In 1974, on his first visit to the Northwest Territories, the Canadian political scientist Peter Russell met with Dene leaders. A Dene woman opened the discussion by asking him two questions: “What is sovereignty? And how did the Queen get it over us?”
Years later he described his response.
“For the first question, I had a nice, pat answer based on Bodin, Hobbes, and my understanding of European international law. But I stumbled over the second. The truth of the matter is that I didn’t have a clue how Queen Victoria and her Canadian henchmen had ‘got sovereignty’ over the Dene.” Later, he said he “came to know that the right answer to the Dene woman’s second question was, in a word, ‘trickery.’ Or, to use the more ironic concept I learned from an Australian Aboriginal friend, it was ‘the white man’s legal magic’ that did the trick.”
I came across that story in a speech about Russell and in the opening passages of his book entitled, Sovereignty: The Biography of a Claim. At the time, I was about two thirds of the way through a year of reading and trying to answer some much smaller questions than the Dene.
We’re awash in headlines, social posts, and talk about sovereignty these days in Canada. And fair enough. There’s good reasons to be discussing it. For the past couple of years, I’ve been simultaneously drawn to the topic and confused by it. In particular, I’ve been vexed by the flavour of sovereignty known as digital sovereignty. And of all the sovereignties being discussed, it’s the one that feels most related to the nature of work that I do and therefore, important for me to comprehend.
So given sovereignty’s significant role, one that our collective Canadian well-being (and my personal well being included in that) appears to hinge upon, I did what comes natural to me: I read about it.
I did that in order to improve my understanding of it, such that maybe, just maybe, I too can contribute to achieving better outcomes for Canada and Canadians, as an independent, small business owner who helps government deliver effective services, primarily through digital means.
My reading isn’t done, and generally never is, but I felt like I had learned enough over the past year to share a few ideas and thoughts, ones that I hope you as a reader also implicated in this sovereignty discourse and moment, may find somewhat clarifying. With that clarity, I hope you and I find a way to better act, to make decisions about technology, policy, and services, so we are able to see the dimensions of control, authority, independence, and integrity that our future selves and our future well-being depend upon.
The current chapter of my exploration ends with a formulation. A fill-in-the-blanks sentence that I hope to now use to work out what any given sovereignty claim actually says. Getting there took most of a year. If that sort of thing interests you, this is an attempt at describing that year of reading, and some things that stood out along the way.
April 2025: seeing the sovereign forest for the trees
Not long after the 51st state rhetoric resurfaced in our Canadian political sphere in spring of 2025, I found myself noticing and reading an increasing number of articles about the topic of digital sovereignty. While the topic has been subject to academic debate and writing since the late 1990s, starting with notions of “cyberspace sovereignty,” its salience has certainly increased in the past few years as nation states grapple with their dependencies upon American hyperscalers with global reach, the ever-increasing technological underpinnings of governments’ core capabilities, and the use of technology for disinformation and propaganda by foreign adversaries.
Amongst the many articles that passed through my inbox and feeds, one that caught my attention was Simon Wardley’s three-part essay series in April 2025 (Part 1: Sovereignty and Landscape, Part 2: Societal vs Market benefit, and Part 3: Whose interests are you serving?).
Given Simon’s particular form of value chain mapping, his interest in borders, territories, capabilities, and strategy, he’s well equipped to discuss the topic of sovereignty and digital sovereignty, not to mention his signature style of wry humour makes for the occasional chuckle along the way.
“Most discussions I hear on digital sovereignty normally degenerate into some story about data or ownership of something. It’s the territorial equivalent of saying sovereignty is about trees. What trees? Where? All of them or just our trees? Of course, we define what are ‘our’ trees by looking at the map. The problem with the digital discussion, is we rarely have a map or anything which is functionally useful as one. Of course when I point this out, people normally yell ‘We do have maps.’ Really? Let’s explore that a bit.”
One thing Simon’s mapping method does that’s helpful in thinking about digital sovereignty is to draw a border: to decide, component by component, where you need control and where collaboration or cooperation around a shared standard serves you better. If you can, hold onto that idea, as I’m going to come back to his digital sovereignty prescription at the end of this, which I believe has a special utility for people making decisions about government digital services and investments in technology and the state capacity required to deliver them.
