Written by the ENSI Foresight Division on a library of 114 primary documents from the EU institutions, OECD, UN bodies, NATO, world governments, and the leading think tanks. Compiled August 2026.
The argument, before the list
Sovereignty is not autarky. No serious government believes it can fabricate its own leading-edge chips, train its own frontier models, lay its own transoceanic cables and write its own operating systems — and the one audit that priced full self-sufficiency in even a single layer found it absurd: the European Court of Auditors concluded that in the microchip value chain “total autonomy is impossible”, before showing that even the EU’s far more modest 20% production target is very unlikely to be met (ECA, The EU’s Strategy for Microchips, 2025). The states that talk loudest about digital autarky tend to be the ones building censorship regimes, not capabilities. That is not the sovereignty this report is about.
Sovereignty, properly defined, is the ability to decide, act, and recover without asking permission — from another state, or from a foreign platform whose incentives are not yours. The EPRS puts it in one line: digital sovereignty is “Europe’s ability to act independently in the digital world” (EPRS, Digital Sovereignty for Europe, 2020). Fraunhofer ISI, in the paper that made “technology sovereignty” respectable as a policy concept, is careful to define it as a state’s capacity to provide or reliably access the technologies it deems critical — explicitly distinct from autarky and from protectionism (Fraunhofer ISI, Technology Sovereignty: From Demand to Concept, 2020). The academic mapping most cited on the subject makes the same move along three dimensions — the state, the economy, the individual — and finds that what governments actually mean by the word is control over their own digital environment, not isolation from everyone else’s (Internet Policy Review, Pohle and Thiel: Digital Sovereignty, 2020).
The reason this now belongs at the centre of statecraft rather than in a digital-ministry annexe is that the modern state has quietly become a tenant in its own house. Its registers sit in rented clouds, its communications cross cables it neither owns nor can repair, its chips arrive through a supply chain with single points of failure on the other side of the planet, its officials authenticate through platforms governed by foreign law, and its AI ambitions run on compute operated — even when physically located at home — by companies answerable to another jurisdiction. Each of these arrangements was individually rational. Renting is cheaper, faster and usually better-run than building. But the sum of rational rentals is a structural condition: the rented state can be switched off politely, contractually, completely — no invasion required, merely a sanctions decision, a licence withdrawal, a change in terms of service, or a distant boardroom concluding that your market is no longer worth the compliance risk.
This is not a hypothetical mechanism. The scholarship on weaponized interdependence has documented how the states and firms that sit at the hubs of financial, informational and technological networks convert that position into coercive leverage — surveillance of what flows through the hub, and the ability to cut adversaries off from it (CSET, From Cold War Sanctions to Weaponized Interdependence). And the accidental version is just as instructive as the deliberate one: the United Kingdom’s official risk register opens by citing the CrowdStrike IT outage as proof of how widely a single technology failure propagates through services essential to daily life (UK Cabinet Office, National Risk Register, 2025). A state can be partially switched off by a bad software update it never installed, in a product it never chose, running in systems it does not operate.
The actor in this report is therefore the state — not the firm. Firms optimise for efficiency and can exit a bad dependency by dying and being replaced; states cannot. Only the state carries the four functions that must survive stress: managing crises, making decisions under uncertainty, knowing what the nation has and depends on, and steering its scientific capacity toward its own problems. Those four functions stand on a stack of assets — physical substrate, compute, data, platforms, models, operations, people and rules — and for every layer of that stack the state faces the same three-way choice: own it, share it with allies, or rent it with a tested exit plan. All three are legitimate. What is not legitimate, after the evidence assembled here, is the fourth option most states have actually chosen: renting by default, without knowing it, with no fallback and no list of what has been rented.
The good news is that the map can be drawn. The best states already draw it — the UK enumerates 89 acute risks with reasonable worst-case scenarios; the US maps 55 national critical functions rather than a list of buildings; Estonia has decided precisely which ten datasets constitute its continuity as a state and backs them into an embassy abroad. This report walks the seven layers of the sovereign stack, names where the dependencies actually bite — with numbers — and ends with a ranked shortlist for a mid-sized EU state: what to own outright, what to federate at European level, and what to go on renting, eyes open, exit plan in hand.
The map in brief
Sovereignty is a capability, not a slogan — the ability to decide, act, and recover without asking permission; it is explicitly not autarky, which even the richest blocs cannot afford in a single layer (ECA; Fraunhofer ISI).
The state’s assets stack into seven layers — physical substrate; compute and cloud; data; platforms; intelligence and models; operational capabilities; people, rules and trust — and each layer demands an explicit own/share/rent decision.
The dependencies are measured, not rumoured: 48% of 775 non-US data centre projects are operated by US companies when weighted by investment value (arXiv, How Sovereign Is Sovereign Compute, 2025); three hyperscalers hold a combined 70% of the EU cloud market (Clingendael, 2024); the EU’s own forecast puts its 2030 chip share at 11.7% against a 20% target (ECA, 2025); upwards of 95% of intercontinental internet traffic runs through roughly 475 submarine cables (Atlantic Council, 2021).
