August 12, 2026
The new Office of AI – housed within the Department of the Prime Minister and Cabinet – has shifted the sovereign AI debate in Australia from principle to policy.
This signals a more coordinated national approach to a technology increasingly viewed through an economic, security and sovereignty lens.
“The office isn’t housed in a technology agency and that’s an important differentiation – that placement tells us a lot,” observed Angela Fox, Senior Vice President and Managing Director of Australia and New Zealand (A/NZ) at Dell Technologies.
“Because the office actually sits within the Department of the Prime Minister and Cabinet, AI has moved from being a technology issue.”

Established in July – and coordinating across Australian Government agencies – the office is tasked with designing and legislating the new AI standard while also unlocking AI training in Australia.
These standards will include mandatory requirements for large AI data centres, alongside setting standards for energy and water, with strong copyright protections for Australian creators.
“I recently attended a session with the Prime Minister, and the one thing he was talking about was AI, and of course data centres – it’s now a national economic priority,” Fox said.
“That office is tasked with coordinating government policies, AI rollout, setting Australian standards and balancing risk with opportunity. That’s possibly been one of the criticisms: how do we ensure that we’ve got momentum while balancing that risk and opportunity?”
In the opinion of Fox, when a capability sits at the centre of government, the conversation “definitely changes” – it’s no longer about tools and it’s no longer just about technology.
“Government is starting to talk about infrastructure, data residency, governance and public interest,” Fox added.
According to IDC – based on research commissioned by Dell Technologies and Nvidia – 76% of government IT decision-makers in Australia consider sovereign AI as “essential” in protecting sensitive data and meeting local regulations.
As a result, 52% are “actively evaluating” sovereign AI technologies while 40% are conducting “initial testing or proof of concepts” without a defined spending plan in place.
“The intent is clearly there, but moving from that concept to deployment is where the real work begins,” Fox outlined.
“Most agencies are still very early in the journey and while we as a technology industry have often been at the forefront, this is probably one area where Australia has been a little slower to the mark.”
As a concept, sovereign AI is rapidly becoming part of the language of governments, technology providers and enterprise leaders. But agreement on its importance has arrived faster than agreement on what it actually means.
Infrastructure is part of it, as well as data, security and regulation.
At a national level, the conversation stretches further into economic policy, domestic capability and the role governments should play in ensuring their countries participate meaningfully in an AI economy increasingly shaped by enormous concentrations of compute, capital and expertise.
According to John Roese – Global Chief Technology Officer and Chief AI Officer at Dell Technologies – such ambiguity is “inevitable” because sovereign AI itself remains a relatively young concept.
“The term is fairly new – and maybe a year and a half ago, it became a term of art,” Roese explained. “The concept of sovereignty is not new, however. Every government for all of time has tried to benefit their society by creating rules and frameworks that do that.”
After engaging with governments across nations including Singapore, Japan and the UK, Roese has arrived at a relatively simple overarching definition.
“At the macro level, sovereign AI is just simply a government creating a framework to guide and ultimately benefit their society with this technology,” he added.
What sits underneath that framework is considerably more complicated. For Roese, sovereignty reaches across infrastructure, energy, data, governance, identity, security, regulation, observability and skills.
As AI moves deeper into institutions and starts doing more than generating answers, the question is increasingly about how much control governments and organisations retain over what happens next.
Roese sees three patterns playing out internationally:
The first – Government for Government – is anchored on applying AI to public services while establishing the architectures, policies and controls necessary to protect national interests. For example, the implications can stretch from healthcare to defence.
“As we move to things like autonomous warfare – which can be quite a controversial statement – having control of the entire drone system is essential,” Roese said. “Being able to not have the robot’s presence in your country and everything else somewhere else is actually a sovereignty strategy.”
The same principle applies in a very different setting.
“Having healthcare that is powered by AI but not in your environment as a government would be a bad idea,” Roese expanded.
“The concept of ‘Government for Government’ is a set of rules and frameworks that say when AI is applied for government services, we are going to create policies and structures to benefit us and to make sure that we are not creating undue risk.”
