States retain the power to make laws, levy taxes and embody popular sovereignty. Yet a growing share of their capacity to act depends on infrastructure, software and expertise controlled by private transnational companies. Between necessary interdependence and diminished control, democracy must redefine the practical conditions of its authority.
A government can amend a law, mobilise public funds or declare a state of emergency. It cannot, within the same timeframe, build a satellite constellation, manufacture advanced semiconductors, replace an operating system or recreate the digital infrastructure on which its administration depends. This difference in tempo captures a fundamental transformation of contemporary power: the state retains legal authority, but it does not necessarily possess the technical means required to exercise it.
Sovereignty has not disappeared. It has been fragmented among public institutions that decide, companies that design, infrastructure that carries, software that organises and supply chains distributed across several continents. A democratic decision must now travel through multiple technological layers before producing a tangible effect. At each layer, a supplier, technical standard, licence, component or foreign jurisdiction may intervene.
The question, therefore, is no longer simply whether the state remains sovereign in law. It is whether it can still understand the systems on which it relies, shape their development, secure their operation and, when circumstances require it, disengage from them. The future of democratic power is increasingly being determined within this gap between formal sovereignty and operational control.
The Power Behind the Infrastructure
Technology was long treated as one economic sector among many, subject to industrial policy, competition law and the cycles of innovation. It has since become the environment through which the entire state operates. Tax administrations process declarations through digital platforms. Healthcare systems rely on databases and specialised software. Courts, social services, police forces, local authorities and energy networks depend on communications infrastructure, data centres, digital equipment and authentication systems.
This dependence does not mean that technology companies have replaced governments. It means that public authority increasingly operates through systems that the state neither designed nor, in many cases, can maintain independently. An administration may legally own its data while depending on foreign software to process it, a cloud provider to store it, Asian manufacturers to supply its servers and international operators to transmit it.
The physical foundations of the digital world are often concealed by the apparent fluidity of online services. The cloud appears immaterial, yet it rests on buildings, electricity, processors, cooling systems and physical networks. The European Commission estimates that submarine cables carry around 99% of intercontinental internet traffic. In February 2026, it announced €347 million in funding for cable security, resilience and European repair capacity. Invisible infrastructure has consequently returned to the centre of security, industrial policy and state power (European Commission, 2026).
Concentration deepens the vulnerability. A 2026 brief from the European Commission’s Joint Research Centre estimates that three US-based companies control more than 70% of the European cloud market, while European providers account for only around 15%. This is more than a commercial imbalance. It means that a growing share of Europe’s economy, public services and research operates through architectures developed and administered outside the European Union (JRC, 2026).
Sovereignty Without Control
Classical sovereignty was built around territory, population and legal authority. Technological power adds an operational dimension. Sovereignty can no longer be reduced to the ability to issue a rule. It must also include the capacity to verify its implementation, maintain essential services and preserve an alternative when the principal supplier becomes unavailable or politically unreliable.
That capacity depends on elements that rarely enter public debate: data portability, interoperability, access to source code, control over encryption keys, software documentation, domestic expertise and contractual exit provisions. A state may formally remain free to change providers while being practically locked into an ecosystem whose replacement would require years of work, substantial investment and the reorganisation of entire administrations.
The CrowdStrike incident of July 2024 made this vulnerability visible. A defective cybersecurity software update affected an estimated 8.5 million Windows devices, according to Microsoft. This represented less than 1% of the global Windows estate, yet the disruption reached airlines, banks, hospitals and other essential services. The scale of the crisis resulted not from the absolute number of affected devices, but from their position within critical organisations (Microsoft, 2024).
Dependence is also industrial. Semiconductors are embedded in telecommunications, energy, transport, medical equipment, military systems and artificial intelligence infrastructure. Even the United States, which occupies a central position in the global technology economy, does not control the entire supply chain. A January 2026 presidential proclamation, citing findings by the US Department of Commerce, stated that the country consumed roughly one quarter of the world’s semiconductors but fully manufactured only around 10% of the chips it required. The document characterised this dependence as an economic and national security risk (White House, 2026).
Even the world’s leading technological power therefore lacks complete autonomy. The production of an advanced chip draws on equipment, materials, patents, design software and manufacturing plants distributed across the United States, Europe and East Asia. Absolute technological sovereignty has become practically unattainable. What distinguishes states is their ability to identify critical dependencies, diversify them and retain bargaining power when global supply chains come under pressure.
Companies as Quasi-Institutions
Some technology companies no longer merely sell products. They administer spaces in which citizens receive information, companies conduct business, governments store data and political leaders communicate with the public. Their terms of service determine what may be published, recommended, monetised or removed. Their interfaces structure access to markets. Their algorithms organise visibility. Their identity systems control entry into a growing range of services.