The trap is mechanical, not moral. Lock-in is built from egress fees, closed APIs and path dependence (ACM Netherlands, 2022); interdependence becomes a weapon at the network hubs (CSET); the chokepoints sit in exactly three arenas of internet infrastructure — naming, routing, and cables (SWP, Cracks in the Internet’s Foundation, 2019).
The best practice is to map functions, not assets — the shift CISA made with its National Critical Functions (2019), the UK made with its 89-risk register (2025), and the EU is forcing on member states through the CER and NIS2 regimes.
Continuity can be engineered. Estonia’s data embassy — ten strategic registers replicated under Estonian legal control in Luxembourg — proves a state’s core can survive the loss of its territory’s infrastructure (e-Estonia, Data Embassy Factsheet); Ukraine’s wartime cloud migration proves it at war-scale (Atlantic Council, Building the Digital Front Line, 2025).
For a mid-sized EU state the ranking is knowable: own the registers, identity, the data-exchange bus, continuity copies and crisis operations; federate compute, chips, space and standards at EU level; rent hyperscale cloud and frontier models — with contractual exits, tested annually.
The first move is an inventory: no state can decide what to own until it has enumerated what it currently rents, from whom, under whose law, and what breaks first when it is withdrawn.
How this report is organised
The body follows the seven layers of the ENSI sovereign asset map, from the ground up — Layer 0, the physical substrate, through Layer 6, the human and governance assets — because each layer stands on the ones below it and inherits their fragilities. For each layer the treatment is the same: what the layer is, the documented evidence of dependency, the own/share/rent decision a state must make explicitly, and the signals that tell you the decision needs revisiting. After the seven layers comes a section on the mechanics of the dependency trap — how interdependence is weaponized and where the chokepoints sit — because the mechanism repeats across every layer and deserves to be understood once, properly. The close ranks the layers for a mid-sized EU state, with the Czech Republic as the home example.
1. Layer 0 — the physical substrate: energy, chips, cables, space, quantum
What it is. Everything digital is physical somewhere. Layer 0 is the matter under the stack: electricity for compute, semiconductors, the fibre and submarine cables data actually travels through, the space assets that provide positioning, timing, observation and fallback communications, and — arriving now — the quantum technologies that will reset both sensing and cryptography. A state that skips this layer builds its sovereignty on someone else’s ground.
Where the dependency bites. Semiconductors are the best-audited case. The EU’s share of global chip manufacturing stood at roughly 9% in 2020, and in 2021 — with its production sites at full capacity — the bloc still ran a trade deficit in microchips of almost €20 billion (ECA, The EU’s Strategy for Microchips, 2025). The Chips Act mobilised at least €43 billion in policy-driven investment, yet the auditors found the Commission directly responsible for only around 10% of the public funding and concluded the flagship 20%-by-2030 target is very unlikely to be met — the Commission’s own July 2024 forecast projects just 11.7% (ECA, 2025). The pandemic previewed the stakes: chip shortages collapsed German car production to 1975 levels (ECA, 2025). The chokepoints are structural, not cyclical — advanced fabrication concentrated in Taiwan and South Korea, lithography in one Dutch firm, design software in the US — a topology mapped supplier by supplier in CSET’s supply-chain brief (CSET, The Semiconductor Supply Chain). Cables tell the same story one layer down: upwards of 95% of intercontinental internet traffic crosses roughly 475 submarine cables, whose ownership is shifting toward large internet platforms and, on some routes, Chinese state-linked builders, while remote management systems create new single points of operational failure (Atlantic Council, Cyber Defense Across the Ocean Floor, 2021). The European Parliament’s own assessment reaches the equivalent conclusion for EU connectivity (EP Policy Department, Security Threats to Undersea Communications Cables, 2022), and Taiwan is the live experiment: an island economy of world-systemic importance connected through 15 undersea cables, with documented sabotage pressure on them (Stanford FSI, Taiwan Undersea Cable Network Resilience, 2024; DSET, Vulnerabilities at Depth, 2025). In space, Europe has drawn the lesson from Ukraine’s dependence on a single private constellation and is building IRIS² as a sovereign secure-connectivity layer (ESPI, IRIS² Growing Up, 2025) — while the space-cyber intersection becomes its own attack surface (ESPI, Space Cyber and Defence, 2023). Quantum sits at the edge of the layer: RAND’s sober reading of commercial and military timelines argues against panic and for sequencing (RAND, Applications and Timelines for Quantum Technology) — but post-quantum cryptographic migration is a defensive asset a state must start owning now, because harvested traffic decrypts retroactively.