The second model is Government for Industry.
Here, sovereign AI moves into national capability. Building large-scale compute creates infrastructure that can be used by researchers, businesses and institutions, with benefits flowing beyond government itself.
Roese cited the UK as one leading example.
“The UK made a strategic decision that they will require 25 times the amount of compute in the country over the next several years to power their AI ambitions as a nation,” he said.
“Their policies are very much around how do we get there? Not how many data centres do we build for the government, but how do we do this to create at-scale compute? And I think Australia is on that journey also.”
Then comes Government with Industry.
“Singapore is probably the most advanced at this, and it’s essential,” Roese said.
“It has nothing to do with data centres or technology. It has to do with the fact that the government has a role – either good or bad – in the success of its industrial base.”

That can mean regulatory clarity, incentives, taxation or actively connecting domestic organisations with emerging technology companies and capabilities.
Roese highlighted discussions in Singapore around bringing leading indigenous businesses together with start-ups and AI companies, with government actively helping those organisations compete.
“That is absolutely a sovereignty strategy,” he advised.
“But it doesn’t mean that a country picks one of them. You might do all three but you also don’t need to do all three to have a sovereign strategy.”
At Monash University, the conversation has already progressed from definitions to construction in the form of Project MAVERIC – a $60 million investment to build and operate an advanced AI supercomputer.
The platform – Monash AdVanced Environment for Research and Intelligent Computing (MAVERIC) – launched in June and is designed to enable researchers based in Australia’s higher education sector to perform large computational projects that currently lie beyond their reach.
Developed and deployed in collaboration with Nvidia, Dell Technologies and the CDC Data Centres (CDC), the program of work aims to place the University as a leader in AI-driven research within the international higher education and research sector.
Project MAVERIC forced the University to assess what sovereign AI means when an institution starts building the capability required to deliver it.
For Dr. Amr Hassan – Director of Emerging Technologies and Program Director of Project MAVERIC at Monash University – one distinction captured much of that thinking.
“Sovereignty for us was – as you can expect being a university – not just about what the government is voting as a policy,” he said. “It was about the difference of being a tenant in someone else’s infrastructure and being able to have full control of our AI stack.”
Dr Hassan’s definition of that stack starts well below models and applications.
“When I’m talking about AI stack, I’m talking from the ground up,” he continued. “I’m talking from how is the energy going to be provided to our AI stack? What’s the impact on the environment of having this infrastructure exist?”
Those aren’t secondary considerations.
“It doesn’t make any sense for us to say that we are going to build this infrastructure to advance research and advance the community around us and increase the benefits of AI for Australia while we are impacting the environment badly while we’re building this infrastructure,” Dr Hassan added.
For Monash, control therefore extends from where infrastructure is hosted through energy, technology selection, power efficiency and cooling, before reaching the software and AI layers themselves. It also has to account for how quickly those layers are changing.
“How do you optimise this infrastructure to ensure that it’s innovative, allowing you to operate over the next four to five years with a very rapidly changing landscape of what the existing software and what the use of AI is, what the scale of AI is?” Dr Hassan asked.
“And at the same time, how can you control the security of this infrastructure and the software stack you’re going to add to it?”
That control matters because Dr Hassan sees a trust problem sitting alongside the technical challenge.
“There is a significant lack of trust in how AI is going to be used,” he said. “There is a significant lack of trust on how this technology is going to be implemented in reality, and if it’s going to really benefit the community.”
The answer isn’t simply to reassure people that infrastructure is secure. Monash needs to be able to demonstrate what will happen to the information entrusted to it.
Dr Hassan said the University must be able to tell data providers and collaborators across industry, government and healthcare that “their data will be safe, their data will be secure, it will be only used for the purpose that this data was collected for.”
“It’s going to be de-identified before we can actually use it for other activities as well,” he explained.
“We are not going to break the privacy laws or the access laws within Australia. Effectively, we are going to use AI in our own terms within the Australian law.”
