The return of the state to the digital economy
For much of the internet age, digital policy was framed by an assumption that networks should be globally interoperable, data should move with minimal friction and scale would naturally concentrate in a small number of transnational platforms and infrastructure providers. That settlement is fraying. Governments now treat cloud capacity, semiconductors, submarine cables, identity systems, software supply chains and cross-border data transfers as matters of strategic concern rather than merely commercial efficiency.
This shift is often described as digital sovereignty. The phrase can sound vague, or worse, rhetorical cover for protectionism. Yet the underlying problem is concrete. States have discovered that their public services, industrial systems and knowledge economies depend on infrastructure they do not control, legal regimes they do not write and supply chains they cannot guarantee in moments of stress. At the same time, they remain deeply reliant on open standards, foreign investment and international research networks. Sovereignty in the digital age therefore cannot mean self-sufficiency in any literal sense.
Digital sovereignty is not digital isolation. It is the practical ability to decide which dependencies are tolerable, and which are too risky to leave unmanaged.
The policy question is thus less whether sovereignty matters than how it should be operationalised. A state can pursue strategic capacity without sliding into fragmentation; but if every government seeks absolute control, the likely result is a balkanised digital order with higher costs, weaker innovation and fewer freedoms. The hard task is to identify where autonomy is essential, where resilience can come from diversification and where openness remains a strategic asset.
What sovereignty means in practice
In classical political theory, sovereignty denotes ultimate authority within a territory. In the digital realm, authority is distributed across code, contracts, standards bodies, extraterritorial laws and privately owned infrastructure. That makes sovereignty less an absolute condition than a set of capabilities. Can a government secure critical systems? Can it enforce its privacy, competition and safety rules? Can public institutions continue to function if a foreign supplier fails, exits a market or becomes legally constrained by another jurisdiction?
European institutions increasingly define the matter in these operational terms. The European Commission has tied digital policy to the capacity to act independently while remaining open, from data governance and cyber resilience to semiconductors and connectivity. The OECD, meanwhile, has emphasised trusted government access, data governance and cross-border digital trade as core tensions in the emerging landscape. Across these debates, one theme recurs: control is rarely binary. The relevant metric is not ownership alone, but whether critical functions can be audited, substituted, governed and, in extremis, maintained.
This is why digital sovereignty spans several layers at once. There is infrastructural sovereignty, concerning telecoms, cloud, chips and cables. There is jurisdictional sovereignty, concerning the reach of domestic law over data and services. There is technical sovereignty, concerning standards, interoperability and cryptographic assurance. And there is civic sovereignty, concerning whether citizens retain meaningful rights over identity, privacy and expression in digitally mediated life.
Data as a jurisdictional fault line
Data governance has become the most visible theatre of sovereignty because it sits at the intersection of commerce, security and rights. The European Union’s General Data Protection Regulation established a broad rights-based framework for personal data. But the deeper sovereignty issue emerged in the legal conflict over international transfers. Judgments of the Court of Justice of the European Union, particularly in the Schrems cases, exposed how difficult it is to reconcile European privacy guarantees with foreign surveillance laws when data is processed across borders.
The consequence has not been the end of data flows. Rather, it has been a push towards conditional openness: adequacy decisions, standard contractual clauses, transfer impact assessments, local processing for sensitive sectors and stronger technical safeguards. Similar dynamics appear elsewhere. India’s Digital Personal Data Protection Act takes a different route, but it too reflects concern with state capacity, lawful access and the governance of nationally significant datasets. China has built an extensive regime for data security reviews and cross-border transfer controls, linking economic governance tightly to national security.
Digital sovereignty is not digital isolation. It is the practical ability to decide which dependencies are tolerable, and which are too risky to leave unmanaged.
These approaches diverge sharply in values and methods. Even so, they respond to the same structural reality: data is no longer viewed as a neutral by-product of digital activity. It is a strategic resource, a regulatory object and a vector of power. The policy challenge is to avoid reducing every transfer question to a location question. In many cases, robust encryption, access controls, auditable processing and legal redress matter more than simple localisation. Mandating local storage can create domestic chokepoints without materially improving protection.
Where data resides is often less important than who can compel access to it, under what law, with what oversight and what technical safeguards.
Infrastructure dependence and the cloud question
If data governance concerns the movement of information, infrastructure sovereignty concerns the substrate on which digital societies run. Public administration, health systems, scientific research and industrial operations increasingly depend on remote computing and software services. This model offers flexibility and scale, but it also concentrates risk. Outages propagate quickly; exit costs are high; and jurisdictional exposure can be opaque.