The own/share/rent decision. No mid-sized state should own a leading-edge fab — the ECA audit is effectively a proof that even the EU cannot buy its way to one-fifth of the market. The rational portfolio is: own the dependency map (which chips, from whom, substitutable where), own stockpiles for the chips its critical infrastructure actually consumes, and own niche positions where it has genuine comparative advantage — design, packaging, materials, instruments. Share the rest at EU level: EuroHPC for the big iron, the Chips Act for what it can realistically deliver, IRIS² and Galileo for space. Connectivity is the exception that demands ownership: internet exchange points on national territory, redundant cable routes, vetted 5G/6G vendors, and — the most neglected asset in Europe — guaranteed access to cable repair capacity, which Taiwan’s analysts identify as the binding constraint in every sabotage scenario (Stanford FSI, 2024). Energy for compute must be owned as a matter of grid planning: it is the input every layer above silently assumes.
What to watch. The EU’s actual (not announced) fab investment against the ECA’s 11.7% trajectory; cable-laying and cable-repair fleet ownership by flag; the ratio of national IXP-routed traffic to traffic that hairpins through foreign hubs; IRIS² deployment against schedule; national PQC migration deadlines — and whether your own government has one.
2. Layer 1 — compute and cloud: the most rented layer in the stack
What it is. The machines the state’s digital life actually runs on: the cloud estates hosting government workloads, the AI compute national ambitions depend on, and the continuity copies that let a state survive the loss of its own data centres. This is the layer where the gap between the rhetoric of sovereignty and the accounting of it is widest — because it is the layer states have rented most completely, and most invisibly.
Where the dependency bites. Start with the number that should reframe every “sovereign cloud” announcement in Europe: an audit of 775 data centre projects outside the United States found that 48% are operated by US companies when weighted by investment value — and that is on top of the estimated 54% of worldwide compute capacity that sits inside US borders to begin with (arXiv, How Sovereign Is Sovereign Compute, 2025). The paper’s conclusion is the uncomfortable one: building data centres on national soil does not confer sovereignty if the operator answers to another legal system, because jurisdiction follows the operator’s nationality as well as the facility’s territory. A domestically sited hyperscaler region is, legally, a foreign object on home ground — this is the CLOUD Act problem in physical form. The market structure compounds the legal one. In the EU, three American providers hold a combined 70% of the cloud market (Clingendael, Too Late to Act? Europe’s Quest for Cloud Sovereignty, 2024); the Dutch competition authority found Microsoft Azure and Amazon Web Services each holding 35–40% of the IaaS and PaaS layers in the Netherlands and in Europe, with Google a strong third (ACM Netherlands, Market Study Cloud Services, 2022). And the lock-in is engineered, not incidental: the ACM documents how free ingress and expensive egress, closed APIs, complex tariff structures and deep service interconnection create path dependence from the first moment of choice — the initial procurement decision is effectively the permanent one unless exit is designed in from the start. Clingendael’s framing is the right strategic register: Europe is living its “5G moment” on cloud — the same slow realisation it went through with Huawei, one layer up, with the dependency this time running through allied rather than adversarial firms, which changes the threat model but not the structure. Demand for something better is real — Capgemini’s survey of a thousand organisations found sovereignty concerns now shaping cloud procurement across Europe (Capgemini, The Journey to Cloud Sovereignty, 2022) — but supply has lagged: Gaia-X chose to build a federation and trust framework rather than a European hyperscaler (Gaia-X, Architecture Document, 2022), and a decade of EU digital-sovereignty initiatives has produced, in the words of the Commission’s own commissioned stock-take, a “convoluted journey” (IDC, Digital Sovereignty in the EU, 2025).
AI compute sharpens all of it. Compute is the most governable input to AI — physical, detectable, concentrated in its supply chain — which is precisely why it is becoming an instrument of policy between states (arXiv, Computing Power and the Governance of AI, 2024). A state with no public AI compute has outsourced not just a workload but the option to have an AI strategy at all. The pattern responses exist and are documented: the OECD’s blueprint tells governments to plan national compute the way they plan energy — measuring capacity, effectiveness and resilience, not just buying GPUs (OECD, Blueprint for Building National Compute Capacity for AI, 2023); the UK ran a national needs assessment and stood up the AI Research Resource on the back of it (UK Government, Independent Review of the Future of Compute, 2023); the US designed the NAIRR to democratise access to research compute as public infrastructure (NSF, NAIRR Task Force Final Report, 2023); and EuroHPC is the working proof that mid-sized states can co-own big iron none could afford alone, now extending into AI factories and quantum machines (EuroHPC JU, Multi-Annual Strategic Programme 2021–2027).
