Digital sovereignty is changing the cloud strategy
For years, the cloud decision was largely about cost, performance, scale, and access to better technology. That calculation is changing. Geopolitics and regulation now matter almost as much as technical capability.
Kyndryl’s 2025 Cloud Readiness Report makes the shift clear. Three-quarters of business leaders are concerned about the geopolitical risks of storing data in global cloud environments. Another 65% are changing their cloud strategies because of digital sovereignty requirements. This is already affecting infrastructure decisions.
Digital sovereignty is essentially about control. Where is your data stored? Which laws govern it? Who can access it? Who operates the infrastructure? And what happens if regulations or relations between countries change? These questions become more important as companies put sensitive corporate data, intellectual property, and critical processes into AI systems.
For the C-suite, this changes how cloud infrastructure should be evaluated. A platform may be technically excellent and still create regulatory or geopolitical exposure. Keeping data inside a country can reduce some of that exposure, but data location alone does not create sovereignty. A company can operate infrastructure locally while remaining dependent on foreign software, chips, cloud management systems, or AI models.
That distinction matters. Executives should examine the entire technology stack and determine where meaningful dependencies remain. Procurement decisions should account for the ability to move data, switch providers, maintain operations during regulatory changes, and negotiate future contracts. Sovereignty is therefore becoming part of enterprise risk management.
There is also no reason to assume global cloud infrastructure and sovereign infrastructure are mutually exclusive. Many multinational businesses will need both. The practical objective is to decide which workloads require stronger local control and which can continue to benefit from global cloud scale. Getting that architecture right can preserve access to innovation without creating unnecessary regulatory exposure.
Governments want more control over critical technology
Governments are moving beyond rules for data protection. They increasingly want domestic control over the infrastructure required to build and operate AI. Europe is a major example of this shift.
The European Union recently unveiled its European Technological Sovereignty Package with the stated objective of reducing reliance on U.S. technology companies. European policymakers are also showing a willingness to invest in domestic alternatives. This creates a different competitive environment for cloud providers, AI companies, and the enterprises buying their technology.
The underlying issue is strategic dependence. AI increasingly touches government services, industrial systems, healthcare, finance, defense, and other critical activities. Governments therefore have incentives to ask whether essential digital infrastructure can continue operating if access to an overseas provider becomes restricted, commercially unattractive, or politically complicated.
For businesses, this creates both constraints and opportunities. Enterprises operating across jurisdictions may face stricter requirements around data residency, infrastructure ownership, cloud operations, and technology procurement. At the same time, governments investing in sovereign capabilities can create new demand for local data centers, AI infrastructure, cybersecurity, software, and implementation services.
Executives should also distinguish between sovereignty by policy and sovereignty in practice. Buying from a domestic provider does not automatically remove external dependencies. That provider may still rely on foreign semiconductors, software platforms, AI models, or cloud technology. The relevant question is where control actually exists across the infrastructure.
The direction is clear even if individual regulations continue to change. Governments increasingly consider computing capacity and AI infrastructure strategic assets. Companies that account for this early can design systems with greater choice, portability, and local control. Those that treat sovereignty as another compliance requirement may discover later that changing their infrastructure is expensive and slow.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
U.S. cloud giants are adapting quickly to sovereign demand
Digital sovereignty creates pressure for U.S. technology companies, but it also creates a substantial new market. Microsoft, Amazon Web Services (AWS), and Google are responding by expanding sovereign cloud offerings designed to satisfy national and regional requirements, particularly in Europe.
According to Stanford HAI, these companies now offer the “largest and most global set of solutions” in this area. Their approach allows customers to keep using mature global cloud platforms while gaining additional controls over data location, access, operations, and regulatory compliance. For enterprises already deeply invested in these platforms, that can be easier than replacing core infrastructure with a new provider.
The commercial opportunity is significant. Gartner expects global sovereign cloud spending to increase 35.6% this year. Growth at that level shows that sovereignty is becoming a meaningful infrastructure category rather than a specialist requirement limited to governments and highly regulated sectors.
