Do you actually control your data environment, or are you just consuming it?
For some workloads, it won’t matter. For others, particularly anything sensitive, regulated, or business-critical, it very much does.
For years, data sovereignty has been treated as a simple concept: keep your data within the right geographic boundary and you are compliant and secure.
That interpretation is now outdated. For a long time, data sovereignty was treated as a simple question:
is our data stored in the right country or region?
That was fine ten years ago. It’s not fine now.
The reality is that data sovereignty has evolved. It’s no longer just about where data sits at rest. It’s also about where it’s processed, who has access to it, which laws apply to it, and ultimately who controls the infrastructure it runs on. In recent years this has become increasingly opaque, especially in the world of AI and large language models.
What used to be a compliance discussion has become a much broader question of control and risk.
The Illusion Most Organisations Are Still Operating Under
There is still a common assumption that if your data is stored in the UK or EU, you’re covered.
In practice, that’s not how it works.
If your platform is owned or operated by a company outside your jurisdiction, then the legal reach doesn’t stop at the data centre door. Foreign legislation can still apply, and access can still be compelled, regardless of where the data physically sits. The US government now has laws that compel US companies like Microsoft to hand over information held in any of their data centres irrespective of the country it resides or local laws.
They think they have sovereignty because of geography, when in reality sovereignty is defined by control and jurisdiction, not location.
Why This Is Starting to Matter Now
Technically it has mattered for years, but as a negligible risk threat. It has only recently become a real concern as the risk profile has increased dramatically, due in part to the following three things.
- Geopolitical stability is no longer something you can take for granted. The idea that technology platforms could be influenced or even restricted by political or trade tensions is now being discussed openly. Whether it happens or not is almost secondary.
In the recent war between Iran and the US, the Iranian’s declared US technology companies as military targets, with data centres being a focus. Taking out a core data centres can cause huge global economic destruction, they are “soft” targets for terrorism and cyber-attacks.
The fact that it is plausible is enough to make it a risk worth planning for.
- Organisation over dependence has been built on a small number of global cloud providers. When most of your core platforms sit with companies headquartered in another jurisdiction, you are effectively betting on long-term alignment — politically and commercially — that you don’t control.
- The way data is used has changed. It’s no longer something that just sits in a database. It’s constantly being processed, analysed, fed into models, and moved around. That means sovereignty isn’t just about storage anymore — it’s about where decisions are being made from your data and under whose control.
AI Large language models are becoming subject to government control, the US has limited the distribution and use of some of the latest models. If you have applications that are dependent on those models you are at risk of them being unusable.
The Market Has Already Started to Respond:
Sovereign Cloud
What’s notable is that the hyperscale’s have clearly seen this shift coming.
You can see it in the way they’re positioning sovereign cloud offerings. These aren’t about local regions anymore — they’re about ring-fencing operations, limiting external access, and giving a degree of local control. That tells you that customer demand has changed.
More telling, though, is the move back towards running cloud services on your own premises. A few years ago, the message was simple: move everything to the cloud. Now we’re seeing services designed to bring cloud capability back into the data centre.
For example, AWS has launched a European Sovereign Cloud designed to operate independently within the EU, reflecting direct demand from customers and regulators. [aws.amazon.com]
These offerings aim to address sovereignty—but they also highlight the fact that standard cloud models no longer satisfy all requirements.
The Return of “On-Prem Cloud”
The most telling shift is, the hyperscale’s are bringing the cloud, back into your data centre.
Services like AWS Outposts allow organisations to run full cloud stacks on their own premises, keeping data and processing local while still consuming cloud services.
This is a significant evolution. For years, the industry pushed everything toward centralised public cloud. Now, we’re seeing:
- Hybrid and distributed cloud architectures
- Local execution for sensitive workloads
- Cloud models designed for jurisdictional control
In fact, this move strongly suggests that hyperscale’s recognise sovereignty is no longer optional, it’s a buying criterion.
Customers still want the cloud model, but they also want control over where and how it runs. Those two things used to be seen as trade-offs. Now they’re being combined.
The Bottom Line
Data sovereignty hasn’t just evolved — it’s become a different problem entirely.
It now sits somewhere between architecture, legal risk, and business continuity. And it’s being driven as much by geopolitics as it is by technology.
Organisations need to start looking beyond simple hosting location and understand the full chain of control. That includes who owns the infrastructure, which laws apply to the provider, where processing takes place, and what the fallback looks like if that setup is disrupted.
In a lot of cases, this will lead to more hybrid thinking. Not because cloud is wrong, but because a one-size-fits-all model no longer aligns with the risk profile most organisations are now dealing with.
It’s no longer enough to ask where your data is. You need to understand who ultimately controls it — and what happens if that control is tested.
If you want to know more about how SmallNet can help you with your data sovereignty, get in touch.