Ukraine ran a war on commercial cloud infrastructure. Not because it was the ideal setup, but because Russian strikes had made physical data centers a liability, not a safeguard. The mission continued anyway.
That single fact is quietly rewriting how defense and government organizations define sovereignty. For decades, sovereignty meant hardware on national soil, physical custody of servers, and air-gapped isolation from anything resembling the open internet. That model was built for a static threat environment. It is being tested against a dynamic one, and it is losing.
The organizations rethinking this fastest are the ones already under the most pressure: defense ministries, prime contractors, and government agencies racing to adopt AI without losing control of classified code and data. What they are converging on is a different definition of sovereignty, one built around resilient access and enforced control rather than geography.
Physical isolation made sense when the primary threat was a foreign government gaining direct access to a server rack. It makes less sense when the primary threat is an AI agent with too much network access, a compromised credential, or a supply chain dependency nobody audited.
Defense organizations are not abandoning control. They are relocating it. The real question, as one HPE executive put it to a room of NATO officials at TechNet, is not where the data center sits. It is who controls access and who can see it. Those two answers define an organization's actual security posture, not the address on the building.
The market is already voting on this. The latest market analysis pinned the global sovereign cloud market at $154.69 billion in 2025 and is projected to reach $195.35 billion in 2026. That growth is driven largely by government and public sector demand for infrastructure that offers control without requiring physical isolation.
For the last several years, government AI initiatives lived mostly in pilot programs and press releases. That phase is over. Brookings found that the value of federal AI funds obligated increased 966% between 2024 and 2026, rising from $355 million to $7.2 billion, with the Department of Defense accounting for $90 billion in AI contract spending alone.
The number of federal agencies holding AI contracts rose from 17 in 2022 to 28 in 2026, out of 441 total agencies. That is not experimentation. That is procurement at scale, moving faster than most agencies' existing security review processes were built to handle.
Speed at this scale creates a new kind of exposure. Every agency now racing to deploy AI coding tools and autonomous agents is also racing past the infrastructure questions those tools require: where do agents run, what can they touch, and who is watching when something goes wrong.
The instinct in a fast-moving procurement environment is to treat governance as friction. The data says the opposite is true. According to Coder's 2026 AI Maturity Assessment of 100 engineering organizations, 78% are already running AI agents in some form, but 69% have no security protections or only ad-hoc controls against data exposure and secret leakage.
That gap between adoption and control is where the real exposure lives: agents with broad access to code and systems, operating without the safeguards that would catch a leak or contain a mistake. In a defense context, that gap is not a productivity annoyance. It is classified code and sensitive data moving through infrastructure nobody is actively protecting.
The alternative is not slower AI adoption. It is AI adoption that is legible from the start, with humans in the loop and every agent action attributable to a person and a policy. Organizations that build this in from the beginning move faster later, because they are not stopping every six months to retrofit controls onto systems that were never designed for them.
One U.S. defense intelligence organization felt this gap directly. Engineers spent days manually configuring local machines before they could write a line of code, and every setup drifted slightly from the last, turning routine debugging into environment archaeology. Leadership had no centralized way to see who was working on what or whether development practices matched security policy.
The organization moved development onto Coder, self-hosted on AWS GovCloud inside a fully air-gapped network, with every environment defined as a Terraform template rather than a manually configured machine. Onboarding time dropped from multiple days to three to five minutes, and usage grew 500% over the following years as engineers pulled the platform into more teams once they saw it work.
The pattern holds at a larger scale, too. A separate U.S. Defense Intelligence platform built the U.S. military's first true multi-tenant Coder deployment, giving more than 2,500 developers pre-approved, ATO-compliant environments instead of forcing each 20-person mission team to certify its own infrastructure from scratch. Centralizing that approval process did not just speed up onboarding. It gave the organization one place to enforce the same security posture across every mission team, at any scale.
Every argument above resolves at the same layer: where code actually gets built and what it can touch while it is being built. Commercial enterprises can get away with "build it on a laptop and figure out governance later." Classified and regulated environments cannot.
Coder's AI governance capabilities exist for exactly this reason: agents and developers work inside self-hosted, policy-controlled infrastructure, with every model call authenticated and logged and every agent's network access restricted by default rather than by exception. Coder Agents extend that same model to autonomous coding agents specifically, running on infrastructure the organization already controls, whether that is a cloud VPC or a fully air-gapped environment, with no API keys scattered across individual workspaces. A defense agency evaluating AI adoption today is really evaluating one question: if an agent misbehaves, what is the blast radius, and who finds out first.
The demand signal here is public and it is not subtle. The EU's Defense Readiness 2030 agenda, NATO's push to compress procurement cycles from years to months, and the sharp rise in U.S. federal AI contract spending all point in the same direction. The organizations that win are not the ones with the boldest AI strategy on paper. They are the ones that already built the governed infrastructure to execute it before the mandate arrived.
Coder works with public sector and defense organizations building exactly that kind of infrastructure today, on their own terms and their own hardware. If your teams are already navigating this shift, an AI governance assessment is a reasonable next step before the procurement cycle forces the question.
Want to stay up to date on all things Coder? Subscribe to our monthly newsletter for the latest articles, workshops, events, and announcements.