Abstract 3D blue-whiterounded square blocks

What is operational sovereignty?

Operational sovereignty, defined

Operational sovereignty refers to control over how a computing environment is operated. It is realized through a customer-operated control plane, meaning the customer, not the cloud vendor, holds authority over configuration, operations and lifecycle management such as updates, patches and decommissioning.

The term is defined variously, with vendors and analysts drawing its boundaries differently. What most share is a shift in cloud computing's central question, away from "where does the data sit?" and toward "who operates the system, and can they keep operating it?" Operational sovereignty emerges when governance, compliance and control are built into a system from the start.

Operational sovereignty as a key component of digital sovereignty

Operational sovereignty is one of four key components of digital sovereignty, the broader idea that an organization should hold meaningful control over the digital infrastructure, data, software and digital assets it depends on for digital transformation. Digital sovereignty is sometimes framed in terms of four pillars:

  • Data sovereignty — control over data at rest, in use and in motion.
  • Technology sovereignty — open, modular architecture that avoids vendor lock-in.
  • AI sovereignty — control over where models run and how inference is governed.
  • Operational sovereignty — control over how environments are operated.

Data sovereignty

Data sovereignty is control over data at rest, in use and in motion. Two related terms sit underneath it: data residency is where data is physically stored, and data localization is complying with the laws that govern where data of a given kind must reside. Sovereign cloud is one mechanism that can be used to help achieve data sovereignty.

Technology sovereignty

Technology sovereignty is the use of open, modular architecture that avoids vendor lock-in. Sometimes called software sovereignty or technology independence, it centers on the ability to run and move workloads across providers rather than being bound to one proprietary stack. Open standards and open-source software can be means towards the end of technology sovereignty, because they can often make a system both portable and transparent.

AI sovereignty

AI sovereignty, sometimes called sovereign AI, is control over where artificial intelligence and machine learning models run, as well as how inference—the actual work of a trained model producing outputs—is governed. As organizations embed AI workloads into core operations, sovereignty extends from where data is stored to how models are accessed at runtime, how their decisions are logged and how AI security is maintained. IBM's research has found that 83% of CEOs say AI sovereignty is essential to their business strategy.

Operational sovereignty

Operational sovereignty refers to control over how digital environments are operated. One key feature of operational sovereignty is a customer-operated control plane. An organization with high operational sovereignty is resilient, having the ability to keep critical workloads running under crisis conditions. Put another way, operational sovereignty enables independent management and operations within a region.

Why operational sovereignty matters now

Operational sovereignty matters now because several forces are converging:

  • Geopolitical reach of national law over global providers.
  • Regulatory pressure turning sovereignty into a legal obligation.
  • Operational resilience demands in a crisis.
  • Vendor lock-in from hyperscaler concentration.
  • AI as an accelerant moving control to the runtime layer.

Geopolitical reach

In theory, one nation’s laws can compel a provider to act against a customer in another jurisdiction. The US CLOUD Act of 2018, for instance, lets US authorities compel US-headquartered providers to produce data in their possession, custody or control, regardless of where it is stored.

What is AI Data Management?

Discover, Clean, & Secure Data with AI

Discover how AI Data Management tackles shadow data, poor data quality, and security risks, using AI-powered classification, natural language queries, and anomaly detection to unlock insights and streamline operations.

Regulatory pressure

Regulatory pressure is increasingly steering digital sovereignty into a legal obligation. The EU's General Data Protection Regulation (GDPR) restricts transfers of personal data outside the bloc; the Digital Operational Resilience Act (DORA) imposes operational-resilience and third-party-risk duties on financial services firms and their technology suppliers; and the EU Data Act gives cloud customers a statutory right to switch providers. Such regulations make operational sovereignty increasingly a matter of regulatory compliance.