June 2025: Agency or ownership
Not long after Simon’s posts, my colleague and friend David Eaves (UCL) (also a Wardley-mapping enthusiast, it should be noted) published a piece with Public Digital’s Mike Bracken and UCL’s Michelle Wronski about the EU’s International Digital Strategy. Like Simon, they too reach a similar conclusion that defining digital sovereignty as owning every layer of a stack is not a useful frame, for if that approach is pursued fully, it would lead to balkanised systems and retrenchment from global cooperation. Instead, they write, “Sovereignty comes from having agency over policy decisions, not through ownership of every level of technology architecture.” (emphasis mine).
Bracken further elaborated his points about agency in a debate at UCL with Francesca Bria, which can be viewed online. Bria’s main argument is that you are only sovereign if you control the critical layers of the stack while Bracken says you are sovereign if you can set policy, deliver services and switch suppliers, no matter who owns the layers. Bracken’s firm Public Digital refined and further re-iterated the position a bit later in the summer, publishing their view on digital sovereignty.
That is an axis to consider throughout the various ideas surrounding digital sovereignty and its continued debates in Canada and abroad: agency or ownership. Almost everything I read afterwards felt in some ways shaped by the argument about where to land in that debate, or at least to what extent.
The summer reading and thinking through these perspectives was interesting on the one hand and had left me unsatisfied on the other. While our context in Canada shared some aspects of the EU debate, it also has a different historical sovereignty narrative, one that includes the Indigenous people of this land, a broader colonial context (treaties and unceded territories) as well as its own digital sovereignty and related Indigenous data sovereignty discourse. So by the fall I was searching for Canadian ideas to help better understand the wider context of sovereignty and the specifics of our own digital sovereignty questions.
October 2025: sovereignty is a claim
One answer came in the form of a small hardcover book that arrived on my desk in October from University of Toronto Press. It was the late Canadian political scientist Peter Russell’s 2021 publication, Sovereignty: The Biography of a Claim. I had come to encounter Russell’s work through a talk I’d found online, given by Kent McNeil, lawyer and professor emeritus at York’s Osgoode Hall Law School, on the topic of “Indigenous and Crown Sovereignty in Canada.” He opens the speech with Russell’s Dene anecdote I started with.
Russell’s book zoomed me out from the specifics of digital sovereignty questions like who owns the tech stack and whether you should use a standardized data storage layer, to the origins and history of the idea of sovereignty, what it is and how it works, and the many historical instances of the idea, up to our current moment, many of which are grounded in Canadian Indigenous/crown relations. The book covers a lot of ground in its brief 145 pages.
Russell’s big idea, one that I found immediately helpful: sovereignty is a claim.
He writes, “It is a claim made by humans. The effectiveness of the claim depends on how well it is supported by coercive force, the people subject to it, and outside forces. The legitimacy of the claim—whether it is morally right to accept it—depends on the ethical judgment of people. That is why it is important to recognize that sovereignty is a claim that for ethical reasons can be rejected. It is not an incontestable fact. It connotes a relationship, not a thing.”
Russell continues, “A sovereignty claim’s effectiveness has both an internal and an external dimension. The claim requires acceptance through consent or force by people living in the territory of the political unit making the claim; and externally the claim, to be effective, must be recognized by political forces outside the sovereign claimant. A sovereignty claim’s legitimacy also has internal and external dimensions. Peoples over whom sovereignty is claimed may not regard a claim as legitimate if it adversely affects their interests or is contrary to their own norms or laws. And peoples who have had sovereignty imposed on them by force or fraud may not be effective in resisting that imposition; that is the fate of colonized peoples. But their failure to successfully resist the dominating power does not overcome their objection to the legitimacy of that power’s sovereign claim.”
Russell proposes (and even illustrates) a 2x2 to think about the dimensions of the claim: effective and legitimate, internal or external.
The Biography of a Claim
I’ve since come to think of the four quadrants as:
- Consent (internal legitimacy): do the people governed by this accept it as right?
- Compliance (internal effectiveness): does it actually hold inside the territory?
- Standing (external legitimacy): do others accept it as rightful?
- Recognition (external effectiveness): do others act as though it holds?

My affinity towards a good 2x2 is cliche, but I figure given Russell’s reputation and scholarship, this one is probably better than most. After reading the book, I considered which quadrant claims of digital sovereignty tended to land. I couldn’t help but feel that almost everything written about digital sovereignty lives in one quadrant in particular...
