All articles

Press · 12.08.2026 · Max Buchan

The Challenge of Digital Sovereignty

Optionality and control determine whether an organisation truly commands its own infrastructure.

The Challenge of Digital Sovereignty

This letter first appeared in SoTA Letters on 12 August 2026.

Dear SoTA,

Sovereignty is optionality and control. It’s about being able to secure your data, your intellectual property, your ideas and even state secrets from third parties.

When I started Valarian, digital sovereignty was something of a niche concern. That is no longer true. The geopolitical environment has fundamentally changed in the last few years - sovereignty has shifted from a “nice to have” to a necessity. That’s true for national governments, right down to organisations of any size. It’s also true that different customers define sovereignty differently. In Germany, it might come down to geolocating data in the region, whereas for our American customers, sovereignty means third party frontier model labs can’t train on their IP.

There have been many moments that have contributed to the necessity of digital sovereignty, but I think the most immediate and dramatic is the overnight restriction of Anthropic’s Fable 5 model for all non-US citizens. The result was for Anthropic to remove the model for everyone, but the legal compulsion was restricted only for those outside of US citizenship. If government departments, or core aspects of the state, were running on a model like this, and restrictions were passed in the same way as they already have been once before - we could see entire departments grind to a halt, or key defence capability lost overnight.

I am not making a judgement here on whether the restriction was the right thing to do, rather that we live in a world in which a non-US citizen restriction on frontier technology was implemented with immediate effect. There are no two ways about it: digital sovereignty is a clear necessity if we want reliable digital infrastructure.

The 6 Tests of Digital Sovereignty

For an organisation handling sensitive data – a government department, a provider of financial services, a defence supplier, a hospital trust, and so on – six tests make digital sovereignty concrete. Fail any of them and you are not sovereign, whatever your contracts say.

1. Model independence. Your data should never be used to train someone else’s system, and you must be able to swap models without re-architecting everything built on top of them. Fable 5’s shutdown proved the last point. An organisation wired directly into a single closed model was, for eighteen days, wired into nothing. An organisation whose systems treat the model as a replaceable component could have moved to an open-weight or domestic alternative that afternoon. Independence is not refusing to use the best foreign models. It is being structurally indifferent to losing any one of them.

2. Extraterritorial jurisdiction and strategic autonomy.Key infrastructure cannot be tied to a foreign jurisdiction. If you have an infrastructure provider that is based elsewhere (or their parent company), foreign governments can compel access to the software code bases, proprietary updates, and administrative privileges on which your intelligence runs. This is true despite any local hosting commitments or UK-based data processing agreements.

Additionally, platforms risk data exfiltration or unauthorised exposure when they rely on closed, proprietary algorithms, or remote update and maintenance pipelines that are not contained. With technical non-containment these risks are baked into a software’s architecture - they aren’t something that can be patched via settings or non-disclosure clauses.

3. Context control.Models, agents and people must only get access to exactly the systems and data their task requires, and nothing more. This is the principle of least privilege, an old discipline made urgent again by agentic AI, because an agent with broad access is a breach that has not happened yet. It comes with a second right: the encryption keys are yours. Not held by the platform on your behalf, not escrowed with the vendor, but yours, so that not even the infrastructure provider can read your content. Access defines who may reach what, custody defines who can see it - sovereignty requires both.

4. Optionality and open access. Customers must be able to export their data and logic in open formats and run them on open-source alternatives, preventing vendor lock-in.

5. Infrastructure independence.The same control and security policies apply across cloud, on-premises, sovereign, and edge environments—allowing the underlying infrastructure to change without compromising trust or creating vendor lock-in.

6. Public trust.This final test is true for any customer, but is especially true when providing a service, platform or deliverable to a public body or the wider state. Widespread public concern regarding the commercial, political, or ethical alignments of suppliers or vendors directly undermines public faith in the institutions that enable modern life or the core protection of the public. This is something that is easy to lose and hard to gain — and it is not something anyone should take for granted. Sovereignty requires consent, and that requires trust - that’s true for the consumer, enterprises, as well as governments.

There can be no substitutes - for sovereign systems these tests are non-negotiable requirements.

Our platform ACRA was built around a simple belief: organisations should never have to surrender control to access the best technology. Wherever their data is hosted, it remains theirs—protected from the provider beneath it and accessible only to the people, models and agents that genuinely need it.

Built in the UK and designed to run across clouds, data centres and edge environments, ACRA gives organisations the freedom to change providers, models and applications as their needs evolve. Technology can move forward without control slipping away. Sovereignty no longer comes at the expense of capability.

Meeting the Challenge

Sovereignty is a defining issue of the next technological leap. The world is rapidly changing and Britain must change with it. Sovereignty must become the expectation — optionality and control must be the default. Without it, we cannot move with the confidence and the speed required to keep ourselves at the forefront. This is true for businesses as well as for the most central, significant parts of our state.

To control our future we must have the sovereign technologies with which to do it.

Yours,

Max Buchan

Founder & CEO, Valarian

Read it on SoTA Letters

Deploy infrastructure
you control.

Company

About Careers

Resources

Blog Contact

Compliance

Privacy
Established 2020 · London

Control infrastructure for high-consequence systems.
© 2026 Valarian · London

Made in the UK