Navigating geopolitics for control of data in the AI era
With AI advancing faster than rule books, measures that are now voluntary could become mandatory; it’s happening in South Korea
ARTIFICIAL intelligence (AI) is reshaping the global balance of power, compelling countries and regions to confront new risks and opportunities in data governance. In the Asia-Pacific, a patchwork of national data regulations has created digital fault lines.
While many nations have historically favoured flexible guidelines, the landscape is shifting rapidly. South Korea has emerged as a regional leader by enacting the AI Basic Act, the first comprehensive AI law in Asia, which took effect in the country from January 2026.
Regulatory volatility and geopolitical uncertainty have brought to the fore concerns around data sovereignty. In essence, data sovereignty determines who holds the authority to manage, access and use data in today’s increasingly interconnected, data-driven environment.
A recent survey jointly conducted by Pure Storage and the University of Technology Sydney (UTS) found that all global leaders are already rethinking where they store data amid sovereignty risks, including potential service disruption.
While the principle of data sovereignty may seem straightforward, its implementation and implications are anything but. In the digital economy, losing control of data means a lack of control within the business.
Beyond escalating regulatory fines, inaction can cause irreparable reputational damage and loss of customer trust. Knowing how to navigate the delicate balance between borderless innovation and strict mandates on data location, transparency and infrastructure control is now imperative for success in the AI era.
Managing risk amid shifting regional standards
Most Asia-Pacific markets, including Singapore, Japan and Australia, have so far favoured principles-based, non-binding AI guidelines.
However, South Korea’s AI Basic Act marks a significant move towards more prescriptive regulation. Under this new framework, “high-impact” AI applications such as those used in critical sectors like healthcare, energy, recruitment and public decision-making will face stringent oversight.
Under the Act, businesses operating in South Korea must:
- demonstrate adequate risk assessment and mitigation processes throughout the AI life cycle;
- ensure meaningful human oversight and supervision of high-impact systems;
- maintain transparency by notifying users when they are interacting with AI-powered services; and
- implement clear labelling for generative AI outputs, including the use of watermarks for “deepfake” content to prevent deception.
Evolving legislation demands an intentional approach to risk assessment, anchored in a clear, forward-looking data strategy. This strategy should define where data resides and how it is managed, guided by metrics like sensitivity of data, type of personal information, downstream impact and potential for re-identification.
South Korea’s AI Basic Act will serve as a regional bellwether, signalling an end to the “soft law” era in the Asia-Pacific. As the Act applies to any entity with an impact on the South Korean market, businesses can no longer rely on voluntary compliance.
This shift will likely force a “highest common denominator” approach, under which organisations adopt South Korea’s stricter standards as a baseline for the entire region to ensure seamless cross-border operations.
Architecting for geopolitical agility
No single technology stack can meet every jurisdictional requirement, especially as AI advances faster than rule books. Measures that are voluntary in the Asia-Pacific today could quickly become mandatory; South Korea’s proactive stance is an example.
Like the European Union’s regulations, South Korea’s AI Basic Act has extraterritorial scope, potentially applying to Asia-Pacific-based organisations if their AI services affect the South Korean market or use the data of its residents.
Escalating regulatory and geopolitical uncertainty demands architectural flexibility. Incorporating data portability, advanced encryption and comprehensive governance in the data architecture ensures that sensitive workloads are able to shift seamlessly between public, private and sovereign environments without compromising security or regulatory compliance.
This empowers organisations to unify disparate resources, apply policy consistently across their entire data estate and safeguard technical sovereignty, while continuing to harness the efficiencies of global cloud ecosystems.
Ultimately, a resilient AI and data future depends on visibility, control and automation of massive data sets. These are the foundation of any compliant and agile architecture, ensuring that organisations can adapt quickly to shifting regulatory, operational and sovereignty requirements, while continuing to innovate with confidence.
The writer is vice-president and general manager for Asia-Pacific and Japan at Pure Storage