For Dr Hassan, that confidence doesn’t merely protect information. It creates the conditions for more information to be used.
“This was critical to be able to unlock a significant amount of datasets available in Australia to the benefit of the community without having the side effect of being exported overseas or being used by someone else,” he added.
That distinction matters because governance in this context isn’t only a brake applied to AI – it can be what allows valuable data to enter the system in the first place.
AI infrastructure is visible while data readiness is often much less so. Because of this, many organisations can underestimate how difficult the latter becomes once AI starts moving beyond isolated experimentation.
“The main challenge that faces businesses is how to correctly classify data, how to understand which data they are allowed to use, and which data they are not allowed to use, and for which purposes,” Dr Hassan said.

Then comes the critical question of: “How we can actually transform this data into a useful outcome with the AI infrastructure that we have to generate a good return of investment?”
Monash deliberately avoided building an entirely separate governance universe around AI. The University already has ethics approval, research approval and data governance processes.
Instead, Dr Hassan’s team looked at how those controls could be adapted rather than discarded.
“We intentionally, from the beginning, tried to avoid reinventing the wheel,” he clarified.
“Rather than trying to create new processes just for this purpose, we looked into these processes to see how we could actually adjust and reuse these processes in order to be able to use it for AI as well. I wouldn’t say that was an easy journey, and I wouldn’t say that we reached the destination yet. It’s still a work in progress.”
Having control across the environment means those established principles can follow the data through the AI process.
“Since the data is coming to the system, you can effectively ensure that the guardrails, guidance and compliance are going to be applied for the process from the beginning,” Dr Hassan continued.
In parallel, Roese sees much the same opportunity at an enterprise level.
“I don’t think you have to reinvent the wheel,” he said. “But if you don’t have any data management hygiene, you have to create one.”
Dell applied such thinking when rolling out its own internal agent platforms.
“One of our requirements is all data that is used by an agent must be consumed as data products,” Roese said. “We were very specific about that, which meant that the data, primary data, went nowhere near the agent.”
Instead, the data remained where it belonged and was exposed through a governed architecture.
“It exists somewhere,” Roese added. “It was emitted through a data mesh. It was described as a data product. It was consumed over an API.”
The benefit was control.
“What that gave me is strong governance,” Roese explained. “I could explicitly decide what data got to that agent or not, and the agent didn’t have any override capability.”
Organisations with existing data governance can therefore extend those controls into AI rather than treating AI as a separate world.
“At the end of the day, the same data that you use for non-AI things will likely be used by agents and other AI things, and having a common control around it is absolutely necessary,” Roese expanded.
When asked to identify one priority for organisations strengthening their sovereign AI posture, Dr Hassan returned immediately to the same issue.
“If I have to select one, focus on your data because people don’t know what data they have,” he advised.
Once years of datasets have accumulated across different systems, departments and environments, creating coherent control over them can prove harder than standing up the infrastructure designed to consume them.
“While building an AI factory or sovereign AI is difficult – I’m not saying for a second it’s easy – understanding your data and having this identity system in place is much harder,” Dr Hassan said.
Data provides one control point but agentic AI introduces another. Agents don’t simply consume information, they can increasingly perform work across distributed systems, which changes what organisations need to know about the AI operating on their behalf.
In response, Roese placed identity at the centre.
“Probably the single largest security and risk mitigation mechanism that you have in agents is identity,” he said.
“Agents do work. That work is done in distributed fashion. Some of the agents do it in your environment. Some do it somewhere else.”
Wherever that activity occurs, an agent needs authority to perform it.
“If you control the digital identity, the actual core of security, and the only way for an agent to exist – whether it’s in your environment or elsewhere, and do work on your behalf – is you issuing them a digital identity, then you immediately have a control point,” Roese advised.
“You have a kill switch.”

Identity then provides the basis for controlling exactly what an agent is permitted to do.
“Once you issue identity, it usually correlates to authorisation, and so now you have the basis to start to describe fine-grain authorisation, token-based authorisation, so every API call, every MCP (model context protocol) interface can actually be defined and governed,” Roese added.