November 2025: the federal government enters the chat
Shortly after I had made my way through Russell, Canada’s federal government entered the chat with its policy paper, “Digital Sovereignty: A Framework to improve digital readiness of the Government of Canada.”
“For the GC, digital sovereignty is defined as the ability of the GC to exercise autonomy over its digital infrastructure, data and intellectual property. It is the capacity to operate effectively and make independent decisions about digital assets, regardless of where technologies are developed, hosted, or supported.
Digital sovereignty relies on the GC’s shared ability to govern, access, and secure its digital systems so that programs and services can continue without interruption. It is a collective responsibility across government to keep those systems reliable, resilient, and available. It is impossible for the GC to obtain a state of complete digital sovereignty, known as digital autonomy, due to the absolute interconnected nature of the digital world.”
Perhaps most interesting about this was the acknowledgement and recognition that agency was again more important than ownership, that complete or total digital sovereignty is all but impossible in a networked global context.
Also worth considering: the paper’s emphasis on programs and services continuing without interruption. An important reminder that government’s job is so often first and foremost to keep the lights on, and how both mundane and miraculous our modern digital infrastructure is at times, only noticing it when it ceases to work.
In Russell’s terms, I read the paper as a compliance oriented piece of work. It is mostly about whether the claim holds (effectiveness) inside our own territory (internal), while acknowledging the influence of foreign governments and global technology companies’ role in diminishing that effectiveness.
December 2025: standards as portability
By December, David had a piece published in Tech Policy Press, exploring more ideas around the role of standards and commoditized services as affording portability (and therefore also affording the agency required by nation states to move or migrate if things go pear-shaped). One of the most significant ideas in this piece, especially for governments who might believe they have a role in creating or defining standards, is that “De facto standards almost always beat untested de jure standards.”
His argument uses the example of AWS’s S3 cloud-based object storage service API as the 21st century railway gauge we should all adopt. He’s bullish on this idea and is finding a wide audience for the argument, including NATO (Foreign Policy). How some of this S3 idea might work in practice, if you’re keen on the details, can be found on GitHub as a Request for Comments (RFC).
April 2026: two Canadian contributions bloom
Spring-time yielded two significant Canadian contributions to the digital sovereignty discourse, emerging from the still-frosty side of the country. The first was the Munk School’s report by Sean Mullin and Jaxon Khan, Sovereign by Design: Strategic Options for Canadian AI Sovereignty, dealing with perhaps the most noisy sub-area of digital sovereignty. And the second was a body of reports and a policy instrument / scorecard from Vass Bednar and the Canadian Shield Institute.
These two contributions are helpful in that they provide some tools that help us think with, to ask questions that help lead to decisions, to consider the benefits of policies as well as their vulnerabilities and risks. They attempt to get down to the options and trade offs behind the decisions.
The Canadian Shield Instutite Sovereignty Score
The Canadian Shield Institute provides a scorecard, a series of questions to ask if policy decisions are making us, Canadians, better.
In the first section of questions, the framework looks at the various pressure-points that foreign actors can use to undermine Canada’s ability to assert sovereign governance: supply chain chokepoints; technology platforms that resist government regulation; defence and national security threats; corporate market dominance; extractive foreign investment.
In the second section, the framework looks at whether the policy shapes the Canadian economy in ways that make it more resilient and prosperous for Canadians: Canadian ownership of vital assets; job creation; skills utilization; shared economic prosperity; pro-social economic growth.
“Put simply: We believe Canada will be more sovereign if our policies reduce reliance on unreliable foreign actors and build domestic capacity that allows us to control our own destiny.”
The Canadian Shield scorecard straddles the agency and ownership debate, with questions pointing both ways. A stronger position to govern technology systems, greater competition rather than entrenched concentration, and skill utilisation are all about having options and being able to move off some tech towards more favourable ones (agency). The ownership theme is clearly present in supporting Canadian innovation and in value and intangibles retained by Canadian entities.
Against Russell’s dimensions, almost every one of the ten questions is a claim about compliance (effectiveness). They ask whether the Canadian state can make its decisions stick at home. Only two, shared prosperity and affordability, seem to touch on consent, and none of them seem to address external standing or recognition at all. That is not a criticism of the scorecard. It is an observation about the nature of the Canadian digital sovereignty debate and how external legitimacy may perhaps be perceived by many as a dead-end when it comes to the behaviours of the nation state that supplies much of the stack.
