Interviews, insight & analysis on digital media & marketing

Digital Sovereignty: why Boards can no longer treat dependency as a technical detail

By Angela Bishop, UK CEO, Zühlke

Digital sovereignty has moved rapidly from a technical concern to a board-level priority across the UK and Europe. Not because organisations suddenly want to own every piece of technology they use, but because boards are recognising a more practical reality: their businesses increasingly depend on infrastructure, software platforms and AI services that sit outside their direct control.

This is not about protectionism or abandoning global technology partners. Cloud, software-as-a-service and AI platforms have delivered enormous benefits. The question is no longer whether organisations should use external platforms, but whether they understand the dependencies and could continue operating if circumstances changed.

Digital sovereignty is best understood as operational autonomy; maintaining enough visibility, flexibility and control over critical systems and data to adapt when circumstances change. The goal is resilience, not isolation.

Driving forces

Several forces are pushing this issue into the boardroom. One driver is regulatory divergence. The UK, EU and US are taking different approaches to data governance, AI regulation and cyber security, creating new complexity for organisations operating across borders. The EU AI Act, the UK’s Cyber Security and Resilience Bill and the National Cyber Security Centre’s roadmap for post-quantum cryptography all point in the same direction: organisations are being expected to understand and demonstrate control over their digital estate. For boards, that is no longer an IT issue but one of governance, compliance and business continuity.

A second driver is market concentration. Azure, AWS and Google Cloud now account for roughly two-thirds of the global cloud market. This has shifted questions about pricing, service continuity, jurisdictional exposure and exit readiness from procurement to the boardroom.

Recent events have shown that dependency risk rarely arrives in the form organisations expect. The SolarWinds breach demonstrated how vulnerabilities can spread through trusted suppliers and affect organisations far removed from the original compromise. VMware customers experienced how quickly commercial terms can change following Broadcom’s acquisition. At the same time, geopolitical and regulatory shifts have shown that technology relationships cannot be assumed to remain stable indefinitely.

The lesson is not that organisations should depend on no one. That would be unrealistic and, in many cases, counterproductive. The lesson is that dependency must be understood, governed and chosen deliberately.

A pragmatic response

Leading organisations are responding pragmatically; mapping critical dependencies, identifying business-critical systems and data, strengthening exit strategies and embedding sovereignty requirements into procurement decisions.

For many workloads, the right answer will still be hyperscale cloud. Sovereignty does not mean treating every system as equally sensitive. It means applying controls proportionate to what is at stake. The operational majority can remain efficient, scalable and cost-effective, while the most critical systems and data receive stronger protection.

The encouraging news is that the tools to achieve this are maturing quickly. Sovereign cloud regions provide an important baseline by keeping data within a chosen jurisdiction, while customer-managed encryption keys and confidential computing give organisations greater control over who can access sensitive data and how it is protected. These capabilities are moving rapidly into the mainstream.

Portability is another important part of the answer. Open standards, modular architectures, containerisation and well-designed exit plans can reduce unnecessary lock-in and make switching providers a realistic option rather than an emergency response. 

The practical path is straightforward: understand your critical dependencies, identify your crown-jewel data, apply stronger controls where they matter most and design enough portability to preserve choice. 

Digital sovereignty is often portrayed as a choice between global cloud and national control. In reality, it is neither. It is about understanding where dependency creates unacceptable risk and designing enough autonomy to manage it. The organisations best placed for the years ahead will not be those trying to own everything themselves. They will be the ones that know exactly what they depend on, have made those choices deliberately and retain the freedom to adapt when circumstances change.