Hub
Digital sovereignty after globalisation
Digital Sovereignty

Digital sovereignty after globalisation

Why states are rebuilding control over data, chips, clouds and standards

Society OS Research28 June 202614 min read

Key Insight: Digital sovereignty is not autarky in cyberspace; it is the attempt to reduce strategic dependence while preserving enough openness to remain economically and technologically competitive.

The return of control

For much of the internet age, digital policy was shaped by an assumption that openness would be both efficient and broadly stabilising. Data would flow across borders, software supply chains would be globally distributed, and the physical infrastructure of computing would be treated as a technical rather than geopolitical question. That assumption has weakened. Governments now view digital systems not only as engines of productivity but also as strategic assets, vulnerabilities and instruments of state capacity.

The phrase digital sovereignty captures this change. It is used loosely, often to mean everything from data protection to industrial policy. Yet at its core lies a specific concern: whether a state, or in some cases a political union, can exercise meaningful authority over the digital systems on which its economy, public services and security depend. The issue is not merely who writes the code or owns the servers. It is who can compel access, interrupt service, set standards, extract value and define the legal conditions under which data and infrastructure operate.

Digital sovereignty is less about sealing borders than about deciding which dependencies are tolerable and which are strategically reckless.

This is why the debate has widened beyond privacy. Questions that once sat in separate policy silos now converge: semiconductor manufacturing, cloud infrastructure, submarine cables, encryption, identity systems, artificial-intelligence compute, open-source security and cross-border data transfers. What joins them is the growing recognition that digital dependence can translate into political and economic leverage.

From market efficiency to strategic resilience

The turn towards sovereignty did not emerge from one event. It reflects a cumulative reassessment shaped by cyber attacks, supply-chain disruptions, geopolitical rivalry and the concentration of critical digital markets. The pandemic exposed the fragility of just-in-time systems. Semiconductor shortages showed how a handful of bottlenecks could ripple through industries from cars to medical devices. Meanwhile, disputes over data transfers and foreign access to communications infrastructure highlighted the tension between globalised digital business models and national legal orders.

Public authorities have also become more dependent on outsourced digital infrastructure. Cloud computing, managed security services and software platforms can deliver speed and efficiency, but they may also move essential functions outside direct sovereign control. If a government relies on external providers governed by another jurisdiction, the question is not simply technical competence. It is whether critical state functions remain contestable by foreign law, sanctions regimes or extraterritorial surveillance powers.

International institutions increasingly frame digital dependence in resilience terms. The Organisation for Economic Co-operation and Development has argued that digital policy must account for both openness and trusted cross-border conditions. The World Economic Forum, for its part, has described digital sovereignty as the capacity to have control over one’s digital destiny. These formulations differ in emphasis, but both acknowledge that the old binary between open internet idealism and national control is no longer adequate.

Data jurisdiction is the first frontier

Data is often treated as the centrepiece of digital sovereignty, though that can be misleading. Data on its own is rarely useful without software, legal rights, standards and compute. Even so, jurisdiction over data remains politically potent because it sits at the intersection of civil liberties, commercial power and state authority.

Digital sovereignty is less about sealing borders than about deciding which dependencies are tolerable and which are strategically reckless.

In Europe, the Court of Justice of the European Union’s judgments in Schrems I and Schrems II did more than unsettle transatlantic data-transfer arrangements. They underscored a structural problem: personal data transferred abroad may become subject to legal regimes that do not meet domestic constitutional standards. That made data governance a sovereignty question in a direct legal sense. The answer has not been simple localisation. Rather, policymakers have sought a more layered approach involving adequacy arrangements, contractual safeguards, encryption requirements and public-sector rules for sensitive workloads.

Elsewhere, approaches differ sharply. Some states pursue broad data-localisation mandates to increase control, support domestic industry or facilitate law-enforcement access. Others favour trusted data corridors among like-minded jurisdictions. The variation matters. A country can impose localisation and still remain strategically dependent if the software stack, hardware, technical talent and standards are controlled elsewhere. Sovereignty over data without sovereignty over the systems that process it is partial at best.

Cloud infrastructure and the problem of delegated statehood

No area better illustrates the practical tensions of digital sovereignty than cloud infrastructure. Modern public administration increasingly depends on scalable computing, storage and security tools that few states can build efficiently on their own. Yet the cloud is not a neutral utility. It is a layered stack of physical assets, operational processes and legal obligations. Control can sit in the ownership of data centres, the administration of encryption keys, the nationality of personnel, the location of metadata or the jurisdiction governing the provider.

That is why official guidance in several countries now distinguishes between ordinary public-sector workloads and sovereign or strategic ones. Defence systems, intelligence processing, electoral systems, tax administration and core citizen registries are increasingly treated as requiring stricter guarantees around jurisdiction, auditability, incident response and continuity of service.

A state that cannot verify who may lawfully reach into its most sensitive systems does not fully possess those systems, however modern they appear.

