Critical infrastructure needs more than cameras that record
By Kasper van Kekem, CEO of VAIBS
When I speak with organisations about Vision AI, data sovereignty is becoming an increasingly important topic. And rightly so. Organisations want to know what happens to their video data, where it is processed and who has access to it. However, I sometimes feel the discussion is made too simple. Data sovereignty is often reduced to a single question: is the server located on-premises or in the cloud? But simply knowing where a server is located does not tell you enough.
To me, data sovereignty is ultimately about control. Control over where data is processed. Over who has access to it. Over how long information is retained. Over how the infrastructure is secured. Over which functionalities are enabled. And over the conditions under which the technology is used within an organisation. That also means there is no single technical architecture that is right for every organisation.
Some organisations want maximum local control and deliberately choose a fully on-premises environment. Others prefer the flexibility and scalability of cloud infrastructure. And some combine both approaches in a hybrid architecture. At VAIBS, we support all of these models. Alongside local deployments, we can also provide a secure and certified Dutch cloud environment in which data can be processed and stored within the Netherlands. But here too, one important principle applies: the fact that data is stored in the Netherlands does not automatically make a solution secure or compliant.
A professional Vision AI implementation should therefore look beyond the technical infrastructure alone.
I would want answers to questions such as:
That last question is becoming increasingly important. With legislation such as the GDPR and the European AI Act, it is no longer only about what technology can do, but also about how organisations use that technology.
This brings me to another misconception I regularly encounter. An AI platform is not compliant simply because the word “GDPR” appears somewhere on a website. Compliance depends on how a solution is designed, configured and used. The same technology can have a completely different impact in two different situations. What data is processed? For what purpose? Which functionalities are enabled? Who receives an alert? Is a decision made automatically, or does a person assess the situation? These are not questions that can be solved with a checkbox afterwards. They need to be part of the design from the very beginning.
That is also how we look at Vision AI at VAIBS. Not every customer needs to use the same cloud infrastructure. Not every customer needs to activate the same functionality. And not every organisation needs to retain the same data. A hospital has different requirements from a seaport, a police organisation or an industrial site. The technology should therefore be capable of adapting to the security, privacy and compliance requirements of the organisation. Not the other way around. Because ultimately, data sovereignty does not simply mean knowing where your data is located.
It means having control over your data, your infrastructure and the conditions under which technology is used.