The own/share/rent decision. Own three things outright: a protected enclave for the workloads whose exposure to foreign jurisdiction is intolerable — registers, security, justice, crisis systems; the continuity copies of the state’s critical systems, held under the state’s own legal control (the data embassy pattern, of which more in Layer 2); and the contractual and technical machinery of exit — portability tested annually, egress priced into every contract, no critical workload without a rehearsed landing zone elsewhere. Share AI compute at European level through EuroHPC and its AI factories, buying national slices of shared capacity. Rent the hyperscale bulk — it is genuinely better run than anything a ministry will build — but rent it knowingly: classified workload tiers, jurisdiction mapped per workload, and the ACM’s lock-in mechanics treated as a checklist of what to contract away. The unglamorous prerequisite for all of it is data classification: Clingendael identifies proper classification of government data — knowing which workloads are sovereignty-critical and which are commodity — as one of the two capabilities European governments most conspicuously lack, alongside the talent to manage hybrid estates (Clingendael, 2024). A state that cannot classify its workloads cannot tier its cloud, and defaults to treating everything as commodity — which is how registers end up next to newsletters. The test of cloud sovereignty is not where the servers sit; it is whether the state can move, and has proven it can.
What to watch. The operator-nationality share of new national data centre capacity (the How-Sovereign metric, tracked annually); egress fees and portability obligations as the Data Act bites; the ratio of state workloads with a tested exit plan to those without — a number almost no government currently knows about itself; EuroHPC AI-factory capacity actually allocated to your national researchers and firms.
3. Layer 2 — data: the registers are the crown jewels
What it is. The state’s knowledge of its own nation: the base registers — population, property, business, address, vehicle — that every other function reads from; the statistical system; the geospatial and infrastructure maps; health, education and welfare records; and the economic micro-data that reveals dependencies before they bite. If Layer 1 is where the state runs, Layer 2 is what the state is, informationally. A state that cannot enumerate its people, firms and land cannot tax, mobilise, respond, or rebuild — whatever else it still controls.
Where the dependency bites — and where the proof case lives. The canonical framework here is the World Bank’s: data as a national asset governed under a “social contract for data”, with the infrastructure, institutions and safeguards that make reuse possible without destroying trust (World Bank, World Development Report 2021: Data for Better Lives, 2021). The OECD maps the same terrain across member states — openness against control, and the governance machinery that lets a state have both (OECD, Going Digital to Advance Data Governance, 2022). National strategies show what taking the layer seriously looks like: the UK’s five-mission strategy treats government’s own data use as sovereign capability, not administrative plumbing (UK Government, National Data Strategy, 2020); Germany’s Datenstrategie runs to some 240 measures, from data trusteeship to state modernisation (German Federal Government, Data Strategy, 2021); the EU is building sectoral data spaces — health, energy, mobility, public administration — as shared European infrastructure with common governance (Council of the EU, Common European Data Spaces, 2022). And because data crosses borders even when law does not, UNCTAD’s mapping of the world’s divergent data-flow regimes is the reminder that this layer is foreign policy as much as domestic administration (UNCTAD, Digital Economy Report 2021).
But the document that should be pinned above every CIO’s desk is two pages long. Estonia — the state that has thought hardest about digital continuity because its history obliges it to — has enumerated precisely ten strategic datasets whose survival constitutes the survival of the state: the population register, the business register, the land and cadastral registers, the identity documents register, the taxable person’s register, the treasury information system, the court e-file, the State Gazette, and the national pension insurance registry. These are continuously replicated to a data embassy in Luxembourg — a Tier 4 data centre that is legally Estonian territory in the relevant senses, fully under Estonian control, with the immunities of a physical embassy, under an agreement signed in 2017 (e-Estonia, Data Embassy Factsheet; European Commission, Estonia Data Embassy Initiative Case EE05). Read that list carefully: it is the revealed-preference answer to this report’s central question. Asked “what must a state actually control?”, the state that has thought longest answered with ten registers — not a fab, not a search engine, not a social network. The registers are the crown jewels; everything else in the stack exists to serve, protect, move and reason over them.
One class of data deserves separate emphasis because almost no state collects it deliberately: economic micro-data — firm-level supply chains, customs flows, payments telemetry. This is the data that would have shown the chip chokepoints before they collapsed German car production to 1975 levels (ECA, 2025), and it is the raw material for the strategic-dependencies mapping the EU now attempts at Union level and RAND has methodised at entity level (RAND, Identifying and Prioritizing Systemically Important Entities, 2023). A state that cannot see which of its firms depend on which foreign inputs is running its economy on the same blind trust it has been running its cloud — and this is the dataset Layer 4’s simulations and early-warning agents will starve without.
The own/share/rent decision. This is the one layer where the answer is nearly absolute: own it. Base registers, the statistical system and the authoritative geospatial map must sit under national legal control without exception — including their backups, which is the data embassy’s real lesson: ownership of the primary copy means little if continuity depends on infrastructure that falls with the territory or sits under foreign law. Share at European level where sharing multiplies value without transferring control — the data spaces, cross-border register interoperability, statistical standards. What may be rented is processing capacity underneath the data, under the Layer 1 rules — never the stewardship, the schema, or the legal custody of the registers themselves. Health and welfare records add the trust constraint: the WDR’s social contract is operational guidance here, because a population that stops trusting the state with its data will stop feeding the registers, and the asset degrades from within.