I’ve enjoyed reading the results of the scorecard in action. As a rubric it’s provided some good writing, like the one on the federal government’s investment in Cohere.
Sovereign by Design
Speaking of AI and Canada, that brings us to the Munk School report Sovereign by Design: Strategic Options for Canadian AI Sovereignty written by Sean Mullin and Jaxon Khan. This report has lots of structures, categories, and frameworks. I appreciated the wonkiness. One aspect I valued was how the report does a tidy job of tracing the ideas of sovereignty to digital sovereignty and again to more specifically AI sovereignty.
Amidst the various categorization schema, the authors introduce the concept of the five dimensions of digital sovereignty: jurisdictional, operational, technological, societal, and economic. I think Simon would call these territories in his work, and they have an affinity with PESTEL categories. They also introduce a threat for each dimension, noting that there is something that may undermine your claim.
Considering each through Russell’s work, I believe these dimensions fall across internal effectiveness (jurisdictional, operational, and technological), internal legitimacy (societal), and external effectiveness (economic). Yet again, four of these five dimensions are about the ability to do things and their effects. The agency part of the sovereignty debate seems to be more present, rather than the idea of being the “supreme authority” over some domain and whether anyone (internal or external) believes that to be legitimate. Back to one of David’s turns of phrase, these appear to be de facto claims about what you can do, rather than de jure claims about what you are entitled to.
In their application of these dimensions to AI sovereignty, Mullin and Khan consider the technology stack, the value chain that makes up what we know as AI. While my Wardley-ian informed reading of this would have preferred the stack be reversed and perhaps re-arranged a bit (most visible to least visible), all the right parts are there for analysis purposes.
After a chunk more writing, the authors combine these two structures together (dimensions and layers), viewed through the idea of threats and resulting vulnerabilities to come up with a risk heatmap for each area.
This then becomes the basis of their analytical pivot from so-what to now-what for Canada’s sovereign AI capacity, concluding:
“The previous section assessed Canada’s sovereign AI capacity layer by layer, revealing critical vulnerabilities at the computer hardware and cloud infrastructure layers, moderate concerns at the foundation model and application layers, and relative strength at the physical infrastructure layer. This section translates that vulnerability assessment into actionable strategic options.”
Special shout-out for those who are in the business of developing policy options. This is a well thought-out framework and method to get to some high-level-enough, yet detailed-enough options that are real things people can discuss, debate, and interrogate. While not directly dealing with the risks inherent in the evolution of any given component explicitly (like you would with a Wardley map) there’s quite a bit of detail for each level.
June 2026: start with the threat, not the solution
Threats, risks, and vulnerabilities were clearly on David’s mind as well in the spring. He brought forward the idea of threat modelling to work through ideas about the trade-offs inherent in the specific topic of data localization. Paraphrasing Cedric Price’s famous “technology is the answer, but what was the question?” David digs into when data localization may be appropriate and when it might not by considering threats. His list of threats is useful when considering what’s going to eat your data hosting strategy (and by extension digital sovereignty claim) for lunch. He writes,
“Lawful (or unlawful) access remains a threat. And there are others:
- Access denial: not someone reading your data, but someone simply turning the servers off, or severing connectivity to them, because they can.
- Cyber attack: an actor stealing or ransomwaring your data.
- Data colonialism: an actor exporting data outside your jurisdiction to be exploited by foreign firm(s).
- Lack of capacity: an inability to use or protect your own data.
- Competitiveness: when storing, managing and accessing your data is simply more expensive than in other jurisdictions, leaving you at a competitive disadvantage.
- Act of God: Your ability to access your data (particularly if stored in a single location or region) is at risk from a natural disaster.”
He uses these threats against options to articulate the trade-offs inherent in different data hosting options.
As we like to say around our office, with some options you get some stuff for free and some things you have to pay for. Other options are often the exact inverse of each other in terms of costs and benefits.
Helpfully, David concludes and suggests how this can be yet another pathway into thinking about tangible decisions about parts of the stack implicated in the digital sovereignty domain:
“So what would a more successful strategy for achieving ‘sovereignty’ look like? First and foremost, it means not starting with a solution but with a threat model, and being honest about the tradeoffs in addressing each threat. As we’ve just seen, that exercise rarely lands on a single answer.” (Emphasis again mine.)