This power is not sovereignty in the constitutional sense. A platform cannot legitimately levy taxes, pass laws or claim a legal monopoly over coercion. It nevertheless exercises infrastructural power: it can make certain actions possible, expensive, invisible or technically unfeasible. Its decisions may produce effects comparable to those of public regulation without passing through the procedures of representation, deliberation and oversight that legitimise democratic authority.
Artificial intelligence deepens this shift. The most advanced models are not ordinary programs that can simply be installed on a local machine. They require vast amounts of computing capacity, data, energy and capital. The companies controlling processors, cloud infrastructure and foundation models partly determine who can develop advanced applications, in which languages, under what conditions and with what scope for independent auditing. The OECD has warned that shortages, exclusive agreements and vertical integration may allow dominant providers to favour their own projects or selected partners, turning access to compute into a strategic lever (OECD, 2025).
The war in Ukraine gave this development a particularly striking expression. Commercial satellite communications became important to Ukrainian military operations and national resilience. In 2023, the US Department of Defense confirmed that it had entered into a contract with SpaceX for Starlink services, while withholding operational details. The significance of the arrangement lay less in its financial value than in its function: a contractual relationship was used to secure access to privately owned infrastructure that had become strategically essential (US Department of Defense, 2023).
This episode does not mean that a private entrepreneur governs in place of states. It shows that capabilities once reserved for public powers — military communications, Earth observation, space launch and large-scale data analysis — can now be controlled by commercial groups. The state remains responsible for strategy, but it must negotiate access to some of the instruments through which that strategy is carried out.
Democracy and the Asymmetry of Time
The democratic state moves according to a particular timetable. It must consult, legislate, justify its decisions, uphold fundamental rights and submit to judicial review. A technology company can deploy a feature, alter an interface or relocate infrastructure within weeks. Public law often intervenes only after a market has concentrated, habits have become established and government agencies already depend on the system they are attempting to regulate.
This relative slowness is frequently interpreted as weakness. It is also the price of legitimacy. A democracy cannot respond to technological power by abandoning the safeguards that distinguish it from authoritarian rule. Generalised surveillance, arbitrary access to data and the forced subordination of companies may create an appearance of immediate control. They merely transfer the danger towards political concentration and the disappearance of institutional counterweights.
Authoritarian regimes are not free from technological dependence. They may exercise more direct control over domestic companies, but they remain reliant on international supply chains, external expertise and imported components. Political control does not automatically create innovation or resilience. A technology that is obedient to the government may remain industrially vulnerable.
The deeper democratic disadvantage lies elsewhere. Public institutions sometimes lack the independent technical expertise needed to assess the systems they purchase. They must then ask a supplier to explain the operation, risks and performance of the very product they are supposed to evaluate. The company becomes simultaneously a contractor, a source of information and an interlocutor of the regulator. The state retains the final legal word, but it may no longer possess the knowledge required to exercise that authority independently.
The Return of Law
The growing power of technology companies has not eliminated the regulatory capacity of states. It has prompted its return. The European Union represents the most advanced attempt to transform law into an instrument of digital sovereignty. The Digital Markets Act no longer relies solely on retrospective penalties for anticompetitive behaviour. It identifies gatekeepers and imposes obligations designed to protect market contestability. By 2026, 23 core services provided by Alphabet, Amazon, Apple, Booking, ByteDance, Meta and Microsoft had been designated under the framework (European Commission, DMA Gatekeepers Portal).
The AI Act follows a different logic, centred on risk, transparency and intended use. It entered into force in August 2024 and became broadly applicable on 2 August 2026, although some requirements concerning high-risk systems were granted longer transition periods. The European AI Office can request technical documentation, evaluate general-purpose models, require corrective action and impose penalties for non-compliance (European Commission, AI Act).
These measures demonstrate that states, or political entities such as the European Union, are not condemned to powerlessness. Access to a market of several hundred million consumers creates substantial regulatory leverage. Technology companies may dominate infrastructure while remaining dependent on legal protection, public procurement, energy systems, radio spectrum, territorial access and consumer demand organised by states.
Law, however, cannot substitute for industrial capacity. A regulator may require interoperability without immediately producing a viable competitor. It may guarantee data portability without creating the computing facilities needed to host that data. It may penalise a company while lacking an alternative to services that have become essential. Regulatory sovereignty becomes more effective when supported by expertise, infrastructure and an industrial base capable of turning legal choices into operational reality.
Autonomy Is Not Autarky
The pursuit of technological sovereignty can easily drift towards an unrealistic promise: replacing every foreign technology with a national equivalent. Such a strategy would be beyond the reach of most countries and prohibitively expensive even for the largest powers. Digital value chains have become too specialised to be reproduced entirely within every national border.
Strategic autonomy pursues a different objective. It seeks to prevent any single dependency from interrupting a vital function or neutralising a political decision. A state can use foreign technologies while requiring data portability, open standards, continuity arrangements, audit rights and enforceable exit provisions. It can distribute its infrastructure across several providers, preserve public capacity in its most sensitive functions and develop the expertise needed to avoid outsourcing its entire understanding of the systems it operates.