Governments have responded in several ways. Some have created security certification schemes for cloud services handling sensitive workloads. Others have revised procurement rules to require interoperability, portability and clearer contractual control. In Europe, debate has focused on whether strategic sectors need assured domestic or regional capacity for certain classes of data and computation. The point is not that all computing must be nationally owned. It is that overreliance on a narrow supplier base can become a constraint on public policy, especially when legal or geopolitical conditions change.
This logic resembles older debates about energy security. Few countries insist on producing all their own energy inputs. Many do, however, seek diversified supply, strategic reserves, domestic generation for critical uses and market rules that prevent excessive dependence. Digital infrastructure is moving in the same direction. The strongest sovereignty strategies therefore prioritise substitutability and governance over symbolic ownership. Open standards, data portability and modular procurement often do more for strategic autonomy than attempts to recreate every layer of the stack domestically.
Semiconductors and the politics of choke points
No area better illustrates strategic dependency than semiconductors. The production chain for advanced chips is globally dispersed and unusually specialised, spanning design software, intellectual property, fabrication equipment, materials, foundries, packaging and testing. A disruption at a few critical nodes can reverberate across automotive production, defence systems, telecommunications and artificial intelligence.
This has driven a wave of industrial policy. The European Union’s Chips Act, the United States CHIPS and Science Act and parallel efforts in East Asia seek to expand manufacturing capacity, support research and reduce exposure to external shocks. Yet these policies also reveal the limits of sovereignty. Even the largest economies cannot replicate the entire ecosystem efficiently, let alone in the short term. The relevant strategic aim is therefore not complete independence, but a more balanced and resilient geography of production.
Export controls add another dimension. Restrictions on advanced semiconductors and manufacturing tools show that interdependence can be weaponised through regulatory choke points. For smaller and medium-sized states, this is a warning. Dependence is not only about market concentration; it is also about the legal and diplomatic leverage attached to critical technologies. Sovereignty in this domain requires better mapping of exposure, support for research capacity and alliances that reduce single-point vulnerability without freezing international scientific exchange.
Cyber security as sovereign capacity
Cyber security is often treated as a technical discipline, but at national scale it is a test of sovereign competence. A government that cannot identify risks in public systems, compel baseline security in essential sectors or co-ordinate response to major incidents has limited practical authority in the digital domain. The EU’s NIS2 Directive and Cyber Resilience Act, alongside similar measures elsewhere, indicate a move from voluntary guidance towards enforceable obligations across critical and widely used digital products and services.
Where data resides is often less important than who can compel access to it, under what law, with what oversight and what technical safeguards.
Here too, sovereignty is inseparable from institutional capacity. Laws matter, but so do regulators, incident response teams, procurement expertise and a workforce able to audit complex systems. Many states have discovered that they can legislate faster than they can supervise. The result is a gap between nominal control and operational control. Closing it requires investment not just in defence, but in public-sector technical literacy and independent testing capability.
Cyber policy also exposes a central tension. States want stronger access to data and systems for law enforcement and intelligence purposes, but broad access mandates can undermine the security and trust on which digital sovereignty depends. Weakening encryption in the name of sovereign power may, in practice, reduce sovereign resilience by making citizens, firms and institutions more vulnerable to exploitation. Durable sovereignty rests on trustworthy infrastructure, not merely expanded state reach.
A state that can compel access but cannot guarantee security is asserting authority while eroding the very trust that makes digital governance viable.
The standards arena and the quiet politics of interoperability
Sovereignty is not decided only in parliaments and courts. It is also shaped in technical standards bodies, procurement specifications and software architectures. Standards determine whether systems interoperate, whether users can switch suppliers, whether security claims can be verified and whether national rules can be implemented without excessive friction. Countries that neglect this layer often find themselves rule-takers even when they are active regulators.
The strategic importance of standards is one reason governments have become more engaged with international technical organisations. Participation, however, should not be confused with domination. The value of standards processes lies in their capacity to sustain interoperability across borders. If they become instruments of geopolitical bloc formation, the costs to innovation and security could be severe. Fragmented standards increase complexity, raise compliance costs and create new vulnerabilities at system boundaries.
For policymakers, the practical lesson is that digital sovereignty benefits from open, contestable and well-governed standards ecosystems. Interoperability can be a sovereign asset because it reduces lock-in and expands room for manoeuvre. A system built on open specifications and portable data is easier to govern, audit and replace than one tied to proprietary formats and opaque interfaces.