August 2026: mapping sovereignty with fifty strangers
My year of sovereignty reading had a happy twist when Simon Wardley announced a research group into the topic of sovereignty at the start of August. I had the good fortune to convene with about 50 other people from around the world to participate in one of his multi-part mapping, discussion and research events.
Across 6 days in late August and early September, we spent our time mapping and debating the idea of sovereignty from a variety of perspectives. While run under Chatham House rules, I can say I did have the opportunity to try and work through Russell’s notions of effectiveness and legitimacy with people from around the world, and I felt both reassured and a tad overwhelmed at times with the vast scope and breadth of the topic.
There were many genres of claims, many objects upon which the claims were based, and many threats against which the claims were set. Simon’s format afforded lots of structured moments of divergence and convergence, bringing together small groups and larger groups to collectively make sense of the topics in a semi-structured and quite emergent fashion.
Even for those die-hard mapping types, it was quite the journey across the 6 workshop sessions, in particular grappling with something as abstract and conceptual as sovereignty. I’ll hold off on delivering the punchline of the research, as Simon will at some point publish the findings about areas to invest. If you’re curious about the overall research group / mass mapping method, Simon, in typical fashion, outlines the whole thing in a blog post.
September 2026: the claim itself
That conveniently led me to one final paper, read just this week after we wrapped up the final Wardley mapping session. While not referencing the work of Russell or others named here, I felt like it managed to confirm what I’d yet been unable to articulate about these various claims of sovereignty I’ve catalogued.
Mauro Santaniello’s article, “Attributes of Digital Sovereignty: A Conceptual Framework,” explores the theory and practice of digital sovereignty claims and in doing so provides a conceptual framework to understand them.
Like Russell, Santaniello takes a constructivist approach, treating digital sovereignty as “a discursive resource that is employed by actors in a context of political struggles over the control of digital networks.” For Santaniello, it’s also a claim, not a thing. That claim is doing political work and is considered an action. When thinking about those actions, five attributes help you understand the claim:
Adversariality: every sovereignty claim is directed against someone, an adversary that makes the claim a political act (think Bednar’s first part of the Canadian Shield score).
Multiversity: the same sovereignty claim can legitimize several policy directions at once, including contradictory ones, because actors switch between meanings to suit the moment.
Latency: sovereignty discourse can lie dormant or be deliberately withheld, appearing where authority is weak and staying unspoken where it is already held.
Instrumentality: a sovereignty claim takes its meaning from the specific policy problem it is attached to, and migrates across arenas as those problems change.
Hypocrisy: sovereignty claims routinely diverge from what is actually implemented, and the discourse survives rather than being discredited by it. What people say and what people do.
There’s lots of utility in this paper, including tons of examples and genres of various digital sovereignty claims being made. Reading it just this week has likely induced some form of recency bias, but I really admired how it seemed to gather up all of the other genres of digital sovereignty and provide additional language and thinking on how they work, beyond the effectiveness and legitimacy lens that I had been carrying around with me.
Some key takeaways included the importance of the role of adversariality (sometimes made explicit, other times more implicit in nation-states’ claims) and the idea that democratic countries and totalitarian regimes often make very similar claims. Perhaps it’s not that surprising how digital sovereignty can play such an important role across very different political and ideological beliefs.
I also felt somewhat despondent when I encountered the passage on the idea of latency:
“‘it is where authority is weak that the sovereignty discourse appears more strongly.’ This perspective helps explain why the U.S. has never fully developed a digital sovereignty discourse; since American companies and the U.S. government already have the capacity to exercise control in the digital sphere, there is little need to explicitly assert digital sovereignty. It could be said that it is the anti-sovereign, rather than the sovereign itself, that generates sovereignty as a discourse. [...] In other words, hegemony is present when sovereignty is unspoken.”
Or indeed, why it is not a coincidence that we are having so many conversations about sovereignty in Canada at the moment and why that discourse feels so urgent.
Where I’ve landed
For now, I have come to agree with the idea that digital sovereignty is a claim (Russell, Santaniello). Those claims can be understood across the ideas of effectiveness and legitimacy, both through an internal and external dimension, contingent upon who’s the subject (states, companies, individuals) and the object (value chain components) of the claim.
I also believe that claims require an effect or an outcome they are seeking. In the digital realm, these outcomes might sound like continuity (keep operating), decisional autonomy (choose without coercion), exit (leave and switch), conditional control (exclude or set terms on others’ access), and development (capture value, build capability).
