Hub
Explainer
Digital sovereignty and the new politics of control
Digital SovereigntyExplainer

Digital sovereignty and the new politics of control

Why states are rethinking who owns, governs and secures the infrastructure of the digital age

Society OS Research29 June 202611 min read

Key Insight: Digital sovereignty is less about sealing borders than about expanding a state’s practical capacity to govern data, infrastructure and standards without becoming dangerously dependent on others.

What digital sovereignty actually means

Digital sovereignty is one of those policy terms that has spread quickly because it captures several anxieties at once. Governments worry about dependence on foreign cloud providers, semiconductor supply chains, undersea cables, mobile network equipment, software ecosystems and online platforms. Regulators worry about whether national laws can still be enforced when data, services and corporate structures are distributed across multiple jurisdictions. Security officials worry that critical systems may be vulnerable to espionage, coercion or disruption. Citizens, meanwhile, worry about privacy, accountability and democratic control.

At its simplest, digital sovereignty is the capacity of a state or political community to make meaningful decisions over the digital systems on which its economy, public services and security rely. That does not imply autarky, nor does it require every server, chip or line of code to be domestic. Rather, it asks a practical question: when pressure mounts, who can decide, who can inspect, and who can intervene?

Digital sovereignty is not absolute control. It is the ability to govern critical digital dependencies before those dependencies govern you.

This is why the concept resists neat definition. In European policy, it is often linked to strategic autonomy, competition, privacy and industrial capability. In other settings, it is tied more tightly to national security, data localisation or control over online information. The common thread is an effort to reduce dangerous asymmetries of power in the digital domain.

Why the idea has moved from theory to policy

For years, many countries assumed that digital integration would naturally deliver efficiency, innovation and resilience. It did deliver much of that. But it also created concentrated dependencies. A small number of firms came to dominate cloud computing, operating systems, social media, advanced chip design tools and large parts of the software stack. Manufacturing of critical components became geographically concentrated. Cyber attacks demonstrated that vulnerabilities in one part of the system could cascade across borders.

Recent years have sharpened these concerns. Supply-chain disruptions during the pandemic exposed the fragility of just-in-time production and dependence on distant suppliers. Geopolitical rivalry has made export controls, sanctions and technology restrictions more central to statecraft. Cyber incidents against hospitals, pipelines, public administration and telecoms networks have shown how digital dependence can become a strategic liability. As the World Economic Forum and the OECD have both noted, resilience now sits alongside efficiency as a core policy objective.

The result is not a retreat from digitalisation, but a more political understanding of it. Governments increasingly treat cloud services, data centres, semiconductors, digital identity systems and secure communications as foundational infrastructure rather than merely commercial services. Once that shift occurs, questions of ownership, jurisdiction and interoperability become unavoidable.

Data sovereignty is only one part of the story

Public debate often reduces digital sovereignty to data sovereignty: where data are stored, who can access them and which legal regime applies. Those questions matter. Rules on personal data, health records, financial information and public-sector information affect privacy, competition, law enforcement and trust. The Court of Justice of the European Union’s Schrems II judgment, for example, illustrated how transatlantic data transfers can become entangled with concerns about surveillance and legal redress.

Yet data location alone does not settle sovereignty. Data may sit on domestic soil while the software managing them, the encryption systems protecting them, the maintenance teams operating them and the parent company controlling the service all remain abroad. Conversely, some cross-border data flows are essential to scientific research, global commerce, fraud prevention and cyber defence. The policy challenge is therefore not simply to trap data within national borders, but to ensure appropriate legal safeguards, technical assurances and operational visibility.

Digital sovereignty is not absolute control. It is the ability to govern critical digital dependencies before those dependencies govern you.

That distinction is increasingly recognised by international institutions. The OECD has argued against unnecessary fragmentation of data flows while accepting that trust, security and public-interest protections are indispensable. The question is less whether data cross borders than whether institutions can uphold rights and enforce rules across them.