What to watch. Whether your state can produce its own ten-dataset list — and how long the argument over its contents takes, which measures how little the question has been asked; the existence, location and legal instrument of continuity copies for each register on the list; time-to-restore, exercised rather than asserted; administrative-data pipelines replacing surveys in the statistical system — the difference between quarterly hindsight and operational awareness; and the share of critical registers whose processing sits with operators under foreign jurisdiction, which quietly re-imports the Layer 1 problem into the layer the state believed it owned.
4. Layer 3 — platforms: identity, payments, exchange, and the state’s front door
What it is. The digital public infrastructure through which citizens and firms actually meet the state: a guaranteed way for every person and business to authenticate and sign; payment rails; a secure data-exchange bus connecting registers and agencies; the trusted channels through which the state speaks and delivers; and the open-source capacity to read, fork and maintain the software all of it runs on. Layer 2 is what the state knows; Layer 3 is how that knowledge becomes services, and how the state remains present in its citizens’ lives when everything else is mediated by platforms it does not control.
Where the dependency bites. The platform layer is where the sharpest sovereignty question hides in the friendliest packaging: if identity, payments and communication between citizen and state run through private foreign platforms, the state has outsourced the relationship itself — and with it the ability to reach every citizen in a crisis, to guarantee a firm can transact, to know its channels will exist next year on the same terms. The global policy consensus has now converged on the answer: identity, payments and data exchange are the three building blocks a state must guarantee as public infrastructure — the G20-endorsed DPI framing (UNDP, Accelerating the SDGs Through Digital Public Infrastructure, 2023), with Carnegie’s thesis making the design point that states must own the rails and the rules while markets build on top (Carnegie Endowment, The Future of Digital Public Infrastructure). The proof cases are no longer theoretical. India built identity and payments as public rails — Aadhaar and UPI — and the BIS’s analysis of the India Stack is the standard reference for what sovereign digital financial infrastructure at population scale looks like (BIS, Design of Digital Financial Infrastructure: Lessons from India, 2019). Estonia built the exchange layer: X-Road, the secure data-exchange bus that turns a pile of siloed registers into a networked state, now exported worldwide (e-Governance Academy, X-Road Secure Data Exchange Concept, 2022; e-Governance Academy, e-Estonia: e-Governance in Practice). Singapore built the delivery machine — strategic national projects run by a dedicated engineering agency rather than procured wholesale (Smart Nation Singapore, The Way Forward, 2018). Europe is now building identity at continental scale through the EUDI wallet’s common architecture (European Commission, EUDI Wallet Architecture and Reference Framework), on assurance foundations set by NIST’s identity guidelines — the IAL/AAL/FAL framework underpinning government digital identity worldwide (NIST, Digital Identity Guidelines SP 800-63-3) — with the World Bank’s ID4D guide as the institutional playbook (World Bank, ID4D Practitioner’s Guide, 2019) and GovStack packaging the whole pattern as reusable building blocks for any state (ITU, GovStack and Digital Public Infrastructure).
The own/share/rent decision. Own the three rails — identity, the exchange bus, and at least a public option in payments — plus the state’s crisis-grade channel to every citizen. Ownership here means the state guarantees the rail, sets its rules and holds its keys; building and operating can be contracted, but the rail must not be a private product the state merely uses. Share the standards and wallets at EU level — eIDAS and the EUDI wallet are exactly the right altitude, one specification, twenty-seven sovereign implementations. Rent the commodity underneath — app development, hosting under Layer 1 rules — and cultivate the open-source escape hatch deliberately: the capacity to read, fork and maintain critical software is what converts an unexitable vendor lock into a negotiation, and procurement is the lever that builds it. What to watch: EUDI wallet adoption and the share of high-value services accepting it; whether a public instant-payments option exists and merchants actually route through it; the number of registers connected to the exchange bus versus point-to-point integrations; the share of critical government software the state could fork and maintain if it had to.
5. Layer 4 — intelligence and models: the state’s ability to ask “what if?”
What it is. The reasoning layer: access to frontier AI models and sovereign fine-tuned models for the state’s languages, laws and classified domains; simulation and digital twins of the economy, infrastructure and territory; nowcasting and early-warning feeds that shorten the state’s observation loop from quarters to days; and an institutionalised foresight capability wired into budgeting rather than shelved in reports. Layers 0–3 determine whether the state can act; Layer 4 determines whether it acts intelligently — whether it can ask “what happens if?” before reality answers on its own schedule.
