Nicole Reader, Head of Technology Solutions & Delivery at The Bunker (part of the Cyberfort Group), on finding a measured path forward for the future of cloud

For more than two decades, UK organisations have embraced the cloud as the default model for digital growth. Hyperscale platforms have offered flexibility, speed and a route to innovation that would once have required years of capital investment. Cloud first became the business mantra. Cloud native became the ambition. Few stopped to ask what this meant for long term control. Today that question is becoming unavoidable.

Geopolitical relationships are shifting at pace. Trade tensions, regulatory divergence and new data access laws are reshaping the digital landscape as quickly as any technological change. At the same time, businesses are generating and storing more information than ever before. AI tools, collaboration platforms and SaaS applications are accelerating data creation at a rate that is testing infrastructures, supply chains and budgets alike.

In that context, many UK organisations are starting to ask a difficult question. When we moved to the cloud, did we quietly export more control over our data than we realised? The uncomfortable answer in many cases is yes.

The Assumption of Cloud Control

A significant proportion of UK businesses rely on global services, whether hyperscalers such as Amazon Web Services and Microsoft Azure or SaaS platforms headquartered overseas. These providers are sophisticated, resilient and often highly secure. However, their global footprint means that data is frequently stored, processed or managed beyond UK borders.

The challenge is that many boards assume that if data is accessible from the UK, or if a provider has a UK presence, it remains firmly under UK control. This assumption is often incorrect.

There is a crucial difference between data location and legal jurisdiction. Data residency refers to where data is physically stored. Data sovereignty refers to which who ultimately governs access to that data. Those two concepts are not interchangeable.

Legislation such as the US Cloud Act demonstrates why this matters. Under certain circumstances, US authorities can compel US headquartered providers to provide access to data, even if that data is stored outside the United States. The geographic location of a data centre does not automatically determine who can lawfully demand access.

Boards often conflate these terms, believing that selecting a UK service resolves sovereignty concerns. In reality, the corporate structure of the provider, contractual arrangements and cross border processing activities can all shape the legal framework that applies.

This is not an abstract legal debate. It is a question of operational control, regulatory exposure and risk appetite.

The Convenience Compromise

The rise of public cloud was driven by many compelling advantages. Flexibility, scalability and rapid deployment transformed how businesses launched products and expanded into new markets. For many organisations, the cost of building and maintaining their own infrastructure was prohibitive and the hyperscalers offered an attractive alternative at a great price.

However, that convenience came with trade-offs that were not always fully understood at the time. Cloud contracts can be complex. Consumption based pricing models include ingress and egress charges. Including API calls and a range of ancillary costs that can quickly exceed initial forecasts. It is not uncommon for organisations to reach the midpoint of their financial year and discover their cloud budget has already been used.

Meanwhile, operational design decisions made years ago may not have been stress tested against today’s regulatory expectations or geopolitical realities. Many mid-market IT teams have spent the past decade maintaining estates rather than redesigning them. In some cases, institutional knowledge has not kept pace with the evolution of cloud services and their associated risks.

The result is a landscape in which data has been distributed widely, often for operational reasons, but without a holistic understanding of the sovereignty implications.

Repatriation is Not a Silver Bullet

In response, there has been a growing push towards data return and sovereign cloud offerings. European initiatives are seeking to create regional alternatives to US dominated platforms. In the UK, there have been calls by government to expand domestic data centre capacity to retain greater control over national data assets.

The instinct is understandable, particularly for government, defence and heavily regulated sectors where sovereignty can become a non-negotiable requirement. However, it would be naïve to assume that bringing data back to the UK automatically makes it secure or resilient.

Local does not necessarily mean safe. High profile breaches over the past year have affected organisations across multiple jurisdictions, regardless of where their infrastructure is hosted. Security is not guaranteed by postcode.

There are also practical constraints. Data volumes are expanding rapidly, fuelled by AI workloads and increasing digitalisation. Hardware supply chains are under pressure, with significant demand driven by hyperscale AI investments. Price volatility is already evident, with some organisations seeing substantial cost increases within weeks.

Simply building more UK data centres does not eliminate capacity constraints or environmental considerations, particularly around power and cooling.

Furthermore, many businesses rely on global platforms to serve international customers and partners. A purely national approach can undermine interoperability and performance. For most organisations, the right answer will involve a hybrid strategy rather than wholesale repatriation.

From Technical Detail to Board Level Risk

What has changed is not simply the technology, but the level at which these decisions must be made.

Data sovereignty is no longer a technical footnote for the IT department. It is a board level risk issue. Directors must understand where critical data is stored, where it is processed and which legal regimes can assert authority over it. They must assess whether current arrangements align with the organisation’s risk appetite and regulatory obligations.