Infrastructure is where sovereignty becomes concrete

If data are the visible symbol of digital power, infrastructure is its material base. Digital sovereignty depends on the availability and integrity of the systems that store, route, process and secure information. These include terrestrial and submarine fibre networks, internet exchange points, cloud and edge computing facilities, domain-name systems, satellite services, energy supplies for data centres, semiconductor fabrication capacity, cryptographic tools and the software supply chain.

Control over such systems need not be direct state ownership. In most advanced economies, private operators build and run much of the infrastructure. But sovereignty requires that governments understand these dependencies, regulate them effectively and preserve options in times of crisis. This means mapping concentration risks, testing continuity plans, setting procurement standards and ensuring that critical operators can comply with domestic law without compromising security.

The importance of this approach is reflected in legislation and strategy documents across multiple jurisdictions. The European Union’s framework on critical entities resilience and network and information security, for instance, treats digital infrastructure as part of a wider resilience agenda. Similar thinking appears in national cyber strategies and telecoms security reforms elsewhere. The underlying logic is straightforward: if a system is critical to the functioning of society, its governance cannot be left entirely to market incentives.

Where servers are located matters less than whether a government can audit, regulate and, in extremis, sustain the systems on which society depends.

Cloud dependence and the problem of jurisdiction

Cloud computing captures many of the tensions at the heart of digital sovereignty. On one hand, cloud services offer scale, reliability, security tooling and innovation that many organisations cannot replicate on their own. Public administrations and regulated industries increasingly rely on them. On the other hand, concentration in the market raises concerns about vendor lock-in, operational dependence and exposure to foreign legal orders.

Jurisdiction is especially delicate. A provider may operate local facilities while remaining subject to another country’s laws concerning lawful access, sanctions or export restrictions. That creates a gap between physical location and legal control. It is one reason governments have explored requirements around encryption, key management, trusted operational staff, auditability, procurement diversification and the use of domestic or regionally governed providers for the most sensitive workloads.

Still, sovereignty cannot simply be legislated into existence by procurement mandates. Public institutions need technical capacity to assess risk, negotiate contracts, migrate systems and avoid lock-in through open standards and portability where feasible. Without in-house expertise, sovereignty rhetoric can mask deeper dependency. The most effective strategies therefore combine regulatory oversight with institutional competence and a realistic understanding of what can, and cannot, be domestically supplied.

Semiconductors, standards and the hidden layers of power

Much of digital sovereignty is decided far below the level visible to ordinary users. Semiconductors are a clear example. Advanced chips depend on intricate global supply chains spanning design software, specialised materials, fabrication plants, packaging and equipment. No country controls the entire stack. Yet access to chips is now recognised as a strategic matter because semiconductors underpin everything from consumer electronics to defence systems and artificial intelligence.

Policy responses have therefore centred on capability, not self-sufficiency. Governments are using subsidies, research funding and industrial policy to strengthen domestic production, attract fabrication investment and secure access to mature-node as well as cutting-edge chips. The aim is to reduce acute bottlenecks and improve resilience, even if full autonomy remains unrealistic.

Where servers are located matters less than whether a government can audit, regulate and, in extremis, sustain the systems on which society depends.

Standards are another overlooked layer of sovereignty. Technical standards determine interoperability, cybersecurity requirements and market access. States that participate effectively in standards-setting bodies can shape the rules embedded in future infrastructure. Those that do not may find themselves adopting norms designed elsewhere. In this sense, sovereignty is exercised not only through law and ownership, but also through expertise, presence and coalition-building in technical institutions.

Cybersecurity and sovereignty are increasingly inseparable

No country can claim meaningful digital sovereignty if its core systems are persistently vulnerable to intrusion, sabotage or criminal extortion. Cybersecurity is therefore not a separate agenda but a central component of sovereign capacity. This includes hardening critical infrastructure, improving incident reporting, securing software supply chains, developing national cryptographic policies, and building trusted channels between government and operators of essential services.

