What is digital sovereignty?
On February 6, 2025, US president Donald Trump ordered sanctions against Karim Khan, chief prosecutor at the International Criminal Court in The Hague, the court that prosecutes war crimes. The International Criminal Court was a customer of Microsoft, an American corporation. Microsoft complied with the order by blocking the prosecutor’s account. Khan and others lost access to their email, which disrupted the court’s operations for months.
A common definition of sovereignty is supreme authority within a territory. Digital sovereignty then, must be supreme authority within the digital landscape: the software and computer systems we use. If a foreign ruler can cause your digital infrastructure to stop working simply by publishing a document, then your authority is not supreme, and you are not digitally sovereign. There is nuance to this though. The world today is interconnected, supply chains are deep and global, and digital infrastructure is a cross-border collaborative effort. Sovereignty is not the same as complete independence. In this article we will explore what it means to be digitally sovereign and digitally autonomous.
Autonomy is about having options
Being digitally autonomous is not the same as being fully independent. Autonomy is the ability to make your own decisions. It implies having options to choose from. When we depend on hardware, software, and services offered by a foreign vendor, as long as we retain a real choice of vendors, we retain our autonomy. When we have no real choice, the dependency is at risk of being turned into political leverage. How risky a dependency is, depends on two factors: how difficult it is to switch, and how vulnerable the vendor is to abuse.
Switching vendors can be difficult for many reasons. There may be few vendors who offer a suitable product, or alternative vendors may not be able to meet demand. Even with commodity services that have a very low marginal cost for the operator, such as e-mail, switching vendors is often difficult because the service is so deeply integrated into our organizations. On top of that, migrating the data is always a challenge.
How vulnerable a vendor is to abuse, depends on their position in the ecosystem. A hardware vendor who is barred from supplying us with new GPUs is a problem on a time scale of weeks to months, but will not make society stop functioning overnight. A manufacturer of network routers can be forced by their government to push a firmware update that makes their devices sabotage network traffic, but if the goal is overt intervention, there are far easier targets: services and cloud resources. Their users are trivial to identify, and a block can be enforced immediately. As more and more products have moved away from software that runs locally on your computer, towards subscription services that depend on a server managed elsewhere, we have become more vulnerable to access being suddenly cut off.
Data residency is not sovereignty
Part of digital autonomy is the ability to decide who to share your data with. In digital systems, the only reliable way to protect data is through encryption. When data is encrypted, the physical location of the computers that store it, is irrelevant for privacy. Conversely, a promise that data is processed only by servers in a specific geographic location is not a privacy guarantee when foreign parties can assert authority over the software that handles the data.
If you want to make a third party responsible for storing your data at all, there are two ways to do so that preserve sovereignty. Either the third party must fall completely, unambiguously, under your authority. Privacy in this case is a legal requirement, but not guaranteed by construction. Hackers can still steal your data; geopolitical risk is just one of many risk factors! The safer alternative is to encrypt your data with a key not known to the third party. Note that the transparent encryption features that clouds offer do not satisfy this requirement, as the encryption key is known to the cloud provider. While it protects your data against physical theft, it does not shield it from access by foreign governments.
American clouds cannot provide European sovereignty
The software that makes the American hyperscaler clouds tick is global. Whether in the United States, Europe, or elsewhere on the planet, each of their data centers runs the same software. Uniformity is the power of the hyperscalers, and their economy of scale. But with this power comes a weakness: the corporation that controls the software is subject to US jurisdiction, and to the capriciousness of their ruler, who is increasingly meddling in matters of private businesses.
Because the US government has supreme authority over what happens in the hyperscalers’ data centers — even when they are built on European soil — a Europe whose infrastructure depends critically on American hyperscalers, is not digitally sovereign. No matter how many times the hyperscalers use the word sovereign in their marketing copy, and no matter how many local subsidiaries they set up to give decisionmakers a convenient excuse to evade responsibility, the hyperscalers’ internal software remains governed by the United States. When that software starts to interfere with European institutions, society stops functioning. Never mind taking legal action against the local subsidiaries when the courts’ IT systems no longer work. The only way for Europe to become digitally sovereign, is to start reducing our dependence on US big tech.
Towards true digital sovereignty
The path towards digital sovereignty is not going to be an easy one. It’s not always the case that the best products have the most adoption, but usually it is. Organizations always face a trade-off between risk and convenience, and the early movers who are taking the new levels of geopolitical risk seriously, are going to have to accept some temporary discomfort. Fortunately there are feedback loops: as we direct more resources towards sovereign alternatives, they will get better.
There are two ways in which we can spend those new resources. We might build European alternatives to foreign clouds and SaaS products. We would again end up in a situation where organizations are critically dependent on third parties, but at least in Europe they now depend on a local vendor, a sovereign cloud, rather than one in a foreign jurisdiction. Alternatively, we can invest in open source, and products and software that enable everybody to be in control of the infrastructure they depend on, no matter where they are based or who they are allied to. Reality will of course be a mix of both, but our actions will determine where the ratio ends up. At Soverity, we are working hard to tip that ratio towards the second kind: open source.