Roese connected that directly to emerging regulatory requirements.
“It turns out if you get identity correct, you have a kill switch for agents,” he said. “That’s what we’ve implemented, and that’s what many businesses are moving towards.”
But stopping an agent and understanding an agent are different problems. The second is considerably less mature.
“We also don’t have mature telemetry frameworks for agentic or AI systems in general,” Roese acknowledged.
“We have plenty of telemetry tools, but as they become more complex, monitoring an agent is more than knowing it exists, or knowing what its performance is, or how many tokens it’s used.
“You have to understand its behaviour. You have to understand drift. You have to understand biases.”
The level of visibility required is therefore fundamentally different from conventional application monitoring.
“To fully understand and control it, you do actually have to see a lot more than you’ve ever seen into an application,” Roese said.
No single framework yet provides Dell everything Roese believes it needs.
“There isn’t really a unified framework in the industry,” he said. “There are standards like OTel that control the protocol of moving data, but they don’t describe what I just described.”
Dell is combining different technologies instead.
“Even at Dell, we are actually using multiple telemetry tools, put together in a framework, to get to a place where we feel comfortable that we have the right visibility,” Roese explained.
The maturity varies noticeably between the different control layers.
“Identity is maturing very nicely, and data governance is something that I think we can make work, and we have a lot of strong foundation,” Roese said. “Telemetry, we have kind of a weaker foundation, and we’ve never done this before.”
Whatever future sovereign AI regulation ultimately looks like, Roese believes organisations will repeatedly be forced to answer the same fundamental questions.
“You need to be able to control what agents exist and what they do,” he said.
“You need to be able to know what they are doing, and you need to know what the data access they have. So, regardless of what rule gets applied to you, you’re going to have to answer those questions.”
Infrastructure can be funded, governance frameworks can be designed and technology can be acquired. The people required to make all of that work are harder to produce, however.
“The skills needed to do most AI projects are not available in abundance right now,” Roese said. “But they are creatable Most of the people inside of Dell that do AI engineering today were created inside of Dell. We didn’t hire them, we built them.”
The company has also used approaches including paired programming and dojo models to transfer emerging skills between people.
“When a new skill is required, you find people who have that skill,” Roese added.
“You create a methodology around it. You bring people who have aptitude but not that skill to work with them on the common projects. They do a few rounds of projects, and suddenly you have more people who can do that skill.”
The problem is speed and scale.
“We probably are not going to sufficiently staff the number of humans that we’re going to need to do this work through just that mechanism,” Roese accepted.
Nor does Roese believe the conventional career ladder will solve it quickly enough.
“To become a super user, you need deep institutional knowledge and very good AI skills, and that takes a long time in the traditional career ladder,” he said.

That has pushed him towards a deliberately unconventional experiment.
“About a month ago, I launched an apprenticing program for AI,” he said. “It’s not broad but I’m trying to experiment all kinds of places.”
Roese took some of Dell’s senior distinguished engineers – among the company’s most experienced AI experts and individuals who would not normally manage teams – and gave each of them two junior technical hires.
“I said, you own them for two years, maybe three,” he shared.
“But at the end of that cycle, I want them to be able to do your job. You need to turn them into you. I didn’t tell them how to do it. I didn’t give them a guidebook. I didn’t create a big program.
“I can’t wait for the world to figure this out because I’m going to need more of these people, and the only way I know will work is taking people with high aptitude and putting them right into the fire with people who know how to do this job.”
Roese is realistic about its limitations.
“I don’t think that will scale,” he stated. “I think it will have all kinds of challenges but it will produce marginally more AI superusers in that time frame.
“Apprenticing as a concept has fallen out of favour in the white-collar jobs. I actually see it as one of the fastest paths to create more people that can do this, and so I’m being contrarian and just going and doing it.”
The stakes extend beyond filling AI vacancies.
“I think sovereign strategies will actually collapse and fail to execute if you cannot build the talent base,” Roese added. “This is probably the single most significant risk that we’re facing.”
