Core42’s Rajeev Nair on how AI governance, security are moving into the infrastructure layer
As AI moves deeper into critical services, Core42’s Rajeev Nair says governance, sovereignty and cyber resilience will increasingly need to be engineered into the systems supporting it
16 September, 2026
TT
16
Artificial intelligence is moving rapidly from experimentation to production, raising new questions about security, governance, and control. For governments, financial institutions and other regulated sectors, the challenge is no longer where data is stored, but how AI models, compute, infrastructure and access are governed as systems become more autonomous and critical to daily operations.
Rajeev Nair, SVP for Special Projects at Core42, explains how the company sees AI infrastructure and cybersecurity converging, why agentic AI will put greater pressure on governance frameworks, and how sovereign cloud models could shape the next phase of AI deployment in the UAE and beyond.
Tell us about your participation at GISEC Global this year.
GISEC Global is one of the region’s most important cybersecurity events, and our participation this year reflects how closely cybersecurity, digitally enabled sovereignty and AI are becoming interconnected.
A key focus for Core42 will be announcing new strategic collaborations with the National Regulator, government and regulated-sector organisations that strengthen the ecosystem to support the UAE’s broader digital transformation ambitions.
Core42 is participating to demonstrate how sovereign cloud infrastructure and cyber-resilience can come together to address the requirements of highly sensitive and regulated environments.
Together with our sister company, CPX, we are bringing the digital sovereignty story to life by helping governments and enterprises retain greater control over their critical data, infrastructure and operations while continuing to access the scale and innovation they need.
Central to our presence will be Core42’s Signature Private Cloud, designed for Secret and Top Secret data, Sovereign AI orchestration and mission-critical workloads. It combines data, operational and technology-enabled sovereignty with classified-grade security, bringing together the scalability of cloud with the control and assurance required by government, critical infrastructure and regulated sectors.
GISEC also gives us an important platform to engage with customers, partners and government stakeholders on how digital sovereignty is evolving beyond compliance into an operating model for resilience, security and control.
The UAE is fast becoming a hub for developing the technologies that defend it, and at GISEC we’re excited to show how home-grown capability strengthens security across the region.
As AI moves from experimentation into production and becomes embedded in critical services, those foundations will become increasingly important to how organisations in the UAE adopt and scale Cloud and AI securely.
How do you see digital sovereignty and national cybersecurity resilience connecting?
Digital-enabled sovereignty and national cybersecurity resilience are increasingly inseparable because resilience ultimately depends on control. For governments and regulated sectors, understanding where data is stored is only one part of the equation. They also need clarity over who can access and operate the infrastructure, which jurisdiction applies, how policies are enforced, and whether services can continue securely through disruption.
This is why digital and data sovereignty have moved beyond data residency. It now encompasses control over data, operations and technology, and as AI adoption grows, that extends to models, compute and inference as well. Security must therefore be engineered into the infrastructure from the outset, with strong access controls, zero-trust architecture, continuous compliance, auditability and resilience built into the operating environment.
For national infrastructure, sovereignty enables control over the digital environment, while cybersecurity protects and reinforces that control. Together, they provide the resilience needed to operate government services, critical infrastructure and increasingly AI-driven systems securely and at scale.
What trends are you anticipating will govern AI in the next few years?
One of the biggest shifts will be from policy-based AI governance to governance and sovereignty controls built directly into AI systems and infrastructure. As AI moves into production, organisations will need controls that can be continuously enforced, monitored and audited, rather than relying on periodic compliance exercises.
Accountability will also become increasingly important as agentic AI gains greater autonomy. Governance will need to extend beyond model and data safety to address how agents behave, how decisions are traced, as well as who remains accountable for outcomes.
Gartner predicts that by 2027, 40 per cent of enterprises will demote or decommission their autonomous AI agents because of governance gaps that only surface after a production incident. This reinforces the need for stronger governance if agentic AI is to move successfully from experimentation to deployment at scale. We also expect governance frameworks to align more closely with international standards, while remaining adaptable to local requirements so compliance is built in from the outset.
Resilience will be another defining priority. Once AI supports public services, financial systems and other critical operations, performance alone will not be enough. Organisations will increasingly assess AI environments on their ability to operate securely, reliably and at scale while maintaining governance and sovereignty controls.
Where do you see AI infrastructure and cybersecurity heading in the next few years?
The distinction between AI infrastructure and cybersecurity will continue to narrow as security, sovereignty and resilience become fundamental requirements of the infrastructure itself rather than separate layers added after deployment.
AI is already becoming part of critical government services and regulated industries, including financial services, where systems need to operate reliably every day and at scale. Once AI supports these environments, downtime, cyber disruption, data loss, or governance failures can have significant operational consequences. Resilience therefore becomes essential, with secure architecture, redundancy, governance and recovery capabilities designed into the environment from the outset.
In the UAE, we are already seeing this at scale through sovereign-enabled infrastructure supporting more than 11 million daily digital interactions for Abu Dhabi Government and a sovereign-enabled financial cloud for the Central Bank of the UAE.
Governance will increasingly need to operate in the same way. Rather than relying only on policies and periodic compliance checks, organisations will need greater visibility into how requirements are applied across their infrastructure. Core42’s Insight application, for example, maps regulatory requirements to technical controls, enabling customers to understand what applies to their workloads and how those controls are being implemented.
AI infrastructure itself will also become more heterogeneous. Training, fine-tuning, inference, agentic systems and real-time applications have different requirements around performance, latency, cost and energy efficiency. Organisations will increasingly want the flexibility to match workloads to the right infrastructure rather than being locked into a single architecture or technology roadmap.
What is the anticipated growth of the AI and data sovereignty industry in the next few years?
We are seeing two fast-growing markets converge — AI infrastructure and sovereign-enabled cloud. According to data from Grand View Research (GVR), the UAE’s AI ecosystem is projected to reach approximately Dhs170bn, or around $46bn, by 2030, reflecting the scale of investment in AI infrastructure, adoption and capability development.
At the same time, Gartner forecasts the global sovereign cloud IaaS market to grow at a CAGR of 36 per cent, reaching $169bn by FY2028. This reflects a broader shift as governments and regulated industries seek the benefits of AI while retaining greater control over data, workloads and infrastructure.
With AI expected to contribute around 14 per cent of the UAE’s GDP by 2030, the need for secure, resilient and sovereign infrastructure will only become more important.
As AI becomes more deeply embedded in regulated industries and critical national systems, digital sovereignty will increasingly become part of the infrastructure decision itself.
Sovereign-enabled AI and sovereign-enabled cloud will therefore move further into the mainstream, with organisations looking to combine scale and innovation with security, governance, resilience and jurisdictional control.





















