeah. It's interesting to me that when you started Giovanni in your in this field, you were probably either down the hall or on another floor and now you have to be directly in the C suite. I mean, these are. You've, it's. Over the course of your career, you've probably gone from being marginal to being essential, which is very fascinating. I'm wondering, did you, did you anticipate that transformation a little bit?
A
Yes. Because I've always been convinced that in reality, the more the world was going to modernize and digitize, the more the technology was going to be inevitable. But again, I've not anticipated the speed of the current disruption that I've not anticipated. I was thinking about some of the statements that I was making five years ago, announcing that a certain number of elements were going to happen probably in five to ten years time frame. In the meantime, it's over. We have already another disruption and I'm not talking 50 years ago, I'm just talking five years or 10 years ago. So, yeah, I always had that feeling that technology was going to be really critical. But I have to be honest and modest, not at the level it is today.
B
Yeah. The irony of this conversation is that I over the. I've been a journalist for several decades and I realized a few months ago that my data, in which case is just interviews that, you know, interview tape and transcript was scattered across a million different places. So I did my own version of this and I hired a 21 year old to sit in my office and physically go through all my old archives. I do my own version of Malcolm Data Sovereignty is going on this summer. A lot less elaborate.
C
Good practice. Good practice. Yes, that's good.
B
But thank you very much for joining us on Smart Talks at IBM and good luck and thank you all out there for coming and listening.
C
Thank you.
B
Thank you. Smart Talks with IBM is produced by Matt Romano, Amy Gaines McQuaid, Trina Menino and Jake Harper. Engineering by Nina Byrd Lawrence. Mastering by Sarah Brugera. Music by Grammascope. Strategy by Cassidy Meyer. Smart Talks with IBM is a production of Pushkin Industries and ruby studio at iHeartMedia. To find more Pushkin podcasts, listen on the iHeartRadio app, Apple Podcasts or wherever you listen to podcasts. I'm Malcolm Gladwell. This is a paid advertisement from IBM. The conversations on this podcast don't necessarily represent IBM's positions, strategies or opinions.
Show: Smart Talks with IBM
Host: Malcolm Gladwell
Guests: Ana Paula Asis (SVP & Chair, IBM EMEA and APAC), Giovanni Daniello (Group CIO, AXA)
Date: July 28, 2026
Recorded at: VivaTech, Paris
This episode, recorded live at VivaTech in Paris, dives deep into the urgent and increasingly complex issue of digital sovereignty in the age of AI and cloud computing. Malcolm Gladwell sits down with Ana Paula Asis of IBM and Giovanni Daniello of AXA to discuss what it really means for organizations to control their technology and data—touching on regulatory shifts, the technical and operational challenges of sovereignty, the impact of AI, and the growing importance of trust and intentionality in business strategy.
[02:15 – 04:21]
Quote:
“That’s the headache. Given that there are so many dependencies, given that we are living in a world that is so interconnected, how do you gain autonomy?”
— Ana Paula Asis [02:15]
[05:02 – 07:27]
Quote:
“Very often people believe that, once you know where your data are located, you are safe. Well, it’s absolutely not enough.”
— Giovanni Daniello [05:21]
[07:27 – 11:26]
[11:26 – 15:52]
Quote:
“AI moves from just somebody operating a system to the technology actually making decisions.”
— Ana Paula Asis [12:09]
Quote:
“If you’re not careful, you can suddenly see the world around you becoming more intelligent than you on your own business.”
— Giovanni Daniello [15:33]
[15:52 – 19:15]
Quote:
“You need technology to govern the technology.”
— Ana Paula Asis [16:14]
[19:42 – 26:20]
Quote:
“I normally say that sovereignty is not about building walls, it’s about building bridges.”
— Ana Paula Asis [21:36]
Quote:
“Make the things explicit. There’s no right or wrong answer in a limited time frame... It’s extra work. But it’s worth doing to always keep this equilibrium.”
— Giovanni Daniello [24:07]
[26:20 – 30:29]
Quote:
“If that understanding is not there, there is no way we are going to rely on that strategic partner to build whatever future strategic orientation.”
— Giovanni Daniello [29:36]
[34:01 – 36:29]
Quote:
“The management of the keys is yours, and do that from day one. Don’t do that later.”
— Giovanni Daniello [36:29]
[37:40 – 41:45]
Quote:
“We need to make sure we have a certain number of activities back under our control. But it’s not only us deciding that. It’s also regulation forcing us.”
— Giovanni Daniello [38:31]
[40:21 – 41:45]
“The headache… is how do you gain autonomy? How do you get back control?”
— Ana Paula Asis [02:15]
“If you’re not careful, you can suddenly see the world around you becoming more intelligent than you on your own business.”
— Giovanni Daniello [15:33]
“Sovereignty is not about building walls, it’s about building bridges.”
— Ana Paula Asis [21:36]
“Make the things explicit… There is something that is best today for the company and may not be the case tomorrow.”
— Giovanni Daniello [24:07]
“If that understanding is not there, there is no way we are going to rely on that strategic partner to build whatever future strategic orientation.”
— Giovanni Daniello [29:36]
This episode offers clear guidance: As technology accelerates, only deliberate architecture, trusted partners, and constant vigilance can ensure control, continuity, and innovation in the digital age.