
From Information Science to Infrastructure: How Data Science Shapes the Future of AI
July 16, 2026 • Nicole M. Laine • 6 min read
Read moreLast week, I was at the United Nations (UN) in New York for Open Source Week. It included a hackathon and four days of sessions on AI, Digital Public Infrastructure, open source governance, and community-led technology work. Ministers, engineers, researchers, and practitioners from 100+ countries attended.
I work for amazee.io and its sibling brand amazee.ai. We have been building open source infrastructure for enterprise organizations for a decade. When I sat in those sessions, I kept hearing the same problems described by governments, development banks, and cybersecurity practitioners that led us to create amazee.ai in the first place.
This article is about what I heard and why it is important for organizations to consider AI now.
Tricia Wang from Advanced AI Society put it clearly during the AI day: we live in a claims-based AI world. Models assert things. They assert them with confidence. And in most enterprise deployments, there is no mechanism to verify what the model did with the data you gave it, where that data went, or whether it was used to improve a model someone else will query tomorrow
This concern isn't hypothetical. When you send a prompt to OpenAI, Anthropic, or Google directly, your data ends up on US infrastructure. It is stored, at least temporarily. You are relying on contractual commitments from providers whose enterprise-tier privacy controls are not available on standard plans. You are, in most cases, not covered by the kind of auditable, independently certified data governance that regulated industries require.
David Shrier from Imperial College described intelligence as the next sovereign battlefield. The concentration of AI capability inside a handful of companies is a structural problem. And it is accelerating.
Organizations building AI workflows on top of a single provider's proprietary API are making a bet they may not have fully thought through:
Tanzania's Minister of Technology, Angellah Kairuki, said something at the UN that stayed with me: her government is no longer a passive consumer of technology. It's an active creator. The shift happened when they stopped accepting vendor terms and started owning the stack. The same logic applies at the enterprise level. Vendor lock-in in AI is real, it is coming fast, and the time to address it is before your workflows are deeply embedded, not after.
The DPI sessions at the UN drove home a point that applies directly to enterprise AI: the technical system is rarely the failure point; the governance layer is.
Ethiopia's DPI case was striking.
The technology works, but the governance doesn't. Armando Manzueta from the Dominican Republic put it plainly: treat AI with the same governance rigor as your core infrastructure. Without proper guardrails and centralized oversight, you should not be deploying it at all.
Furthermore, the zero-day exploit window has collapsed from 60 days in 2020 to just 7 days today, according to the Linux Foundation's Jim Zemlin. The security argument for running AI workflows on certified, auditable, open-source-founded infrastructure is becoming urgent.
Brian Behlendorf made a vital point that most organizations still miss: people talk about AI as if it were the model itself. It isn't. The foundational model is just one layer. What truly matters is the harness: how you orchestrate models, constrain them, route information, log outputs, and build verification in. That is where risk lives. But it is also where value is created.
For teams using agent frameworks or automation workflows, this is significant. The agents that Sara Hooker and Mostafa Elkordy described at the UN are systems that will live alongside organizations for years, aggregating intelligence across sources, operating with some degree of autonomy, and those agents need to be built on infrastructure you can trust. That is the architecture amazee.ai is built on.
Sitting in those UN sessions, it became clear that the challenges keeping world leaders and cybersecurity experts up at night are the exact friction points we have spent the last decade solving.
At amazee.io, we have managed open source enterprise hosting for highly regulated entities, including 310 government sites through Australia's GovCMS and complex multi-site structures for enterprise clients.
We built amazee.ai and our Private AI Gateway to extend that same strict infrastructure discipline to the AI layer, directly answering the core issues raised at Open Source Week:
We engineered our gateway so that privacy is dictated by architecture. When an organization routes AI workloads through us, their data is bound to an isolated tenant in their chosen jurisdiction (EU, Switzerland, Germany, UK, US, or Australia) with zero cross-region routing.
We built Zero-Token Retention (ZTR) into the default framework, which means we never log, store, or train on prompts, and model providers never see the data. To move past a "claims-based" model, this setup is independently audited and verified against ISO 27001 and SOC 2 Type II standards as a baseline, providing compliance teams with actual proof.
To address the lock-in problem highlighted by Tanzania's Minister of Technology, our Private LLM API infrastructure gives organizations true ownership of their stack. The gateway provides a single, OpenAI-compatible API endpoint that acts as a secure abstraction layer.
This allows development teams to access and swap between GPT, Claude, Gemini, Mistral, DeepSeek, and others using a single key. If a model changes or a new provider outperforms the incumbent, organizations can instantly reroute their workloads via the dashboard without rewriting application code or touching active integrations.H3: Securing the "Harness" Layer
Because the true risk and value live in how models are orchestrated, our focus is entirely on securing that "harness." The architecture seamlessly integrates with the developer tools and automation frameworks teams are already using, such as Claude Code, Cursor, VS Code, n8n, or LangChain.
By changing just the API key and base URL, your existing engineering tools are instantly routed through a private, compliant environment. For teams building autonomous agents or pairing AI with structured content platforms like Drupal, this creates an environment in which AI is strictly constrained by your approved data and editorial workflows
The UN confirmed what we already believed: AI adoption at enterprise and government scale is not primarily a model problem. The models are good enough. The real challenges are sovereignty, governance, lock-in, and trust.
Those are infrastructure problems wrapped up in policy mandates, which ultimately become compliance hurdles. They are the exact kind of problems amazee.io has been solving for a decade. amazee.ai is the sovereign AI layer built on that exact same foundation—private by default, certified, and model-agnostic.
If you are building AI workflows today and you are not entirely certain where your data is traveling, who can see it, or what it would take to switch models next year, those are questions worth asking now before those workflows land in production. We have the answers and the infrastructure to back them up.
amazee.io provides managed open source enterprise hosting and private AI infrastructure for enterprise and government organizations worldwide. The amazee.ai Private AI Gateway is available now at amazee.ai.

Author
Matthew Saunders, AI Ambassador
J Matthew Saunders is an AI strategist and agile delivery leader operating at the intersection of open source software and cognitive automation for amazee.io and amazee.ai. He specializes in Drupal AI integration, prompt engineering management, and the architectural design of persistent AI agents within decoupled web environments. Matthew holds specialized credentials in AI Agents for Product Leaders, alongside foundational certifications as a SAFe 6 Lean Portfolio Manager, Scrum Master, and Scrum Product Owner. An influential voice in the global open source community, he frequently presents and organizes milestones on the global stage, including United Nations Open Source Week, API Days NYC, and Decoupled Days, where he actively champions data sovereignty, trustworthy AI frameworks, and workplace neurodiversity.

July 16, 2026 • Nicole M. Laine • 6 min read
Read more
June 24, 2026 • Jason Lewis • 5 min read
Running autonomous AI agents locally or on public clouds leaks data. Learn how to deploy them securely via a secure, private LLM infrastructure.

June 16, 2026 • Katy Walsh • 6 min read
Anthropic suspended Claude Fable 5 & Mythos 5 over US export controls. Learn why a private LLM API & sovereign AI infrastructure are critical for continuity.