Operational resilience

Operational resilience is the ability to keep critical workloads running under crisis conditions. One episode involving the International Criminal Court in 2025 illustrates the point. Shortly after a US executive order in February 2025 sanctioned ICC chief prosecutor Karim Khan, Khan found his Microsoft-powered email account to be disconnected. Though the exact cause and extent of the disruption was disputed, and though Microsoft President Brad Smith wrote a blog post promising resilience commitments to European clients, the ICC in October 2025 announced it was moving away from Microsoft to the German-developed, open-source openDesk platform.

Vendor lock-in

Vendor lock-in is the risk of being unable to leave a single dominant provider. According to Synergy Research Group, the three US “hyperscalers”—giant cloud computing companies, namely Amazon, Microsoft and Google—hold about 70% of the European cloud market, while all European providers combined hold roughly 15%, down from 29% in 2017.

AI as an accelerant

AI is accelerating the shift by moving sovereignty from where data is stored to how models run at runtime. Governing an AI system means controlling where its models execute, how they are accessed and how their outputs are logged.

What it takes to achieve operational sovereignty

At the core of achieving operational sovereignty is a customer-operated control plane, which should give the customer full authority over configuration, IT operations and lifecycle management—rather than delegating these controls to the vendor. Also important are customer-held encryption keys: with external key management, the provider cannot decrypt customer data without the customer’s approval, even when served with something like a CLOUD Act order. Identity and access control kept inside the sovereignty boundary further ensure that access is governed locally.

Continuous auditability—through compliance monitoring, automated evidence generation and drift detection that flags unauthorized changes—lets an organization prove its controls and security posture are working. Workload portability built on open standards avoids lock-in. Disaster recovery planning helps ensure operational resilience and business continuity in the event of failures, cyberattacks and cutoffs.

Frequently asked questions about operational sovereignty

What role does open source play in operational sovereignty?

Open source is a foundational enabler of operational sovereignty because it supplies both transparency and portability. Inspectable code lets an organization verify how a system behaves rather than trust a vendor’s assurances, and open standards let workloads move between providers instead of being locked to one stack.

What are the biggest challenges to operational sovereignty in a hybrid cloud environment?

The biggest challenge in a hybrid environment is fragmentation: control planes, key management and audit evidence can scatter across cloud and on-premises IT systems. Red Hat, for example, describes hybrid cloud management as involving “disparate sets of fragmented tools” and says distributed environments require integrated management and consistent policy enforcement. One approach is to establish a consistent sovereign control layer across hybrid infrastructure. IBM Sovereign Core, for instance, provides a customer-operated control plane and integrated governance on a Red Hat OpenShift foundation, with authentication, authorization, encryption keys and access management kept within the sovereign boundary under customer control.

What are the risks of neglecting operational sovereignty in critical infrastructure?

Neglecting operational sovereignty in critical infrastructure risks losing the ability to keep essential digital services running when an external party intervenes. The International Criminal Court’s abrupt loss of access to an email account after US sanctions shows how an action originating abroad can disrupt operations regardless of where data is stored. Regulators treat this as systemic risk in finance: DORA’s oversight regime for critical technology providers exists precisely because concentrated dependence on a few operators can threaten an entire sector’s stability.

David Zax

Staff Writer

IBM Think

Related solutions
IBM Sovereign Core

Purpose-built sovereign software that empowers enterprises, governments and service providers to create, deploy and manage secure, AI-ready environments.

Explore IBM Sovereign Core
Digital sovereignty solutions
Stay ahead of evolving regulations. IBM helps organizations meet compliance requirements, govern AI responsibly and maintain visibility across data, applications and infrastructure.
Explore digital sovereignty solutions
Cloud strategy consulting 
Build a cloud strategy that balances innovation with control. IBM helps organizations design hybrid cloud environments that support data sovereignty, security, compliance and business agility. 
Explore cloud strategy consulting
Take the next step

Discover how IBM Sovereign Core empowers enterprises, governments and service providers with purpose-built sovereign software to create, deploy and manage AI-ready environments, while maintaining full autonomy over data, infrastructure and technology.

  1. Discover IBM Sovereign Core
  2. Explore digital sovereignty solutions