Digital sovereignty describes an organization’s ability to retain control and authority over its technology systems and ecosystems, data, operations and artificial intelligence (AI)—as well its ability to prove that control and authority when it matters. Digital sovereignty is a form of independence and autonomy.
Definitions of digital sovereignty have evolved over the years. Much of the conversation emerged in Europe in the wake of the revelations associated with whistleblower Edward Snowden, whose leaks exposed the reach of many large tech companies. Legislators and civil society groups in Europe began to frame digital sovereignty (and related terms like digital autonomy) as a form of national security, self-sufficiency and strategic autonomy.
More recently, the rise of powerful new AI technology has reframed the debate for many, as have increased regulatory actions in Europe and elsewhere. In such a climate, it may not be surprising that Futurum, in its Q4 recent CIO Insight Survey, determined that 54% of organizations are activity reevaluating where workloads run.
Though much of the regulatory focus has recently been in Europe, it’s important to note that different nations and regions hold varied concepts of digital sovereignty. A 2025 article from World Economic Forum (WEF), for instance, notes differences among U.S., European and Chinese discourse and policy with respect to digital sovereignty. The U.S., WEF notes, does not typically adopt language of digital sovereignty; China promotes a government-led approach to the topic; Europe tends to frame its discourse with a focus on individual rights.
There are several reasons why digital sovereignty has become a topic of increasing concern in board rooms. These include:
Geopolitical tensions have turned dependence on foreign-controlled technology and infrastructure into a strategic risk. Export controls, sanctions and economic coercion can affect access to critical technologies or services. Digital sovereignty helps organizations reduce single-country and single-provider dependencies while retaining greater control over where data and workloads can move, notes the European Commission.
As data and workloads spread across providers, attackers can exploit third-party relationships and other indirect routes into an organization. Digital sovereignty can provide clearer control over administrative access, encryption keys, monitoring and recovery. ENISA’s Threat Landscape 2025 notes that “supply chain risks make up 10.6% [of attacks], showing that attackers are actively leveraging indirect pathways through third-party providers and dependencies.”
The evolving digital risk landscape has led to regulatory action, compelling compliance (or hefty sanctions for the failure to be compliant). Increasingly, boards and regulatory bodies demand clear proof or resiliency and business continuity. Particularly since the advent of the General Data Protection Regulation (GDPR), the European Union’s sweeping data security law, many governments demand stricter controls over how personal data is collected, stored and monetized.
GDPR was just the beginning; subsequent years have seen further regulation emerging from the EU and likeminded governments, including various cybersecurity laws and personal information protection laws.
Artificial intelligence (AI), and more specifically companies’ race to scale AI, intensifies the pressure on the above. Realizing AI benefits requires more systems, more models and more data—but as AI scales, it can become gets difficult to govern.
Companies need to show compliance to more regulations wherever they do business. In the EU alone, AI and related technologies are touched on by the Data Governance Act, Digital Markets Act (DMA), Digital Services Act (DSA) and the EU AI Act—all in addition to the aforementioned GDPR.
Join security leaders who rely on the Think Newsletter for curated news on AI, cybersecurity, data and automation. Learn fast from expert tutorials and explainers—delivered directly to your inbox twice weekly. See the IBM Privacy Statement.
Since digital sovereignty is a diffuse and complex concept, it helps to break digital sovereignty into four main components. The first three may be thought of as “pillars,” while the fourth—the emerging concept of AI sovereignty—cuts across the first three.
Operational sovereignty refers to control over how environments are operated; it emerges when governance, compliance and control are built into a system. One key capability of operational sovereignty is a customer-operated control plane, which ideally enables full authority over configuration, operations and lifecycle management.
One theme within operational sovereignty is resilience, since one cannot possibly have control over a system that is brittle. When true operational sovereignty is achieved, organizations can run critical workloads even under crisis conditions. A related theme is visibility, since one cannot stabilize what one cannot see or verify. A third theme is governance. Without governance, oversight breaks down—and if organizations can’t oversee their systems, they cannot control outcomes. (Many of these concepts are explored in NIST’s 2024 Cybersecurity Framework).
Though digital sovereignty (and its constituent pillars) represent a global concern, again it is Europe which has arguably done the most to recently turn the concept into concrete policy and procurement guidelines for that region. One recent EU document defines operational sovereignty as a metric evaluating “the practical ability of EU actors to run, support, and evolve a technology independently of foreign control.”
