# Executive Summary

Digital sovereignty is the ability of an organization, or a country, to run its technology on infrastructure, data, and people it controls, and to keep running if a supplier or a foreign government cuts it off. No organization achieves that end to end: chips designed in the United States are made in Taiwan, and US cloud providers still run most of Europe's workloads. The word covers several things at once: where data sits and whose law reaches it; whether the business keeps running, under its own control, if a supplier or government cuts off software it depends on; and where the AI it uses comes from and where it runs. Organizations weigh these three differently by region and by industry. Most have already worked out where their data sits; what they are working on now is keeping the business running under their own control, and controlling the AI they use.

Sovereignty is no longer a question of intent. It is a question of operational readiness. Organizations are funding programmes, assigning ownership, and tightening governance, yet few can prove that they could keep critical services running if a cloud provider, software supplier, or geopolitical event disrupted access. The gap between commitment and capability is now the central problem in digital sovereignty.

At the same time, production workloads are consolidating onto US-headquartered hyperscalers: the only environment expected to gain share over the next decade. That concentration does not make sovereignty less relevant. It makes operational readiness more important.

This divide between strategic intent and operational reality is the sovereignty readiness gap. Closing it requires shifting focus from where data resides to whether the enterprise can maintain independent control. True resilience hinges on three capabilities: secondary support sources, enterprise-grade open source, and genuine cross-environment workload portability.

**Respondents that consider digital sovereignty a critical priority:** 66%

**Organizations that have all four of the essential operational sovereignty capabilities:** 2.9%

**Share of production workloads that run on US hyperscalers today:** 17.0%

**Respondents that rate an alternative source of support and maintenance critical:** 64%

**About this study**

Futurum surveyed 1,940 technology and risk decision-makers in 28 countries in July and August 2026, across North America, EMEA, Asia-Pacific, and Latin America, and six industries: financial services, public sector and defense, healthcare and life sciences, telecom and digital infrastructure, manufacturing and energy, and retail and consumer. Global numbers give the four regions equal weight for all analysis, with deeper insights as relevant for regions, industries, and beyond. Futurum also incorporated its proprietary ongoing research findings including forecasts and recurring buyer and decision-maker surveys, and conducted 12 in-depth interviews with CIOs, CTOs, CISOs, and other senior technology executives about sovereignty to incorporate deeper experiences and context into the analysis.

[Learn more →](methodology.html)

**The sovereignty maturity ladder: where organizations stand on sovereignty**
*All respondents*

| Category | All respondents |
|--- |--- |
| Not on our agenda | 4% |
| Exploring — researching requirements | 16% |
| Planning — building strategy or business case | 26% |
| Piloting — sovereign initiatives in flight to test strategy on a small scale | 21% |
| Deploying — launching sovereign initiatives to full organizational scale | 18% |
| Deployed — sovereignty is embedded in operations | 15% |

*Source: n=1,940 respondents, normalized by region*

**Where production workloads run, today and in three, five, and ten years**
*All respondents*

| Category | US-headquartered hyperscaler cloud | Sovereign / in-country hyperscaler offerings | Regional or local cloud providers | Private cloud | On-premises infrastructure | Managed hosting or colocation |
|--- |--- |--- |--- |--- |--- |--- |
| Today | 17% | 16% | 17% | 18% | 17% | 16% |
| In 3 years | 23% | 15% | 15% | 16% | 17% | 15% |
| In 5 years | 25% | 16% | 15% | 15% | 16% | 14% |
| In 10 years | 27% | 16% | 15% | 14% | 15% | 13% |

*Source: n=1,940 respondents, normalized by region*

## Sovereignty Is a Funded Priority Stalled in Planning

Digital sovereignty now commands dedicated budget and executive governance, yet only one in seven organizations has progressed past planning into daily operations. Risk mitigation drives the investment case: operational resilience, regulatory compliance, and data control consistently win internal funding over growth-oriented outcomes. Furthermore, strategy ownership is split almost evenly between infrastructure and security leadership. Any program built exclusively for platform engineering teams misses 28.6% of key executive decision-makers.

**Respondents that are likely to make a major sovereignty investment in the next 12 months:** 66.5%

**Organizations that have sovereignty embedded in operations:** 14.7%

**More from the interviews**

> It's hard to make time for a project that brings no direct value and is purely about controlling risk.
> — *CIO, retail organization (EMEA)*

## The Workloads Are Not Leaving

Sovereign and in-country offerings remain broadly flat, while private cloud, on-premises infrastructure, regional providers, and managed hosting all lose share. That does not mean sovereignty has failed. It means organizations are pursuing sovereignty inside the estate they already run, rather than replacing that estate wholesale. They are seeking more control over risk, support, governance, and workload movement while continuing to use hyperscale cloud.

