Analysis by
Founder, Lex Wire Journal • Technology, Governance & Sovereignty Strategist
Owning the Data May No Longer Mean Controlling Its Value
For much of the digital era, information governance has revolved around a familiar set of questions: Who owns the data? Who can access it? Where is it stored? How is it protected? And what rights does an organization retain when a technology relationship ends?
Artificial intelligence does not make those questions obsolete. It makes them incomplete.
AI systems increasingly sit between an organization and its own information. They search it, classify it, connect it, summarize it, generate from it, and help people decide what the information means and what to do next.
As a result, the practical value of information can increasingly depend on technological capabilities that are distinct from the information itself.
The Bottom Line
AI is widening the distinction between ownership of information and control over what can be learned, generated, and done with it. An organization may retain legal rights in its data while depending on someone else’s models, infrastructure, interfaces, and computational systems to transform that data into useful intelligence. In the AI era, meaningful information ownership increasingly requires examining both legal rights and technological control.
This is not an argument that artificial intelligence has created a new universal legal definition of ownership. Property, intellectual property, contract, privacy, confidentiality, and other bodies of law continue to determine legal rights in different forms of information and technology.
The issue is more fundamental. Formal rights and practical capabilities do not always reside in the same place.
“The law may tell us who owns the information. Architecture increasingly determines what the owner can actually do with it.”
Jeff Howell, Sovereignty & Law
The Difference Between Data and Intelligence
The distinction begins with something deceptively simple: information and the capability to understand information are not the same thing.
An organization may possess millions of documents, messages, transactions, research files, customer interactions, contracts, matter histories, policies, and other records. Those materials can have substantial value on their own. But their usefulness increases when the organization can identify relationships among them, retrieve relevant knowledge, recognize patterns, synthesize prior experience, and apply that knowledge to new problems.
As explored in the previous Sovereignty & Law analysis, Who Controls the Intelligence? The Hidden Governance Question Behind Enterprise AI, artificial intelligence increasingly performs part of that interpretive function. Models, retrieval systems, indexes, embeddings, permissions, integrations, workflows, and interfaces can collectively form an intelligence layer between an organization and its accumulated information.
That layer may contain components controlled by different parties. The organization may own the source documents. A cloud provider may operate the infrastructure. One company may provide the model. Another may provide the application through which employees interact with it. Integrations may connect additional systems, while contractual terms govern how information and outputs can be used.
The question of control therefore becomes distributed across an architecture rather than answered by a single ownership clause.
Ownership Has Never Been the Same as Possession, Access, or Control
Law already recognizes that different rights and forms of control can coexist around the same information or asset.
A party can possess information it does not own. A service provider can have authorized access to confidential information without acquiring ownership of it. Intellectual property may be licensed while ownership remains elsewhere. Contracts can allocate rights to access, use, process, retain, disclose, or delete information without transferring every associated legal interest.
AI adds technological capability to this already layered structure.
An organization may retain contractual rights to its information while another party controls critical infrastructure required to interpret that information at scale. The resulting issue is not necessarily a dispute about legal title. It is a question about the relationship between formal rights and practical agency.
That relationship connects directly to the problem examined in The Age of Digital Dependence: Why Technological Sovereignty Is Becoming a Legal Issue. Dependence is not inherently undesirable. The sovereignty question emerges when dependence materially affects the ability of an individual or institution to act independently when necessary.
AI Adds a New Layer Between Information and Use
Consider what happens when an organization connects an AI system to years of accumulated institutional information.
The source materials remain important. But the usefulness of the system can also depend on how information is indexed, how relevant material is retrieved, which models process it, what context is supplied, how permissions are structured, how prompts and workflows are designed, and how the resulting capability integrates with the organization’s operations.
Those layers can become increasingly valuable as the system improves and employees incorporate it into their work.
NIST’s Generative Artificial Intelligence Profile recognizes the complexity created when organizations acquire, embed, incorporate, or use proprietary or open-source third-party AI models and systems. NIST specifically identifies third-party considerations involving areas such as intellectual property, data privacy, information security, acquisition, procurement, and transparency.
The significance is broader than risk management. It illustrates how enterprise AI can consist of multiple technological and contractual layers controlled by different actors.
“If you can possess your data but cannot reproduce the intelligence built around it, ownership and control have begun to separate.”
Jeff Howell, Sovereignty & Law
The Contract Says You Own the Data. Then What?
A contractual provision confirming that the customer retains ownership of its data can be important. But from a technological sovereignty perspective, it is the beginning of the inquiry rather than the end.
An organization evaluating an AI relationship may also need to ask what happens operationally if it decides to leave.
Can the underlying information be exported in a usable form?
Will metadata, relationships, permissions, and organizational structure survive the export?
Can another model or system operate effectively on the exported information?
What happens to indexes, embeddings, configurations, integrations, and workflows?
Can accumulated institutional knowledge be reconstructed elsewhere?
How much capability disappears when access to the provider disappears?
These questions do not determine legal ownership by themselves. They determine something different: whether ownership can be exercised with meaningful independence from the existing technological relationship.
Portability Is Becoming Part of the Practical Ownership Question
This makes portability increasingly important.
