Why 85% of Governments Face Critical AI Sovereignty Risks,And What They're Doing About It
Government leaders worldwide are waking up to a sobering reality: their dependence on foreign technology providers for critical services has become a national security vulnerability. A new Capgemini Research Institute study shows that 85% of government organizations are classified as having "significant exposure" to digital sovereignty risks, with 90% of public sector leaders now discussing the issue at board level.
Digital sovereignty, the ability of a nation to maintain control over its critical digital infrastructure and data, has shifted from theoretical debate to urgent strategic priority. The concern is straightforward: if a geopolitical crisis disrupted access to a single cloud provider, AI system, or connectivity vendor, could governments still deliver essential services to citizens? For most, the honest answer is no.
What Specific Risks Are Governments Most Worried About?
The research identifies several interconnected vulnerabilities that keep government leaders up at night. Operational resilience tops the list, cited by 80% of government respondents as the strongest driver behind digital sovereignty efforts. In plain terms, this means governments want assurance that critical services like healthcare systems, tax processing, and emergency response won't collapse if a foreign provider cuts off access or faces sanctions.
Beyond resilience, governments are concerned about losing control over their own data. Some 76% of public sector respondents cite the need for greater autonomy and control over data, models, and intellectual property as a key motivation. This reflects a broader anxiety: as AI becomes embedded in government operations, nations worry about foreign entities having visibility into sensitive citizen information or the ability to influence how AI systems make decisions affecting millions of people.
The visibility problem is equally alarming. Only 15% of public sector organizations have fully mapped their technology dependencies, while 64% have only partial or reactive visibility, and 21% report no visibility at all. In other words, most governments don't even know where their vulnerabilities are.
Which Technology Layers Pose the Highest Risk?
When asked to identify the areas posing the highest risk to operational continuity, government organizations pointed to several critical layers:
- Cybersecurity: Cited as a risk by 51% of respondents, reflecting concerns about attacks on digital infrastructure.
- Connectivity: 44% see risk here, with 65% of those relying on foreign connectivity providers.
- Data systems: 41% identify data as a vulnerability, with 53% relying on foreign cloud providers.
- AI systems: 41% cite AI as a risk area, a growing concern as governments embed AI into public services.
- Hardware: 63% rely on foreign hardware providers, creating supply chain exposure.
The European Commission's eGovernment Benchmark Report 2026 reinforces this concern, noting that government portals and data systems across the European Union often rely on hosting providers and cloud services that fall under non-EU jurisdictions, creating dependencies that "affect strategic autonomy and weaken the long-term resilience of Europe's digital public infrastructure".
How Are Governments Building Sovereign AI Capabilities?
Rather than pursuing complete isolation, leading governments are adopting a pragmatic approach: building the capacity to choose and manage dependencies strategically. This means identifying which capabilities must remain under direct national control and which can safely rely on trusted partners.
A concrete example is unfolding in the German state of Schleswig-Holstein, which is undertaking a digital sovereignty transformation program based on open-source models and a deliberate move away from reliance on big tech companies. This approach allows governments to maintain control while still benefiting from innovation and external expertise.
In the Middle East, governments are moving faster. Abu Dhabi is positioning itself as a global leader in sovereign AI, with over 50 UAE government entities participating in the region's largest AI conference to showcase public sector AI use cases. The UAE's Department of Government Enablement announced plans to become the world's first AI-native government, with the infrastructure and governance models already taking shape.
"Abu Dhabi will become the world's first AI-native government next year, and the evidence is already clear in the way we're redefining public services for millions of people and businesses. We have built the blueprint, and Ai Everything Abu Dhabi is our invitation to the world to examine it, to see what intelligent governance looks like at scale, and the enormous benefits it delivers to people's lives today," said H.E. Wesam Lootah, Director General of GovDigital at the Department of Government Enablement.
H.E. Wesam Lootah, Director General of GovDigital, Department of Government Enablement, Abu Dhabi
Similarly, du, a major telecommunications provider in the UAE, is showcasing sovereign AI cloud and cybersecurity capabilities designed specifically for enterprise and government organizations operating in the region. This reflects the UAE's broader National Strategy for Artificial Intelligence 2031, which emphasizes building local technology foundations that allow organizations to adopt AI securely while maintaining control over critical data.
Steps Governments Can Take to Reduce Sovereignty Risks
The Capgemini research outlines a practical framework that government leaders can implement to strengthen their digital sovereignty posture:
- Map critical dependencies: Conduct a comprehensive audit of all technology suppliers, data flows, and infrastructure components supporting essential services. This visibility is the foundation for all subsequent decisions.
- Apply risk-based prioritization: Not every system requires sovereign control. Identify the smallest set of capabilities, assets, and controls that must remain under direct or assured national control to safeguard critical operations.
- Establish federated governance: Combine local oversight with trusted international partners. This allows governments to benefit from external innovation while maintaining control where it matters most.
- Build exit strategies: Ensure portability, interoperability, and the ability to switch vendors or reconfigure services if conditions change due to geopolitical shifts or supplier disruption.
- Embed resilience into strategy: Digital sovereignty and resilience are interconnected. Resilience depends less on isolation than on managed interdependence, knowing which capabilities must be controlled and where trusted partnerships are essential.
The research emphasizes that digital sovereignty should be treated as a strategic leadership issue rather than a narrow technology program. Some 44% of government and public sector leaders now classify it as a top board-level priority, recognizing that sovereignty enables governments to stay in control of their infrastructure during times of crisis.
As geopolitical tensions intensify and cyber threats evolve, the question is no longer whether governments should pursue digital sovereignty, but how quickly they can build the capabilities and governance structures to do so effectively. The leaders moving fastest are those treating it as a strategic imperative today, not a future consideration.