Key takeaways
- Data residency does not equal data sovereignty. Storing data in Australia does not necessarily mean you control it.
- Full digital sovereignty is rarely realistic or necessary. The goal is the right balance of control, security and resilience.
- More control does not always mean less risk. Digital sovereignty requires deliberate trade-offs.
- Digital sovereignty is an ongoing governance issue that should evolve with regulation, technology and risk.
In the age of AI, ‘digital sovereignty’ has become a strategic priority for both parliament and Australian boardrooms (as well as many overseas jurisdictions), particularly following the Australian Government’s release of ‘expectations’ on data centres and AI infrastructure developers in March (see our earlier article), and announcement of a proposed mandatory national framework for large-scale data centres and establishment of a new Office of AI in July (see our earlier article). This article explores the concepts of digital sovereignty, data sovereignty and AI sovereignty, examines the layers of the ‘digital sovereignty stack’, and offers a framework for approaching digital sovereignty decisions - centred on balancing the three pillars of control, resilience and security. It also analyses how Australia's privacy and cyber laws may shape organisations’ pursuit of digital sovereignty in the AI age.
What is digital sovereignty, data sovereignty, and AI sovereignty?
Digital sovereignty, data sovereignty, and AI sovereignty are related, yet different, concepts.
- Digital sovereignty is a broad, umbrella term that refers generally to the ability of an entity to govern, control and protect its digital technologies, systems and infrastructure. It looks at the entity’s ability to exert authority over its digital ecosystem ranging from hardware and software to data and related infrastructure, operations and networks, regardless of where technologies are developed, hosted or supported. The layers of the ‘digital sovereignty stack’ are discussed below.
- Data sovereignty relates specifically to the governance and control of data. Traditionally, it has been thought of as ensuring data is subject to the laws and regulations of the country in which it is collected, stored and processed. There is, however, tension in this concept in today’s cloud-based and AI-driven environment, where data may be collected in one country, processed in another, and stored in a third. Importantly, data sovereignty is broader than data residency or localisation, as storing data in Australia does not necessarily ensure control over the security, access and resilience of such data.
Data residency ≠ Data sovereignty
Data residency is often confused with data sovereignty. Although related, these two concepts are not synonymous. Data residency requirements place obligations on data storage service providers to physically store data in a particular location. Data that resides in Australia may still be accessed by foreign entities and operators of associated infrastructure and be processed offshore. Note, ‘data localisation’ is an even stricter variant that typically requires all storage and processing of data to occur within a nation’s borders. Data sovereignty, on the other hand, is centred on maintaining jurisdictional ‘control’ over relevant data no matter where it is stored or processed. It encapsulates residency considerations as well as security, access and cyber resilience controls.
- AI sovereignty refers to an entity’s (or nation’s) capacity to govern and control its AI stack and supply chain. This encompasses the development, deployment, and operation of AI models and applications, as well as the management of data inputs and outputs, model training practices, data storage and retention, access controls, processing arrangements, and supporting infrastructure.

Layers of the digital sovereignty stack
The digital sovereignty stack consists of four primary layers, each representing a distinct domain organisations need to consider when assessing digital sovereignty outcomes.
- Infrastructure – The foundational layer that encompasses the physical components that underpin digital systems, including hardware, compute, submarine cables, data centres, networks and telecommunications infrastructure. Infrastructure sovereignty concerns who owns, operates and controls the physical and computing resources on which digital services depend. Organisations should consider whether they have sufficient visibility, redundancy and contractual rights over the infrastructure on which their critical systems operate.
- Data – The data layer addresses data ownership and control, location, access and processing rights, cross-border transfers, retention and deletion policies, and the legal regimes to which data may be exposed. As discussed above, data localisation alone does not guarantee data sovereignty outcomes – the jurisdictional controls, rather than physical location of servers, determine the laws that apply to data collection, disclosure, storage and processing. In the AI context, organisations must also consider which datasets are used for model training and their relevant weights in AI models. This includes ensuring that proprietary or institutional data and competitive insights are not inadvertently used for model training or secondary purposes.
- Technology – The technology layer encompasses the software platforms, applications, and interfaces through which organisations and individuals engage with digital systems, along with the underlying model and hosting infrastructure. AI applications currently rely predominantly on a small number of global AI model providers supported by hyperscale cloud service providers, often driven by security requirements and technical capabilities. However, this concentration can create dependencies that limit an organisation’s ability to switch providers, negotiate favourable terms, or maintain service continuity in the event of disruption or withdrawal. Organisations can address sovereignty concerns at this layer through robust contractual protections, portability provisions, and business continuity arrangements.
- Operations – The operational layer concerns the day-to-day running and governance arrangements around how systems are managed, maintained and supported. Operational sovereignty considerations include assessing who the critical workers are that operate critical systems, where they are located and what access controls (security clearances, key management, etc.) apply, and what risk mitigations are in place to address personnel and other operational hazards (including incident response and escalation). This layer is distinct from the infrastructure layer because operational control can be exercised independently of physical asset ownership. An organisation may use foreign-owned infrastructure while retaining operational sovereignty through contractual arrangements, personnel vetting and governance frameworks.
