When Steven J. Vaughan-Nichols writes about open source, I pay attention. Steven is a friend, one of the technology journalists I have respected for years and a regular contributor to Techstrong. He has been warning about proprietary lock-in and defending open source since long before politicians discovered the phrase “digital sovereignty.”

That is why I read his recent Register column, “Digital Sovereignty Is Real in Europe. The UK? Not So Much,” with great interest. Steven has the central issue right. Governments cannot credibly claim to be sovereign when a foreign government or technology provider can interrupt essential services, change the rules under which they operate or use access to technology as geopolitical leverage. Europe has awakened to that risk, while the United Kingdom remains deeply dependent on American technology companies.

Where I part company with Steven is not over the threat. It is over where the next threat is taking shape.

Much of his column’s practical discussion returns to Microsoft, Windows, SharePoint, Office and the open source alternatives that could replace them. The German state of Mecklenburg-Vorpommern is replacing SharePoint with Nextcloud and OpenProject. Ireland halted a potentially enormous Microsoft procurement while critics asked why LibreOffice, Linux, Thunderbird and other alternatives had not been considered.

Those may be perfectly sensible decisions. Governments should examine whether proprietary software has become too deeply embedded and whether open source can provide greater control and negotiating leverage. But replacing Microsoft Office is not the same as achieving digital sovereignty. A government could move every employee to Linux and LibreOffice while remaining entirely dependent on American hyperscalers, American frontier-model companies, NVIDIA’s accelerator ecosystem and foreign-controlled AI infrastructure. It could win the battle over yesterday’s desktop while losing the war over tomorrow’s intelligence.

Steven is fighting the right war. I am just not sure he has followed the battlefield far enough from where it used to be.

Sovereignty Has Moved Up and Down the Stack

Microsoft became indispensable by controlling the operating system and productivity layers. That gave it enormous influence over how organizations purchased software and performed work. But the center of technological power is now shifting both below and above those layers.

Below them sit the data centers, electricity, water, networks, storage systems, semiconductors, accelerators, interconnects and cloud platforms required to run the digital economy. Above them sit the AI models, agents and interfaces through which people and institutions will increasingly obtain information and make decisions. Digital sovereignty must now encompass that entire intelligence stack.

The central question is no longer simply whether the source code is open or whether the servers are physically located within a country’s borders. The more important question is who possesses the authority and practical ability to keep the system operating, examine it, change it, move away from it or prevent someone else from switching it off.

AI models create a much deeper dependency than desktop software. Windows helped determine how work was performed. AI models will increasingly influence what workers, companies and governments know, recommend, decide and do.

The company controlling a model can change its behavior, pricing, retention policies, safety restrictions and permitted uses. It can retire the model, replace it with another or restrict access in a particular market. Its home government can impose export controls or other requirements on the provider. Customers can wake up one morning to discover that the intelligence layer embedded throughout their operations is no longer available on yesterday’s terms.

When models become part of health care, finance, defense, public administration and industrial operations, access to intelligence becomes an issue of national sovereignty. A government that cannot control or replace the models operating inside its critical systems has surrendered something far more consequential than its choice of office suite.

Agents take the problem another step. They will not merely summarize documents and produce text. They will possess credentials, invoke APIs, modify infrastructure, access private data, make purchases and take actions across organizational boundaries. An organization must therefore control which models power its agents, where their decisions are processed, what information they can access, how their actions are audited and whether those agents can be stopped or replaced.

An agent operating from a European data center but controlled through a foreign model and foreign platform may meet a residency requirement. That does not necessarily make it sovereign.

The same distinction applies to data. Data sovereignty is too often reduced to data residency, as though keeping information in a European or British facility settles the matter. It does not. We must also ask who can compel access to the data, whether the provider can retain it or use it for training, whether embeddings and derivative models can be created from it, who owns those derivatives and whether every copy can be deleted. We also need to know whether the customer can move the information into another platform without losing the context, relationships and operational value accumulated around it.

The address of the server matters, but sovereignty requires enforceable control throughout the data lifecycle.

The UK Story is More Complicated

Steven is correct that the UK does not have one overarching policy formally called “digital sovereignty.” A House of Commons Library briefing said precisely that. But the absence of a single umbrella policy does not mean Britain has remained passive or is simply marching in lockstep with the United States. When we look at AI infrastructure rather than desktop software, a more complicated picture emerges.

In April 2026, OpenAI paused Stargate UK, the flagship data-center project at the center of Britain’s bet that American frontier-model companies would build critical AI infrastructure on British soil. OpenAI cited energy costs and regulatory uncertainty. The project had been presented as an important part of Britain’s AI future, yet the decision about whether it would proceed ultimately belonged to an American company. (Reuters)

The UK was not literally barred from entering a completed facility. What happened was more revealing. Britain found itself outside the decision-making process for strategic infrastructure that it had incorporated into its national plans. OpenAI could pause the project, and the British government could negotiate, improve conditions and wait. The concrete would have been British, but the ultimate control was not.

