Digital sovereignty beyond the buzzwords: a practical decision lens for executives
Where do our dependencies limit our room to act?
Geopolitical tensions are increasing. AI is rapidly becoming embedded in business processes. Regulatory requirements continue to expand. At the same time, many organizations choose to use the AI solutions from the limited number of technology providers that they have already selected in their technology stack (like Copilot by Microsoft). These decisions are often driven primarily by efficiency and innovation, but increasingly have implications for continuity, resilience, compliance, and strategic flexibility.
Digital sovereignty is not equally urgent for every organization, and the impact of digital dependencies varies significantly by organization type. However, it remains relevant more broadly, because nearly every organization depends on cloud platforms, software vendors, data chains and AI tooling.

Why the debate often misses the point
A major weakness in the current debate is its strong focus on technological solutions and idealized vision of independence from a legal perspective. Instead, digital sovereignty is the degree to which an organization can consciously shape and, when necessary, reshape its position within digital ecosystems. It is about understanding dependencies and maintaining sufficient room to act when circumstances change.
The problem is not the dependency itself. Dependence on hyperscalers, platforms or external providers is often entirely rational and beneficial. In today’s globally interconnected digital economy, some level of dependency is unavoidable. Even if Europe were to achieve a complete Eurostack, structural dependencies would remain outside the reach of technology policy. This leads to a fundamental insight: digital sovereignty is relative, not absolute. Dependency only becomes problematic when it is invisible, unchallenged, or impossible to change.
The goal is therefore not to eliminate dependencies or maximizing autonomy, but to understand which ones matter, which ones are acceptable, and where additional control or flexibility is worth the investment. Not every dependency is a risk, not every form of autonomy is feasible or desirable, and not every technical intervention creates meaningful strategic control.
Limiting room to act?
One of the questions to demystify the debate around digital sovereignty is: Where do our dependencies limit our room to act?
Almost every organization depends on external technology. The dependency itself is rarely the problem. Dependency becomes a strategic risk when it limits the organization’s ability to respond to changing circumstances. How does an organization respond if token costs rise and the business case changes? How does an organization respond if a frontier LLM is available to their competitors, but not to them?
Organizations should start by identifying where dependencies are most concentrated and most business-critical. This requires more than an inventory of suppliers. It means understanding how providers, cloud platforms, AI services, data flows, contracts, identities and ecosystem interfaces together support critical business capabilities.
Equally important is understanding the nature of those dependencies. Some primarily create operational risk, while others affect legal compliance, negotiating position, resilience, innovation capacity or the ability to respond quickly during geopolitical or market disruptions.
To understand the dependencies, it is important to distinguish between different types of dependency. Within digital ecosystems, at least four can be identified.
Technical dependency refers to reliance on specific technologies, standards, or interfaces. In principle, these dependencies can be mitigated by a strong modular architecture, allowing for switching LLMs or migrating data storage. However, these can come with considerable cost, complexity, and risk. Even successful technical migrations do not necessarily eliminate the underlying dependency.
Legal dependency arises from applicable legislation, contractual obligations, and regulatory oversight. Unlike technical dependencies, these are only partially influenced by technological measures. For example, legislation such as the U.S. CLOUD Act and GDPR demonstrate that legal jurisdiction can extend beyond physical borders, and that technical data residency can be overruled by legal data soeverignty.
Organizational dependency concerns the loss or absence of internal capabilities in areas such as operations, security, architecture, and governance. It often develops gradually through long-term outsourcing or reliance on external providers, but it can also be a deliberate strategic choice driven by specialization or economies of scale. This type of dependency is particularly difficult to recognize because it often only becomes visible when an organization wants to change direction and discovers it no longer possesses the capabilities to do so.
Ecosystem dependency emerges when technical, legal, and organizational dependencies reinforce one another. The integration of identities, data, platforms, AI services, governance, and operational processes within a single ecosystem makes separation increasingly costly and complex. This is characteristic of many hyperscaler ecosystems and represents the least visible and most difficult form of dependency to reverse.
Although these four dependency types can be distinguished analytically, they rarely exist in isolation. In practice, they accumulate and reinforce one another. As a result, interventions that address only one dimension of dependency are unlikely to provide a sustainable solution.
A practical decision lens for executives to support sovereignty discussions and decisions
Digital sovereignty is often discussed in absolutes. Either the debate is captured by skeptics saying things like “We will never be fully independent, so why bother” or by advocates saying things like “We cannot use US-based AI tools”. In reality, the challenge lies in making deliberate choices about dependency, control, resilience, and investment. At Anderson MacGyver, we help organizations gain insight into their critical dependencies, understand where they limit strategic freedom of action, and develop realistic pathways to increase resilience and control where it matters most.
In our latest position paper, Digital Sovereignty: Always assess, act only where it matters, we suggest four questions to shift away from abstract claims about sovereignty and aspirations of independence toward a more useful and concrete management discussion based on questions about dependency, responsibility, resilience and freedom of action.
Download the paper and discover how your organization can move from abstract discussions to informed decisions.
Sources: whitepaper Digital Sovereignty (Anderson MacGyver, 2026), Digitale Soevereiniteit in perspectief (Arnold J.D. van der Veen Meerstadt, 2026)