Sovereignty Is the Freedom to Act
This is a subtitle for your new post

I have been thinking a great deal about the word sovereignty lately. It's becoming increasingly common in conversations about defence, intelligence, cloud infrastructure, AI and data, but I sometimes wonder whether we are making something quite fundamental sound more complicated than it needs to be.
For me, sovereignty starts with a simple question: if something changed tomorrow, would you still be in control? Would you still have access to your data and be able to operate your systems? Could you move your capabilities somewhere else or change technology providers without losing years of investment, institutional knowledge, workflows or critical functionality? Most importantly, could you continue making decisions and acting independently?
These are no longer theoretical questions. Across defence and intelligence, we are connecting more sensors, systems, platforms and sources of information than ever before. We are moving workloads into the cloud, introducing AI into analysis and decision-support processes, and sharing information across organizations, agencies, domains and national boundaries. The opportunity is extraordinary, but so is the dependency we can create if we are not careful.
Convenience Has a Cost
Technology has become remarkably easy to procure as a complete stack. One provider can deliver the infrastructure, cloud environment, analytics, user interface, processing tools and applications. Everything works together, deployment is faster and procurement can be simpler. There are very good reasons organizations choose this approach. The question is what happens five, ten or twenty years later.
Technology changes. Commercial relationships change. Suppliers change direction. Legislation and jurisdictions change. Geopolitical circumstances change. Better technologies emerge.
If your data can only be understood by one application, your processes only operate inside one platform, and your institutional knowledge has effectively been encoded inside technology you do not control, then I think we have to ask a difficult question: how sovereign are you really? You may own the data, but you may no longer own the capability.
This Matters Differently in Defence and Intelligence
In many industries, vendor dependency is primarily a commercial problem. In defence, intelligence and national security, it can become an operational one.
Information needs to move between organizations, systems and nations while remaining protected and controlled. Capabilities need to continue functioning in degraded or contested environments. Technology needs to evolve rapidly without forcing organizations to rebuild the foundations beneath it.
This is why I believe interoperability, open standards and data-centric architectures matter so much. It is also increasingly reflected in the direction of the defence community itself.
NATO's digital strategy describes data as an enduring strategic asset and calls for interoperable, secure-by-design infrastructure, federated platforms and architectures designed to reduce vendor lock-in. Importantly, it recognizes that data can be shared across an alliance while nations retain sovereignty, autonomy and accountability.
Those ideas belong together because sovereignty does not mean isolation.
It does not mean refusing to use commercial technology, cloud services or capabilities developed by trusted partners. In fact, I believe the opposite is true. A genuinely sovereign architecture should make it easier to adopt the best technology available because no individual technology becomes impossible to replace.
What Should We Actually Own?
This is where I think we need to challenge some traditional thinking about enterprise systems. The objective should not necessarily be to own every piece of technology. Instead, organizations should ensure that they retain control of the things that matter most:
- Their data — accessible, understandable, portable and protected.
- Their processes and business rules — not buried inside a proprietary application.
- Their institutional knowledge — preserved independently of any individual technology provider.
- Their ability to make decisions and operate — regardless of which applications, platforms, infrastructure or providers are being used.
The application should therefore be replaceable. The analytics engine should be replaceable. The user interface, cloud provider, content management system and even the underlying infrastructure should be replaceable. What should endure are the organization's data, processes, rules, knowledge and ability to operate.
That requires deliberate architectural choices. Processing should not disappear inside proprietary applications. Business rules should not become inseparable from a vendor's software. Interfaces between systems should use open standards wherever practical, and data should remain accessible, understandable and portable.
Build the architecture correctly and technology becomes something you can continuously improve rather than something you become dependent upon.
AI Makes This Conversation More Urgent
Artificial intelligence adds another dimension to this discussion because AI systems consume enormous amounts of information. For defence and intelligence organizations, that information can represent decades of investment, operational knowledge, geospatial intelligence, infrastructure, behaviours, relationships and patterns.
As we introduce AI into these environments, we need to understand where our information goes, who can access it, what models interact with it and what those models may retain or learn from it. We should know whether we can change AI providers without losing capability, whether the underlying data and processes can move with us, and whether we can understand how information travelled from source data to a decision.
These are not arguments for slowing innovation. They are arguments for building the foundations that allow innovation to happen safely and continuously. In fact, I believe sovereignty should allow us to innovate faster because we know we can change technology without surrendering control of the mission.
The Future Will Be Federated
No nation, defence organization or intelligence agency operates alone. We need to share information, allied systems need to communicate, and data needs to move securely between different classifications, organizations, platforms and operational environments.
The answer therefore cannot simply be to build higher walls around everything. The challenge is to create environments where information can move without control moving with it. That, to me, is a much more meaningful definition of sovereignty. It is not simply about where a server happens to sit or which company supplied a particular application. It is about who ultimately controls the information, the processes and the ability to make decisions.
A Question Worth Asking
When evaluating the next major digital capability, perhaps one of the first questions should not only be, What can this system do for us today?
We should also ask: What happens if we need to replace it tomorrow?
If removing a supplier means losing access to your data, rebuilding your processes or abandoning critical capabilities, then you have purchased more than technology. You have also purchased dependency.
For defence and intelligence organizations operating in an increasingly unpredictable world, I believe we can do better. We can embrace commercial innovation without surrendering control. We can share information without surrendering ownership. We can adopt cloud and AI while retaining the ability to change them, and we can collaborate across borders while preserving national autonomy.
Ultimately, sovereignty isn't about owning every piece of technology. It is about ensuring that no piece of technology owns you.
Own the data. Own the processes. Own the decisions. And above all, preserve the freedom to act.












