All articles
SovereigntyLock-in

Sovereignty Is Not Autarky

The sovereignty debate keeps offering a false choice: cut yourself off from the world's best technology, or accept permanent dependence. There is a third option, and it's the only realistic one.

Ilke Tosunoğlu
Ilke TosunoğluMay 28, 20267 min readUpdated July 20, 2026
A spectrum dial running from "Open / dependent" on the left to "Sovereign / isolated" on the right, with the marker set in a pragmatic middle position labelled "Selective autonomy: control where it matters, not isolation everywhere." Supporting notes: strategic control where it matters, trusted partnerships, operational resilience, innovation without lock-in.

Part of the pillar series Sovereignty You Can Actually Operate.

Whenever "digital sovereignty" comes up, someone reaches for the strawman: so you want Europe to build its own version of everything and wall itself off? It's an easy position to dismiss, because it would be slow, expensive, and worse for everyone. But it is not what sovereignty means, and treating it as the goal is how organizations talk themselves into doing nothing.

The first three posts in this series mapped the dependence, showed how ordinary tools become critical, and explained why compliance isn't the finish line. This is the pivot. The realistic objective is not autarky. It is selective autonomy: sovereign capacity where it genuinely matters, openness everywhere else, and the ability to tell the difference.

What digital sovereignty actually means

Start with the definition that the EU's own research service uses. The Joint Research Centre defines digital sovereignty as "the EU's capacity to exercise independence in the digital realm while remaining open and connected to global networks" (JRC Policy Brief JRC146878, May 2026). The clause after the "while" is not decoration; it makes the definition itself anti-autarky.

That phrase is the whole argument. Not closed. Not powerless. The goal is the capacity to decide: to operate, switch, secure, and scale critical infrastructure without unacceptable exposure to foreign compulsion, lock-in, or coercion. Self-sufficiency is one possible means to that end, and usually a bad one.

Autarky (the strawman) Selective autonomy (the goal)
Aim Build everything yourself Control what matters; stay open elsewhere
Scope The whole stack Sensitive workloads and chokepoints
Cost Enormous, slow, often worse Targeted, achievable now
Posture Closed Open but not powerless

Europe already proves the point

The case for selective autonomy isn't theoretical. Europe lives it. The continent is deeply dependent in cloud and AI, yet it holds one of the most asymmetric chokepoints on the planet: a single Dutch company builds close to 100% of the world's most advanced lithography machines, the tools required to make every leading-edge chip (Yole Group). When Washington wanted to restrict China's access to advanced chipmaking, it needed Dutch cooperation to do it.

That is sovereignty as leverage, not isolation. Europe didn't get it by building everything; it got it by being indispensable at one critical point. The lesson scales down to any organization: you don't need to own the whole stack. You need control where control is decisive.

How to decide what needs to be sovereign

The practical tool is workload tiering: sorting what you run by how much sovereign control it actually requires, then spending your scarce sovereignty budget where it counts.

A three-tier pyramid for workload tiering. Tier 1 "Fully sovereign": defence, justice, health, core administration, critical infrastructure. Tier 2 "Sovereign-sensitive": regulated data, security telemetry, high-trust operations. Tier 3 "Interoperability-first / multi-vendor": general workloads. Caption: the goal is control where it matters, not isolation everywhere.

Most organizations discover that the share of workloads needing full sovereignty is smaller than they feared, but that those workloads are exactly the ones they'd been treating most casually. The point of tiering is not to move everything. It's to stop treating your crown jewels like your marketing site.

The honest part: what sovereignty costs

A credible sovereignty argument has to be honest about price, because pretending it's free is how trust gets lost. So, plainly: there are two cost stories, and which one applies depends on what you mean by "sovereign cloud."

  • Sovereignty bolted onto a foreign hyperscaler, a "sovereign region" SKU, typically carries a 15–30% price premium over standard regions (BCG, 2025). You pay more, and you still inherit the parent company's jurisdiction.
  • Sovereignty as "use a European provider" is frequently cheaper, not more expensive. European providers are often far less costly on compute, and dramatically cheaper on data egress, where hyperscaler fees can run dozens of times higher.

There are real costs to genuine sovereignty: duplicated AI inference capacity per region, smaller economies of scale in some places. We won't pretend otherwise. But the framing that "sovereignty always costs more" is simply false; often the dependency is what's quietly expensive.

Where US "sovereign cloud" offers help, and where they stop short

To be fair to the alternatives: the major US providers' sovereign offerings are real engineering, and they do reduce some exposure: EU data boundaries, EU-resident operations, customer-managed keys, EU-governed subsidiaries. For some workloads, that's enough.

What they don't change is the part that matters most for Tier 1: the controlling parent remains subject to foreign law, the software roadmap stays foreign-controlled, and as CarMax's Eric Swanson put it to InfoQ, "US ownership and headquarters mean US law can still apply to the provider, regardless of where the infrastructure runs. Sovereign cloud offerings do not override the Patriot Act." (InfoQ, 2026). Selective autonomy means using those offers where they fit, and reserving genuinely sovereign infrastructure for the workloads where "mostly sovereign" isn't good enough.

Why we built Soveryne for the middle path

This is the worldview the whole company is built on, so we'll state it plainly. We did not build Soveryne to help anyone wall themselves off from the world's best technology. We built it so that European organizations can keep the workloads that matter under genuine EU control: by default, pragmatically, without a multi-year rebuild.

That's why the Soveryne Cloud Foundation is EU-sovereign by default, not by upgrade: keys in EU jurisdiction, compute in the EU regions you choose, AI inference that stays home, and an open-source core you can inspect. It's why Command and Counsel run on that foundation rather than treating sovereignty as a checkbox. And it's why our pitch is pragmatic to the point of bluntness: get in touch, and if we're not the right fit for a given workload, we'll say so. That is what selective autonomy looks like as a product.

FAQ

What does digital sovereignty actually mean? The capacity to exercise independence over your digital infrastructure (to decide, operate, switch, and secure it without unacceptable foreign exposure) while remaining open and connected to global networks. It is not self-sufficiency.

Is digital sovereignty the same as building everything in Europe? No. That's autarky, and it's neither realistic nor desirable. Sovereignty is about control where it matters, achieved through leverage, portability, and selective autonomy.

Does sovereign cloud always cost more? No. Hyperscaler "sovereign region" SKUs carry roughly a 15–30% premium, but independent European providers are often cheaper than hyperscalers, especially on data egress. The cost depends entirely on the approach.

Are US "sovereign cloud" offerings good enough? For some workloads, yes. For Tier 1 (defence, justice, health, core administration, critical infrastructure), they leave the controlling parent under foreign law, which is exactly the exposure those workloads can't accept.


Sovereignty isn't a wall; it's a dial you set per workload. The companion technical post shows how that dial is enforced in code. To see sovereign-by-default in practice, explore the Soveryne Cloud Foundation or get in touch.

Sources