Sovereignty or Dependency
Why Digital Control Is Becoming the Defining Business Metric of the AI Era
The End of the Location Illusion
For years, digital sovereignty was largely discussed as a question of data location.
Could data be stored inside the European Union?
Could organisations satisfy local regulatory requirements?
Could information be kept within national borders?
These questions remain important, but they are increasingly insufficient.
A company may store data in Europe and still remain strategically dependent on external providers, foreign jurisdictions, proprietary technologies and infrastructure it does not control.
Location is not control.
Ownership is not control.
Access is not control.
The decisive question is becoming far simpler:
Who ultimately has the ability to decide?
Why DORA Changes the Conversation
Many organisations interpret DORA as another compliance exercise.
This is a mistake.
DORA is not primarily a cybersecurity regulation.
DORA formalises the transfer of digital operational resilience into the responsibility of executive management.
The regulation recognises a reality that many organisations have avoided confronting:
Technology dependencies have become business dependencies.
Operational resilience can no longer be delegated exclusively to technical teams.
The board remains accountable.
This shift is significant because it changes the language of digital risk.
The conversation moves from technical controls to governance, accountability and decision rights.
Agentic AI and the New Dependency Problem
The rise of Agentic AI introduces a second transformation.
For decades, organisations deployed software that supported decisions.
Increasingly, they are deploying systems that participate in decisions.
Agentic systems can analyse information, trigger workflows, communicate with customers, initiate transactions and coordinate operational activities.
The benefits are substantial.
So are the dependencies.
Every autonomous capability relies on infrastructure, identities, permissions, data quality, governance rules and execution environments.
As autonomy increases, control becomes more important rather than less.
The question is no longer whether an organisation uses AI.
The question is whether it can govern AI at scale.
Digital Sovereignty Is an Architecture Question
Many discussions around sovereignty focus on vendors.
The deeper issue is architecture.
Digital sovereignty does not emerge from a procurement decision.
It emerges from structural design choices.
Organisations should evaluate four dimensions:
Jurisdiction
Which legal frameworks ultimately apply?
Identity
Who controls authentication, authorisation and trust?
Portability
Can systems, workloads and data be moved if required?
Operational Independence
Can critical functions continue under adverse conditions?
Together these dimensions determine freedom of action.
The objective is not isolation.
The objective is optionality.
Control Becomes the New Executive Metric
For years, executives measured digital progress through indicators such as:
- Cloud adoption
- Automation
- Data volume
- AI implementation
- Cost efficiency
These metrics remain relevant.
However, they increasingly fail to answer a more important question:
How much strategic control remains?
An organisation may become more efficient while simultaneously becoming more dependent.
It may become more automated while becoming less resilient.
It may become more innovative while losing freedom of action.
Control therefore emerges as a new management metric.
Not because autonomy is undesirable.
But because autonomy without control creates fragility.
The Emerging Importance of the Kill Switch
Every critical system requires a final layer of authority.
As organisations deploy increasingly autonomous technologies, the ability to intervene becomes strategically important.
A sovereign organisation must retain the ability to:
- revoke access
- modify policies
- isolate systems
- redirect workloads
- suspend autonomous processes when required
The issue is not distrust of technology.
The issue is governance.
Control mechanisms are not evidence of weakness.
They are evidence of responsibility.
APIS Assessment
Digital sovereignty is increasingly becoming a governance challenge rather than a technical challenge.
The defining risk of the next decade is unlikely to be insufficient technology adoption. It is more likely to be the accumulation of unmanaged dependencies hidden beneath successful technology adoption.
Boards that understand their dependencies will retain strategic freedom of action.
Boards that do not may discover that they own the business but no longer control the system on which it depends.