Photo by Kindel Media on Pexels
The Sovereignty Problem That Nobody Planned For
For years, data sovereignty debates have centered on a relatively straightforward question: where is the data stored? Regulators from Brussels to Beijing have built entire legislative frameworks — GDPR, China’s Data Security Law, India’s Digital Personal Data Protection Act — around the premise that controlling the location of data means controlling the data itself. But a new class of technology is quietly dismantling that assumption, and the telecom industry is sitting squarely at the intersection of the crisis.
Physical AI — the umbrella term for AI systems embedded in real-world hardware like autonomous vehicles, delivery robots, connected drones, and smart manufacturing equipment — doesn’t just generate data. It generates data while moving. And when that hardware crosses a national border, the question of who owns, processes, and can intercept that data stream becomes exponentially more complex.
The challenge isn’t hypothetical. Cross-border autonomous freight is already operating in parts of Europe and Southeast Asia. Connected vehicle fleets routinely traverse multiple jurisdictions within a single delivery cycle. Industrial robots in global manufacturing supply chains maintain persistent cloud connections that span continents. Every one of these systems is punching holes through existing sovereignty frameworks with every kilometer traveled.
Why Traditional Roaming Architectures Fall Short
The telecom industry’s existing answer to cross-border connectivity — international roaming — was designed for a very different era. When a smartphone user crosses from France into Germany, their device hands off to a local network operator, their data may briefly traverse international routing infrastructure, and their carrier settles the wholesale charges through established inter-operator agreements. The user barely notices. Regulators largely look the other way.
Physical AI systems operate on an entirely different level of sensitivity. An autonomous vehicle’s real-time sensor fusion — combining LiDAR point clouds, camera feeds, GPS telemetry, and V2X communication data — can reveal critical infrastructure vulnerabilities, military facility locations, crowd density patterns, and behavioral data about entire populations. This isn’t metadata. It’s a continuously updated, high-resolution map of the physical world, transmitted in near-real-time over whatever network happens to be available.
Current roaming agreements provide zero framework for governing what a foreign network operator can access, log, or share with their national intelligence apparatus when routing this kind of data. The visited network has full visibility into the traffic passing through its infrastructure — a reality that existing regulatory models were never designed to address.
The eSIM Dimension
The proliferation of eSIM and iSIM technology in IoT and connected devices has added another layer of complexity. Unlike traditional SIM-based roaming, eSIM-enabled devices can dynamically switch operators mid-journey, potentially shifting their data through multiple network jurisdictions within minutes. For regulators attempting to apply data residency requirements, this creates a near-impossible enforcement scenario. The device — and its data stream — may technically never “reside” in any single network long enough to trigger existing compliance thresholds.
Defining “Network Sovereignty” for the Physical AI Era
The concept gaining traction in telecom policy circles is “network sovereignty” — a framework that extends governance rights beyond data storage to encompass the entire connectivity layer through which physical AI systems operate. Rather than asking only “where is the data?”, network sovereignty asks: “who controls the pipe, who can see the flow, and under what legal framework can that access be compelled?”
This reframing has profound implications for how operators architect their international connectivity services. Multi-network operators offering global IoT connectivity — particularly those serving automotive OEMs, logistics companies, and industrial automation clients — are already facing pressure to demonstrate that their network routing decisions respect national sovereignty requirements. That means not just complying with data localization laws, but actively engineering connectivity paths that avoid routing sensitive traffic through jurisdictions where legal intercept risks are deemed unacceptable to the customer.
For mobile network operators and MVNOs serving the physical AI segment, this translates into a tangible product differentiation opportunity. The ability to offer “sovereignty-aware” connectivity — with granular control over which networks carry which traffic types, supported by audit trails and contractual guarantees — is rapidly becoming a procurement requirement rather than a nice-to-have.
The Regulatory Gap in Numbers
The scale of the coming challenge is significant. Industry analysts project that the number of connected vehicles alone will exceed 400 million globally by 2030, with autonomous and semi-autonomous systems accounting for a growing share. Add in an estimated 1.5 billion industrial IoT devices expected to be operational by the same year, and the volume of cross-border physical AI connectivity events will dwarf anything the current regulatory architecture was designed to handle.
What Operators and Regulators Must Do Now
Bridging the network sovereignty gap will require parallel action on multiple fronts. For regulators, the priority should be updating bilateral and multilateral telecommunications agreements to explicitly cover physical AI data flows, with specific provisions around real-time sensor data, AI model updates transmitted over-the-air, and the obligations of visited network operators when handling traffic from foreign autonomous systems.
For telecom operators, the imperative is architectural. Building network slicing capabilities that can enforce jurisdiction-aware routing policies, investing in edge computing infrastructure that can process and anonymize sensitive data locally before it traverses international links, and developing transparent audit mechanisms for enterprise customers will be foundational requirements for competing in the physical AI connectivity market.
Standards bodies including 3GPP and ETSI are beginning to acknowledge the issue within their working groups, but formal standards that address sovereignty-aware network management remain nascent. The industry cannot afford to wait for standards to mature before building operational frameworks.
The Road Ahead
Physical AI is not a future concern — it is a present reality that is already exposing the seams in a global connectivity architecture built for a different era. The telecom operators that recognize network sovereignty as a core service dimension, rather than a compliance footnote, will be positioned to capture the premium connectivity contracts that physical AI deployments demand. Those that don’t may find themselves locked out of one of the decade’s most consequential growth markets — or worse, implicated in the sovereignty violations that will inevitably trigger the next wave of international telecommunications regulation.
The borders haven’t moved. But the machines crossing them have changed everything.
