Diplomats.Digital
Knowledge Base · Companion Analysis

Digital Sovereignty Under Interdependence

What Foreign Ministries Need to Retain Across Providers, Technology Stacks and Alliances

Companion analysis to Foundational Guide IX:Building Sovereign Diplomatic Capabilities

Diplomats.Digital Knowledge Base·Published 18 September 2026·Last updated 19 September 2026·16 min read
Abstract layered dependency field showing multiple upper pathways converging into shared deeper substrates while independent routes remain available at the outer edges.
Executive Brief

A practical orientation for ministries governing digital capability across technological interdependence

How to use this analysis — read this companion piece alongside Building Sovereign Diplomatic Capabilities to examine where institutional dependencies sit, how they accumulate across technology layers, and whether the ministry retains credible options when providers, infrastructures or strategic relationships change.

Executive Summary

Foreign ministries operate through technology environments that are inherently interdependent. Cloud infrastructure, compute, AI models, identity systems, software, expertise, standards and international partnerships frequently extend beyond direct institutional control.

This analysis examines what digital sovereignty requires within that reality. It distinguishes between the type of dependency — vendor, workflow or model — and the level at which dependency sits: provider, technology stack, ecosystem, or strategic partnership or alliance.

The distinction matters because apparent diversification can conceal deeper concentration. Several providers may depend on the same infrastructure, standards, models, expertise or jurisdiction. A ministry can therefore have multiple suppliers while retaining relatively few genuinely independent paths to continuity.

For foreign ministries, digital sovereignty increasingly depends on understanding these deeper dependencies well enough to govern them, preserve meaningful institutional authority and retain realistic options when circumstances change.

Why This Matters
  • International technology cooperation can expand sovereign capability, but it can also create dependencies that become difficult to change over time.
  • Provider diversification does not necessarily produce dependency diversification when apparently separate services rely on the same underlying technology stack or ecosystem.
  • Technology dependencies can acquire foreign-policy significance when access is shaped by jurisdiction, export controls, sanctions, standards or interstate relationships.
  • Exit capacity becomes more difficult as dependency moves from an individual provider into infrastructure, ecosystems and strategic technology relationships.
  • Foreign ministries need visibility across both headquarters and missions because dependency patterns can differ significantly across jurisdictions and operating environments.
Audience

MoFA leadership, secretaries-general, CIOs and CDOs, diplomatic technology teams, AI governance leads, cybersecurity and information-security leaders, procurement teams, legal advisers, policy-planning units, economic and technology diplomacy teams, embassy leadership, and institutional reform teams.

Core Strategic Question

Where does the ministry’s technological dependency actually sit, what authority does it retain within it, and how realistically could it change course if circumstances required it?

What reading this helps you do

  • Distinguish provider diversification from genuine dependency diversification.
  • Identify dependencies that sit deeper in technology stacks, ecosystems and strategic partnerships.
  • Assess whether apparently separate capability paths converge on common infrastructure, standards, models, expertise or jurisdictions.
  • Examine exit capacity at the level where dependency actually exists.
  • Connect technology architecture and procurement choices with their longer-term institutional and foreign-policy implications.

Key Insights

01Primary insight

Digital sovereignty under interdependence depends on preserving meaningful institutional choice across the layers where technological dependency actually sits.

  1. 02

    Vendor diversity does not necessarily mean dependency diversity. Several providers may rely on the same cloud, compute, models, identity systems, standards or technical ecosystem.

  2. 03

    Dependency becomes harder to change as it moves deeper into the technology environment. Provider-level exit may be possible while stack- or ecosystem-level exit remains operationally difficult.

  3. 04

    Trusted international cooperation can strengthen sovereign capability. Its long-term value depends on whether the resulting dependencies remain visible, governable and realistically changeable.

  4. 05

    Some technology dependencies eventually become foreign-policy dependencies. Access to infrastructure, standards and capability can be affected by jurisdiction, export controls, sanctions and changing strategic relationships.

Full Analysis

Digital sovereignty is often discussed through questions of ownership and location: where infrastructure sits, who controls the cloud, where data is stored, whether domestic compute exists, or whether national institutions rely on foreign technology providers.

These questions still matter, but they no longer capture the full problem.

Modern digital capability is built through extensive interdependence. Artificial intelligence depends on compute, energy, cloud infrastructure, models, software, connectivity, research networks, technical expertise, standards and global supply chains. The degree of concentration varies across these layers, but few states — and even fewer individual public institutions — can reproduce all of them internally.