The layers of the digital sovereignty stack do not operate in isolation. Decisions made at one layer can expand or constrain the options available at others. For example, imposing strict data localisation requirements (data layer) may limit the range of available AI and cloud solutions (technology layer) and reduce resilience options if infrastructure and workforce are concentrated in a single geography (infrastructure and operation layers). This interdependence means that achieving ‘full-stack’ sovereignty is rarely realistic (and arguably unnecessary) for most organisations. Instead, the practical challenge lies in finding the right balance of control, security and resilience to achieve an organisation’s intended digital sovereignty outcomes.
Balancing control, security and resilience to achieve digital sovereignty outcomes
Digital sovereignty postures vary significantly between organisations. Procurement and policy decisions regarding each layer of the digital sovereignty stack will be determined by an organisation’s strategic and operational priorities, budget, risk tolerance and internal capacity and capability. They are also affected by external factors such as regulatory obligations and guidelines that apply to the organisation and its customers, contractual requirements, and advances in technology (and its accessibility to the organisation).
A helpful framework for determining and achieving digital sovereignty objectives is to assess decisions at each layer of the stack against three pillars:
- Control – The ability to determine ownership of systems and data, exercise rights to access, modify, retrieve and delete information, and govern third-party access. Greater control can be achieved through clearly documented ownership rights, implementing encryption, key, and access controls, and ensuring adequate contractual protections regarding the use of data and infrastructure, and effective exit rights.
- Security – The measures in place to protect systems and data from unauthorised access, cyber threats, and operational vulnerabilities. Stronger security can be achieved through robust identity management, encryption, continuous monitoring and threat detection, personnel vetting and security clearances, and compliance with applicable security standards and frameworks.
- Resilience – The capacity to maintain operations, recover from disruption, and ensure continuity through redundancy, failover and recovery arrangements. Greater resilience can be achieved through geographic diversity of infrastructure, automated failover and disaster recovery capabilities, regular backup and restoration testing, business continuity planning, and contractual service level commitments.

None of the three pillars should be pursued in isolation or as an absolute. Instead, organisations must find the right balance of control, security and resilience (the Goldilocks zone). Like weighting parameters in an AI model, the optimal balance will vary depending on the organisation’s industry, regulatory environment, risk tolerance, and the sensitivity of the information being handled. A government defence agency may weight control heavily, while a consumer-facing business may prioritise resilience and availability.
Attempting to maximise any single pillar in isolation carries risk:
- Over-prioritising control at the expense of resilience: The September 2025 South Korea fire incident is a cautionary example. A government-linked data centre that lacked effective backups or redundancies lost approximately 858 terabytes of government data permanently. Domestic hosting alone does not guarantee resilience - aggressive data localisation strategies can inadvertently compromise an organisation’s ability to recover from disruption.
- Over-prioritising security and technical capability at the expense of control: In June this year, Anthropic, in compliance with a US export control order, suspended access to its Mythos 5 and Fable 5 models for certain customers, demonstrating how quickly access to critical AI capabilities can be withdrawn due to geopolitical factors outside an organisation’s control. Australia, as a downstream consumer of global AI and cloud infrastructure, must assess any dependency risk against the benefits of accessing advanced technologies and global threat intelligence.
Finding the Goldilocks zone requires deliberate trade-offs. Technology providers are increasingly recognising this tension and offering solutions that provide optionality, such as ‘sovereign cloud’, regional storage and processing capabilities, and hybrid architectures. Importantly, organisations are not navigating these trade-offs without regulatory guidance. Australia’s existing cyber and privacy law regimes already establish a foundation for digital sovereignty decision-making.
Australia’s digital sovereignty-related laws
Australia’s cybersecurity and privacy regulatory frameworks provide a foundation for navigating digital sovereignty decisions:
- Privacy Act 1988 (Cth) (Privacy Act) – The Australian Privacy Principles (APPs) under the Privacy Act set a foundational framework for the handling of personal information in and outside Australia. APP 8 regulates overseas disclosure of personal information by requiring ‘APP entities’ (agencies, organisations with over $3 million annual turnover, and certain small business operators) with an Australian link, to take reasonable steps to ensure overseas recipients also do not breach the APPs (unless an exception applies). This extends Australian privacy law to cross-border data flows, supporting data sovereignty even when personal information is processed offshore.
- Hosting Certification Framework (HCF) – The HCF is a framework for protecting Australian Government systems and data, requiring all sensitive government data, Whole-of-Government systems, and ‘PROTECTED’ systems to be hosted using certified services. Service providers that provide hosting services to Australian Government customers, including foreign-owned entities, are required to be certified at Strategic, Assured, or Uncertified levels.
Certified Strategic Level service providers provide the highest level of assurance to the Australian Government and may be subject to ownership and control conditions (aimed at addressing foreign ownership, control or influence (FOCI) risk) specified by the Australian Government. Such providers are also subject to key personnel vetting, remote-in support restrictions, supply chain requirements, and proactive disclosure requirements. The HCF currently only applies to Data Centre Providers and Cloud Service Providers.