Where the dependency bites. This layer inherits every dependency below it and adds one of its own: model dependency. A state whose analytical stack runs on rented frontier models has rented a component of its own judgement — the models’ availability, pricing, refusals and failure modes are all set elsewhere, and the compute-governance literature makes clear that access to AI capability is becoming an explicit instrument of interstate policy, granted and withdrawn like any other strategic export (arXiv, Computing Power and the Governance of AI, 2024). The concentration of what AI Now calls infrastructural power — compute, models, and the platforms in one set of corporate hands — means the state is not one customer among many but a dependent among giants (AI Now Institute, 2023 Landscape: Confronting Tech Power, 2023). The answer is not a national frontier lab — for a mid-sized state that is the fab fallacy one layer up. It is a portfolio: rented frontier access for the general case, sovereign fine-tuned models for the domains where language, law and classification make foreign models unusable, and — the part almost every state still lacks — the simulation and early-warning assets that no vendor sells off the shelf because they must be built on the state’s own Layer 2: a digital twin of the production network fed by firm-level micro-data, grid and epidemic nowcasts fused from the state’s own sensors, scenario machinery connected to the risk register rather than to a shelf.
This is where the agentic engine becomes the design pattern. The functions of Layer 4 are precisely the ones AI agents can now run continuously rather than annually: scanning agents sweeping signals against the risk register; simulation agents keeping the national digital twin warm and running counterfactuals overnight; early-warning agents watching the dependency map — operator nationality, cable repairs, chip inventories, register anomalies — and escalating on threshold; red-team agents attacking the state’s own assumptions; briefing agents compressing all of it into the morning’s decision documents. Humans own judgement and accountability; the agents own the cadence. A foresight function staffed only by humans reports quarterly; a foresight function run as an agentic engine reports continuously — and the difference is measured in the length of the state’s observation loop, which is the quantity this whole layer exists to shorten.
The own/share/rent decision. Own the twins, the nowcasts, the early-warning wiring and the foresight institution — they are made of your own data and are worthless rented. Own fine-tuned models for law, administration and the classified domain. Share evaluation infrastructure, safety testing and model-access agreements at EU level, where collective weight buys terms no mid-sized state gets alone. Rent frontier capability — with more than one supplier, and with the fine-tuned sovereign fallback tested against the day rented access is degraded, priced up, or withdrawn. What to watch: the state’s observation loop, function by function — days or quarters; whether a national digital twin of the production network exists and is fed continuously; the share of government AI workloads that would survive the loss of a single model vendor.
6. Layer 5 — operations: cyber defence, crisis machinery, and the standing map
What it is. The layer where sovereignty is exercised rather than possessed: national cyber defence covering the critical sectors; crisis-management systems — a common operating picture, resilient communications, population warning, rehearsed continuity plans; the decision infrastructure of the centre of government; science and innovation planning; and the continuous mapping of the nation’s assets and dependencies. Everything above Layer 5 is inventory; Layer 5 is practice.
Where the evidence points. On cyber defence the doctrine has converged across the Atlantic: the US strategy rebalances responsibility for security away from end users and toward the actors most capable of bearing it, using regulation and market incentives (White House, National Cybersecurity Strategy, 2023), executed by CISA’s plan to harden critical infrastructure sector by sector (CISA, Cybersecurity Strategic Plan FY2024–2026, 2023); the UK runs a whole-of-government hardening programme to 2030 (UK Cabinet Office, Government Cyber Security Strategy 2022–2030); the EU drags every essential and important entity up to a common floor through NIS2 (EPRS, The NIS2 Directive, 2021), with ENISA’s threat landscape naming the actors and techniques the floor is being raised against (ENISA, Threat Landscape 2024) and its Union-wide assessment measuring how unevenly member states are climbing (ENISA, State of Cybersecurity in the Union, 2024). NIST’s CSF 2.0 added a Govern function to the world’s reference framework — the standards body’s way of saying cyber risk is now a board and cabinet matter, not an IT matter (NIST, Cybersecurity Framework 2.0, 2024). And a mid-sized state need not imagine what national capability looks like at its scale: the Czech Republic’s NUKIB strategy is a working model of small-state cyber sovereignty — national CERT coverage, regulated critical sectors, exercised response (NUKIB, National Cyber Security Strategy 2021–2025).
On crisis machinery, three exemplars define the standard. Estonia 2007 is the founding case — the first state-scale cyber campaign, and the origin of the lesson that resilience is an information-warfare posture, not an IT department (CCDCOE, Estonia 2007 Cyber Attacks Analysis, 2008). Ukraine 2022 is the modern proof: pre-scripted legal changes and a wartime migration of state systems to cloud infrastructure outside the country kept the government operating under physical attack — digital continuity as a survival capability, improvised well only because it had been prepared (Atlantic Council, Building the Digital Front Line, 2025). Finland is the peacetime model: comprehensive security as a whole-of-society doctrine, with vital functions assigned, exercised and drilled across government, business and citizens (Finland Security Committee, Security Strategy for Society, 2017).
