Cooperation Without Dependency

Cooperation Without Dependency

January 6, 2026
Allegory of the 1st partition of Poland. Engraving of European powers dividing Poland, symbolizing loss of national sovereignty.

Allegory of the 1st Partition of Poland

the European powers carving up a nation.

“The greatest danger in times of turbulence is not the turbulence; it is to act with yesterday’s logic.”

— Peter Drucker

The institutional order built after 1945 is fraying. I did not expect to be writing in 2026 about digital infrastructure as a matter of national security. Yet here we are: the critical systems of Western democracies sit concentrated in foreign jurisdictions, vulnerable precisely when stability matters most.

Digital sovereignty has moved swiftly from legal abstraction to practical necessity. States, and the societies they serve, can no longer afford to ignore who controls their infrastructure.

The foundation: data sovereignty

At the core of digital sovereignty is data sovereignty: who can govern, access, and move data, even when the servers are elsewhere. Physical location is only part of the picture. For example, the GDPR’s territorial rules can apply to processing outside the EU when it is connected to an EU establishment or to services offered to, or monitoring of, people in the EU. They do not simply follow the origin of the data or a person’s citizenship.

For decades, this arrangement rested on trust. Governments in Europe, Canada, and elsewhere accepted American technological dominance, assuming transatlantic partnerships would ensure reliability, stability, and legal alignment. The balance held as long as those partnerships remained durable.

How did we get here?

American technological dominance was not accidental. Silicon Valley emerged from decades of U.S. defense spending, public research funding, and a regulatory environment that favored rapid experimentation and massive scale. Over time, U.S. companies came to define global standards: operating systems, cloud infrastructure, productivity software.

The world adopted American technology out of pragmatism. It worked, was cheaper than domestic alternatives, and offered economies of scale impossible to match. Why spend billions recreating AWS when you could simply subscribe?

This made sense as long as Western democracies appeared permanently aligned.

Things fall apart

Those assumptions have weakened. Trade tensions, strained intelligence-sharing arrangements, withdrawal from multilateral frameworks, and rising volatility in U.S. politics and foreign policy have altered the landscape. 2026 began with military action in Venezuela and rhetoric over territorial claims in Greenland. Both show how quickly geopolitical assumptions can shift, even among long-standing partners.

We must build technological infrastructure that can withstand not only technical failure modes, but also rapid geopolitical change.

The vulnerability appears in two forms:

  • Surveillance. Section 702 of the Foreign Intelligence Surveillance Act (FISA) permits targeted collection of foreign intelligence about non-U.S. persons reasonably believed to be outside the U.S., without an individual warrant. The CLOUD Act means U.S. providers can be required through legal process to disclose data they control even when it is stored abroad; conflicts with foreign law can still arise. These authorities complicate the protection of sensitive data held by foreign providers.
  • Access limitations. The United States could compel American technology companies to stop serving specific nations. Gmail inaccessible. AWS shut down. Microsoft 365 suspended. This is not hypothetical: in 2025, the ICC’s Chief Prosecutor reportedly lost access to his Microsoft email after the Trump administration sanctioned the court. Microsoft disputes its role in that decision, but the court has since started moving away from Microsoft software. A decision in Washington could disrupt government operations, healthcare systems, and private-sector activity within hours. Dependence on foreign infrastructure is leverage.

Dependency is not collaboration

Cooperation between democracies remains essential, but dependency is not the same as collaboration. Strategic autonomy requires systems that function even when partners reverse course. Intelligence agencies must operate when diplomatic relations sour. Healthcare must continue when cloud providers receive conflicting directives. Fundamental rights cannot hinge on another nation’s political stability.

Lessons from recent history

COVID-19 exposed what happens when critical resources concentrate in a single jurisdiction. Western nations discovered their medical supply chains depended on Chinese manufacturing. Masks, ventilators, and protective equipment went from abundant to scarce overnight.

Russia’s weaponization of gas dependency revealed the same dynamic: economic interdependence repurposed as political leverage. Pipelines that once symbolized shared prosperity became instruments of coercion.

More recently, rumors that American military aircraft might contain remote “killswitches” prompted European governments to reconsider procurement plans. The rumors are almost certainly false, but plausibility alone was enough to raise strategic concern.

Digital infrastructure follows the same pattern. Amazon, Microsoft, and Google control roughly 70% of the European cloud market, while European providers account for just 15%. Healthcare systems run on AWS, intelligence workflows on Microsoft infrastructure, government services on Google Cloud. All of it exposed to surveillance and access denial.

The cost of inaction

Supply chains for N95 masks can be rebuilt in months. Energy suppliers can be diversified in years. Military procurement can redirect over a decade. Digital infrastructure is different. It is deeply layered, slow to replace, and harder to substitute with each passing year.

Legal frameworks help, but cannot substitute for direct control. The GDPR can apply beyond the EU under its territorial rules, strengthening privacy protections. The collapse of Privacy Shield reinforced those protections, but revealed a different reality: when critical systems sit outside domestic jurisdiction, legal safeguards cannot guarantee operational continuity.

Maintaining cooperation while preparing

Europe’s sovereign cloud initiatives, Gaia-X and various national projects, have to coordinate 27 member states with different priorities while staying cost-competitive. Canada faces different constraints: trade agreements that limit its ability to require data to be stored in the country, difficulty retaining skilled immigrants, and deep economic integration with the U.S.

The core problem is timing. Building resilient infrastructure requires sustained multi-year investment while global competitors offer immediate, cheaper solutions. The cost of sovereignty shows up now. The cost of dependency stays theoretical until the day it doesn’t. Some countries, especially in Europe, are beginning to wake up to this realization, but they have a long way to go.

Designing for continuity

The age of naive optimism is over. Democratic nations must prepare for scenarios previously unthinkable: alliances fracturing, partners becoming unreliable, frameworks collapsing. Essential functions must remain operational even when cooperation falters.

For those of us in tech, the message is clear: build systems that respect sovereignty without sacrificing interoperability. Open standards, federated systems (many independent providers that can talk to each other), encryption, and the ability to take your data elsewhere: these are the foundations of infrastructure that can survive a shift in political alignment.

Related: Escaping the internet’s walled gardens