The policy challenge is not to reject external infrastructure wholesale. It is to determine where substitutability is low and consequences of disruption are high. In those domains, governments are looking for legal insulation, operational control and technical portability. This may involve multi-cloud architectures, sovereign hosting requirements, domestic key management, open standards or in-house capacity for the most sensitive functions. Such measures can be costly, but dependence in critical systems has costs too; they simply arrive later and under worse conditions.

Semiconductors and the material basis of autonomy

Digital sovereignty is often discussed as if it were weightless. In fact, its hardest constraints are material. Chips, lithography equipment, rare inputs, fabrication capacity and advanced packaging determine who can build and maintain modern digital systems. A country may have strong software capabilities and still be vulnerable if it lacks secure access to semiconductors.

This has pushed industrial policy back to the centre of digital strategy. The European Union’s Chips Act, the United States’ CHIPS and Science Act and comparable initiatives in East Asia reflect a broad effort to diversify supply, strengthen domestic capability and reduce exposure to concentrated chokepoints. The goal is not complete self-sufficiency, which would be unrealistic for most countries. It is a more resilient distribution of capacity across trusted networks.

The problem is that semiconductor ecosystems do not bend easily to national ambitions. They are capital-intensive, technologically specialised and deeply international. Design, tooling, fabrication, packaging and materials are distributed across different regions. Efforts to onshore everything are likely to prove prohibitively expensive and technologically inefficient. For that reason, the more plausible form of sovereignty in semiconductors is not autarky but managed interdependence: domestic capacity in selected layers, stockpiling where sensible, and strategic alliances to protect access to key inputs and capabilities.

Standards, protocols and the quiet politics of technical order

A state that cannot verify who may lawfully reach into its most sensitive systems does not fully possess those systems, however modern they appear.

Digital sovereignty is not only about assets one can count. It is also about rule-setting. Technical standards determine how systems interoperate, how security is implemented and which business models become durable. States that are absent from standards-setting processes may find themselves adapting to architectures designed elsewhere, with little leverage once those architectures are embedded.

This matters in areas from telecommunications and cloud interoperability to digital identity, cryptography and machine-readable regulation. Standards can encode assumptions about privacy, lawful access, portability and governance. They can also favour firms or ecosystems that already possess market power. Hence governments are paying more attention to participation in standards bodies and to procurement as a tool for shaping de facto standards in public markets.

The rise of open-source software adds another layer. Open source can strengthen sovereignty by reducing vendor lock-in, improving inspectability and broadening local capability. Yet open-source dependencies can also create hidden fragility if maintenance is concentrated in tiny communities or if critical packages are insufficiently funded and secured. Sovereignty here requires stewardship, not just adoption.

Artificial intelligence and the new compute divide

As artificial intelligence systems become more central to public administration, research and industry, digital sovereignty is acquiring a new dimension: access to compute and high-quality data under acceptable governance conditions. Advanced AI development depends on chips, data-centre capacity, electricity, specialist talent and access to large datasets. These are unevenly distributed and increasingly strategic.

For many states, the concern is not only whether they can build frontier models domestically, but whether they can deploy AI in sensitive sectors without ceding too much control over training data, model behaviour, auditability or service continuity. Public administrations using external AI systems may discover that core decisions become dependent on opaque models, external update cycles and foreign legal frameworks. That is a sovereignty problem even when the immediate service appears efficient.

In the age of AI, sovereignty will depend not merely on who holds data, but on who controls the compute, the models and the terms of deployment.

The likely result is a tiered landscape. A few countries will aim for end-to-end capability across compute, research and deployment. Many others will seek strategic competence in selected domains: trusted public-sector use, local language models, regulated sector applications and stronger bargaining power in procurement. For most, the realistic objective is not independence from global AI ecosystems but the institutional capacity to adopt them without strategic blindness.

The European experiment in pooled sovereignty

No polity has pursued digital sovereignty more self-consciously than the European Union. Its approach is distinctive because it combines regulation, market integration and selective industrial policy. Rather than attempt national self-sufficiency, the European project seeks to pool sovereignty: to create a large enough legal and economic space to shape digital markets, protect rights and support strategic capabilities.

This has produced mixed results. On one hand, European rules on data protection, platform governance, cybersecurity and digital competition have had global influence. On the other, Europe remains dependent in several foundational layers, notably hyperscale cloud, advanced semiconductors and some AI infrastructure. The gap between regulatory power and industrial capability is the central tension in the European model.

Still, the experiment matters well beyond Europe. It suggests that digital sovereignty can be pursued through federated governance rather than national enclosure. It also shows the limits of regulation absent investment, procurement reform and technical capacity inside the state. Rules can shape markets, but they cannot manufacture capability by themselves.

In the age of AI, sovereignty will depend not merely on who holds data, but on who controls the compute, the models and the terms of deployment.

The risk of sovereignty theatre

Because the term has become politically attractive, digital sovereignty is vulnerable to overuse. Governments may invoke it to justify protectionism, censorship or ineffective industrial spending. Symbolic localisation measures can create the appearance of control without reducing underlying dependence. Domestic ownership can be presented as sovereignty even when the relevant software, chips, patents or expertise remain foreign-controlled. In some cases, sovereignty rhetoric is used to expand state surveillance rather than to strengthen constitutional accountability.