On the standing map — the function ENSI regards as the quiet core of the layer — the methodological shift is documented in Layer 6’s own sources: from listing assets to mapping functions (CISA’s 55 National Critical Functions, 2019), from protection to resilience (OECD, Good Governance for Critical Infrastructure Resilience, 2019), from static lists to ranked systemic importance (RAND, Identifying and Prioritizing Systemically Important Entities, 2023), all published transparently enough to steer the private owners of the infrastructure (UK Cabinet Office, National Risk Register, 2025). The EU’s CER regime exists precisely because most member states had not done this work: under the old directive just 94 European critical infrastructures were designated across the whole Union — two-thirds of them in three member states, and sixteen member states had designated none at all (EPRS, Improving the Resilience of Critical Entities, 2021). A map that two-thirds empty is not a map; it is an assumption.
The own/share/rent decision. Own all of it — this layer is the definition of the state’s job, and renting incident response, crisis coordination or the national risk map means renting government itself. What can be shared is intelligence and exercises: threat intelligence through ENISA and allied CERTs, crisis exercises with neighbours, mutual-aid response capacity. What can be bought is tooling and surge expertise — under contracts that survive the crisis they will be invoked in, which is exactly the clause worth testing before it is needed. What to watch: exercise cadence — when the state last rehearsed a register restore, a cloud exit, a cable cut, a cell-broadcast to the whole population; NIS2/CER designation coverage against the 94-entity baseline; mean time from national incident to common operating picture, which is the single best proxy for whether Layer 5 exists at all.
7. Layer 6 — people, rules, and trust: the assets that cannot be procured
What it is. The top of the stack is not technology. It is a digitally capable civil service with retained in-house engineering, so the state is a competent buyer and builder rather than a hostage of its integrators; surge-capable reserves of technical talent that can be mobilised in crisis; seats at the tables where the defaults of the digital world are written; legal capacity to act fast under oversight; and the trust of a population that will believe official channels when it matters. Every other layer can, in principle, be bought or federated. This one compounds or decays, and does either slowly.
Where the evidence points. The delivery-capable states are distinguishable by one organisational fact: they kept engineering inside government. Estonia’s digital state was built by a state that could build (e-Governance Academy, e-Estonia: e-Governance in Practice); Singapore’s Smart Nation runs on a government engineering agency executing strategic national projects directly (Smart Nation Singapore, The Way Forward, 2018); and Finland’s comprehensive-security model treats trained people across society — not agencies — as the resilience asset itself (Finland Security Committee, Security Strategy for Society, 2017). Rules are made in rooms, and absence from the rooms is a dependency like any other: the governance of naming, routing and standards is contested terrain where authoritarian states push for a state-controlled internet through the ITU while the multi-stakeholder bodies drift toward politicisation — a state with no standards capacity simply inherits whichever defaults win (SWP, Cracks in the Internet’s Foundation, 2019). And trust is the layer’s load-bearing wall. Global internet freedom has been declining for years as states normalise digital controls (Freedom House, Freedom on the Net 2024) — which sets the trap precisely: a state that defends its information space by closing it destroys the trust the defence was meant to protect, while a state that ignores the information layer entirely finds, as Estonia did in 2007, that trust is exactly what a hostile campaign targets (CCDCOE, Estonia 2007 Cyber Attacks Analysis, 2008). The narrow path — openness plus institutional credibility plus channels the population actually believes in a crisis — must be built in peacetime, because it cannot be improvised under attack.
The own/share/rent decision barely applies — people, standards seats and trust cannot be rented, which is the point. The actionable form: pay the salary premium for a core in-house engineering cadre and treat it as critical infrastructure; build the reserve model before the crisis; fund standards participation as a strategic expense, pooling with EU partners where one delegation can carry twenty-seven states’ interests; and treat every crisis communication as a deposit in, or withdrawal from, the only account that matters in the worst week. What to watch: the ratio of state engineers to contractor engineers on critical systems; national names on standards-body rosters; measured trust in official channels — tracked, like any other strategic stock, before it is needed.
8. The mechanics of the trap — how rented layers become leverage
The seven layers share one failure mode, and it deserves to be understood once, precisely, because it repeats at every altitude of the stack.
Interdependence is weaponised at the hubs. The networks the digital economy runs on — financial messaging, cloud platforms, chip supply chains, cables — are not flat; they have hubs, and whoever controls a hub gains two powers over everyone routed through it: the ability to watch what flows, and the ability to cut adversaries off. That is the weaponized-interdependence thesis, and the sanctions record shows the machinery being used deliberately and repeatedly (CSET, From Cold War Sanctions to Weaponized Interdependence). The strategic consequence inverts the free-trade intuition: integration into someone else’s network is not neutral efficiency — it is exposure whose price is set later, by the hub.