There is an important tension, however. European policymakers are investing in domestic alternatives partly to reduce reliance on U.S. technology companies. At the same time, those same U.S. providers are developing products that allow customers to satisfy more sovereignty requirements without leaving their platforms. As a result, regulation intended to encourage greater technological independence may also generate demand for new services from established hyperscalers.
Executives therefore need to examine what a vendor means by “sovereign.” Local data storage is only one consideration. Companies should also assess who controls encryption keys, who can administer infrastructure, which jurisdiction governs access, how software updates are managed, and whether workloads and data can move to another provider without excessive cost or disruption.
There is no inherent problem with choosing a global provider for sovereign infrastructure. These companies offer scale, security capabilities, extensive services, and large investment budgets. The strategic question is whether the resulting architecture preserves enough choice. Contract terms, interoperability, data portability, and exit plans should be considered before deeper technical dependencies develop.
More local control can still mean more vendor dependence
Sovereign AI sounds straightforward: increase control over data, computing infrastructure, and AI operations. In practice, achieving that goal is more complicated. Stanford HAI argues that Big Tech sovereignty products can change the structure of technological dependence without necessarily removing it.
A company may keep its data and infrastructure inside a specific country while continuing to depend on one supplier’s proprietary software, hardware, management tools, and AI services. That arrangement can satisfy important sovereignty requirements, but it does not necessarily provide technological independence.
This becomes more significant as vendors expand across the AI technology stack. A single supplier can potentially provide computing infrastructure, AI accelerators, development software, models, deployment systems, and operational tools. Integration across these layers can simplify deployment and improve performance. It can also increase the cost and complexity of replacing that supplier later.
Stanford HAI highlights this risk with cross-stack sovereignty products, including Nvidia’s AI factories. The study warns that such products “may promise greater control and integration across different layers of the AI tech stack, but they can also tighten long-term vendor lock-in, reducing interoperability and hardening reliance.”
For C-suite leaders, the distinction between sovereignty and independence is important. Sovereignty can provide greater control over where infrastructure operates and how information is governed. Independence requires something more: credible alternatives if commercial conditions, technology requirements, regulations, or geopolitical circumstances change.
That means interoperability should become part of the executive discussion before major AI infrastructure commitments are signed. Leaders should understand which components can be replaced, whether applications and data can migrate to competing platforms, which proprietary technologies are difficult to substitute, and how much a future transition could cost.
Vendor integration itself is not necessarily negative. A tightly integrated platform may provide better performance, faster deployment, and simpler operations. The issue is whether those immediate advantages justify the long-term dependency. For major AI investments, the strongest position is one where the company gains the control it needs today while maintaining practical options for tomorrow.
Nvidia’s AI factories bring sovereign AI into one integrated platform
Nvidia is moving beyond its traditional role as a chip supplier. Its sovereign AI strategy increasingly covers the infrastructure and software needed to train, deploy, and operate AI systems. Stanford HAI describes the company as positioning itself as a “one-stop-shop” infrastructure provider, with its AI factory program providing sovereignty at the foundational layer.
Nvidia describes AI factories as locally owned and operated AI clouds for training and inference, the process of running trained models to generate results. These environments can be built through public-private partnerships, allowing governments and companies to increase domestic computing capacity while using Nvidia’s underlying AI platform.
There is clear demand for this model. According to the Stanford HAI, sovereign AI represents about 14% of Nvidia’s total revenue, or roughly $30 billion. That makes sovereignty commercially significant for Nvidia and shows how national AI investment is creating a substantial market for infrastructure suppliers.
For governments, the proposition is compelling. Countries can expand local computing capacity, keep sensitive workloads within their jurisdiction, and support domestic AI development without building every technology component independently. Nvidia’s broader AI Nations initiative is designed around this objective, helping countries develop AI ecosystems using locally controlled infrastructure.