There is also an economic risk. Excessively restrictive localisation and procurement rules can reduce competition, raise costs and lock public institutions into inferior systems. If every state seeks to duplicate complete digital stacks, the result will be fragmentation without resilience. Smaller economies in particular may find that an uncompromising sovereignty agenda weakens innovation while failing to secure true autonomy.

The more serious versions of the concept therefore focus on proportionality. Which functions are genuinely critical? Which dependencies are acceptable if they are transparent, diversified and reversible? Where is domestic capability essential, and where are trusted partnerships more efficient? These questions are less politically dramatic than declarations of independence, but they are more useful.

What strategic maturity looks like

A mature digital-sovereignty strategy starts with mapping dependencies in operational rather than rhetorical terms. Governments need to know which systems are critical, who controls each layer, under what jurisdiction they operate, how quickly they can be replaced and what failure would mean. Many public institutions still lack this basic visibility.

From there, priorities usually fall into five areas. First, legal control: ensuring that the governance of sensitive data and services aligns with constitutional standards. Secondly, technical portability: reducing lock-in through open standards, modular architectures and exit planning. Thirdly, domestic capability: investing in the talent, procurement competence and institutional memory required to be an intelligent customer rather than a passive buyer. Fourthly, supply resilience: diversifying hardware, software and service dependencies where concentrations create strategic risk. Fifthly, international alignment: building trusted arrangements with partners where purely national solutions are unrealistic.

Public procurement is especially important. States often speak the language of sovereignty while buying systems that maximise dependence. Contracts can require audit rights, data portability, code escrow, incident transparency and interoperability. They can also support local capability-building when designed intelligently. Sovereignty is not simply declared in strategy papers; it is built in procurement specifications, technical architectures and staffing models.

A doctrine for an interdependent world

Digital sovereignty is best understood as a doctrine of disciplined interdependence. It accepts that no advanced economy can master every layer of the digital stack, yet rejects the complacent belief that strategic dependence will remain benign. The task is to identify where dependence creates coercive exposure, constitutional conflict or unacceptable fragility, and then to reduce that exposure without severing the benefits of international exchange.

This balance will be difficult to maintain. Geopolitical tensions will push some states towards more assertive control over data, infrastructure and standards. Commercial concentration will continue to tempt public authorities into dependencies that are efficient in the short term and risky in the long term. Meanwhile, AI and cyber conflict will increase the strategic value of compute, talent and secure digital administration.

The countries that navigate this shift best are unlikely to be those that promise total technological independence. More likely, they will be the ones that build institutional competence, make sharper distinctions between critical and non-critical systems, and use alliances as instruments of autonomy rather than substitutes for it. In the end, digital sovereignty is neither a retreat from globalisation nor a simple continuation of it. It is the attempt to govern interdependence on terms that remain politically legitimate and strategically survivable.

Sources & Further Reading

  1. 1.
  2. 2.
  3. 3.
  4. 4.
  5. 5.
  6. 6.
  7. 7.
  8. 8.
  9. 9.
  10. 10.
Digital SovereigntyData GovernanceCloud InfrastructureSemiconductorsAI PolicyCybersecurityStandardsStrategic Autonomy
The engine behind the Signal

Where this connects to Society OS

The Sovereign Intelligence Hub is the free, open front door of Society OS — the sovereign operating system that turns the ideas you just read into working governance. Where this piece names a problem, Society OS is building the machinery to solve it: AI agents that act with your authority, trust you can verify, and compliance that runs as code.

The 42-Protocol Stack

The governance engine beneath every article — led by the Sovereign Trinity: Human-Twin-Agent identity, HEARTrank trust, and WISE Contracts that execute law, not just code.

F-ACT — the open agent standard

The vendor-neutral framework for governing AI agents before they act: Authority, Scope, Data, Audit, Revocation — free to read, cite and implement.

The Sovereign Platform

Put it to work: govern a fleet of AI agents with verifiable authority, tamper-evident evidence, and compliance-as-code across your whole operation.

Explore membershipRead the F-ACT standard

Continue Reading

More from the Sovereign Intelligence Hub

Digital sovereignty and the new politics of control
Digital Sovereignty

Digital sovereignty and the new politics of control

11 min

Digital sovereignty after globalisation
Digital Sovereignty

Digital sovereignty after globalisation

14 min

Digital sovereignty will be won in the plumbing
Digital Sovereignty

Digital sovereignty will be won in the plumbing

14 min

How digital sovereignty became a governing principle
Digital Sovereignty

How digital sovereignty became a governing principle

14 min

Digital Sovereignty Without Illusion
Digital Sovereignty

Digital Sovereignty Without Illusion

14 min

The New Chokepoints of Digital Sovereignty
Cybersecurity & Resilience

The New Chokepoints of Digital Sovereignty

15 min read

Never miss a signal

Weekly intelligence, no noise

The Sovereign Intelligence Hub — Society OS

© 1989–2026 Society OS Pty Ltd. All rights reserved.