For an enterprise AI agent, where it runs is only part of the control question.
IBM and Yotta announced general availability of their Sovereign Agentic AI Platform on September 29. Available through Yotta’s Panvel and Greater Noida cloud regions, the offering is designed to keep data, operations, and governance controls within India.
For Indian enterprises evaluating AI automation, local hosting is only part of the buying decision. Teams also need to verify where connected applications process data and who can authorize or stop an agent’s actions.
What the platform includes
The platform combines IBM watsonx Orchestrate with Yotta’s Shakti Cloud. IBM describes watsonx Orchestrate as the layer for managing, securing, and governing agents, while Shakti Cloud supplies infrastructure including compute, GPUs, networking, and security.
Yotta’s Shakti Studio adds tools to explore, fine-tune, deploy, and run open-source and proprietary models. The companies identify security operations, document processing, and HR automation among the intended workflows.
Together, those components address different parts of deployment: the infrastructure supporting an agent, the models it uses, and the software coordinating its work. Buyers will still need to examine how each component connects to their existing systems.
From a May proposal to an available service
The launch follows IBM and Yotta’s May 7 partnership plans, which proposed hosting watsonx Orchestrate on Shakti Cloud for enterprises and government organizations. That earlier plan covered functions including IT service management, finance, procurement, and customer support.
The May announcement also proposed bringing IBM Sovereign Core to Shakti Cloud. IBM described that software as supporting sovereign environments through capabilities including compliance monitoring, evidence generation, and governed AI execution.
What eWeek found: Local deployment needs a wider control check
Comparing the May proposal with the September launch reveals an unresolved scope question: May explicitly proposed bringing IBM Sovereign Core to Shakti Cloud, but September’s announcement does not confirm whether it is included. Buyers should verify which sovereignty and compliance capabilities are included in the available service.
Beyond the product’s scope, buyers should ask whether any configured model calls or application connections send data outside India. The launch announcement does not describe those connection-level data flows.
The broader concern echoes the AI model-access dependency problem: infrastructure location and continued control over the services a business relies on are separate questions.
Enterprise teams should request a data-flow map covering prompts, retrieved documents, model calls, logs, and connected applications. They should also establish who can authorize agent actions, inspect activity, and stop a workflow when it exceeds its intended permissions.
A shared inventory can help, but cross-platform agent visibility depends on what each integration exposes. Buyers should test those connections rather than assume every agent produces equivalent audit evidence.
The launch announcement does not disclose pricing, service-level commitments, or customer performance results. A useful evaluation would start with one bounded workflow and measure accuracy, human-review requirements, cost per completed task, and recovery from failed actions before expanding access.
Read more: Microsoft’s latest agent discovery and data-loss controls show how enterprises are approaching visibility and sensitive outbound data as separate security requirements.