The paradox is that consolidation can make the readiness gap more consequential. Organizations most concerned about dependence on US-headquartered providers still expect US hyperscaler use to grow, and those that say they are bringing work back in-house project the steepest increase in US hyperscaler share. In practice, many buyers are treating contingency as insurance around a concentrated operating model rather than building a genuinely independent alternative.

The ten-year projection reflects the options buyers can see today. Futurum's three- to five-year market outlook is less linear. Regulation is becoming more region-specific and enforceable; sovereign and in-country cloud offerings are becoming more operationally distinct; and local providers and telecom operators are expanding their role in cloud and AI supply. The likely result is a more fragmented set of deployment and supplier options than respondents' long-term forecasts imply. Leaders should therefore treat a ten-year allocation to any provider model as a strategic assumption to test regularly, rather than as a plan that can be set once and left unchanged.

**Share of production workloads that run on US hyperscalers today:** 17.0%

**Respondents that say it is extremely important that sovereignty comes from the vendors they already use:** 41.3%

**More from the interviews**

> We have no concern using U.S. cloud. Our group has bought AI companies in the U.S. But regulations in India mandate that our data reside in our own data centers.
> — *CTO, financial services (Asia-Pacific)*

## Worry Does Not Translate Into the Ability to Act

Nearly nine in ten organizations fear being cut off by a supplier or a government, but the risk named most is being unable to leave, not foreign government access to data. Few hold the full set of capabilities needed to respond, as current strategies prioritize compliance and planning over operational readiness. Moving a critical workload takes most organizations months, and the largest, most exposed enterprises are the least able to do it quickly.

**Respondents that are at least moderately concerned about a supply-chain kill switch:** 87%

**Organizations that could move a critical workload off one cloud within 30 days:** 24%

**More from the interviews**

> The ability for [a country or vendor] to actually… to invoke a kill switch and lock us out of our data is very real.
> — *CDIO, public-sector (EMEA)*

## Readiness Is Bought as Support and Portability

Asked what they need to be ready, buyers rate a second source of support above every other requirement, including data location. Open source underpins most sovereignty strategies but it does not remove the need for vendor support: organizations are highly concerned about unsupported packages and place a premium on a credible alternative source of maintenance. Sovereignty has become decisive in a large share of infrastructure renewals, but buyers who have made it decisive are no more able to move a workload than anyone else, and reliability is what they say makes a vendor sovereignty-ready, ahead of data location.

**Respondents that rate an alternative source of support and maintenance critical:** 64%

**Organizations that give open source a role in their sovereignty strategy:** 87.1%

**More from the interviews**

> Open source is probably more secure than closed source, but support is the issue. I wouldn't switch to an open-source ERP or point-of-sale system without support for critical failures.
> — *CIO, retail organization (EMEA)*

## Sovereign AI Is Where It Gets Concrete

About half of organizations call sovereign-AI capability and independence from a single AI chip vendor critical, and the same readiness gap shows up here, on a faster timeline. Buyers choose AI models by workload rather than by type, and open-weight models they can run themselves outrank proprietary frontier models reached through a vendor's interface. Control decides where sensitive AI workloads run, and what organizations say they prefer and what they deploy are not always the same.

**Respondents that call a sovereign-AI capability critical:** 51.9%

**Respondents that call independence from a single AI accelerator vendor critical:** 49.7%

**More from the interviews**

> We don't factor sovereignty into AI. We use [a leading US AI assistant] and [another leading US AI assistant] because they're better than [a French AI vendor]. We want the best model.
> — *CIO, retail organization (EMEA)*

## Recommendations

Closing the gap starts with testing the exit against a clock, and writing that exit, with a named second source of support, into the contract at the next renewal. From there, organizations should prefer open, commercially supported software wherever being trapped is the risk; build an inventory that reaches the encryption keys and open-source components underneath; assess every supplier, and make the assessment include a way out; settle who owns sovereignty and report it to the board as a risk; revisit the decision to consolidate every year; and, especially for large organizations, don't delay while risks are growing.

**Organizations that could move a critical workload off one cloud within 30 days:** 24%

**Organizations that have none of the four essential operational sovereignty capabilities:** 24.6%

**More from the interviews**

> If we cannot deliver the services people depend on, it disrupts their daily lives. In the worst case, it could lead to civil unrest.
> — *CDIO, public-sector (EMEA)*
