Thursday, July 30, 2026

The rise of sovereignty

My first customer roadshow when I was at Red Hat highlighted governance (and security) as one of the concerns that many folks had about doing everything in a public cloud. This was at a time when the popular narrative, as well-written about in Nick Carr’s The Big Switch built on an earlier concept by computer scientist John McCarthy about utility computing. The gist was that computing was just a utility.

The basic idea, although it seems a bit outdated today given various distributed renewable power generation methods such as solar, was simple. How could you not go all in on centralized power plants and huge hydroelectric dams? At the time, power was something that self-evidently required large investments at any scale. And the concept expanded beyond compute itself to other forms of the compute hierarchy such as Platform-as-a-Service (PaaS) and even many forms of Software-as-a-Service (SasS). It suggested a winner-take-all and probably ultimately globally-regulated world. Sun CTO Greg Papadopoulos at the time even opined that “the world needs only five computers.” He was hyperbolic and echoing something IBM’s Thomas J. Watson probably never said but it did reflect a popular tech industry sentiment—even if Sun’s own cloud computing efforts never really got off the ground.

What wasn’t as much emphasized early-on was the location where data was stored and compute happened. Organizations like Amazon Web Services (AWS) did recognize this concern and started to expand their regions to more and more datacenters in different legal locales. This was partially for technical reasons like latency but it also recognized that governments and corporate governance were increasingly clamping down on where citizens and corporations were storing and executing on their information.

What was often perceived as a concern of “server huggers” who simply didn’t want to have compute operations and data stored off-prem—for reasons—has increasingly shifted to being a real IT management concern. It is no longer theoretical.

What were the real historical concerns?

In the early public cloud days, a lot of folks did have genuine security concerns—even if “security” often served as a shorthand for a broader set of governance matters. It was often mostly about control. Or just not being comfortable with outsourcing functions they weren’t used to effectively outsource—at least for business-critical functions.

Unless you’re a large enterprise, Hyperscalers probably have better security folks on staff than you do though I’m sure your staff are awesome. A lot of the early marquee customers for vendors like AWS weren’t really mission-critical. Though Netflix and Flickr did pretty well leaning heavily on AWS. But a widespread early-on thought in IT departments was at least your security people worked for you and this led to at least a comforting illusion that you were in control.

Over time, enough large enterprises including entities such as stock markets went into cloud in a big way though, and it became increasingly hard to argue that the hyperscalers were mostly for consumer services. There was certainly within many in the tech industry a question of when not if public clouds would become dominant.

Where are we today?

The first reason is sort of orthogonal to the rest of this discussion so I’ll dispose of it quickly. The superior finances of clouds versus industrialized data centers (including co-location facilities) never made a huge amount of sense to me as I wrote in 2009. Lots of reasons to use the hyperscalers (AWS, Google, Microsoft Azure) to be sure. But cost of services was often not one of them—especially for large organizations—and especially for specific types of services like data egress (which does tie at least indirectly into data sovereignty). I’m not sure to what degree FinOps ever took off as a formalized discipline even if I plugged it for a time, but I do think there has been an increasing awareness of the grass not always being greener on the other side of the fence in the public cloud. To be sure, many organizations aren’t great about understanding the burdened cost of engineers “just” doing a side-job. Cloud costs remain a background hum but that’s a topic for another day.

Today’s big topic is digital sovereignty. There are a couple of related threads to this. The first is sovereignty more broadly, perhaps especially data sovereignty. As I noted earlier, this has simmered at some level since the early days of public clouds. Portability and interoperability were part of an open cloud story even if it was never as easy and seamless as sometimes promised. However, both standards and open source do simplify portability, flexibility to use another (or multiple) vendors, or to move to hosting workloads yourself.

However, many saw these as theoretical concerns early-on that weren’t important for IT executives who had a business to run. Geopolitical risks in particular have transformed sovereignty into concerns that many boards are looking into. Is our data and IP safe from being looked at, copied, or even deleted unless we pay ransomware? This is not purely an issue with the actions of unfriendly nation states of course. Intelligence agencies and others around the world are interested in your data. You may not be able to stop every actor trying to access your data and workloads but the better you can put them out of easy reach and secure them, the better your odds.

You also need to be aware of maintaining compliance with government regulations like the type of data about citizens that is allowed to be stored or transferred/used elsewhere.

The latest wrinkle is AI sovereignty. This doesn’t require bringing all AI in-house. But it does suggest a deliberate approach to training data, models and their updates, and the locations and manner in which AI is deployed. To be sure, AI is still a rapidly developing area. Many, probably most, organizations are still unsure of the best way to use it to fit their business needs—and, indeed, what business needs it’s even best suited for. There are also various unresolved legal questions related to which data AI models can be trained on and a variety of other issues that mostly touch on copyright and privacy in various ways.

Conclusion

You might have been forgiven just a few years back if you thought the tech industry was entering one of those relatively stable lulls where a lot of energy would be going into stabilizing and improving something that looked a lot like the existing landscape. It never quite plays out that way, of course. But the combination of LLMs (and, presumably, what comes next in AI) and geopolitics/sovereignty have certainly upended a great deal.