Note: The HCF is currently undergoing reform and registration of prospective service providers is currently paused. Updates on the reform are expected later this year.
- Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act) – The SOCI Act places obligations on owners, direct interest holders, operators and managed service providers to protect critical infrastructure assets across 11 critical infrastructure sectors in the Australian economy. Depending on the entity and asset type, entities may be subject to registration, mandatory cyber security incident reporting, and critical infrastructure risk management program (CIRMP) requirements, as well as obligations to comply with ministerial directions and government assistance and intervention requests. Importantly, compliance obligations apply regarding assets located in Australia regardless of where relevant entities are domiciled.
Note: Following publication of the final report on the independent review into the SOCI Act, conducted by Dr Jill Slay AM on 25 March 2026 (see our earlier article), the SOCI Act is under reform in two tranches – the first proposing enhanced CIRMP rules, ministerial direction powers and increased penalties (see our earlier article), and the second tranche focusing on streamlining and expanding the scope of the SOCI Act. The enhanced CIRMP rules took effect on 10 June 2026. Consultations on the remaining reforms have closed and updates are expected later this year.
- Protective Security Policy Framework (PSPF) and Defence Security Principles Framework (DSPF) – The PSPF sets mandatory requirements for Australian Government entities regarding governance, personnel, physical and information security. The PSPF requires government entities (and by extension, their contractors) to classify information according to its sensitivity and to apply commensurate protections, including to consider FOCI risks and undertake security risk assessments, implement access controls, and comply with information sharing and handling requirements. The DSPF applies similar requirements to Defence-related information and systems. These frameworks create a layered regime designed to ensure that Australia's most sensitive government data and digital infrastructure remain under sovereign Australian control.
- Aus-US Data Access Agreement – The Agreement between the Australian Government and the US Government on Access to Electronic Data for the Purpose of Countering Serious Crime (commonly referred to as the Aus-US Data Access Agreement), which entered into force on 30 January 2024, promotes Australia’s ability to exercise its own law enforcement powers over data held by foreign (predominantly US-based) communications providers (recognising that the Agreement also applies reciprocally). The Aus-US Data Access Agreement, which is the reciprocal pact of the US Clarifying Lawful Overseas Use of Data Act 2018 (CLOUD Act), allows Australian law enforcement agencies to reach data wherever it is stored, so long as it is held by a covered provider for the purposes of enforcing criminal law, monitoring persons and for national security reasons. Importantly, both the Aus-US Data Access Agreement and CLOUD Act contain procedural safeguards that allow technology providers to challenge requests if compliance creates a conflict with foreign law.
- Foreign Investment Review Board (FIRB) – The FIRB plays a significant role in promoting Australia’s digital sovereignty, primarily through the screening and conditioning of foreign investments in ‘national security businesses’ that are deemed to be critical to the operation of the Australian economy and society, and to hold sensitive and valuable national data assets. FIRB will consider whether investment proposals are contrary to the national interest, considering factors such as national security, competition, Australian Government policies and impact on the Australian economy, and the character of the investor. The FIRB provides advice to the Treasurer, who can block or impose conditions on investments found to be contrary to the national interest.
- Sector-specific requirements – Several sector-specific legislative instruments impose additional data governance and outsourcing requirements that intersect with digital sovereignty. For example, the My Health Records Act 2012 (Cth) governs Australia's national digital health records system and requires My Health Record data to be processed and stored within Australia. Further, in the financial services industry, the Australian Prudential Regulation Authority (APRA) imposes robust information security and data governance requirements on banks, insurers and superannuation funds through Prudential Standards CPS 234 (Information Security) and CPS 230 (Operational Risk Management). Technology providers servicing APRA-regulated entities may be contractually required to demonstrate control effectiveness aligned with these standards.
Each of the regimes above applies extraterritorially as long as there is an Australian link, and most of these frameworks do not require that data be stored exclusively within Australia. This recognises the practical realities of operating in a cloud-native environment, global workforces, and ever-increasing cross-border data transfers as AI adoption continues to grow.
Key actions
- Identify your Goldilocks zone – Determine your organisation’s optimal balance of control, resilience and security. This will vary depending on industry, regulatory environment, risk tolerance, and the sensitivity of information being handled. Avoid equating digital sovereignty with data localisation alone - a coherent strategy must address resilience, redundancy and recovery alongside jurisdiction and control. Absolute sovereignty across all dimensions is neither realistic nor necessary; the goal is deliberate, risk-based decision-making.
- Understand your legal and regulatory obligations – Map how Australia’s privacy and cybersecurity frameworks apply to your organisation. These legal requirements directly shape digital sovereignty strategy and should inform technology and procurement decisions.
- Explore technical solutions – Technology providers increasingly offer solutions that support digital sovereignty, including sovereign cloud options, regional storage and processing, and customer-managed encryption and access controls. Assess available options against your organisation’s Goldilocks zone.
- Treat sovereignty as ongoing governance – Digital sovereignty is an ongoing governance outcome. Your organisation’s intended balance of control, security and resilience will shift over time. Organisations must ensure digital sovereignty decisions are well documented, reviewed regularly and adjusted as circumstances change.