Digital Sovereignty: Do you really have control of your IT?

The gap between “where the data sits” and “who's ultimately in control of it” is where a lot of current sovereignty strategy is now focused.

On 12 June 2026, just three days after launching its most capable AI models yet, Anthropic was ordered by the US government to switch them off, following a Department of Commerce export control directive citing national security authorities.

It’s a dramatic illustration of a question every UK business working on the cloud should already be asking: what happens to our business if the government of the country where our technology supplier sits, decides to intervene?

The power of global hyperscalers

Long before GDPR, organisations (particularly in government and the public sector) ran their own servers, their own storage, their own rules.

As commercial cloud matured, a wave of providers emerged offering something similar as a managed service. Skyscape Cloud Services, later rebranded UKCloud, was the best-known UK example: a British provider offering sovereign cloud services to the public sector, the NHS, and the Ministry of Defence. It couldn’t survive indefinitely against the scale and pricing of the global hyperscalers, and went into compulsory liquidation in October 2022.

Essentially, digital sovereignty is the ability of an organisation to control its own IT systems, data, technology and operations, without being unduly dependent on external providers. It applies whether you’re talking about storage, compute, applications, networks, or AI.

The UK is already reacting

Where is our data stored and who can access it? Which laws apply to our supplier? These are some of the fundamental questions. 

Modern businesses are stitched together by integrations in a way that would have been unimaginable even a decade ago. A single customer-facing application might quietly depend on a dozen external services, each with its own jurisdiction, licensing terms and risk profile. Laws, tariffs, taxes and licensing conditions are shifting faster than most procurement cycles can keep up with.

In January 2026, 45 MPs tabled an Early Day Motion calling for a “UK digital sovereignty strategy”, flagging that AWS, Azure and Google Cloud between them supply cloud services to more than 90% of UK public sector organisations.

The UK’s Cyber Security and Resilience Bill, alongside a new Cyber Action Plan and Government Cyber Unit announced in January 2026, raises the compliance bar for critical suppliers, with fines of up to £100,000 a day for continuing breaches.

The Data (Use and Access) Act 2025 has introduced the most significant update to the UK’s data protection framework since UK GDPR, with further provisions still being brought into force through 2026.

Data sovereignty and residency are not the same

Hosting your data in a UK data centre tells you where the servers physically sit. It doesn’t necessarily tell you which laws ultimately govern access to that data. A US-owned provider hosting in London can, in principle, still be reachable under US legislation such as the CLOUD Act.

Microsoft spent several years building its EU Data Boundary programme so that European customer data stays stored within the EU. It introduced “Flex Routing” for Microsoft 365 Copilot in spring 2026 so that, during periods of high demand, the AI processing behind a Copilot request could run on GPUs in the US, Canada or Australia rather than in Europe, even though the underlying files and emails stay put. 

This shows a well-publicised, audited data residency commitment can still carry an operational exception that most businesses will not notice, particularly once AI is added into the mix.

That gap between “where the data sits” and “who’s ultimately in control of it” is where a lot of current sovereignty strategy is now focused.

What this means for your business

Most organisations can continue to use the global giants, but it does mean doing a proper audit rather than assuming you already know the answer.

You should know where your critical data and workloads sit, and under whose jurisdiction including the third-party services your applications quietly depend on. Understand your options if a supplier’s terms or ownership changed tomorrow. 

By building flexibility into your systems and integrations you can keep a competitive advantage but be ready to pivot should a supplier – or government – changes the rules.