Public digital infrastructure and civic sovereignty
Much sovereignty debate focuses on states and firms, but citizens are not incidental. Digital identity, payment rails, registries and communication channels increasingly mediate access to public rights and economic participation. Where these systems are weak, exclusion grows. Where they are overly centralised or poorly governed, surveillance and abuse become easier. Civic sovereignty therefore concerns whether individuals can engage in digital life with meaningful agency, legal protection and recourse.
The UN has argued for digital public infrastructure that is safe, inclusive and rights-respecting. Properly designed, common digital rails can reduce dependence, widen access and improve administrative effectiveness. Poorly designed, they can entrench state and market power at the expense of autonomy. The governance details matter: clear purpose limitation, independent oversight, data minimisation, contestability and robust security by design.
This is especially important because sovereignty can be invoked by democratic and authoritarian systems alike. A rights-based account of digital sovereignty must distinguish between state capacity and state overreach. Building domestic capability is legitimate. Treating all digital activity as an object of political control is not. The line may blur in crises, which is why durable institutions and judicial safeguards are essential.
Strategic autonomy without autarky
A state that can compel access but cannot guarantee security is asserting authority while eroding the very trust that makes digital governance viable.
The phrase strategic autonomy has become a useful corrective to maximalist interpretations of sovereignty. It suggests freedom of action under conditions of interdependence, not escape from interdependence altogether. For most countries, especially middle powers, the feasible objective is to reduce dangerous concentrations of dependency while preserving access to global markets, talent and research.
That implies a portfolio approach. Some capabilities deserve domestic or regional assurance because failure would threaten essential public functions. Some are best secured through trusted partnerships and reciprocal legal arrangements. Others should remain globally distributed, with policy focused on resilience, transparency and competition rather than ownership. The optimal mix will differ by country and sector, but the principle is consistent: sovereignty should be calibrated to criticality.
There is a fiscal dimension here too. Pursuing sovereignty everywhere is prohibitively expensive. Advanced fabrication plants, secure cloud environments, national-scale cyber capacity and technical standards engagement all require sustained public investment. Governments therefore need clear prioritisation. Symbolic projects that advertise control but do little to reduce systemic risk can crowd out the less visible work of procurement reform, skills development and institutional oversight.
The danger of sovereignty theatre
As digital sovereignty gains political traction, it risks becoming a catch-all justification for intervention. The danger is sovereignty theatre: policies that proclaim control while entrenching inefficiency, censorship or incumbent advantage. Blanket localisation mandates, vague national security exemptions and discretionary licensing regimes can be presented as strategic necessities even when they primarily serve rent-seeking or political control.
These measures carry costs. They can isolate domestic researchers, burden smaller firms, reduce service quality and invite retaliation. They may also weaken security by forcing data and services into less mature local environments. Most importantly, they can erode the credibility of legitimate sovereignty claims by conflating resilience with exclusion.
Good policy should therefore meet three tests. First, necessity: is the measure addressing a clearly identified strategic vulnerability? Secondly, proportionality: is it the least distortive means available? Thirdly, accountability: are the rules transparent, reviewable and constrained by law? Where governments cannot answer these questions, sovereignty rhetoric is often masking other aims.
What a mature sovereignty agenda looks like
A serious digital sovereignty strategy begins with mapping dependencies rather than denouncing them. Which services are essential to state continuity? Which supply chains have dangerous choke points? Where do foreign legal regimes create material uncertainty? Which standards shape lock-in? Only then can governments choose among the available tools: competition policy, procurement reform, security certification, investment screening, R&D support, data governance, international agreements and targeted industrial policy.
It also requires a more nuanced view of alliances. Trusted partners can extend sovereignty by widening secure options, sharing burdens and creating larger markets for interoperable solutions. This is particularly important for countries that cannot, on their own, sustain every strategic capability. In that sense, pooled capacity can be more sovereign than nominal self-reliance.
Above all, digital sovereignty should be judged by outcomes. Do public institutions retain control over critical functions? Can citizens exercise rights online with confidence? Are key systems secure, auditable and substitutable? Can firms innovate without being trapped by a handful of unavoidable dependencies? If the answer is yes, sovereignty is being strengthened. If not, control may be louder in the rhetoric than in reality.
The age of naive digital globalisation is over. But the alternative need not be digital nationalism. The more plausible future is a world of selective safeguards, layered governance and strategic diversification. In that world, sovereignty is not a wall around the digital realm. It is the disciplined capacity to govern openness on terms consistent with security, prosperity and liberty.