Those outcomes are often posed against a threat (lawful or unlawful access, access denial, cyber attack, data colonialism, lack of capacity, competitiveness, act of God) and an adversary (another sovereign making other claims; Eaves, Santaniello), which imply some kind of instrument, the means by which you defend against or mitigate the threat (e.g. self-hosted, contracts, regulation, open source, cloud-agnostic architectures, and so on).
In doing so, you have to accept some kind of residual, the idea that your instrument will not cover everything (like the trade-off analysis of data localization) and that there will be costs (20% sovereign cloud premium, less access to frontier AI models).
Trying to give this a user-story, mad-libs type construction, I’ve for now landed on this formulation of a digital sovereignty claim as both a conclusion of my inquiry and as a new starting point.
A [SUBJECT] claims the capacity to [OUTCOME] over [OBJECT] against [THREAT] by means of [INSTRUMENT], accepting [RESIDUAL] and paying [COST].
My attempt at re-assembling this against a claim made by our own federal government via their policy paper, I think you get something much more focused and descriptive:
The Government of Canada as an institution claims the capacity to keep operating and to migrate away over the cloud infrastructure and contracts carrying its own Protected B and below workloads, against access denial, lawful access and lock-in, by means of contractual controls, vendor-neutral formats, open standards and exit planning, accepting that Canadian residency does not defeat foreign jurisdiction and that complete autonomy is impossible, and paying an unstated premium.
The helpful thing about the long version is that the empty slots are where the arguments and debates and deliberation can happen. If you can’t name the threat, you don’t have a claim. If the instrument doesn’t deal with the threat, you don’t have a strategy.
The last two, the acceptance that there’s a lack of coverage somewhere (residual) and there’s costs involved in all of this, I hope are also useful and as they seem frequently unstated.
Kudos to the Canadian policy folks who acknowledged there’s no perfect solution and even framed in this way, we cannot gain complete autonomy. Better to be honest about these things than leave them unspoken, look naive, or worse, be naive.
Who should read what
Clearly, grappling with these concepts and the utility of all of this writing, policy frameworks, theoretical investigations, and ideas will likely vary widely depending on your context. I’ve come to recognize that in my own exploration of the topic. While much of it has made for interesting reading across a year or more of unread PDF’s in my “to read” folder, not all of this has applicability to the types of decisions I’m called upon to make. After all, I’m not about to make any sovereignty claims myself, although through my work with government on digital services and systems, I’m bound to be implicated in them.
If you’re studying the nature of these claims and their ongoing evolution through a more academic lens, reading Santaniello seems like a great recent piece to start with, along with the many citations in that paper. There is no lack of resources available for you across nearly 30 years of scholarship into digital sovereignty.
If you’re working in policy shops in a Canadian government context (federal, provincial, territorial, municipal) and trying to understand how to come up with options, their outcomes, and trade-offs, Mullin and Khan, Eaves, and Bednar show some great structured ways of doing that. These are both theory-informed and deeply pragmatic, rigorous enough to help other decision-makers see evidence of the policy options or recommendations.
If you’re at the intersection of policy, service delivery, and technology in government, and considering how these statements of intent and how these objects work in the practice of procuring and designing and building systems, then I’d bust out my whiteboard or piece of paper and start mapping the objects in question using Simon’s Wardley-mapping techniques.
I said I’d return to his methods at the beginning, and here’s his advice on how to begin to map your digital territory with sovereignty in mind:
- Begin with user needs. Start at the top of your map with the users (citizens, businesses) and their needs rather than with technology components.
- Identify key components. List all components that fulfil those needs, including services, practices, data, and infrastructure.
- Graph the value chain. Position components vertically based on their visibility to users (higher) versus their foundational nature (lower). Draw lines showing which components depend on others.
- Assess evolution and turn the graph into a map. Place each component horizontally based on its evolutionary stage, from novel (genesis) to commodity.
- Apply climatic patterns. Consider how evolution will affect your map over the next 5 to 10 years. There are many climatic patterns but at least start with this one.
- Identify sovereignty concerns. Mark which components embed societal values or strategic interests.
- Draw borders. Based on sovereignty concerns, draw where your borders should be. Where you need control versus where collaboration or even standards make sense.
