Operational sovereignty refers to control over how a computing environment is operated. It is realized through a customer-operated control plane, meaning the customer, not the cloud vendor, holds authority over configuration, operations and lifecycle management such as updates, patches and decommissioning.
The term is defined variously, with vendors and analysts drawing its boundaries differently. What most share is a shift in cloud computing's central question, away from "where does the data sit?" and toward "who operates the system, and can they keep operating it?" Operational sovereignty emerges when governance, compliance and control are built into a system from the start.
Operational sovereignty is one of four key components of digital sovereignty, the broader idea that an organization should hold meaningful control over the digital infrastructure, data, software and digital assets it depends on for digital transformation. Digital sovereignty is sometimes framed in terms of four pillars:
Data sovereignty is control over data at rest, in use and in motion. Two related terms sit underneath it: data residency is where data is physically stored, and data localization is complying with the laws that govern where data of a given kind must reside. Sovereign cloud is one mechanism that can be used to help achieve data sovereignty.
Technology sovereignty is the use of open, modular architecture that avoids vendor lock-in. Sometimes called software sovereignty or technology independence, it centers on the ability to run and move workloads across providers rather than being bound to one proprietary stack. Open standards and open-source software can be means towards the end of technology sovereignty, because they can often make a system both portable and transparent.
Join security leaders who rely on the Think Newsletter for curated news on AI, cybersecurity, data and automation. Learn fast from expert tutorials and explainers—delivered directly to your inbox twice weekly. See the IBM Privacy Statement.
AI sovereignty, sometimes called sovereign AI, is control over where artificial intelligence and machine learning models run, as well as how inference—the actual work of a trained model producing outputs—is governed. As organizations embed AI workloads into core operations, sovereignty extends from where data is stored to how models are accessed at runtime, how their decisions are logged and how AI security is maintained. IBM's research has found that 83% of CEOs say AI sovereignty is essential to their business strategy.
Operational sovereignty refers to control over how digital environments are operated. One key feature of operational sovereignty is a customer-operated control plane. An organization with high operational sovereignty is resilient, having the ability to keep critical workloads running under crisis conditions. Put another way, operational sovereignty enables independent management and operations within a region.
Operational sovereignty matters now because several forces are converging:
In theory, one nation’s laws can compel a provider to act against a customer in another jurisdiction. The US CLOUD Act of 2018, for instance, lets US authorities compel US-headquartered providers to produce data in their possession, custody or control, regardless of where it is stored.
Regulatory pressure is increasingly steering digital sovereignty into a legal obligation. The EU's General Data Protection Regulation (GDPR) restricts transfers of personal data outside the bloc; the Digital Operational Resilience Act (DORA) imposes operational-resilience and third-party-risk duties on financial services firms and their technology suppliers; and the EU Data Act gives cloud customers a statutory right to switch providers. Such regulations make operational sovereignty increasingly a matter of regulatory compliance.
Operational resilience is the ability to keep critical workloads running under crisis conditions. One episode involving the International Criminal Court in 2025 illustrates the point. Shortly after a US executive order in February 2025 sanctioned ICC chief prosecutor Karim Khan, Khan found his Microsoft-powered email account to be disconnected. Though the exact cause and extent of the disruption was disputed, and though Microsoft President Brad Smith wrote a blog post promising resilience commitments to European clients, the ICC in October 2025 announced it was moving away from Microsoft to the German-developed, open-source openDesk platform.
Vendor lock-in is the risk of being unable to leave a single dominant provider. According to Synergy Research Group, the three US “hyperscalers”—giant cloud computing companies, namely Amazon, Microsoft and Google—hold about 70% of the European cloud market, while all European providers combined hold roughly 15%, down from 29% in 2017.
AI is accelerating the shift by moving sovereignty from where data is stored to how models run at runtime. Governing an AI system means controlling where its models execute, how they are accessed and how their outputs are logged.
At the core of achieving operational sovereignty is a customer-operated control plane, which should give the customer full authority over configuration, IT operations and lifecycle management—rather than delegating these controls to the vendor. Also important are customer-held encryption keys: with external key management, the provider cannot decrypt customer data without the customer’s approval, even when served with something like a CLOUD Act order. Identity and access control kept inside the sovereignty boundary further ensure that access is governed locally.
Continuous auditability—through compliance monitoring, automated evidence generation and drift detection that flags unauthorized changes—lets an organization prove its controls and security posture are working. Workload portability built on open standards avoids lock-in. Disaster recovery planning helps ensure operational resilience and business continuity in the event of failures, cyberattacks and cutoffs.
Open source is a foundational enabler of operational sovereignty because it supplies both transparency and portability. Inspectable code lets an organization verify how a system behaves rather than trust a vendor’s assurances, and open standards let workloads move between providers instead of being locked to one stack.
The biggest challenge in a hybrid environment is fragmentation: control planes, key management and audit evidence can scatter across cloud and on-premises IT systems. Red Hat, for example, describes hybrid cloud management as involving “disparate sets of fragmented tools” and says distributed environments require integrated management and consistent policy enforcement. One approach is to establish a consistent sovereign control layer across hybrid infrastructure. IBM Sovereign Core, for instance, provides a customer-operated control plane and integrated governance on a Red Hat OpenShift foundation, with authentication, authorization, encryption keys and access management kept within the sovereign boundary under customer control.
Neglecting operational sovereignty in critical infrastructure risks losing the ability to keep essential digital services running when an external party intervenes. The International Criminal Court’s abrupt loss of access to an email account after US sanctions shows how an action originating abroad can disrupt operations regardless of where data is stored. Regulators treat this as systemic risk in finance: DORA’s oversight regime for critical technology providers exists precisely because concentrated dependence on a few operators can threaten an entire sector’s stability.
Purpose-built sovereign software that empowers enterprises, governments and service providers to create, deploy and manage secure, AI-ready environments.
| Stay ahead of evolving regulations. IBM helps organizations meet compliance requirements, govern AI responsibly and maintain visibility across data, applications and infrastructure. |
| Build a cloud strategy that balances innovation with control. IBM helps organizations design hybrid cloud environments that support data sovereignty, security, compliance and business agility. |