Portability does not mean that every system must be interchangeable or that switching providers should be effortless. Sophisticated technology naturally creates implementation costs, specialized configurations, integrations, and operational dependencies.
But there is a meaningful difference between a system that is difficult to leave and one that cannot realistically be left without surrendering an organization’s accumulated capability.
The distinction matters because freedom of contract has practical value only when alternatives can actually be exercised. A theoretical right to terminate a service does not necessarily restore the knowledge architecture that developed around that service.
The ability to retrieve your information is important. The ability to preserve what your organization has learned to do with that information may become equally important.
Law Firms Provide a Useful Test Case
The legal profession makes the distinction particularly visible.
A law firm’s information can include client files, privileged communications, legal research, briefs, contracts, discovery, deposition transcripts, internal work product, matter histories, attorney knowledge, and decades of accumulated experience.
An AI system connected to that information can potentially make the firm’s accumulated knowledge substantially easier to search, synthesize, and reuse. Over time, the firm’s lawyers may begin relying on that capability to understand what the firm already knows.
Yet professional responsibility remains with the lawyers and the firm. ABA Formal Opinion 512 on generative artificial intelligence makes clear that lawyers using generative AI remain subject to established ethical duties, including competence, confidentiality, communication, supervision, candor, and reasonable fees.
That creates an important asymmetry. A law firm can remain responsible for protecting information and exercising professional judgment while relying on technological systems it does not fully control to interpret and operationalize increasing amounts of its institutional knowledge.
The issue is therefore larger than whether an AI provider contractually agrees that the firm owns its documents. Firms increasingly need to understand what parts of their knowledge architecture remain under their control, what can be moved, what can be independently accessed, and what would have to be rebuilt if the underlying technology changed.
From Data Control to Intelligence Sovereignty
The language around data sovereignty requires some care.
In technology and policy discussions, data sovereignty commonly refers to the principle that data is subject to the laws and governance requirements of the jurisdiction in which it is located or otherwise governed. That established usage should not be confused with the broader sovereignty framework being developed here.
Intelligence sovereignty, as used within Sovereignty & Law, describes a different inquiry: whether an individual or institution retains meaningful control over the technological capabilities through which its information can be interpreted, connected, and acted upon.
It does not require that every model run locally, every server be owned directly, or every outside provider be eliminated. Sovereignty is not synonymous with isolation.
The question is whether enough control remains with the organization that dependence does not become incapacity when circumstances change.
“In the AI era, the most important question may not be whether you own your data. It may be whether you can take your intelligence with you.”
Jeff Howell, Sovereignty & Law
What Meaningful Ownership Looks Like in an AI System
If ownership and technological control can diverge, organizations may need a broader framework for evaluating the systems through which their information becomes useful.
Legal Rights
Who owns or possesses contractual rights in the underlying information, configurations, outputs, and other relevant assets?
Access
Can the organization reliably access its information and essential capabilities when needed?
Control
Which decisions and capabilities remain under the organization’s authority, and which have been delegated to providers?
Portability
Can information and strategically important configurations move to another environment in a usable form?
Interoperability
Can alternative systems meaningfully work with the organization’s information and infrastructure?
Verification
Can the organization evaluate important system behavior, outputs, controls, and claims rather than relying entirely on representations from another party?
Continuity
Can essential operations and institutional knowledge survive changes in vendors, models, pricing, policies, or infrastructure?
Exit
Does the organization have a realistic ability to leave the relationship without surrendering essential information or capabilities?
Not every organization will require the same degree of control across every category. The appropriate balance will depend on the sensitivity of the information, the importance of the capability, the available alternatives, regulatory and professional obligations, cost, security, performance, and the consequences of disruption.
The purpose of the framework is not to dictate one architecture. It is to make dependencies visible before they become difficult to reverse.
The Question Is Becoming Bigger Than Ownership
The first three inquiries in Sovereignty & Law reveal different dimensions of the same structural change.
Digital dependence raises the question of who controls the infrastructure.
Enterprise AI raises the question of who controls the intelligence.
Information ownership raises the question of whether formal rights remain sufficient when technological capability resides somewhere else.
Ownership tells us who has rights. Sovereignty asks whether those rights can be meaningfully exercised.
As technology increasingly mediates access to information, intelligence, identity, communication, and economic activity, the relationship between formal authority and practical agency becomes increasingly important.
That distinction moves the inquiry beyond ownership and toward a more fundamental concept: agency.
The next Sovereignty & Law analysis examines that relationship directly: From Access to Agency: What Digital Sovereignty Actually Means.
This article is part of Sovereignty & Law, a Lex Wire Journal editorial initiative examining how technology is changing the relationship between law, ownership, trust, agency, and power.
About the Author
Jeff Howell, Esq., is a dual-licensed attorney and founder of Lex Wire Journal. He leads Sovereignty & Law, an editorial initiative examining how artificial intelligence, digital infrastructure, cryptography, decentralized systems, and emerging technologies are changing the relationship between law, ownership, trust, agency, and power.
His work explores how technological architecture can shape who controls information and intelligence, where institutional dependence resides, and whether individuals and organizations retain meaningful agency within the systems they increasingly rely upon.