Recent policy and research increasingly reflect this reality. Brookings has proposed managed interdependence as a practical approach to AI sovereignty, based on partnerships and strategic management of dependencies across the AI stack. The World Economic Forum has similarly used strategic interdependence to describe pathways that combine national capability with international partnerships. More recently, Carnegie has argued for AI sovereignty through agency, interoperability and openness, describing sovereignty in terms of the capacity to organise and govern strategic interdependence.

Academic work is also moving beyond narrow understandings of sovereignty based exclusively on control of infrastructure. Recent research in Business & Information Systems Engineering defines digital sovereignty around legitimate authority over the digital domain while recognising the role of interdependent actors, infrastructures and sociotechnical practices.

For foreign ministries, this creates a specific institutional problem.

A ministry operates through headquarters, missions abroad, national government infrastructure, commercial providers, foreign jurisdictions, international organisations and increasingly AI-enabled services. Its digital environment is inherently distributed.

Under these conditions, sovereignty rests increasingly on the ability to preserve meaningful institutional choice while operating through unavoidable dependencies.

The practical concern is therefore how those dependencies are structured, understood and governed over time.

Interdependence and institutional choice

Across advanced digital and AI systems, complete technological self-sufficiency is unrealistic for most states.

AI value chains are highly specialised and capital-intensive. Compute may come from one jurisdiction, cloud infrastructure from another, models from several providers, technical support from private companies, open-source components from distributed communities, and standards from international technical processes.

The resulting dependencies do not carry the same implications.

Some forms of interdependence can expand capability, provide access to expertise and infrastructure, improve interoperability or distribute risk. Others can gradually narrow the alternatives available to an institution, particularly when technologies become deeply embedded in critical workflows.

What matters is whether interdependence leaves the institution with meaningful choices over time, or gradually narrows them.

This distinction is important because formal ownership alone provides an incomplete picture. A government may operate domestic infrastructure while remaining highly dependent on external software, proprietary architectures, specialist expertise or models that are difficult to replace. Another government may rely heavily on external providers while retaining strong contractual rights, interoperable architecture, portable data, internal technical competence and credible alternatives.

Who provides the technology is therefore only part of the picture. The more consequential issue is what happens to institutional choice once that technology becomes embedded in everyday operations.

Two developments illustrate different sides of the problem

Canada and Germany provide one useful example.

In September 2026, the first co-chairs' meeting of the Sovereign Technology Alliance marked a step toward operationalising an initiative through which Canada, Germany and other prospective partners intend to strengthen sovereign AI capabilities. The two governments describe the Alliance as a platform for cooperation with trusted partners and for building a more diverse AI ecosystem while reducing strategic technological dependencies.

The initiative reflects a broader approach to sovereignty through trusted cooperation. Shared research, infrastructure, technical expertise and market access can expand the range of capabilities available to participating states. Canada and Germany are also developing more specific forms of cooperation, including planned investment in LawZero's safe-by-design AI research, illustrating how shared technological capability can be pursued alongside national and European sovereignty objectives.

Egypt provides a different perspective.

A recent Carnegie analysis examines competition between Chinese- and US-linked AI infrastructure proposals in Egypt. Huawei had proposed supplying advanced AI chips and data-centre infrastructure, while Egypt subsequently announced plans for a large-scale AI data centre using Nvidia technology. Carnegie argues that the significance extends well beyond the initial hardware decision because chips, software, cloud infrastructure, technical expertise, developer ecosystems and standards can reinforce one another. Once substantial capability develops around one architecture, moving to another can become expensive and technically difficult.

Canada–Germany and Egypt represent very different circumstances, yet both show how technology relationships can expand or constrain the choices available to a state over time.

Interdependence can strengthen sovereign capability when it creates credible options, distributes risk and expands access to capability. Its value depends on whether the relationships involved remain visible, governable and realistically changeable as conditions evolve.

Dependency has a type — and a level

Diplomats.Digital's Building Sovereign Diplomatic Capabilities guide currently distinguishes three forms of institutional reliance: vendor dependency, where a critical capability becomes difficult to separate from one provider; workflow dependency, where institutional processes become shaped around particular tools; and model dependency, where AI systems become operationally important without sufficient understanding or control of their assumptions, limitations, security posture or behaviour.