In a recent interview with Quest Means Business, IBM CEO Arvind Krishna put it this way: “You need sovereignty... But sovereignty doesn’t mean you cannot use things from another country. But it does mean the control of how they operate, the control of how they get upgraded, the control of how they get maintained, has to live within the country.”
Data sovereignty refers to control over data at rest, in use and in motion. It comprises various related concepts, including in-boundary identity, encryption and data services. Optimal data sovereignty would ensure that all access, secrets, keys, logs and audit evidence remain under customer control.
Other, older frameworks have taken more narrow approaches to data sovereignty, often focused heavily on geography. Related concepts include “data residency,” or the idea that data might be created in one country but stored in another, as well as “data localization,” or the idea that such data might additionally be processed in the country where it comes to reside, per Tech Target.
Data location still matters to the concept of data sovereignty, but newer frameworks assert that the location of data is insufficient without expanding to include broader questions of control: that is, the ability to demonstrate independent authority enabling enforceable compliance over data.
The European Union cites data sovereignty often in its publications. The EU’s 2025 “European Data Union Strategy,” for instance, mentions the need to “safeguard the EU’s data sovereignty to strengthen our global position on international data flows.” It continues, “Sovereignty requires openness to trusted partners, including exchange of data across borders, but on terms that are fair, secure, and consistent with EU values and interests.”
Technology sovereignty looks at the bigger picture of the full tech stack; proponents of this aspect of digital sovereignty often point to the need for open, modular architecture that avoids vendor lock-in. Often, technology sovereignty may emerge from building on top of open standards that support portability, suggests the Business Software Alliance.
Since digital sovereignty is about control and independence, broader architectural decisions about an organization’s full stack of software and platforms inevitably influence that organization’s degree of digital sovereignty. Dependence on opaque or non-portable systems erodes sovereignty by shifting control from the organization to the vendor—creating hidden vulnerabilities, compliance gaps and potential vendor lock-in.
Every architectural decision today determines who holds ultimate authority over systems, and true technology sovereignty emerges when an organization may exit or change the stack without great disruption. These topics are discussed, for instance, by lawfirm Greenberg Traurig and Gartner.
European regulators again are shaping much of the discourse and legislation on the theme of avoiding vendor lock-in and supporting portability. The EU’s 2023 Data Act, for instance, requires contracts to include the right to switch providers and port data to on-premises infrastructure. And the EU’s Digital Markets Act demands interoperability, data access and portability from several large, mostly American firms it has dubbed “gatekeepers” (firms like Apple and Google).
A January 2026 European Parliament resolution, “European technological sovereignty and digital infrastructure,” calls for the EU to build digital infrastructure “on common and open standards” that “promote interoperability and interconnection.”
Third-party open-source providers unsurprisingly concur. “Genuine digital sovereignty goes far beyond a European government buying European software. It means a government not having to rely on a specific vendor—European or otherwise,” writes Amandine Le Pape, cofounder and COO of the open-source software firm Element, in a February 2026 post arguing “open source is key to Europe’s digital sovereignty.”
Though AI is of course inherently related to operations, data and technology, AI sovereignty is increasingly cited as a distinct pillar of digital sovereignty due to the rapidity with which this wide-ranging technology is transforming organizations’ operations.
Broadly, AI sovereignty refers to control over where models run and how inference is governed. Highly sovereign AI would entail governed AI execution, ensuring that models, inference and agent operations run within defined sovereign boundaries.
The speed with which AI is being deployed has arguably raised the bar for sovereignty, intensifying the need for transparency and control over AI and its underlying components, according to NIST’S AI Risk Management framework. AI’s rapid adoption adds urgency to bring more systems, models and decisions under enterprise control as it matures. To achieve full AI sovereignty, organizations should be able to verify and govern AI behavior, according to OECD’s AI principles.
The topic is growing in importance to executives, investors and government officials. A recent McKinsey survey of 300 of such respondents found that 71% placed sovereign AI in the category of either “existential concern” or at least “strategic imperative.” At the same time, it remains unsettled what exactly sovereign AI might mean in a world where only two countries (China and the U.S.) dominate the sector.
For this reason, The Economist goes so far as to call sovereign AI with full independence from either of those countries’ firms effectively a “pipe dream,” as of 2026—though it notes that “a degree of protection from coercion” remains possible. It concludes, “Governments will need to decide which parts of the [AI] stack they want to recreate at home and which dependencies are worth living with.”