Yet sovereignty in cybersecurity does not mean unilateralism. Threat intelligence, malware analysis, attribution and law-enforcement action often depend on international co-operation. Cyber resilience is strengthened by alliances, shared standards and common response frameworks. The challenge is to co-operate without creating single points of foreign dependency in the very tools and services required for defence.

That balancing act is particularly important for smaller states. They may lack the scale to build a complete domestic cybersecurity ecosystem, but they can still improve sovereignty by investing in skills, procurement discipline, secure-by-design requirements and regional co-ordination. Sovereignty, in this sense, is not a binary condition. It is a spectrum of capability and preparedness.

The open internet versus the sovereign internet

One reason digital sovereignty is contested is that it can point in two very different directions. In its constructive form, it seeks democratic accountability, resilience, competitive markets and enforceable rights within an open, interoperable internet. In its more restrictive form, it can be used to justify censorship, surveillance, forced localisation and technical fragmentation.

This distinction matters. The internet’s value derives largely from common protocols, global reach and low barriers to innovation. Excessive fragmentation can raise costs, reduce security, impede research and weaken freedom of expression. The risk is a “splinternet” in which diverging technical standards, legal requirements and political controls make cross-border digital life slower, more expensive and less open.

At the same time, appeals to openness should not be used to dismiss legitimate concerns about concentration and jurisdiction. A genuinely open digital order requires more than open markets; it requires fair competition, accountable governance and credible safeguards against coercion. The policy goal is therefore not openness or sovereignty, but a synthesis of both: open systems with trusted guardrails and diversified dependencies.

The real choice is not between global openness and national control, but between resilient interdependence and brittle dependence.

What a serious digital sovereignty strategy looks like

Governments that approach digital sovereignty seriously tend to focus on a limited number of practical levers. First, they identify critical digital dependencies across public services, energy, finance, health, telecoms and defence. Second, they assess concentration risk and legal exposure, including dependencies created by software licences, proprietary interfaces and operational outsourcing. Third, they use procurement and regulation to encourage security, portability and continuity planning.

Fourth, they invest in domestic capacity where it is strategically justified: cyber skills, public-interest technology expertise, secure communications, semiconductor research, trusted cloud architecture, digital identity and standards participation. Fifth, they work with allies to diversify supply chains and align rules where possible. And sixth, they preserve the benefits of international connectivity by avoiding reflexive protectionism in areas where co-operation remains essential.

The real choice is not between global openness and national control, but between resilient interdependence and brittle dependence.

Importantly, not every dependency is a sovereignty problem. Specialisation and trade are normal features of modern economies. The test is whether a dependency could be exploited in ways that threaten essential services, political autonomy or legal accountability. Strategies that try to “localise everything” are usually wasteful. Strategies that ignore concentration and jurisdiction are usually complacent.

Why smaller states face a different calculation

Digital sovereignty is often discussed as if all states had similar options. In reality, smaller and middle-sized countries face a distinct challenge. They rarely have the market size to sustain full domestic alternatives across cloud, semiconductors, platform services and advanced cybersecurity tools. Their sovereignty strategy is therefore less about building complete national stacks than about intelligent diversification, regional co-operation and institutional competence.

That means choosing carefully where local control matters most. Sensitive public-sector data, national identity systems, electoral infrastructure, emergency communications and defence-related networks may warrant tighter governance and domestic operational assurance. Other functions may be better served through trusted international providers, provided contracts, technical architecture and legal arrangements preserve room for manoeuvre.

For such countries, law and diplomacy can matter as much as industry policy. Participation in regional digital markets, data-protection arrangements, mutual assistance agreements and common cybersecurity standards can expand sovereign capacity by reducing vulnerability to unilateral pressure. Properly understood, sovereignty can be pooled in some areas to be strengthened in others.