Vendor, workflow and model dependency describe the form institutional reliance takes. A fuller assessment also needs to identify the level at which that reliance is concentrated within the wider technology environment.

For analytical purposes, a capability can carry dependencies at four levels: provider, technology stack, ecosystem, and strategic partnership or alliance.

These levels are not a fixed hierarchy. Several can coexist within the same capability. Used alongside the existing dependency categories, they help reveal where apparently separate arrangements converge.

Provider level

The provider is usually the most visible layer.

A ministry may rely on a particular cloud service, collaboration platform, cybersecurity provider, AI model, communications system or managed-service partner.

At this level, resilience depends partly on practical factors such as contractual rights, data portability, audit provisions, documentation, interoperability, migration costs, internal expertise and the availability of credible alternatives.

Provider-level exit capacity is useful, although it can overstate resilience when the underlying technology stack remains unchanged.

Moving from one application to another may therefore change the commercial relationship while leaving deeper dependencies intact.

Technology-stack level

A digital service rarely stands alone.

Behind the product visible to the user may sit cloud infrastructure, compute, identity and authentication services, APIs, databases, foundation models, cybersecurity tools, operating environments, proprietary formats, network infrastructure and other technical dependencies.

Recent Carnegie work on AI sovereignty takes a similar stack-level view, examining dependencies across data, software and models, computational capacity, connectivity, energy, research capacity, cybersecurity and AI safety. Its analysis emphasises the importance of agency and interoperability when states cannot control every technological layer themselves.

For a foreign ministry, changing provider may therefore leave much of the underlying dependency intact.

A new application may still rely on the same cloud provider. Two AI services may ultimately depend on the same compute architecture. Several systems may share a single identity layer or use the same technical standards.

Understanding the stack reveals dependencies that a supplier inventory alone may miss.

Ecosystem level

The next level becomes less visible because apparently independent providers may participate in the same wider technological environment.

They can depend on common compute architectures, cloud infrastructure, foundation models, developer tools, identity systems, marketplaces, proprietary standards or jurisdictional arrangements.

Vendor diversity does not necessarily mean dependency diversity.

A ministry could use three AI providers while all three depend on the same underlying infrastructure.

It could procure multiple applications while data, identity and security remain concentrated in one platform.

It could retain technical portability at application level while facing high switching costs across the infrastructure supporting those applications.

Skills create another layer of concentration. An institution may technically have access to several architectures while its people, documentation and operational processes have developed almost entirely around one ecosystem.

The more useful measure is therefore how many genuinely independent capability paths remain available to the institution.

The objective is sufficient visibility to distinguish real alternatives from apparent ones, without duplicating every system.

Strategic-partnership / alliance level

Some technology relationships extend beyond commercial providers and become connected to interstate cooperation.

Strategic partnerships can offer substantial advantages: shared research, access to compute, technical standards, cybersecurity cooperation, specialist talent, joint infrastructure and greater collective bargaining power.

The Canada–Germany Sovereign Technology Alliance reflects the increasing importance of this model. It explicitly links technological sovereignty with cooperation among trusted partners rather than treating sovereign capability as a purely national undertaking.

These arrangements also create dependencies that may be shaped by political relations, export controls, jurisdiction, standards and future access conditions.

A change in bilateral relations can affect technological cooperation. Export restrictions can alter access to hardware. Regulatory divergence can affect interoperability. Sanctions may disrupt previously stable arrangements. Shared standards may evolve in different directions. Infrastructure that was accessible under one political environment may operate under different conditions several years later.

At this level, digital dependency intersects directly with foreign policy.

Decisions about infrastructure, access and standards can acquire diplomatic consequences when technological capability is tied to interstate relationships.

At that point, technology diplomacy becomes directly relevant to sovereignty.

Why vendor diversity can create an illusion of resilience

Diversification can improve resilience, provided that it reaches the layers where critical dependencies actually sit.

Consider a ministry using several AI providers, two cloud environments, multiple external applications and a range of domestic and international technology partners.

The procurement environment appears diversified.

Yet the AI services may depend on the same compute architecture. Several providers may operate through the same cloud infrastructure. Critical workflows may rely on a single identity system. Internal expertise may be concentrated around one technological ecosystem. Data export may be technically possible while migration remains operationally unrealistic.

The ministry therefore has multiple vendors but limited independent paths to continuity.

A procurement inventory alone will not reveal this concentration of risk. Dependency mapping also needs to show what sits underneath each capability and where apparently separate services converge on common infrastructure, standards, models, jurisdictions or expertise.