But integrated infrastructure creates a strategic question. Greater national control over the physical location and operation of AI systems does not necessarily reduce dependence on the technology provider. If processors, networking, development software, libraries, and deployment tools come from the same ecosystem, replacing that ecosystem later can become difficult and expensive.
Stanford HAI identifies this as an important risk of cross-stack sovereignty products. The more layers a vendor controls, the greater the potential for long-term lock-in and reduced interoperability with competing technologies.
Executives evaluating these systems should therefore consider performance and deployment speed alongside portability, procurement flexibility, software compatibility, and long-term operating costs. Nvidia’s integrated approach can offer substantial capabilities. The key business question is whether customers retain credible alternatives as their AI requirements change.
France shows what sovereign AI means in practice
France provides a useful example of how governments can pursue local AI control while continuing to use technology from a global supplier. According to Nvidia, France’s Ministry of Economy and Finance is using AI agents built on the Nvidia AI platform to automate complex workflows and process millions of documents.
The infrastructure supporting these systems is controlled within France. That matters for sensitive government workloads because it gives the country greater authority over where systems operate and how information is handled. At the same time, the underlying AI platform comes from Nvidia, a U.S. company.
This arrangement highlights an important distinction for executives: infrastructure sovereignty does not automatically produce full technology independence. An organization can maintain domestic control over infrastructure and data while depending on foreign processors, software frameworks, development tools, or other proprietary technology.
That does not make the strategy ineffective. Complete technological independence can be costly, slow, and unrealistic for many organizations and governments. The more practical objective may be to identify which parts of the AI environment require domestic control and where dependence on international suppliers remains commercially and strategically acceptable.
France’s implementation also demonstrates why sovereign AI has practical value beyond regulatory compliance. AI agents can automate complex administrative processes and handle document volumes that would otherwise require significant human effort. When deployed under appropriate governance, this can increase operational efficiency while allowing sensitive workloads to remain within nationally controlled infrastructure.
For C-suite executives, the same logic applies to enterprise deployments. Leaders should determine which data and workloads require stronger jurisdictional control, then assess the dependencies that remain at the hardware, software, cloud, and AI-platform levels. Contracts should also address access rights, data portability, continuity of service, and exit options.
The central issue is therefore not whether foreign technology should be eliminated. It is whether organizations understand and can manage their dependencies. Sovereign AI can provide meaningful control while preserving access to advanced global technology, but achieving both requires infrastructure decisions designed for long-term flexibility.
Key highlights
- Sovereignty is now a strategic risk issue: Geopolitics and regulation are changing cloud decisions, with 65% of business leaders adjusting their strategies due to sovereignty requirements. Leaders should assess where critical data and workloads operate and which jurisdictions and vendors ultimately control them.
- Governments are pushing for greater technology independence: Initiatives such as the EU’s European Technological Sovereignty Package signal stronger demand for locally controlled technology. Executives should prepare for changing procurement and compliance requirements while assessing opportunities created by domestic AI investment.
- Hyperscalers are turning sovereignty into a growth market: Microsoft, AWS, and Google are expanding localized offerings as Gartner expects sovereign cloud spending to grow 35.6% this year. Buyers should look beyond data residency and evaluate operational control, portability, jurisdiction, and exit options.
- Sovereignty does not eliminate vendor lock-in: Local infrastructure can still depend heavily on proprietary hardware, software, and AI services. Leaders should make interoperability and switching costs central criteria when selecting sovereign AI platforms.
- Nvidia shows the trade-off of integrated sovereign AI: Nvidia’s AI factories can provide locally operated AI infrastructure, but deeper integration across the technology stack can strengthen dependence on its ecosystem. With sovereign AI representing about 14%, or roughly $30 billion, of Nvidia’s revenue, executives should treat this as a major long-term infrastructure decision.
- France shows how sovereignty can coexist with foreign technology: France’s Ministry of Economy and Finance uses Nvidia technology on infrastructure controlled within the country to process millions of documents. Executives should focus on controlling critical data and operations while explicitly identifying and managing dependencies that remain with global suppliers.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


