Angela Bishop, UK CEO at Zühlke, explains why resilience, portability and operational control are becoming just as important as location when building truly sovereign digital infrastructure.
Digital sovereignty is often described in terms of geography – where data is stored, which cloud region it sits in or which country’s laws apply. But geography alone does not determine whether critical services continue when a supplier fails, a platform becomes unavailable or geopolitical conditions shift. Sovereignty is ultimately about operational control and making sure organisations keep essential services running when circumstances change.
For UK and European organisations, this is becoming a practical engineering challenge. Data centre operators and digital infrastructure teams are increasingly expected to deliver sovereignty through resilient design, transparent operations and architectural flexibility. Sovereignty does not emerge from a single technology choice. It is the cumulative effect of engineering decisions that determine how adaptable, portable and controllable systems are.
So how do we address this challenge? A strong starting point is to understand where risk is concentrated.
Recent failures, such as the Google Cloud outage in the Netherlands, have shown how disruption at one provider can ripple across sectors in minutes. Many organisations have unknowingly placed critical workloads on identical services, identical update mechanisms and identical infrastructure layers. Behind every cloud platform sits a physical stack of power networks, fibre routes, DNS services, cooling systems, semiconductor supply chains and specialised GPU infrastructure. In the case of the Google Cloud outage, a power and cooling failure in one facility resulted in cloud services going down, impacting businesses across multiple industries that had no visibility into or control over the physical fault that caused it. Sovereignty depends on recognising where apparently independent services converge and where a single point of failure could halt operations.
Applying the right level of sovereignty to the right workloads is equally important. Treating every application as mission-critical is neither practical nor affordable. Rather, organisations should align sovereignty with operational importance. Workloads with high assurance requirements may need dedicated infrastructure, customer-managed encryption keys or regional hosting, while others may prioritise flexibility or performance. As a result, sovereignty becomes a spectrum rather than a binary state. Organisations that design sovereignty intentionally are better placed to balance cost, control and resilience, while infrastructure providers will need to support a range of sovereignty requirements.
Portability is also central to sovereignty. An application hosted domestically may still be difficult to relocate if it relies heavily on proprietary cloud services. Equally, workloads hosted elsewhere may be more flexible if built using open standards and portable architectures. The real measure of sovereignty is not where workloads run today, but how easily they could run somewhere else tomorrow. Technologies such as containerisation, Kubernetes and infrastructure as code help preserve this flexibility when used intentionally. We’re also seeing regulation reinforce this direction, as the EU Data Act aims to make switching cloud providers easier and reduce unnecessary lock-in.
While portability is key, power constraints add a further dimension, particularly in the UK. The country has around 1.6 GW of operational colocation capacity, with more than 6 GW of announced projects aiming to come online by 2030. Developers are now seeking grid connections totalling tens of gigawatts, exposing just how far digital ambition has outpaced available power. Sovereignty goals are increasingly running into physical limits: organisations may want their workloads hosted domestically, but without enough power, cooling or network capacity, that’s hard to deliver. Energy sovereignty is becoming a core part of digital sovereignty, and some operators are responding by investing in their own power generation, battery storage and private energy networks, thereby cutting reliance on stretched national grids.
Resilience remains the final test. Across Europe, the NIS2 Directive is raising expectations for operational robustness, incident reporting and supply chain risk management. In the UK, the Cyber Security and Resilience Bill is expected to extend these obligations to large managed service providers and data centres that deliver services critical enough to fall within the Bill’s regulatory scope. The EU’s AI Act pushes in the same direction, with greater governance and transparency requirements. Compliance is tightening, but trust comes from demonstrable resilience through transparent architectures, tested recovery processes and verifiable operational controls. Sovereignty is not a static state; it is a discipline that requires evidence.
AI only intensifies these expectations and introduces a new layer of infrastructure dependency. As AI models grow larger and datasets become more valuable, moving data to compute is often no longer practical. Instead, compute increasingly needs to be deployed where the data already resides. Organisations are now deciding where models are trained, where inference takes place and who controls the GPU infrastructure behind them. This is pushing infrastructure providers to offer private AI deployments, secure GPU capacity and greater transparency over where sensitive data is processed.
For data centre operators, this represents another area in which sovereignty requirements are likely to shape infrastructure strategy. Providers will increasingly need to consider how high-performance compute can be combined with strong governance and operational control to support sovereign AI requirements.
Ultimately, digital sovereignty isn’t about where data sits; it’s about who stays in control when the ground shifts beneath it. For UK and European organisations, that control is fast becoming a strategic asset, not just a compliance checkbox. Organisations will need to engineer for it with the same discipline they apply to any critical system – designing deliberately for resilience and to hold under pressure. Because sovereignty was never about cutting every dependency. It’s about making sure no single one can bring the whole system down.