Recent research from IBM’s Institute for Business Value, “The calculus of AI sovereignty,” likewise acknowledges that AI sovereignty may occur in fits and starts. The research presents a model of “selective AI sovereignty” where vendor lock-in may be acceptable for less strategic elements of a business (like transcription or translation), but unacceptable for more strategic elements. According to the research, 72% of executives say they would accept a 20% cost increase to maintain multiple AI vendors if it improved strategic freedom.
The EU does not yet appear to have ratified a formal definition of “AI sovereignty” yet. But this might soon change. On June 3, 2026, the European Commission (the EU’s main executive body) proposed the Cloud and AI Development Act (CADA). The Commission says the proposal introduces “a single EU-wide sovereignty framework to assess cloud and AI sovereignty.” It describes four assurance levels based on factors like data location, independence from non-EU countries, EU ownership and control over the software supply chain. But CADA remains just a proposal as of this writing; an April 2026 joint roadmap from the European Parliament, Council and Commission has set the fourth quarter of 2027 as the target for agreement on CADA.
While the above constitute the primary pillars or components of digital sovereignty and digital sovereignty solutions, firms may also want to ensure that a sovereignty solution contains specific components or features to address other concerns. These include:
The rise of digital sovereignty means different things for different types of executives and departments within a business, including:
For CIOs, digital sovereignty means designing an IT architecture an organization can continue to control even as vendors and regulations may change. This means knowing where data and workloads run, maintaining interoperability and preserving the ability to move applications and data between cloud and on-premise storage without lock-in. CIO.com further recommends in a June 2026 article classifying workloads by sovereignty and risk profile, as well as building “portability and exit into every layer of the stack.”
For CISOs, digital sovereignty means maintaining effective security control over sensitive data and workloads: controlling who can access data, gaining visibility into infrastructure changes that could affect security and ensuring critical workloads survive disruption. “It’s crucial for CISOs and board members to regularly assess their current strategies and collaborate with leaders across the organization,” writes Archana Ramamoorthy, a data security expert at Google.
Procurement managers may want to take measure to make sovereignty measurable in the buying process. For instance, they might set a minimum acceptable level of control and compare providers across metrics like jurisdiction, data control, operational autonomy, and interoperability. Some procurement guidance has been promulgated by the European Commission, in its “Cloud Sovereignty Framework” — discussed in more detail below.
For compliance leaders, digital sovereignty means translating jurisdictional requirements into demonstrable controls. That includes mapping where regulated data is stored, processed and transferred; determining which laws apply; verifying that cloud providers and contracts satisfy those requirements; and maintaining audits and documentation that prove compliant handling over time. “Compliance teams should be involved... to identify and address data sovereignty risk,” writes ISACA.
For risk management professionals, digital sovereignty means treating dependence on external technology providers and jurisdictions as an enterprise resilience risk. That includes assessing provider concentration and vendor lock-in risk, among other forms of risk. “A regular review of the supervised entity’s dependence on individual service providers … is strongly advisable,” writes the European Central Bank in its guidance on concentration and lock-in risk.
The increased discourse around digital sovereignty—as well as related concepts like cloud sovereignty, data sovereignty and AI sovereignty—suggest this is a term relevant for anyone in the business world or government. That said, some industries are more affected by regulatory trends than others; the following in particular may want to discuss how to align operations with compliance requirements.
(In many areas, the EU has adopted some of the world’s most stringent legislation. Its requirements can affect not only European organizations, but also companies outside Europe that operate in the EU, serve EU customers or provide technology to regulated EU organizations. For that reason, through much of this article, the focus is on contemporary EU regulations, though there will also be brief explanations of relevant US and Chinese law for a sense of comparison.)
For the European market, legislation known as DORA (for Digital Operational Resilience Act, officially Regulation 2022/2554) requires EU financial institutions to manage ICT failures and risks involving technology suppliers. (Again, such resilience—reducing dependence and single points of failure—is widely considered a crucial aspect of digital sovereignty.) DORA entered into effect on 17 January 2025, according to EIOPA, or the European Insurance and Occupational Pensions Authority.
Similar operational-resilience and critical-provider regimes are emerging elsewhere, including the UK, according to the UK’s Financial Conduct Authority (FCA). The FCA announced that, as of Monday July 13, 2026, it would begin overseeing what it terms “critical third parties” underpinning the UK’s financial system (like Amazon Web Services and Google Cloud, among others).
