In a connected world, digital sovereignty is a spectrum, not an end state. It can – and should – be a guiding principle rather than a checklist.
At a very basic level, digital sovereignty means being able to determine how your digital infrastructure and services are designed, implemented, used. It means having sufficient control — enough so that no external entity can just flip the on/off switch or use your own infrastructure to spy on you or otherwise weaken you.
How we can move towards that goal is up for debate, there are several basic approaches, some of which are complementary: One is to build a more resilient technological foundation by moving towards a stronger open source base for these technologies, which is what Germany’s Sovereign Tech Agency works towards. (Disclosure: I’ve worked with the Sovereign Tech Agency for many years.) Another is to cultivate local (national/European) champions by fostering a strong start-up and corporate ecosystem building independent companies and services. A third is to incentivize the market to produce more locally by leveraging public sector procurement favoring those local competitors.
But let’s start with first things first.
(I) Digital sovereignty, what?
Rather than defining what digital sovereignty is exactly, let’s take two examples of what digital dependency looks like in practice:
A few days ago, the US government decreed that AI company Anthropic must suspend access to two of its most advanced AI models, Fable 5 and Mythos 5. Concretely, the company “received the export control directive to suspend access to Fable 5 and Mythos 5 for all foreign nationals” (The Guardian). So: Export controls on an AI service.
I’m not going to go into the merits of that particular case. Instead, I want to just highlight one aspect: One government imposed export controls on a service (headquartered in their jurisdiction) that serves clients globally, and hence that service is now unavailable. Since AI services are increasingly becoming infrastructure, this is noteworthy.
Less than half a year ago in February, the US government sanctioned (Wikipedia) judges at the International Criminal Court in The Hague, leading to these judges being denied access (The Guardian) to services by American companies, like Google, Amazon, Microsoft and Visa.
Again, the merits of this case are not my focus here. The key takeaway is that access to key digital infrastructure is denied as leverage for geopolitical purposes.
So while there are many ways to think about digital sovereignty and how to build towards it, on a very pragmatic level, digital sovereignty means being safe from a foreign government just deciding to cut you off from essential services.
(II) Does it really matter?
For many, many years, experts have been warning against an over-reliance on Silicon Valley companies for digital services. Often, and for a long time, they weren’t taken all that seriously because it seemed almost unthinkable that in a deeply, deeply globalized world and with close economic transatlantic ties, the US government might really use these companies so bluntly for geopolitical leverage. Now, with these two examples up there, the theoretical threat has turned very concrete almost overnight. It’s not a hypothetical anymore: We’ve seen the warnings turned into a reality. Still at a small-ish scale, but clearly and explicitly enough that it’s impossible to dismiss.
So, does it matter? Clearly. Yes. Obviously, duh.
(III) What are the bigger implications? What do we do with this now?
Now this is where things get interesting.
Two hypotheses I’ll be building on:
- Digital infrastructure is essential for any nation-state and society today, and it has become essential enough to be used as a potential lever or pressure point for geopolitical purposes.
- Governments are central actors in this, but/and so are the companies themselves, who increasingly also become active political actors.
The first point is self-explanatory: Digital infrastructure is key, we simply cannot live without it anymore. If it’s a service run from a third-party server, it can be switched off, which is bad. This isn’t how we should live. Ideally not as individual users, certainly not at the government-scale infrastructure level.
The second is a little less obvious, but I think merits serious consideration. The days of the tech industry being largely apolitical (or at least not actively pursuing an explicit political agenda) are over. Tech companies, especially of the generation where the founders/funders have kept near-total control even beyond the IPO process, are by necessity largely aligned with those few founders/funders: There is significantly less meaningful external governance pressure than public companies historically faced. A weaker moderating influence that might rein them in other than (potentially, hopefully) laws and regulation. Which is a relatively new phenomenon that mostly started with the companies we currently call “Big Tech”.
Why am I elaborating on this point? Take a company like Palantir, which offers services for intelligence and law enforcement, i.e. with deep access and influence on highly sensitive areas of government activity. The main person behind Palantir, Peter Thiel, repeatedly and openly stated that he thinks individual freedom is more important than democracy, which he thinks is overrated. Or in his exact words: “I no longer believe that freedom and democracy are compatible.” (This quote is from his own essay, The Education of a Libertarian. I don’t want to link to his website.) So: If our governments use this company’s services and integrate them into their IT infrastructure, then there’s twice the risk: The US government shutting down access (or using potential backdoors), and also the company posing a governance and alignment risk as per the owner’s political convictions: If Thiel has to choose between democracy and freedom, he’s told us his choice. So Palantir being used to undermine our local governance, intelligence and security infrastructures is not a super far-fetched scenario given how incredibly close Thiel is to the current administration.
Which brings us back around to the question, what to do?
First, to tie it back to the different approaches mentioned at the top, it makes sense to me to use all these approaches to complement each other: Invest heavily in open source, align public procurement towards more sovereignty by favoring open source (where available) or competitors that are based inside their respective jurisdictions. Also, fostering a company ecosystem makes sense, I would just ask that this doesn’t just turn into economic protectionism but something a little more inspired than that.
So, all the steps, all the approaches. If we must, let’s throw spaghetti at the wall and see what sticks.
That said, first and foremost, I think it’s important we stop investing into deepening dependencies: We should under no circumstances introduce new dependencies. Like, for example, introducing Palantir into our systems. It seems like a matter of time before it’s weaponized geopolitically.
Digital sovereignty is a spectrum: Let’s not walk in the wrong direction. Instead, let’s slowly and steadily walk back dependencies while introducing alternatives. This will not be a linear process. It’ll be possible to make some quick steps in one area while others might be too complex to change much on short notice. But as long as we keep sovereignty and resilience as a north star and make it a strategic priority, over time we’ll be in a much better, safer, more stable position.