A blueprint for digital sovereignty you can actually prove

This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time. Here, Natalie Denyer, VP for Client Engineering at IBM, shares practical steps leaders should prioritise now and the sovereignty pitfalls emerging across UK organisations as regulation evolves.

In this article, she warns of “a system that appears ‘sovereign’ on paper but lacks the flexibility required for a dynamic digital landscape”. A problem that is only being exacerbated by the rise of AI. Read on to find out why Natalie believes we need to rethink digital sovereignty in 2026, and actions you can take now.


Digital sovereignty has emerged as a strategic business imperative. Across industries, focus is intensifying on data governance and autonomy as critical drivers of resilience and competitiveness. Yet, in my conversations, I identify a gap between the sovereignty organisations believe they have and the sovereignty they can actually prove.

This gap often stems from an appealingly simple narrative: that control is guaranteed by storing data locally or choosing a provider based on nationality. It seems to offer simplicity in a complex landscape, but simplicity and static definitions can be deceptive, creating a sense of control that masks deeper architectural dependencies.

Sovereignty is more than just location 

Natalie Denyer, VP for Client Engineering at IBM
Natalie Denyer, VP for Client Engineering at IBM (image: IBM)

A common misconception in the sovereignty debate is that geographical borders equate to control that can withstand pressure. Storing data exclusively within national borders may satisfy some data residency obligations, but it does not determine who can access it, how it is governed or whether it can be moved when circumstances inevitably change. An organisation can localise every dataset and still rely on proprietary architectures and closed interfaces dictated entirely by a single vendor, effectively limiting their decision-making control.

Insights from global cloud deployments reinforce this point. Even when data is local, the operational model behind it may not be. Without architectural safeguards and transparency, this can create complexity in governance and accountability. The headquarters of a provider does not itself change this dynamic. A domestic supplier can still operate a closed, nonportable stack that limits an organisationโ€™s ability to adapt or diversify โ€“ in practice, they are still limited in their autonomy and strategic independence in a rapidly changing market and context.

A principles-first approach

In the drive for digital sovereignty, a common approach has been to simply replace one technology provider with another โ€“ this leaves the underlying architecture unchanged. This tactic is often guided by a narrow set of criteria that overlooks the most critical elements for long-term success. 

An architecture that is overly aligned with a single ecosystem can limit an organisation’s ability to adapt to new regulations, expand across borders or integrate emerging technologies. The result can be a system that appears โ€œsovereignโ€ on paper but lacks the flexibility required for a dynamic digital landscape. This challenge is magnified by todayโ€™s security environment, where AI-driven threats can quickly exploit inflexible or opaque systems.

A more effective and credible strategy for sovereignty is defined by foundational principles like openness, portability, and interoperability. Rather than focusing on who the provider is, the emphasis should be on how the technology is designed.

By championing an evidence-based approach centred on these principles, built on open foundations, we can help organisations build architectures that are not only compliant but also inherently resilient and adaptable. 

Sovereignty as an architectural capability

To move beyond these limitations, sovereignty needs to be reframed from a geographical outcome to an architectural capability. Real sovereignty is the ability to choose, move and govern technology on your own terms. That requires openness and genuine interoperability – qualities that cannot be achieved through localisation alone.

In the UK, recent policy steps reflect a similar shift in priorities. The government has outlined plans to deepen co-operation with European partners on AI governance and digital standards, including joint work on AI safety approaches and cross-border data frameworks. Alongside this, the Chancellor has announced a ยฃ2.5 billion investment in advanced computing, positioned as part of a broader effort to accelerate responsible AI adoption. 

Modern sovereignty models increasingly recognise this. They emphasise consistent policy enforcement across environments, the ability to apply controls at the workload level and transparent governance mechanisms that operate across hybrid and multicloud estates. These approaches acknowledge that sovereignty is not achieved by isolating systems, but by designing them to be portable, auditable and adaptable.

Architectures built on open standards allow organisations to evolve without being constrained by proprietary interfaces. Interoperable systems make it possible to switch providers or rebalance risk without rewriting entire applications. In this model, sovereignty becomes dynamic. 

AI raises the stakes

The rise of AI makes this architectural view of sovereignty even more urgent. AI introduces new layers of dependency that localisation alone cannot address. Questions of model provenance, training data governance, algorithmic transparency and regulatory accountability become central to sovereignty strategy. An organisation may run AI models locally, yet still depend on training pipelines, datasets or algorithms that are opaque or controlled by external providers.

As advanced AI capabilities concentrate among a small number of actors, the risk of dependency deepens. Without architectural openness, model portability, transparent governance frameworks and interoperable AI pipelines, organisations risk relying on systems they cannot fully audit, adapt or replace. In this context, sovereignty is not defined by where a model runs, but by whether the organisation can understand it, govern it and switch it when needed.

Sovereignty as strategic autonomy

Reducing sovereignty to a once-and-done set of narrow criteria offers comforting simplicity, but simplicity does not build resilience. Real sovereignty is earned through deliberate architectural choices that prioritise flexibility and control. Organisations that embrace these open architectures will be better positioned to innovate, comply and compete in a rapidly changing digital landscape.

Avatar photo
Ricardo Oliveira

Ricardo Oliveira is a Senior Director at TechFinitive, where he frequently collaborates with TechFinitive's editorial team to write and produce content. He's based in Sydney, Australia.