In the United States, the Gramm-Leach-Bliley Act’s Safeguards Rule requires covered financial institutions to protect customer data and oversee service providers that handle it. In China, financial-sector rules regulate cross-border data transfers, specifying when financial data may be exported and which compliance procedures apply.
The EHDS (for “European Health Data Space,” officially EU Regulation 2025/327) creates EU rules for electronic health records, as well as the access, exchange and reuse of health data. Provisions begin applying in stages from March 26, 2027. Non-EU EHR (electronic health record) manufacturers putting products on the EU market must meet its conformity requirements and appoint an EU representative.
In the U.S., HIPAA’s Security Rule requires covered healthcare organizations and their business associates to protect electronic health information through administrative, physical and technical safeguards.
In China, the Personal Information Protection Law classifies medical and health information as sensitive personal information and imposes added requirements on its processing and transfer abroad.
NIS2, in addition to issuing requirements of the public sector, also covers providers of public communications networks and services. Jurisdiction generally follows the EU country in which the service is provided, so once again, even a telecom company that may be headquartered outside of Europe may need to be compliant if it serves European markets.
UK’s 2021 Telecommunications (Security) Act imposes similar requirements in the UK.
In the U.S., Section 222 of the Communications Act requires telecommunications carriers to protect the confidentiality of customer proprietary network information.
In China, critical-infrastructure rules cover public communications and information services, requiring designated operators to strengthen cybersecurity and store personal information and important data collected in China domestically.
In the EU, the public sector itself is becoming a leading client of digital sovereignty solutions. Directive (EU) 2022/2555, commonly known as NIS2, is the European Union’s central cybersecurity legislation. Adopted in December 2022, it requires certain levels of cybersecurity across critical infrastructure and digital service providers in all EU Member States. (NIS stands for Network and Information Systems.)
More concretely, in 2025, the European Commission (the EU’s main executive body) published its Cloud Sovereignty framework. The framework was not a law, but rather a concrete scorecard the Commission developed to evaluate cloud providers. The Commission announced that it would use the scorecard when evaluating bids in a major cloud-services procurement effort on behalf of EU institutions, offices and agencies—a competitive buying process known as a “tender.”
“The tender establishes a benchmark for how sovereignty is applied in practice,” shared the Commission in announcing its framework, which measures sovereignty across eight concrete objectives (strategic, legal, operational, security, openness and several others). In April 2026, the Commission announced four contract winners, including a Luxembourgish-French partnership led by Post Telecom and a German company called STACKIT. The Commission’s hope is that its own process of using its sovereignty framework to guide vendor purchases will now serve as a model to governments in various member states.
The Commission’s sovereignty framework is nuanced, offering five tiers or “SEALs” (for Sovereignty Effectiveness Assurance Level). Though branded as a “cloud sovereignty” framework, a deeper dive indicates that it is in fact a framework addressing notions of digital sovereignty that extend beyond matters of data storage, particularly at the higher tiers. The five tiers are (with rough descriptors):
The European Commission insisted that SEAL-2 (data sovereignty) was the bare minimum it would accept. Of the four contracts awarded, three attained SEAL-3, one attained SEAL-2. None reached SEAL-4—itself an indicator that the framework is an expression of aspiration of the direction in which business might trend in the future.
A May 2026 study co-authored by Futurum and IBM describes what has been a historically “uneven” market response to the demand for digital sovereignty solutions. Many sovereign offerings take traditional cloud services (sometimes called “public cloud,” since anyone can pay to use the same infrastructure), restrict it to a geographic boundary, then market the result as “sovereign cloud.” The problem, according to the study, is that such an approach proves inadequate for compliance mandates faced by highly regulated enterprises and public sector clients.
Legacy sovereign solutions do address the issue of data residency, satisfying certain regulations around local data retention. But the study identified remaining gaps, among them:
The contention is that data sovereignty is insufficient for full digital sovereignty and that these and other gaps should be addressed. This is part of a broader trend reframing digital sovereignty as evolving beyond mere data sovereignty or “cloud sovereignty” and encompassing a broader set of principles, including operational control, vendor independence and provable compliance.
In addition to the concerns above, firms evaluating sovereignty solutions should keep the following in mind:
Purpose-built sovereign software that empowers enterprises, governments and service providers to create, deploy and manage secure, AI-ready environments.
Maintain full autonomy over your data, infrastructure and technology, ensuring control, security and flexibility in every environment.
Transform your business and manage risk with a trusted global leader in cybersecurity, cloud and managed security services.