Digital sovereignty and the security sector
Who controls the infrastructure of power?
When a government coordinates a military operation, processes intelligence, or manages critical national infrastructure, the software enabling those functions belongs to someone. In most cases across the world today, that someone is a foreign corporation operating under a foreign legal system. The question of who controls that software, and under what legal conditions access to the data it processes can be compelled, has moved from the margins of technology policy into the centre of national security planning.
63% of cloud spending
Three American companies, Amazon, Microsoft and Google, take most of the world’s cloud infrastructure spending.
Synergy Research Group, Q1 2026
99.98% of smartphones
Almost every smartphone runs one of two American operating systems, Android or iOS.
StatCounter, September 2026
41% of telecom equipment
One Chinese company, Huawei, earns this share of telecom equipment revenue outside North America.
Dell’Oro Group, 2025
Digital sovereignty
Digital sovereignty refers to a state’s capacity to exercise meaningful legal and operational control over its digital infrastructure, data, and the technology systems on which its functions depend. For decades, this was treated as an administrative concern. The proliferation of cloud computing, the consolidation of the global technology market around a handful of American and Chinese corporations, and a series of legal and geopolitical shocks have forced a reassessment. States are now confronting a structural reality: critical functions of government and security have been built on foundations controlled by others.
The Legal Architecture of Dependency
United States
The clearest expression of this problem is the United States Clarifying Lawful Overseas Use of Data Act, passed in 2018.
The CLOUD Act grants American law enforcement and intelligence authorities the power to compel US-based technology companies to produce data stored on their servers anywhere in the world. Physical location is irrelevant. A government agency in Berlin, Ankara, or Islamabad running its operations on Microsoft Azure, Amazon Web Services, or Google Cloud has no legal shield against a US court order requiring that data to be produced. The data remains subject to American jurisdiction regardless of where it sits.
This provision creates a direct conflict with the European Union’s General Data Protection Regulation, which prohibits transferring personal data outside the EU without adequate safeguards. The CLOUD Act creates conditions under which that transfer occurs without the knowledge or consent of the data subject, the data controller, or the host government. The conflict is not theoretical. Microsoft confirmed under oath during European parliamentary proceedings that data stored in EU data centres remains accessible to US government requests. The European Commission’s own impact assessments have found that sovereign-branded cloud products offered by American providers, which promise European data residency and European administrative access controls, do not remove exposure to third-country laws.
The CLOUD Act is not the only instrument of this kind. The US Foreign Intelligence Surveillance Act grants American security services direct access to data held by US-owned companies. China’s Personal Information Protection Law and its National Security Law impose comparable obligations on Chinese technology firms, requiring them to cooperate with state intelligence requirements on demand. Any state whose critical infrastructure runs on platforms built by corporations subject to these laws has, in effect, outsourced a measure of its sovereign control over that infrastructure to the governments those corporations answer to.
The Security Sector Dimension
United States
The implications for the security sector are the most acute. When defence ministries, intelligence agencies, and law enforcement bodies run their operations on foreign-licensed proprietary software, the vendor controls more than the product.
It controls the terms of service, the update and patch schedule, the conditions under which technical data is shared, and critically, the ability to suspend or terminate service. Licence revocation, withdrawn software support, or vendor compliance with their home government’s sanctions and export controls can interrupt operational systems at moments of maximum pressure.
Levers of control
Department of Defense, The Pentagon, Arlington, Virginia
The United States Department of Defense has identified vendor lock-in as a national security risk in its own procurement context, noting that proprietary closed-source systems leave military operations dependent on commercial timelines and commercial decisions.
Directorate of Defense Trade Controls, State Department, Washington, DC
Export control regimes add a further layer. The United States International Traffic in Arms Regulations govern not only the physical export of defence articles but the software, technical data, and maintenance services associated with them.
When a vendor decides, under pressure from its home government, to restrict access, deny an update, or comply with an export control designation, the purchasing state has limited recourse. The contract governs the commercial relationship. It does not govern what the vendor’s government can require of it.
A state operating US-origin defence platforms does not simply purchase a product. It accepts an ongoing legal relationship in which the US government retains authority over how that equipment is used, upgraded, and shared. That authority can be exercised at any time, and the state on the receiving end has no equivalent leverage in return.
Europe’s Response
Europe
The response across Europe has been substantial and accelerating.
Responses by country
Kiel, Schleswig-Holstein, Germany
Germany’s state of Schleswig-Holstein migrated 30,000 government computers away from Microsoft products toward open-source platforms.
Paris, France
France has moved toward migrating 2.5 million civil servants off American software, with the French Gendarmerie having previously moved over 70,000 workstations to a custom Linux distribution.
Rome, Italy
Italy’s Ministry of Defence standardised on open-source office software for 150,000 military computers.
Vienna, Austria
Austria’s armed forces replaced proprietary office suites with open-source alternatives. Denmark, Austria, and Germany are all pursuing similar transitions at the institutional level.
All 27 member states
The European Union has attempted to address the underlying legal architecture through instruments including the GDPR and ongoing negotiations over transatlantic data transfer frameworks. Each framework has faced legal challenge. The EU-US Privacy Shield arrangement was invalidated by the Court of Justice of the European Union in 2020 on the grounds that US surveillance law did not provide adequate protection for European data. Its successor framework faces similar pressure. The legal conflict between European data protection standards and American intelligence access has not been resolved. It has been managed, incompletely, through successive political agreements.
These decisions reflect a convergence of motivations. Cost savings are real and documented, but they are secondary. The primary driver is control. European governments have concluded that running sensitive state functions on infrastructure they do not legally control, and cannot fully audit, represents a structural vulnerability that savings on licensing fees do not justify.
The Regulatory Gap
European Union
A further complication has emerged from the EU’s own regulatory architecture. The EU AI Act, which came into force in 2024 and represents the most comprehensive regulatory framework for artificial intelligence yet enacted, contains a blanket exemption for military, defence, and national security AI systems. This means that AI tools used within the security sector, including targeting assistance, surveillance systems, intelligence analysis platforms, and autonomous systems, fall entirely outside the Act’s requirements for transparency, human oversight, and risk assessment. The security sector is precisely where the risks of AI deployment are highest, and it is precisely where European regulatory frameworks have chosen not to reach.
The combined effect is a regulatory gap that runs through the most sensitive domain of state activity. Civilian AI systems face detailed obligations. Military and security AI systems face none. Sovereign-branded cloud products promise control but do not deliver legal immunity from third-country access. Open-source migration addresses vendor lock-in but does not by itself address the intelligence access problem.
Conclusion
Worldwide
Digital sovereignty has become a security question because the infrastructure of state power, from communications to intelligence to military operations, now runs on technology whose legal jurisdiction, commercial terms, and continued availability are determined by others. States that have not reckoned with this have built their security architecture on ground they do not own.
The European response demonstrates that the problem is solvable in part. Open-source migration reduces vendor lock-in. Data localisation reduces some exposure to foreign legal jurisdiction. Indigenous capability development reduces structural dependence over time. None of these measures resolves the problem completely, and each requires sustained political will and institutional investment to deliver. What the European experience also demonstrates is that waiting for a crisis to force the issue is a poor strategy. By the time the vulnerability becomes visible, it has already been exploited.