Public procurement therefore becomes an instrument of sovereignty. Every major technology contract creates an architecture of dependence that may last for years. The lowest initial price can conceal much larger migration, licensing, training and lock-in costs. Strategic procurement must consequently assess reversibility, interoperability and operational continuity alongside immediate performance.
Open-source software can strengthen this control, although it is not an automatic solution. Access to source code expands the possibilities for scrutiny and limits some forms of proprietary lock-in, but it requires teams capable of maintaining and securing the software. According to the OECD, 28 of the 36 countries surveyed had a national or federal policy promoting open-source software in 2025. The organisation nevertheless emphasises that its effectiveness depends on clear rules, active stewardship and sustained funding (OECD, Digital Government Outlook 2026).
Technological sovereignty is therefore less about owning every tool than preserving meaningful choice. A system remains politically controllable when it can be understood, audited, repaired and replaced under acceptable conditions. Dependence becomes dangerous when it is invisible, irreversible or concentrated in the hands of an actor capable of unilaterally imposing its terms.
The Challenge for Middle Powers
For middle powers and developing countries, this distinction is decisive. They cannot reproduce American, Chinese or European capabilities across semiconductors, cloud computing, space technology and artificial intelligence. Their sovereignty depends more heavily on selecting critical functions, diversifying partnerships and gradually building domestic expertise.
Morocco illustrates this search for balance. Its National Cybersecurity Strategy to 2030 recognises that uncontrolled digitalisation can expand the attack surface and disrupt the economy, public order and vital services. It places particular emphasis on governance, the legal framework, the protection of sensitive systems, national resilience and human capital development (DGSSI, National Cybersecurity Strategy 2030).
During the January 2026 launch of the “AI Made in Morocco” initiative, Moroccan officials also presented the national cloud established in 2025 as one of the foundations of sovereign artificial intelligence (Maroc.ma, 2026). The challenge will nevertheless extend beyond the physical location of data. A cloud facility based within national territory may still rely on foreign processors, software, cybersecurity tools and maintenance expertise. Sovereignty therefore requires gradual control over the full operational cycle: architecture, administration, cybersecurity, maintenance, auditing and reversibility.
For Morocco, as for many African states, the most credible path lies neither in passive dependence nor in digital autarky. It involves diversified partnerships, protection of strategic data, investment in skills, adoption of open standards and the development of domestic capabilities in a limited number of foundational areas. Sovereignty then becomes a form of bargaining power: the capacity to cooperate with several actors without becoming captive to any one of them.
Governing Without Owning the Entire System
The democratic state no longer governs alone if governing means directly controlling every infrastructure through which its authority is exercised. In truth, it never governed in complete isolation. Banks, energy companies, media organisations, arms manufacturers and transport operators have always participated in the material operation of nations. The contemporary rupture lies in the depth, speed and concentration of technological dependence. A small number of digital systems can now affect thousands of organisations simultaneously, operate across national borders and reshape the conditions of public debate itself.
The state nevertheless retains powers that companies do not possess. It defines the law, authorises economic activity, allocates spectrum, organises public procurement, finances research, sanctions abuses and ultimately guarantees collective continuity. Its role does not necessarily require it to operate every technology directly. It must decide which functions cannot be delegated, which dependencies remain acceptable and which safeguards must accompany the use of private infrastructure.
Democratic sovereignty in the twenty-first century will be less a sovereignty of ownership than a sovereignty of architecture. It will depend on the ability of institutions to map their dependencies, maintain alternatives, require transparency and prevent private infrastructure from becoming politically unavoidable. It will also require major technological choices to be subjected to genuine public deliberation, because a digital architecture can bind the future of a public administration as durably as a law or treaty.
The democratic state still governs, but its authority can no longer be measured solely by the extent of its legal powers. It must be judged by its ability to turn collective decisions into effective action despite the technological dependencies surrounding it. When citizens can understand those dependencies, debate them and alter their conditions, technology remains an instrument. When they become opaque and irreversible, elections may still determine the intended direction, but infrastructure begins to decide which paths remain open.
Main Sources
- European Commission — Strengthening Digital Sovereignty in EU Public Governance, 2026
- OECD — Digital Government Outlook 2026
- OECD — Competition in Artificial Intelligence Infrastructure, 2025
- European Commission — Digital Markets Act
- European Commission — European Regulatory Framework for Artificial Intelligence
- European Commission — Submarine Cable Security, 2026
- White House — US Dependence on Semiconductor Supply Chains, 2026
- Microsoft — The CrowdStrike Outage, 2024
- DGSSI — Morocco’s National Cybersecurity Strategy to 2030
Atlas Limits Research Desk
Atlas Limits’ editorial and analytical desk.