This is particularly acute in sectors such as financial services, healthcare and defence, where the sensitivity of data and the scrutiny of regulators are intensifying. For these organisations, sovereignty and security are intertwined. Compromises made for convenience or short-term cost savings can carry significant long-term consequences.

Security itself must be treated as a foundational approach rather than an add on. Too often, security controls are bolted on after operational decisions have been made. Minimum standards are implemented, arbitrary certificates are obtained and compliance boxes are ticked. While certifications can provide useful benchmarks, they do not replace rigorous design and ongoing validation.

If data is brought back onshore, but not properly segregated, monitored and protected, the sovereignty objective is completely undermined. There is little value in regaining geographic control if the underlying environment remains vulnerable.

The Business Case Reality

It would be unrealistic to ignore commercial pressures. For many mid-market organisations, cost remains a primary driver of decision making. Risk appetite is frequently calibrated against budget constraints. The perfect solution is rarely affordable.

That is why compromise becomes central. The critical question is not whether to compromise, but where. Does an organisation prioritise flexibility over jurisdictional control? Does it accept higher costs to secure local hosting? Does it rely on hyperscale security capabilities while accepting overseas governance frameworks?

There is no universal answer. The correct balance depends on the nature of the data, the regulatory environment and the strategic objectives of the business. A small retail operation will have different requirements from a growing fintech or a defence contractor. Supplier selection must reflect that risk profile. Not all cloud or data centre providers are equal in capability, assurance or sector expertise.

Boards should therefore ask their providers some direct questions. Where exactly is our data stored and where is it processed? Which legal jurisdictions apply, and under what circumstances could external authorities demand access? Who within your organisation has access to data, and how is it segregated from other customers? What is the exit plan, and how do we ensure data is fully returned and deleted at the end of a contract?

These are not confrontational questions. They are governance essentials.

A Measured Path Forward

As a result the UK should not retreat from global cloud ecosystems, nor should it blindly assume that everything must be deported. The objective is not isolation, but informed control.

Where sovereignty is genuinely critical, particularly in government and national security contexts, local hosting and specialist providers may be essential. In other scenarios, public cloud may remain the most effective platform, provided its legal and operational implications are fully understood and managed.

The most significant risk today is not that UK businesses have embraced the cloud. It is that many have done so without fully mapping the sovereignty, jurisdictional and security consequences that come with relinquishing control of data.

As data volumes grow and geopolitical uncertainty continues, that gap in understanding becomes a strategic vulnerability. The cloud has delivered extraordinary value. Now all these years later, it demands a more mature conversation.

Convenience built the digital economy. Control will define its resilience.

Learn more at thebunker.net

  • Cybersecurity
  • Digital Strategy
  • Infrastructure & Cloud

Rob Vann, Chief Solutions Officer at Cyberfort, on the importance of the human factor for successful AI integration in financial services

Financial service institutions are currently navigating an increasingly complex digital landscape where opportunity and risk walk hand in hand. According to The Bank of England’s 2024 report, 75% of financial service firms are already using Artificial Intelligence (AI). Afurther 10% are planning to use AI over the next three years.

It goes without saying that the rapid uptake can be attributed to the benefits of AI for financial service firms. These include enhancing fraud detection and automating customer service, to improving risk assessment and streamlining compliance processes. Financial institutions are undeniably seeing faster, more accurate decision-making and cost saving as a result of AI integration.

However, the reality is more complicated. The same report also reveals security has emerged as the highest perceived risk of AI integration. Both now and looking three years ahead. With this in mind, banks and fintechs alike are struggling to address these immediate security concerns. As well as implementing and keeping ahead of new AI regulation. Meanwhile, also trying to prepare and anticipate what is next for AI technology. With AI becoming essential to the future of financial services, is there too much focus on technical integration and not enough on the human element?

The Current Limitations to AI Integration

While Generative AI’s (GenAI) ability to understand plain language makes it easier to use, this creates an abundance of potential security risks. Financial staff using these tools might accidentally share sensitive data when asking questions, or the AI could reveal confidential trading information if it’s not properly trained or restricted. This can also work in reverse, by continually telling the AI tool that an untrue thing is correct, the AI tool will adopt this position and present it as fact. For example, if a GenAI tool was trained that people called ‘Rob’ are always bad credit risks, it would quickly factor that into its answers irrespective of the clear (to humans) fact that it is nonsense. This of course works equally well accidentally and maliciously.