Britain learned that having an AI factory in your country is not the same as having a sovereign AI factory.

I write about this episode in my forthcoming book, The Indispensability Trap, because it demonstrates how a dependency can become a national constraint without anyone behaving maliciously. OpenAI did not have to threaten Britain or deliberately weaponize its position. Energy prices, regulation and OpenAI’s own commercial priorities were enough to expose the vulnerability. Sovereignty is not merely protection against hostile action. It is protection against someone else’s decision becoming your national constraint.

The Stargate episode did not create Britain’s sovereignty strategy. The chronology is important. The UK had already published a Compute Roadmap in July 2025 that called for expanding domestic computing capacity and reducing dependence on foreign compute. The government had also established a Sovereign AI Unit backed by up to £500 million. (UK Compute Roadmap)

But Stargate validated that strategy in real time and gave it new urgency. OpenAI paused the project on Apr 9, 2026. On Apr 16, 2026, the government announced the first companies receiving support through its £500 million Sovereign AI initiative. The government said Britain needed to become an “AI maker, not just an AI taker” if it wanted control over technologies central to its prosperity and national security. The program combines investment with access to national supercomputers, GPU capacity, research support, visas and government procurement. (UK Sovereign AI announcement)

In June 2026, Britain followed with a £1.1 billion AI Hardware Plan. That included £750 million for a national AI supercomputer and £400 million for next-generation AI chips, including an advance purchasing commitment intended partly to support innovative British chip companies. The plan connects the Sovereign AI Fund to domestic hardware development, national compute capacity and the AI Research Resource. (UK AI Hardware Plan)

None of this means Britain has achieved AI sovereignty. These investments are small beside the capital being deployed by American hyperscalers. Britain will remain dependent on imported accelerators, foreign software, international capital and partnerships with American companies. A £500 million fund and a £1.1 billion hardware program cannot wish those dependencies away.

They do, however, show that the UK has recognized the problem and begun pursuing sovereignty where the next contest will occur: compute, chips, AI companies and data-center infrastructure. That makes the Europe-good, Britain-bad distinction more complicated than Steven’s column suggests.

The European Union deserves credit as well. Its AI Continent Action Plan, AI Factories, proposed AI Gigafactories and Cloud and AI Development Act show that Europe understands sovereign AI requires more than alternative desktop software. It requires computing capacity, cloud infrastructure, data and an ecosystem capable of developing and deploying models at scale. The EU says 19 AI Factories and 13 associated antennas are now part of that effort. (European Commission AI strategy; EuroHPC AI Factories)

Europe must still confront an uncomfortable question: How sovereign is a European AI factory if it depends on foreign accelerators, foreign networking, foreign firmware, foreign model tooling and foundational software controlled somewhere else?

A data center operating in Europe under European law provides meaningful jurisdictional protection and resilience. That matters. But geography alone does not create technological independence, just as installing Linux alone does not eliminate dependence on foreign compute and models.

Sovereignty is the Right to Say No

Sovereignty should not be confused with autarky. Europe and Britain do not have to manufacture every semiconductor, build every model or ban every American technology company. That would be economically unrealistic and technologically self-defeating.

Sovereignty means retaining meaningful control, credible alternatives and a practical right of exit. Governments and enterprises should be able to move their data, workloads, models and agents. They should be able to continue essential operations if a provider withdraws. They should know which laws govern their systems and who can compel access to them. Most importantly, they should prevent any single company or foreign government from becoming an unavoidable point of control.

Open source is an important part of that answer, and Steven is right to champion it. Open software and open-weight models can provide transparency, portability and leverage. But openness by itself is not enough. A country does not become sovereign merely because it can inspect source code if it lacks the chips, infrastructure, expertise and energy needed to operate the technology independently.

This is the latest expression of the Indispensability Trap. Microsoft represented an earlier version of the trap at the operating-system and productivity layers. The hyperscalers moved it down into infrastructure. Frontier-model providers are moving it up into intelligence. Agents could complete the enclosure by becoming the operational layer through which work is performed.

Each new layer gives customers more capability while potentially moving them further from control over the systems on which they depend. By the time the dependency becomes obvious, replacing the provider may be technically possible but operationally unthinkable.

Steven is right to sound the alarm. He is right that Europe has moved more aggressively than Britain in articulating a broad digital sovereignty doctrine. He is right that open source must be part of the response. My concern is that a remedy centered on breaking dependence on Microsoft prepares governments for a sovereignty fight whose center of gravity has already moved.

The old battle was about who controlled the desktop. The next one is about who controls the intelligence, the data that feeds it, the infrastructure that produces it and the agents that act upon it. If Europe and Britain prepare only to escape yesterday’s monopolies, they may discover that tomorrow’s indispensable platforms have already surrounded them.