On September 9, 2026, the Electronic Frontier Foundation's Jillian C. York and Eva Galperin published "Digital Sovereignty: What It Is, What It Could Be". The essay arrives as the term has spread from European cloud debates into the policy vocabulary of nearly every government. Its central claim is that sovereignty is only worth having if it increases the control that people and communities have over the technology they use. Control that merely moves from one concentrated power to another does not qualify.
The strongest case for the state-centred view
The state-centred reading deserves a fair hearing. European governments that depend on a handful of US cloud, chip and platform providers have a real strategic exposure. A change in foreign law, a sanctions decision or a commercial dispute could interrupt services that hospitals, tax authorities and courts rely on. The Franco-German joint paper on digital sovereignty, which EFF cites, defines the goal as "the capability and capacity to develop, provide, use, adapt and control digital technologies including hardware in an independent, self-determined and secure manner". Wanting that capacity is reasonable. Dependence on a single foreign supplier is a legitimate risk to manage.
Where the definition goes wrong
The trouble is what governments do with the word. EFF's survey shows how many different things it now covers: EU cloud independence, Indigenous data governance, data jurisdiction concerns in Southeast Asia, public digital infrastructure in Latin America, and African efforts to move from technology consumer to builder. Several of these are about communities controlling their own data and infrastructure, which is autonomy in the sense EFF favours. Others are not.
The risk is plain in the cases EFF flags. Researcher Reem Almasri warns that sovereignty frameworks can become a licence for surveillance in authoritarian settings. Azadeh Akbari, a professor at Goethe University Frankfurt, wrote in Tech Policy Press on January 15, 2026 that Iran's "National Information Network" creates "two parallel realms: a domestic network and the global internet." The same piece describes a shutdown that had by then lasted seven days, along with electronic-warfare interference with Starlink traffic. That is sovereignty used as a mechanism for cutting people off.
This matters for democracies as well. When Brussels, Berlin or Delhi describe sovereignty as state control over data and infrastructure, they hand authoritarian governments a respectable vocabulary for the same claim. A policy debate that never separates "our citizens control their tools" from "our government controls its citizens' tools" cannot tell Germany's cloud strategy from Tehran's national intranet.
Encryption is the test case
EFF's sharpest point is that encryption backdoors and "lawful access" mandates are incompatible with real sovereignty. The logic holds up. A deliberately weakened system has a vulnerability that any capable adversary, including a foreign intelligence service, can look for and exploit. A government that mandates access to its citizens' communications has made a national infrastructure choice that adds a security weakness. It cannot claim to have reduced foreign dependency while doing so. Treating end-to-end encryption as normal infrastructure, which EFF advocates, serves both security and autonomy.
What proportionate sovereignty policy looks like
EFF's positive agenda is concrete, and it is the kind of agenda that proportionate, pro-innovation policy can support:
- Fund open source. Germany's Sovereign Tech Fund says it invests in open software components that underpin Germany's and Europe's competitiveness, such as libraries, package managers, encryption technologies and protocol implementations. Public money for shared infrastructure that anyone can inspect, fork and run lowers dependency without handing anyone a veto.
- Mandate interoperability and portability. If users can leave a platform and take their data and social graph with them, no provider, foreign or domestic, holds them captive. Switching rights are a more direct fix for dependency than a requirement to use a national vendor.
- Rule out surveillance by design. Sovereignty strategies should state explicitly that they do not authorise backdoors, and should not be used to justify data-localisation rules whose real function is to give police easy access.
- Treat community governance as part of the picture. Indigenous data governance and community-run infrastructure are sovereignty in its original sense, and national programmes should make room for them.
There is a market-based case here too. A "sovereign cloud" label is a marketing term that companies are already selling. Without scrutiny, it can mean a rebranded incumbent product with a local data centre. Procurement rules that reward open standards and exit rights give governments real leverage over such vendors. Rules that merely reward a national flag do not.
The limits of the argument
EFF's essay is a framing document, not an evaluation of results. It does not show that open-source funding has measurably reduced dependency, and critics such as Akbari point out an additional problem: the sovereignty debate carries a Eurocentric bias that overlooks how the concept lands in countries with weaker institutions. The remedy is to ask for evidence. Governments that adopt sovereignty strategies should publish what they will measure, such as reduced single-vendor exposure, adoption of open standards, and independent security audits, and report on it.
The test EFF proposes is simple and usable: does a given measure leave users and communities with more control or less? Open standards, portability and encryption pass. Backdoors, shutdown powers and surveillance-friendly localisation fail, whoever invokes the word sovereignty to justify them.