Luigi Caramico on Advancing Data Security and Encryption for the AI Era | Black Hat 2025
August 15, 2025
The Silent Threat: Why Your AI Could Be Your Biggest Security Vulnerability
September 3, 2025

Borderless AI or Local Control? Yes and yes! How Virtual Sovereign AI Changes the Game

By Ravi Srivatsav, Co-Founder and CEO of DataKrypto


As AI takes center stage in the digital realm, every organization, from governments to national banks, is caught in a tug-of-war. On one hand, they need to use powerful AI tools. On the other hand, there are data sovereignty laws saying sensitive data can never leave the country. However, regulations are inconsistent across countries and regions, leading to confusion and hindering companies’ ability to comply. As a result, Gartner predicts that by 2027, more than 40% of AI-related data breaches will be caused by the improper use of generative AI (GenAI) across borders.[1]

The result of this tension and confusion is often expensive, siloed infrastructure that keeps critical data locked down, preventing it from benefiting from the latest AI advances.

That trade-off is unnecessary – and one of the primary reasons DataKrypto has a laser-tight focus on securing AI data and models. Our FHEnom for AI solution provides an architecture for virtual sovereign AI, breaking the data sovereignty deadlock, making it possible to run AI tools anywhere in the world while ensuring your most sensitive data never leaves home soil. We specify “virtual” because sovereignty is enforced through architecture and cryptography, delivering the effect of a secure, on-premises sovereign AI facility without the physical infrastructure overhead. You get the compliance benefits of an in-country AI facility — virtually — without sacrificing global scale.

The Challenge: Sovereignty vs. Scale

Data sovereignty rules exist for a reason. Whether it is classified government intelligence, national healthcare records, or critical infrastructure data, some information is too important to risk. However, AI thrives on massive compute, and the best, most cost-efficient GPUs are not always located in your country. Traditional solutions force you into one of two bad choices:

  • Lock data into local-only AI: safe, but expensive and limited.
  • Send raw data to global clouds: scalable, but risky and often illegal.

DataKrypto’s FHEnom for AI provides a better way to keep your data safe while utilizing global AI resources.

How It Works: End-to-End Secure Processing of Sovereign Data

Every step, from local data handling to global AI computation, is designed so data is never in clear until it is decrypted by a local, authorized user:

  1. In-Country Secure Processing
    • Sensitive data enters a Trusted Execution Environment (TEE) physically located in your country.
    • The TEE handles tokenization, optional normalization, and the first aggregation layer of your model.
  2. Mathematically Non-Reversible Outputs
    • The first aggregation layer mixes information from all input tokens in a way that cannot be mathematically reversed, even if someone has the model weights.
    • No original words, numbers, or images ever leave the secure environment.
  3. Encryption and Transmission
    • Before leaving the TEE, the transformed representations are encrypted with sovereign-controlled keys.
    • Only encrypted, de-identified data moves to the global compute layer.
  4. Global AI Power Without Sovereignty Risk
    • The rest of the AI model, from Layers 2 onward, runs anywhere in the world, on the fastest and most efficient GPUs available, without ever touching raw sensitive data.
    • VSA is more than a security architecture; it’s a way to intelligently place workloads across a distributed, interconnected infrastructure network, reducing latency, optimizing cost, and meeting compliance everywhere.


Figure 1.0: Sovereign AI Architecture

Why It Is Impossible to Reverse

The first aggregation layer entangles* every input token with every other token. It is a one-way process, similar to scrambling an egg. Even with full access to the downstream model and the TEE output, it is not possible to recover the original input. Since the output is encrypted before it leaves the TEE, even a hypothetical future breakthrough in AI cannot reverse-engineer your data.

* In a transformer architecture the first aggregation layer is the Self-attention; this process each token consider and blend information from every other token, creating a context-rich, entangled representation. After this first layer, the original inputs can’t be reconstructed, ensuring privacy.

Regulatory Compliance Built In

This architecture provides technical evidence for declassification, supporting even the strictest legal frameworks.

  • Data Localization: all raw, reconstructable data stays in-country.
  • Clear Boundaries: regulators can audit exactly where sovereignty is enforced.
  • Export Safety: what leaves your borders is mathematically and cryptographically proven to be non-sensitive.

Who Benefits?

  • National Security and Intelligence: analyze classified data with global AI resources without risking leaks.
  • Financial Services Compliance: process transaction data, Know Your Customer (KYC) records, and fraud investigation logs inside sovereign boundaries; leverage global AI for anti-money laundering (AML) detection, fraud ring identification, and compliance monitoring.
  • Healthcare: keep patient data local while tapping into cutting-edge diagnostic AI.
  • Defense Supply Chain Security: keep procurement records, part specifications, and vendor lists local while using AI to detect counterfeit parts, forecast supply disruptions, and identify insider threats.
  • Critical Infrastructure: monitor, predict, and protect without moving sensitive operational data offshore.

Why Datakrypto’s Approach Is Different

Other “data sovereignty” solutions rely on masking, summarization, or local-only models, which are reversible or restrictive. No other vendor offers our unique capabilities:

  • Hardware-isolated TEEs for in-country processing.
  • Mathematically irreversible model segmentation at the transformer layer.
  • Strong encryption with sovereign key management.

The result is that you can say yes to global AI innovation without ever saying goodbye to local control.

The Future of Sovereign AI

Virtual sovereign AI goes far beyond a compliance checkbox; it offers a new way of thinking about – and benefitting from – AI infrastructure. It proves that you can meet the strictest data residency laws and still use the best AI technology available, anywhere in the world.