The debate will intensify with artificial intelligence

Artificial intelligence is likely to make digital sovereignty more salient, not less. Training and deploying advanced models depend on access to data, compute infrastructure, specialised chips, cloud capacity and skilled talent. That creates fresh concentrations of power and raises familiar questions about jurisdiction, accountability and strategic dependence. Public administrations are beginning to ask whether the systems that mediate decision-making, automate services or analyse sensitive information can be audited and governed on acceptable terms.

AI also amplifies the importance of standards, testing and secure infrastructure. If governments rely on opaque external systems for sensitive tasks, sovereignty concerns shift from data ownership alone to model control, explainability, robustness and operational assurance. The same is true for autonomous systems, synthetic media and AI-enabled cyber tools, all of which could deepen dependence on a narrow set of upstream providers.

The likely outcome is not a clean break from global technology markets, but a tougher insistence on accountability and strategic redundancy. States will seek more leverage over the terms under which critical digital capabilities are provided, especially when those capabilities affect public authority or national resilience.

From slogan to state capacity

The phrase “digital sovereignty” can be used loosely enough to mean almost anything. That is precisely why it should be treated with caution. In its strongest form, however, it is not a slogan but a discipline of statecraft. It asks whether a country understands its digital dependencies, whether it can govern them through law and expertise, and whether it has alternatives when systems fail or politics harden.

The most mature approach avoids two mistakes. One is fatalism: the belief that deep technological interdependence makes sovereignty obsolete. The other is fantasy: the belief that complete autonomy is attainable in a complex global digital economy. Between those poles lies a more credible objective—resilient, rights-respecting control over the critical layers of digital life.

That objective is demanding because it is less about declarations than institutions. It requires better procurement, stronger regulators, technical talent in government, clear risk assessments, competition policy that takes concentration seriously and alliances that reduce exposure without closing the door to exchange. Digital sovereignty, in the end, is not about retreating from the world. It is about ensuring that interdependence remains a choice rather than a trap.

Sources & Further Reading

  1. 1.
  2. 2.
  3. 3.
  4. 4.
  5. 5.
  6. 6.
  7. 7.
  8. 8.
  9. 9.
  10. 10.
Digital SovereigntyData GovernanceCybersecurityCritical InfrastructureCloud ComputingSemiconductorsStrategic Autonomy
The engine behind the Signal

Where this connects to Society OS

The Sovereign Intelligence Hub is the free, open front door of Society OS — the sovereign operating system that turns the ideas you just read into working governance. Where this piece names a problem, Society OS is building the machinery to solve it: AI agents that act with your authority, trust you can verify, and compliance that runs as code.

The 42-Protocol Stack

The governance engine beneath every article — led by the Sovereign Trinity: Human-Twin-Agent identity, HEARTrank trust, and WISE Contracts that execute law, not just code.

F-ACT — the open agent standard

The vendor-neutral framework for governing AI agents before they act: Authority, Scope, Data, Audit, Revocation — free to read, cite and implement.

The Sovereign Platform

Put it to work: govern a fleet of AI agents with verifiable authority, tamper-evident evidence, and compliance-as-code across your whole operation.

Explore membershipRead the F-ACT standard

Continue Reading

More from the Sovereign Intelligence Hub

Digital sovereignty after globalisation
Digital Sovereignty

Digital sovereignty after globalisation

14 min

Digital sovereignty after globalisation
Digital Sovereignty

Digital sovereignty after globalisation

14 min

Digital sovereignty will be won in the plumbing
Digital Sovereignty

Digital sovereignty will be won in the plumbing

14 min

How digital sovereignty became a governing principle
Digital Sovereignty

How digital sovereignty became a governing principle

14 min

Digital Sovereignty Without Illusion
Digital Sovereignty

Digital Sovereignty Without Illusion

14 min

The New Chokepoints of Digital Sovereignty
Cybersecurity & Resilience

The New Chokepoints of Digital Sovereignty

15 min read

Never miss a signal

Weekly intelligence, no noise

The Sovereign Intelligence Hub — Society OS

© 1989–2026 Society OS Pty Ltd. All rights reserved.