Rémi Kouby

Rémi Kouby

Director, Cybersecurity and Privacy, France

Digital sovereignty is fundamentally about control: an organization’s ability to maintain authority over its operations, data, digital infrastructure, and technology. It means ensuring these assets are managed, protected, and governed in accordance with applicable laws, organizational requirements, and strategic priorities. More broadly, digital sovereignty is the ability to make, preserve, and enforce strategic choices about the digital capabilities on which the organization depends.

Digital sovereignty doesn’t mean absolute autonomy, nor does it require bringing everything back in-house. In an era where interdependence is the norm, it means defining where control must be retained, at what level, and for what purpose.

Notably, digital sovereignty is often reduced to data location. While that concern is legitimate, it’s no longer sufficient. An organization may host its data in the appropriate region, meet regulatory requirements, and pass audits, yet remain deeply dependent on a provider for identity management, operations, application interfaces, AI capabilities, or contractual supply chains. In that scenario, the organization may be compliant, but it’s not truly in control.

Framed this way, digital sovereignty becomes a strategy for managing risks related to critical dependencies. For organizations seeking to ensure greater control, here are some key considerations to keep in mind.

1. Compliance, cybersecurity, digital sovereignty: Related but distinct logics

Compliance for commercial organizations involves identifying and meeting the legal, regulatory, and, where applicable, sector-specific requirements that govern its activities. It’s maintained through policies and controls, but it shouldn’t be viewed as a purely binary exercise. An organization may formally comply with its obligations while still facing significant operational or strategic dependencies. The perspective is different for a government entity, which operates not only within a legal framework but also defines that framework in pursuit of public policy and strategic autonomy.

Cybersecurity, on the other hand, focuses on reducing the likelihood and impact of incidents affecting confidentiality, integrity, and the availability of systems and services.

This difference is essential. Compliance sets a baseline, while digital sovereignty defines a level of control. It isn’t binary, as if an organization could simply be “sovereign” or “non-sovereign.” It’s more like a dial, adjusted according to activities, markets, dependencies, service criticality, and disruption scenarios that must be absorbed.

The goal is to define objectives for targeted scopes where a high level of control is essential, without trying to make the entire organization “sovereign.”

2. Mastering the entire dependency chain

Reducing digital sovereignty to data location alone is tempting, but incomplete. Dependencies exist across multiple layers of the technology stack—some highly visible, others less so—and each can materially shape an organization’s choices, risks, and constraints. An organization may, for example, store and protect its data entirely within its own jurisdiction while still relying on a foreign provider to manage user identities, administer platforms, monitor critical systems, or supply essential hardware. Where control over key parts of the technology stack rests with external parties, significant exposure can remain—regardless of where the data itself resides.

To be useful, a digital sovereignty analysis must cover the entire digital dependency chain. It begins with data: storage, backups, transfers, encryption, governance, and the ability to isolate or migrate information assets. It must also include identity and access management, covering directories, identity federation, SSO, MFA, privilege management, and administrative accounts.

In many organizations, the most critical dependency isn’t the data itself, but the layer that controls access and enables system administration.

The analysis must then extend to applications and platforms, including SaaS solutions, PaaS services, proprietary APIs, managed components, middleware, and dependencies on non-portable features. The operations layer is equally decisive, covering monitoring, remote maintenance, support, updates, incident management, and reliance on external teams or subcontractors with significant technical authority.

Legal and contractual dimensions must also be assessed, including applicable law, cascading subcontracting, audit rights, reversibility, service suspension conditions, and unilateral changes to commercial policies. Finally, infrastructure and hardware shouldn’t be overlooked, including supply chains, components, firmware, reliance on specialized accelerators, availability of computing capacity, and exposure to commercial or industrial restrictions.

3. Accepting the cost while leveraging its benefits

In an ecosystem dominated by a few major global providers, increasing digital sovereignty comes at a price: less standardized technical choices, reduced functionality, more demanding architectures, complex contracts, maintenance of failover capabilities, additional testing, and sometimes higher short-term costs. However, the absence of digital sovereignty also has costs, often less visible at first, but potentially much higher. These include vendor lock-in, costly late exits, unbalanced renegotiations, inability to respond to tenders, service interruptions, reduced strategic flexibility, and potential regulatory compliance violations.