If you’ve never mapped, there’s plenty of great resources online and some fun talks given by Simon about how he came to map in the first place.
The Dene elder at the start of this article asked Russell two questions. He had a ready-at-hand answer to the first, and no answer at all to the second. That led him to a 40 year journey and writing a book all those years later. A year and a half of reading has given me a reasonable answer to the first question in its digital form. It has not made the second one easier.
How did we get here? How did Canada get to this place of digital sovereignty and our much larger landscape of sovereignty concerns. I don’t think the answer is trickery, this time. Instead, I think the answer is that we bought it (or perhaps better described these days, we rented it).
We did it through one reasonable procurement at a time, each defensible through its own evaluation criteria, each cheaper and faster and better supported than building it ourselves. Nobody was deceived in that process as every one of those decisions was a trade we made. We perhaps did a less good job of documenting what we were trading in return.
I started out intrigued by the debate about agency versus ownership, and I’m no longer totally convinced those are camps you join. In digital sovereignty, they’re just two different types of costs.
Ownership costs capital, it costs capability lag, and it buys less control than it appears to on the surface. If government stands up domestic infrastructure poorly, they’ve shifted their jurisdictional risk into an operational one. If they fund a domestic alternative that underperforms, then government just bought societal sovereignty with economic sovereignty.
Agency has a price too because it’s costs are hidden inside the workforce dealing with all of this plumbing. We design and build systems, we modernize legacy services in government, and none of that work is free. Keeping things portable and having options at certain levels takes discipline and a focus on maintainability, even with commodity layers and standards. In an environment where shipping and launching and delivering things seem to be the priority, there tends to be a lot less focus and investment in ensuring options are kept open for a future that may or may not arrive. It’s hard enough to set aside time to perform basic hygiene in some of these environments, like refactor code bases or perform solid QA.
Like I said before, with some options you get some stuff for free and some things you have to pay for, and other options are often the exact inverse. That’s true at every layer, in every dimension, all the way down.
Which brings me back to Simon’s last step, the one about drawing borders. That step isn’t necessarily a form of analysis or a descriptive act. Rather, it’s a decision about where sovereigns and their delegates are willing to spend, and it can only be made once they’ve been specific about what they are buying, what it won’t cover, and what it might cost elsewhere.
If you’ve made it to the end, thank you. That was a lot of reading about reading.
I said at the outset that my reading isn’t done and generally never is, and that’s still true.
If you’ve got something I’ve missed, or you think I’ve read one of these people uncharitably, or you’re part of a digital decision in government that went well or even badly, I’d like to hear about it: gordonr@oxd.com. That’s the part I can’t get from a reading list.

Further reading
Here’s a list of all sources mentioned throughout the article, in order of appearance:
Simon Wardley, Three-part series, April 2025: “Sovereignty and Landscape,” “Societal vs Market Benefit,” and “Whose Interests Are You Serving?” And his method how to run a mapping research group.
David Eaves, Mike Bracken, and Michelle Wronski, “The Service Gap: Europe’s International Digital Strategy 2025” on the EU's International Digital Strategy. UCL Institute for Innovation and Public Purpose.
Mike Bracken and Francesca Bria, in debate at UCL. Summary and video.
Mike Bracken, “Our view on digital sovereignty.” Public Digital, July 2025.
First Nations Information Governance Centre, “The First Nations Principles of OCAP®.”
Kent McNeil, “Indigenous and Crown Sovereignty in Canada.” Talk. 2019.
Peter H. Russell, Sovereignty: The Biography of a Claim. University of Toronto Press, 2021.
Treasury Board of Canada Secretariat, “Digital Sovereignty: A Framework to improve digital readiness of the Government of Canada,” November 2025.
David Eaves, on standards, commoditized services, and portability. Tech Policy Press, December 2025. With implementation details and the NATO argument covered in Foreign Policy.
Sean Mullin and Jaxon Khan, Sovereign by Design: Strategic Options for Canadian AI Sovereignty. Munk School of Global Affairs and Public Policy, University of Toronto, 2026.
Canadian Shield Institute, The Sovereignty Score methodology and the assessment of the federal investment in Cohere.
David Eaves, “Data Localization is the Answer. What Was the Question?” July 2026.
Mauro Santaniello, “Attributes of Digital Sovereignty: A Conceptual Framework.” Geopolitics 31, no. 2 (2026): 788–809. Open access.