Monash encountered its own version of the same skilling problem while building MAVERIC.
“For Monash, the problem is triple,” Dr Hassan said.
The University must prepare graduates for an AI-shaped economy, equip researchers to use new infrastructure effectively and develop the technical workforce required to build and operate that capability.
“Being able to train them and enable them and ensure that they are first-class citizens when it comes to use AI, that’s very critical and important for us as a University,” Hassan said.
The second challenge is researchers.
“Part of what MAVERIC is doing is to – not only to have the technical capability in place – but to have the handholding and also the infrastructure and the training programs that will allow our researchers to be able to use this infrastructure and be able to transform what they are doing in terms of research,” Dr Hassan outlined.
The MAVERIC team itself demonstrated how existing capability can be developed.
“We have 50% of the team who are actually existing Monash staff, and because of capacity, not because of the capability, we have to hire the remaining team,” Hassan said.
“As long as we have a good architecture, have a good vision and a strategy about what we want to do, the remainder of the skill set is teachable and people can start growing with it. AI helped because being able to use the technology in your hand in order to be able to accelerate people jumping from level zero to level 100 in this case in a very short amount of time was very useful.”
Previously, learning depended heavily on an individual’s existing experience, what they could find online and what they could extract from books.
“You don’t need to do this anymore for some of these capabilities,” Dr Hassan said. “You can actually use AI agents and the AI capability you are building to help them in order to build the system.”
Roese has reached much the same conclusion inside Dell.
“One of the things we don’t do anymore when we roll out new technology or new program inside of a company – we don’t create any manuals,” he said. “We don’t really even create training in the traditional sense.”

Instead, Dell distils the knowledge surrounding a project and makes it accessible through AI. A person entering the project no longer has to hunt for institutional knowledge scattered across different sources.
“They go to one thing, and all information and everything we know is there, including agents that can do work on their behalf,” Roese added. “That gets them up to speed much faster, so they build the institutional knowledge, and it closes the gap.”
In this context, Roese’s message to the public and private sectors of Australia is simple – “don’t think AI is just the problem. It’s actually part of the solution here.”
The task ahead remains substantial, however.
“We have to re-engineer the entire workforce over the next several years, potentially, and that will require creativity and effort and a lot of change,” Roese qualified.
All AI decisions eventually meet regulation. For Roese, the problem isn’t a shortage of rules – as a Chief AI Officer of a global multinational company, he alone has more than 1,000 jurisdictions sharing different AI policies.
“They don’t talk to each other and they’re not coherent,” he noted.
“Businesses will not be able to navigate the regulatory frameworks of AI today. I don’t say ignore them, but don’t take them literally. Go find a grounding framework and adopt that framework.”
Roese referenced the NIST and European Union frameworks as examples.
“They have these meta frameworks,” he outlined. “They’re not specific rules. They just describe what good is, and they give you guardrails.”
Dell has effectively accepted that perfect alignment with every emerging AI regime is unrealistic.
“I can’t literally comply with anything because they’re all in conflict with each other,” Roese said. “But I can put these core principles in place and use them as my guardrails.”
This recommendation is pragmatic for an industry inundated with regulation and frameworks.
“Do not try to chase 1,000 regulatory regimes,” Roese advised. “Figure out what good is, implement that, and hope the regulatory regimes settle down over time.”
For all the infrastructure being built and regulation being written around sovereign AI, Dr Hassan’s starting point is considerably more immediate – “focus on your data.”
Roese approached the same problem from the other direction. With technology changing faster than policy can reasonably follow it, organisations require principles capable of surviving whatever architecture comes next.
“Figure out what good is, implement that,” he recommended.
One starts with what organisations already possess while the other starts with deciding how they intend to govern it. The increasingly complicated territory between those two decisions is where sovereign AI is now being built.
Angela Fox, John Roese and Dr. Amr Hassan shared insights in the session – Sovereign AI: Owning Your Data and Driving Innovation – at Dell Technologies Forum in Sydney.
Inform your opinion with executive guidance, in-depth analysis and business commentary.