05.09.2026
Raghuram Pillai
Computational sovereignty is the nation-state-facing counterpart of computational citizenship. If computational citizenship asks whether individuals can exercise rights through digital systems, computational sovereignty asks whether a political community can govern itself when its essential computational infrastructure is controlled by foreign states, foreign firms, proprietary standards, concentrated cloud markets, extraterritorial sanctions, or opaque AI supply chains.
Traditional sovereignty concerned territory, population, lawmaking power, borders, and coercive capacity. Digital transformation does not replace those elements, but it alters their conditions. States now rely on cloud hosting, identity databases, payment systems, digital documents, AI models, cybersecurity services, data centres, telecom networks, and platform visibility to perform public functions. Whoever controls the infrastructure can influence the state’s practical capacity to govern.
Computational sovereignty therefore arises from a structural fact: public power is increasingly exercised through computational dependencies. Courts file electronically; welfare depends on identity databases; tax systems run on cloud infrastructure; police use digital evidence systems; hospitals rely on electronic health records; schools use learning platforms; regulators need platform data; and central banks supervise digital payments. A state that cannot audit, migrate, secure, or contest these systems may retain formal sovereignty while losing operational sovereignty. This fear seems to manifest in inter-governmental agreements like the Pax Silica.
Computational sovereignty has six elements.
First, infrastructural autonomy: the state must know which digital systems are critical, who controls them, where data is processed, what laws apply, and whether substitutes exist.
Second, data sovereignty: public data must be governed through lawful access, purpose limitation, security, retention, transfer controls, and democratic accountability.
Third, cloud and vendor sovereignty: public authorities must avoid irreversible lock-in through portability, interoperability, exit rights, audit rights, and multi-cloud or sovereign-cloud strategies.
Fourth, AI compute sovereignty: states must develop capacity to access, regulate, or procure the compute and models necessary for public-interest AI, language inclusion, scientific research, cybersecurity, and public administration.
Fifth, cybersecurity sovereignty: critical digital infrastructure must be resilient against attacks, supply-chain compromise, and foreign disruption.
Sixth, legal sovereignty: domestic constitutional and statutory obligations must not be silently displaced by private contracts, foreign surveillance law, sanctions compliance, or proprietary technical standards.
Regulatory Attempts
The EU
The European Union provides the most developed example of computational sovereignty through regulation rather than pure localisation. The General Data Protection Regulation (GDPR) and the EU Charter of Fundamental Rights (CFR) governs personal data and restricts transfers where protection is inadequate. Schrems II intensified European concern about foreign surveillance access and inadequate redress in international data transfers. The Data Act now goes further by creating rules on fair access to and use of data and by facilitating switching between data-processing services, including cloud services.
The Data Governance Act establishes rules for the re-use of protected public-sector data and frameworks for data intermediation and data altruism. The Digital Markets Act regulates gatekeepers and seeks to make digital markets fairer and more contestable. The Interoperable Europe Act supports cross-border interoperability of public-sector digital systems, which is essential for avoiding fragmented or vendor-dependent digital administration. The AI Act creates a risk-based legal framework for AI systems. NIS2 creates a common cybersecurity framework across the Union.
India
India offers a different model through digital public infrastructure. India Stack describes itself as a set of open APIs and digital public goods for identity, data, and payments at population scale. UPI, developed by NPCI, is an instant payment system run by an RBI-regulated entity. A 2026 PIB release stated that UPI processed approximately 22,000 crore transactions in calendar year 2025. DigiLocker, a MeitY initiative, describes itself as a secure cloud-based platform for storing, sharing and verifying documents, with more than 70 crore registered users and more than 900 crore issued documents. This model shows sovereignty through public digital rails rather than only through restrictive data-localization rules.
Sovereigns battling the exposure
Cloud infrastructure is the substrate of modern public administration. Synergy Research Group reported that Amazon, Microsoft and Google together accounted for 63% of enterprise cloud infrastructure spending in Q3 2025. In Europe, Synergy reported that European cloud providers’ market share had fallen from 27% to 13% between early 2017 and Q2 2022, while Amazon, Microsoft and Google were the main beneficiaries of market growth. Concentration is not the same as monopoly in the competition-law sense. But for sovereignty, the concern is different: switching costs, proprietary architectures, foreign legal exposure, service termination, procurement lock-in, and operational dependence.
The EDPS Microsoft 365 decision illustrates this point. In March 2024, the European Data Protection Supervisor found that the European Commission had infringed data-protection rules in its use of Microsoft 365, particularly around purpose limitation, international transfers, and unauthorised disclosures. In July 2025, the EDPS concluded that the Commission had remedied the infringements and closed enforcement proceedings. The lesson is that sovereign cloud dependency requires enforceable governance, not trust alone.
Open-source alternatives
Open source has become a practical sovereignty strategy because it can reduce vendor lock-in, improve auditability, support interoperability, and preserve institutional knowledge. Schleswig-Holstein’s migration toward open-source tools and away from Microsoft dependence has been widely treated as a digital-sovereignty measure. Reports in 2025 described migration of public-sector systems such as office software and email toward open-source alternatives, though implementation produced operational challenges. Denmark’s Ministry of Digital Affairs also moved from Microsoft Office toward LibreOffice while retaining Windows, framing the shift as a way to reduce dependence on dominant foreign technology providers.
Open source is not a magical solution. It requires maintenance, training, security governance, procurement reform, and institutional support. But as a sovereignty tool, it changes the bargaining position of the state. A public body that can inspect code, migrate data, change vendors, and pool development with other public bodies is less vulnerable to unilateral changes in pricing, licensing, sanctions, or product design.
Sanction Risks
The ICC sanctions episode demonstrates how foreign legal power can be translated through private infrastructure. Executive Order 14203 authorised sanctions against certain ICC-related persons. The State Department later listed additional ICC sanctions actions in 2025. Associated Press reported that ICC prosecutor Karim Khan lost access to email and had bank accounts frozen.
For computational sovereignty, the issue is stark. A legal order can project power not only through troops, treaties, or tariffs, but through cloud accounts, email systems, banking rails, payment processors, software licenses, and compliance departments. A court, regulator, or ministry that cannot continue operating when a foreign sanctions regime affects its vendors lacks sovereign resilience.
State Control
India’s digital public infrastructure offers a sovereignty model built around state-enabled, interoperable platforms. Aadhaar supplies identity, UPI supplies payments, and DigiLocker supplies digital documents. UPI’s scale and interoperability show that public digital rails can reduce dependence on foreign card networks or closed payment ecosystems. DigiLocker shows how state-recognized digital documents can reduce reliance on paper bureaucracies and fragmented private verification systems.
The strength of this model is sovereign capacity: the state can define standards, enable private innovation over public rails, and expand inclusion. The risk is surveillance and exclusion. If identity, payments, and documents become deeply integrated, the state must ensure privacy, security, decentralization where possible, alternative access, and remedies.