That distinction becomes increasingly important as public institutions adopt more AI services.

Adding another provider does not automatically create another independent capability path.

Retained authority under interdependence

Diplomats.Digital uses retained authority to describe the capacity of an institution to preserve meaningful control over the identities, data, workflows, decisions, AI functions, records, knowledge and continuity supporting its work, including where capability is delivered through external or shared environments. The existing Sovereign Diplomatic Capability work examines this through institutional control, traceability, continuity, interoperability and exit capacity.

In an interdependent environment, retained authority becomes the practical means through which sovereignty can still be exercised.

Operating every technological layer internally is neither realistic nor necessary. What matters is whether the ministry retains sufficient visibility and authority over the capabilities on which its work depends.

That includes knowing who can authorise consequential actions, where critical data and knowledge reside, how decisions and system actions can be traced, which deeper dependencies support each capability, whether systems can interoperate, how essential functions continue during disruption, and whether alternative arrangements remain technically and institutionally credible.

External capability can remain compatible with sovereign institutional practice when authority is preserved in proportion to the sensitivity and importance of the function involved.

Institutional risk increases when dependency grows faster than the capacity to understand and govern it.

Exit capacity becomes harder at deeper levels

Exit capacity extends well beyond the contractual ability to terminate a supplier relationship.

The difficulty of exit rises with the depth of dependency.

Moving an application may be manageable. Changing the cloud architecture beneath it is more demanding. Leaving an established AI ecosystem can involve significant technical, financial and organisational costs. Changing a strategic technology alignment may ultimately become a foreign-policy decision.

Time matters as well.

An institution may possess a theoretical alternative that would take several years to implement, require skills it does not possess, or depend on documentation that has not been maintained. Such an alternative may have limited value during an operational disruption.

Exit capacity therefore needs to reflect options the institution can actually execute, rather than contractual or architectural possibilities alone.

One question becomes particularly useful:

At what level can the institution realistically change course?

The answer may differ significantly between the provider, stack, ecosystem and strategic-partnership levels.

Technology diplomacy becomes part of sovereign capability

For foreign ministries, the deeper implication is institutional.

Digital infrastructure is increasingly connected to supply chains, standards, AI ecosystems, cloud providers, export controls, research partnerships and strategic relationships. Technology choices can therefore influence diplomatic options long after the original procurement decision has been made.

Foreign ministries increasingly need enough technical and institutional understanding to recognise when an apparently operational technology decision begins to affect national room for choice.

Procurement, engineering and cybersecurity responsibilities can remain within their respective functions, while the foreign-policy consequences of major technological dependencies need to be visible to the ministry when they matter.

That requires stronger connections between areas that have historically developed separately: diplomacy, procurement, digital policy, cybersecurity, legal expertise, economic diplomacy, AI governance and national security.

Dependency usually accumulates incrementally through procurement decisions, integrations, cloud migrations, new AI services, shared identity systems and international technology partnerships.

Each decision may be reasonable on its own, while their cumulative effect gradually shapes which alternatives remain practical several years later.

For a ministry operating globally, those accumulated dependencies can also vary across missions. Different jurisdictions, providers, local infrastructure and host-country conditions may produce a very different dependency picture outside headquarters.

This is why institutional sovereignty cannot be assessed through headquarters architecture alone.

Questions ministries can use in practice

Several practical questions can help ministries examine interdependence more closely.

Where does the dependency actually sit?
A provider may be visible while the deeper dependency lies in the stack, ecosystem or strategic relationship supporting it.

Are apparently diverse providers genuinely independent?
Shared infrastructure, models, standards, jurisdictions or specialist expertise may create common points of dependency.

Where do dependencies converge?
Institutions need to identify the capabilities that would be affected by disruption at a deeper shared layer.

What authority remains with the ministry?
The answer should cover identity, access, data, consequential AI actions, traceability and operational continuity.

What can realistically be changed?
Technical portability, contractual rights and operational capacity are different things.

How quickly could change happen?
An exit path that cannot be executed within the timeframe of a realistic disruption may provide limited resilience.

Does the institution retain the knowledge required to exercise its options?
Documentation, skills and institutional memory determine whether alternatives can actually be used.

Which dependencies have acquired foreign-policy significance?
Technology access may eventually become sensitive to interstate relations, regulation, sanctions, export controls or standards alignment.