Digital sovereignty isn’t just a protective expense and can become a competitive advantage.

This is especially true for organizations that place a premium on control across the digital ecosystem, including regulated sectors, public markets, critical infrastructure, healthcare, defense, finance, and other sensitive industries. In such contexts, transparency, auditability, reversibility, and subcontractor control become selection criteria, and resilience becomes a business argument.

Strengthening digital sovereignty in these sectors can also have a broader positive effect across the ecosystem. Organizations outside traditionally sensitive industries may still be indirectly exposed to hostile-state actions through shared providers, interconnected supply chains, or critical digital dependencies. The practices and safeguards developed for sensitive environments can therefore help improve resilience for a much broader range of organizations.

4. AI: A dependency accelerator

Artificial intelligence introduces a new form of dependency. The debate often centers on data and models. For many organizations, the more pressing issue lies elsewhere: access to computing power, hardware accelerators, cloud platforms, foundation models, orchestration tools, libraries, managed services, and APIs.

Only players with massive investment capabilities can deliver state-of-the-art AI services. Digital sovereignty across the entire AI chain is unrealistic for most organizations.

Without a strategy, AI will add another layer of dependency. Strengthening your posture in this area requires answering where options must be retained, where transparency, auditability and reversibility are needed, and where models must be replaceable, services switched, workloads repatriated or sensitive uses isolated.

5. A pragmatic approach: Digital sovereignty by scope and level

A digital sovereignty strategy must translate strategic objectives into concrete decisions and priorities. To do so, organizations need a structured method, supported by practical tools and deliverables.

The first step is to establish a dependency map covering critical business processes, data, applications, infrastructure, and supplier dependencies. This mapping should reveal where the organization relies on external providers, where switching options are limited, and where a disruption could affect essential activities.

The organization should then define a digital sovereignty framework that sets out the assessment criteria to be applied consistently across these dependencies. These criteria may include data control, jurisdiction, access governance, auditability, portability, reversibility, operational autonomy, supply-chain exposure, and the ability to replace or repatriate a service.

Each critical dependency can then be assessed through a digital sovereignty scorecard or risk matrix that considers the:

  • Criticality of the supported business activity
  • Level of dependency on a provider or technology
  • Consequences of a legal, political, commercial, or operational disruption
  • Current level of control
  • Feasibility and cost of alternative arrangements

Based on this assessment, the organization can assign a target digital sovereignty level to each scope:

  1. Standard: the dependency is acceptable and monitored
  2. Reinforced: additional safeguards, contractual protections, portability measures, and tested exit options are required
  3. Sovereign: the organization must retain a high degree of technical, operational, legal, and strategic control

The main outcome should be a digital sovereignty roadmap that identifies remediation actions, priorities, and timelines.

Enduring versus mastering dependencies

Digital sovereignty is neither a slogan nor a luxury. It’s a practical response to a new reality.

Organizations rely on deep and sometimes invisible dependencies, and AI will accelerate this trend.

The challenge is to decide clearly:

  • What must remain under control at all costs?
  • What dependencies are acceptable?

You don’t need to manage everything internally.

A digital sovereignty strategy is about choosing what you control. CGI’s IT strategy and cybersecurity consultants help clients turn digital sovereignty into an advantage, so they can stop enduring their dependencies and start mastering them.

Further, as AI becomes an increasingly critical part of the digital sovereignty landscape, sovereign AI applies digital sovereignty principles to AI models, data, compute, and governance. Learn more about our sovereign AI experience and capabilities.

Finally, feel free to contact me to discuss this increasingly important topic.

About this author

Rémi Kouby

Rémi Kouby

Director, Cybersecurity and Privacy, France

With more than 15 years of security consulting and data protection experience. Rémi Kouby has served as Director of Cybersecurity and Privacy within CGI’s business consulting practice in France since January 2020.