The chokepoints are few and known. For the internet’s own infrastructure they sit in exactly three arenas — the naming system, the routing system, and the submarine cables — each already an active site of geopolitical conflict, with authoritarian states working to relocate authority over them into bodies they can dominate (SWP, Cracks in the Internet’s Foundation, 2019). The cable arena shows how concentrated a “distributed” system really is: upwards of 95% of intercontinental traffic through some 475 cables, with ownership consolidating into the same few platforms that dominate the layers above, and remote management systems adding a new class of single points of failure (Atlantic Council, Cyber Defense Across the Ocean Floor, 2021). Taiwan is the stress case the rest of the world should read as its own future perfect: fifteen cables, documented grey-zone pressure against them, and repair capacity — not cable count — as the binding constraint (Stanford FSI, 2024; DSET, Vulnerabilities at Depth, 2025).
The micro-mechanics are contractual, not dramatic. Most leverage is never exercised as a cut-off; it is exercised as terms. The ACM’s cloud study is the anatomy: free ingress and priced egress, closed APIs, tariff structures too complex to compare, services engineered to interlock — so that the cost of leaving compounds silently while the cost of staying is always, this quarter, smaller (ACM Netherlands, Market Study Cloud Services, 2022). Multiply that by the market structure — two firms at 35–40% each of the layers everything else runs on, 70% across three (ACM, 2022; Clingendael, 2024) — and by the legal reach that follows the operator across borders (arXiv, How Sovereign Is Sovereign Compute, 2025), and the trap needs no villain. Every actor optimises locally; the dependency assembles itself.
And the leverage runs through allies. The uncomfortable core of the European evidence is that the dependency is overwhelmingly on friendly firms under friendly law — nine of the ten largest GDPR fines have landed on American Big Tech (Clingendael, 2024). Alliance lowers the probability that leverage is used; it does not remove the leverage, and the probability is not under your control — which is why the asset map, not the alliance, is the correct planning basis. States that map their dependencies can price them; states that do not will discover them, as the pandemic’s chip shock and the CrowdStrike outage demonstrated, at the moment of maximum cost (ECA, 2025; UK Cabinet Office, 2025).
What to do first — a ranking for a mid-sized European state
For a state of the Czech Republic’s scale — ten million people, an open economy inside the EU, a capable cyber authority already on the field (NUKIB, 2021–2025) — the seven layers resolve into three lists and a sequence.
Own outright — the sovereign minimum. The base registers and the statistical system, with continuity copies under national legal control in the data-embassy pattern — a state that cannot lose its registers cannot lose its statehood to a server failure. Digital identity, the data-exchange bus, and a crisis-grade channel to every citizen. The national CERT/SOC, the crisis common operating picture, and the standing asset-and-dependency map, run as a continuous function on the NCF/NRR pattern — 55 functions and 89 risks are not American and British numbers; they are proof the enumeration can be done and published. A core in-house engineering cadre. Internet exchange points on national territory and a tested national PQC migration plan. None of this requires frontier technology; all of it requires the decision that it will not be rented.
Federate at EU level — the shared tier. AI compute through EuroHPC and its AI factories; chips through the Chips Act read at the ECA’s realistic altitude — niches, stockpiles and mapped dependencies, not fabs; space through Galileo, Copernicus and IRIS²; identity standards through eIDAS/EUDI; data spaces; standards-body presence pooled with like-minded delegations. The federated tier is not second-best sovereignty — it is the only arithmetic under which mid-sized states get these layers at all.
Rent with a tested exit — the eyes-open tier. Hyperscale cloud for everything outside the protected enclave — under contracts that price egress, mandate portability, and are exercised annually with an actual workload actually moved. Frontier AI via more than one vendor, with sovereign fine-tuned fallbacks for law, administration and the classified domain. Commodity software everywhere, with the open-source fork capacity that turns lock-in into negotiation.
The sequence is a year’s work. First, the inventory: one register of digital dependencies — every critical workload, its operator, its jurisdiction, its exit plan or absence of one — built the way the UK builds its risk register and maintained by a standing cell, not a one-off consultancy. Instrument it with the agentic engine: scanning agents watching the dependency map and the world’s disclosure feeds, early-warning agents escalating on threshold, red-team agents attacking the state’s own continuity assumptions, briefing agents putting one page in front of the cabinet each week — humans owning every judgement, agents owning the cadence no human staffing level can sustain. Second, the ten-dataset decision: name the registers whose survival constitutes the state’s survival, and stand up the continuity copies — Estonia has published the template; copying it is a legal agreement and a data centre away. Third, the first full exercise: restore a register, exit a cloud, lose a cable, brief the public — and let the failures write year two’s budget.
The option-value argument closes where the stack began. A state cannot know which layer will be stressed first — a cable, a vendor, a fab, an update, a campaign against trust itself. What it can know is its own map: what it owns, what it shares, what it rents, and what happens next when any rented layer is withdrawn. Sovereignty in the digital age is exactly that knowledge, held current, exercised annually, and priced into every procurement — a capability, not a report. A state sovereign in this sense can lose systems and still govern. A state that has rented all seven layers without noticing can be switched off — politely, contractually, and completely — and the whole purpose of the map is to make sure that sentence is never discovered to be a description.