These questions are most useful when they feed into existing governance and procurement processes rather than becoming a separate assessment exercise.

Sovereignty as preserved choice

Recent work on AI and digital sovereignty increasingly focuses on how states can govern interdependence while preserving agency and meaningful choice.

Brookings' managed-interdependence approach focuses on reducing risk across the AI stack through partnerships and diversification. The World Economic Forum's work on strategic interdependence places international cooperation within national AI-capability strategies. Carnegie's recent analysis goes further into operational design, emphasising agency, interoperability and openness as conditions that allow states to maintain meaningful choices in concentrated technology markets.

For foreign ministries, the operational challenge is to understand how those dependencies appear inside real institutional environments.

That requires visibility into both the form of dependency and the level at which it sits.

Provider relationships are one visible layer. The underlying stack may create deeper concentration, multiple vendors may belong to the same technology ecosystem, and international partnerships can introduce dependencies of their own.

Some degree of technological dependency is unavoidable for any globally connected foreign ministry. The institutional issue is whether that dependency is understood well enough to be governed: where it sits, what authority the ministry retains within it, and how realistically the institution could change course if circumstances required it.

Sovereignty under interdependence ultimately rests on preserving meaningful choice: enough institutional authority, knowledge, interoperability and continuity to adapt when providers, technologies or strategic relationships change.

For foreign ministries, that may be one of the clearest practical tests of digital sovereignty: whether today's dependencies still leave the institution able to choose again tomorrow.

SELECTED INSTITUTIONAL AND RESEARCH REFERENCES

Selected Institutional and Research References

A curated set of institutional, academic and policy sources that inform this analysis.

  1. Diplomats.Digital
    Building Sovereign Diplomatic Capabilities: From Vendor Dependency to Institutional Control

    Foundational DD guide on retained authority, dependency types, interoperability, continuity, and exit capacity in foreign-ministry digital environments.

  2. Government of Canada
    First Meeting of the Co-Chairs of the Sovereign Technology Alliance

    Trusted-partner cooperation on sovereign AI capability, ecosystem diversity, and reduction of strategic technological dependencies. (17 September 2026.)

  3. Government of Canada
    Canada and Germany Sign AI Joint Declaration and Launch Sovereign Technology Alliance

    Bilateral AI cooperation linking sovereign capability, trusted technology partnerships, and shared strategic priorities. (14 February 2026.)

  4. Carnegie Endowment for International Peace
    Operationalizing AI Sovereignty Through Agency, Interoperability, and Openness

    AI sovereignty as strategic capacity across the technology stack, with emphasis on agency, interoperability, openness, and governing interdependence. (3 September 2026.)

  5. Carnegie Endowment for International Peace
    On AI, Cairo Plays China and the U.S. Off Against Each Other

    AI infrastructure competition, technology-ecosystem dependency, switching costs, and strategic choice in Egypt. (14 September 2026.)

  6. Brookings Institution
    Is AI Sovereignty Possible? Balancing Autonomy and Interdependence

    Managed interdependence, dependency diversification, and practical limits to full-stack AI self-sufficiency. (17 February 2026.)

  7. Business & Information Systems Engineering
    Digital Sovereignty

    Digital sovereignty as legitimate authority across interdependent actors, infrastructures, and sociotechnical practices. (24 August 2026.)

  8. World Economic Forum / Bain & Company
    Rethinking AI Sovereignty: Pathways to Competitiveness through Strategic Investments

    Strategic interdependence, national AI capability, investment priorities, and international partnerships. (20 January 2026.)

  9. Government of Canada
    Canada and Germany invest in LawZero to build a new approach to safe, sovereign AI

    Safe-by-design AI research, sovereign compute, public investment, and trusted bilateral cooperation. (16 September 2026.)

Private Briefing

For ministries assessing where to begin, Diplomats.Digital offers a confidential Sovereign Diplomatic Capability briefing and a maturity-sensitive Retained Authority assessment. The engagement examines dependency, identity and authority, AI oversight, interoperability, procurement, mission coordination, continuity, and realistic implementation paths around existing national systems.

Developed by Diplomats.Digital as part of its institutional capability research and the DiplomatIQ support ecosystem for ministries of foreign affairs. DiplomatIQ functions as a capability-building layer around existing national arrangements, supporting ministries as they clarify governance, test dependencies, and develop institutionally controlled implementation paths. Learn more about the DiplomatIQ support ecosystem at /diplomatiq.