Another considerable limitation of current GenAI systems lies in how the mechanisms are set to prioritise delivering information. Unlike seasoned human financial analysts who possess the experience and time to make informed decisions, GenAI mechanisms are set to prioritise over a number of known and unknown criteria, that are not necessarily trained from that specific use to the model. For example, a user disconnecting without an answer may mean the Gen AI tool prioritises responding within a specific time frame over providing correct information. This is especially prevalent in public GenAI tools where the context and desire of the user will be different to the current question but may be applied as universal learning. Furthermore, Public GenAI rarely sees the reaction to the output, so it is unable to differentiate between the good and bad answers its given, meaning training on dumb makes the GenAI less smart, not more. 

This can lead to potentially dangerous scenarios in critical financial operations. Where the GenAI tool simply guesses or creates an answer that isn’t based on fact, potentially enabling or making the wrong decisions.

A Comprehensive Approach to AI Integration

Instead, financial services and institutions must focus on creating and adopting a comprehensive approach to AI integration and security to address these challenges and limitations.

Firstly, firms should invest in building their own AI models that follow their company’s security rules, rather than relying on unreliable public systems. If public systems are being used by staff though, setting clear rules about, and controls when using these tools, like ChatGPT, will also be essential in ensuring the safety of company information. Staff need to know what they can and can’t share, and monitoring and controls should create clear boundaries and limitations to the use of open AI models.

Companies must also train staff on how to use AI systems safely, as even the best security measures can fail if employees don’t know how to use them properly.


Finally, organisations should also use multiple AI systems that work together with human experts to double-check results, making sure no single system can make unchecked decisions without a human AI partnership.

So, what does a good human AI partnership look like?

How to Leverage Human-AI Partnerships

Finance services institutions need to recognise that the solution should focus on allowing AI and human skills to compliment each other. It isn’t just about better AI – it’s about enabling human expertise to scale efficiently.

The simple principle of “the right tool for the right job” needs to be at the forefront of users minds. A GenAI platform can search through billions of records and identify six that are anomalous in some way. A second AI platform can ask it to validate its findings against the original question. And then a human expert can identify which 4 of the 6 are expected behaviours. And which 2 are malicious, dangerous, or need further action.

In the same way as asking the human to search through billions of records manually is unachievable, asking the GenAI platform to apply context it doesn’t have or retain causal experience is equally unrealistic.

AI excels at processing vast amounts of data to recognise patterns, but humans bring crucial understanding, ethical judgment, and strategic thinking. Working in unison, taking a partnership focused approach can allow organisations to leverage both the processing power of AI and the nuanced decision-making abilities of experienced professionals.

Risk management within this partnership becomes absolutely essential. For instance, if AI flags potential money laundering, a compliance officer needs to review this before any action is taken. Or if AI suggests changes to investment portfolios based on market trends, investment managers must validate these recommendations against their market knowledge and client needs.

Banks too need clear procedures for escalation. If AI suggests unusual trading patterns, there should be a defined process for who reviews this. Whether that’s the trading desk, a separate compliance team, or even senior management. The same applies for credit decisions, fraud alerts, or risk assessments. 

The Real Risk: Avoiding AI Altogether

Interestingly, the biggest risk to financial institutions isn’t from those using AI – it’s from those avoiding it altogether. The key is finding the right balance – embracing AI’s capabilities while maintaining strong human oversight and security measures. Financial institutions must create protected data environments and train AI platforms for specific tasks with specific information. They must establish clear guidelines for AI tool usage. And conduct regular security audits to ensure their AI systems remain both effective and secure.

An AI’s development, training, utilisation and continued learning should be planned monitored and developed. This should be longside its human partner’s usage and of course the overall outputs and results.

GenAI Platform Best Practice

When building a GenAI platform, the following principles should be considered.

  1. Design it carefully, with a restricted scope and a set of agreed outcomes, how will it learn? What makes this the best learning data? And of course GenAI supervised by humans can play a big part in this.

  2. Validate its learning, tell it what’s right and wrong – a GenAI  model will learn (like a human) through mistakes. But it won’t hold the knowledge of why? Or what? So keep the feedback relevant, continuous and tight.

  3. Try to break it – ask it random things. For example, when it replies “I don’t know” tell it that’s a good answer. When it makes something up, be clear and provide feedback.

  4. Ensure the human partners understand its limitations – people don’t get to outsource their thinking. They get to participate with a low level, high volume intelligence. Make sure they know that and are checking every answer.

  5. Measure against your original outcome goals. Don’t scope creep without following the above principles. Yes it can analyse data, but it can’t think if what you’re asking is stupid or not.

  6. Enjoy the financial, time, accuracy and speed benefits of your human/ai partnership

The future of financial services lies in effective human-AI collaboration, not just AI adoption. Success requires building secure, well-trained AI systems that compliment human expertise rather than replace it. Embrace this partnership mindset while maintaining strong security measures and human oversight. Then financial institutions can harness AI’s power while mitigating its risks.

  • Artificial Intelligence in FinTech