The-edit

Digital sovereignty just got real.

By Steph MacLeod – Board Director, Head of Tech

For years, buying US tech was the safe call. The ‘nobody gets fired for buying IBM’ choice. You went with the biggest US vendor precisely so the blame could never land on you. This weekend, the safe choice had a lot of people quietly thinking WTH…

On Friday 12th June, two of the most capable AI models on the planet were running in production. By Saturday 13th they were dark. Washington told Anthropic that no foreign national could use Mythos 5 or Fable 5 (not abroad, not inside the US, not even Anthropic’s own staff) citing national security. The company can’t check passports at login, so it pulled the models for everyone. Days earlier it had filed to float at close to a trillion dollars. A near-trillion-dollar company, and one directive took its best product offline overnight. Whatever you thought you bought when you signed up for “enterprise-grade,” there was an asterisk. Washington was in control.

The reality was that a capability your teams were building on last week was gone by the weekend, and the supplier didn’t choose it. A government most of us don’t get to vote for did.

As @TomBristow reports today in @themorningintelligence, we’re already seeing reactive moves in the UK; “The Cyber Security and Resilience Bill is back in Parliament this afternoon. Expect the “resilience” part to get more attention post-Anthropic switch-off as the Bill was already becoming a vehicle for sovereignty concerns. A cross-party group of MPs have laid an amendment to force the government to come up with a digital sovereignty strategy within 12 months. A Conservative amendment requires a register of foreign powers. Another amendment concerned with existential risks seeks “last-resort” powers for the government to “shutdown” data centres or models.”

Sovereignty has entered the boardroom

The Washington/ Anthropic situation was exactly the (then) abstract scenario discussed at the recent London Tech Week and AI Summit. The shift is that sovereignty has climbed out of procurement and into the comms function and more importantly the boardroom. However, it has almost nothing to do with where your technology is built. Various panellists at the AI Summit said it straight: this is choice and control. Where the data sits. Who can reach it. What happens when the politics shift and not in your favour. The cases everyone kept citing were real life success stories Denmark running its own Gefion supercomputer, Ukraine moving government data to the cloud with missiles already in the air. Sovereignty is a continuity problem wearing a policy hat.

And the money makes the politics obvious. Starmer wants British firms to start, scale and stay here. £1.1bn for AI hardware, the Zenith supercomputer, half a billion behind a homegrown frontier model in Lumen Sovereign. Whoever funds the AI will end up controlling it. Control, safety and scrutiny follow the cheque.

The comms challenge

AI is a policy story now. Whatever you say about it gets read by ministers, regulators, procurement leads and select committees, not only customers and investors. A comms team that can’t hold a policy conversation is shut out of half the rooms that decide its company’s future.

The sovereignty question is coming for every vendor, out loud, in the room. Over the next month, I bet everyone will have a “sovereign” line in their messaging. The quality of that line will be critical. Buyers will smell inauthenticity in a heartbeat. A claim you can’t operationalise is worse than saying nothing.

The buyer owns the dependency

Now the part no tech vendor wants to say, because it’s aimed at the people writing the cheques. If you are buying this technology, the Anthropic weekend is your problem, not the vendor’s. You didn’t buy a tool. You bought a dependency, and this proved that dependency can come with a foreign government attached.

When your AI supplier becomes a geopolitical story, you are in the story; your outage, your regulator’s letter, your board asking why production stopped on a Saturday. The question CIOs were quietly trading at Olympia is the right one: who can switch this off, and what is my move when they do? If the honest answers are “no idea” and “nothing,” you have a continuity risk with your name on it. Multi-sourcing, exit routes and a tested fallback used to be hygiene but now they are strategy.

Different strokes for different folks

What you say depends of course, on who you are. The US vendor has to kill the “can we rely on you?” doubt before a buyer voices it. Effective technology relies on partnership and international co-operation, so this is critical. The UK start-up should heavy on sovereignty as an advantage, not nod politely at it. The established player, knotted into a dozen partnerships, needs one story that holds across all of them. And the buyer needs to stop treating sovereignty as the supplier’s problem and start writing it into the contract. Although different areas of emphasis, the overall centre theme of control unifies and strengthens all parties, if told well.

This is firmly in our patch at Cavendish. Not just strategy, policy and reputation but also through our data centre and infrastructure work. Sovereignty is argued in the messaging and settled in the kit. We do both, which is rarer than it sounds.

The reality check – it’s about options not purity

But let’s be honest here, nobody is getting fully sovereign, and anyone selling you that is selling you an increasingly tattered flag. The UK isn’t about to make all its own chips; even Lumen Sovereign will run on hardware designed elsewhere. The Cabinet Office was blunt at the AI Summit: the aim isn’t to wall off foreign technology, it’s to be the easiest place in the world to build and deploy it, on terms you set. That’s the grown-up version.

It’s about having options. Know your dependencies. Price the risk. Keep an exit. The brands that win the next twelve months won’t be the ones shouting loudest about sovereignty. They’ll be the ones who can say, plainly, where their tech runs, who controls it, and what happens when someone reaches for the plug.

Basically, have a view, or live with someone else’s.

Digital sovereignty is now a live operational risk, we help you understand your exposure, manage dependencies, and communicate with clarity. Get in touch to learn more.

Keep reading