In Micelangelo’s Palazzo dei Conservatori in 1957, a group of European statesmen sat down to sign the Treaty of Rome and committed to one of most daring infrastructure projects in human history: the creation of a single European market. They were thinking, in the way that statesmen used to think, about peace, prosperity, and the prevention of another catastrophic war. What they actually set in motion was something considerably more mundane and substantially more transformative - a slow, unglamorous, decades-long process of standardizing everything from customs forms to product regulations to the permitted curve of cucumbers.
The cucumber regulations became famous for the wrong reasons. Most importantly, the idea worked but not through grand gestures. The common market restructured European industry, redrew economic geographies and made entirely new commercial relationships possible through one of history’s least celebrated activities: getting different systems to talk to each other across borders.
The people arguing about tariff schedules in the 1960s were not thinking about the supply chains of the 2020s. The infrastructure question and its consequences are rarely the same question. The consequences tend to be larger, stranger, and more durable than what anyone in the room could have anticipated.
Infrastructure decisions have always been someone else's problem until they became everyone's.
We are living through a relatively equivalent moment which is, like the Treaty of Rome, unfolding in a way that makes it easy to miss. The infrastructure being built right now, and more importantly the decisions being made about who controls it, on what terms, and according to whose rules, will shape the economic and political landscape of Europe and the world for decades. The infrastructure in question doesn’t seem physical although it is very extractive. It is the layer that determines how data moves, who can access it, who can profit from it, and who can be excluded from it.
Data sovereignty is the name for the set of choices that layer represents. It is the infrastructure question the next decade will be decided by.
Infrastructure is never really about the infrastructure
Roads are about who gets to go where. Railways are about which towns grow and which ones slowly die out. The electrical grid is about who controls the energy that runs everything else. The infrastructure is the physical fact; the governance of the infrastructure is the political one. And it is the governance that matters which is why infrastructure decisions are different from ordinary choices - the kind you can revisit at the next board meeting or reverse with a new government.
Infrastructure is long-lived: once built, it outlasts almost every other decision made in the same period, usually by decades, often by generations. Infrastructure has two characteristics. It is structuring - it doesn’t serve the activities that already exist so much as determine which new activities become possible and which remain useless forever. And it is concentrating - whoever governs critical infrastructure accumulates power over everyone who depends on it, in ways that only become obvious after the concentration has happened and the moment to do anything about it has passed.
The lesson of every major infrastructure wave is not that infrastructure is bad. The lesson is that infrastructure built without deliberate governance of who controls it in which way, tends to end up serving whoever got there first and had the resources to shape it. The railways served the railway barons (the Rothschilds, Vanderbuilt, Stanford, Hudson). The early internet served the platform companies that moved fastest to occupy its application layer (Google, Amazon, Facebook, Microsoft). The question for data infrastructure is whether we are going to notice the pattern before the concrete sets, or after and the time is ticking.
Governance questions about critical infrastructure are historically the ones that matter most and receive the least serious attention until it is too late.
This is why data sovereignty is not a compliance question, a privacy question, or a geopolitical question, though it has a nose in all three. It is a governance question about critical infrastructure and governance questions about critical infrastructure are historically the ones that matter most and receive the least serious attention until it is too late.
Three layers of sovereignty, and the one nobody talks about
“Data sovereignty” is used as though it were a single idea, a concept you can hold in one hand and wave at a conference. But it is at least three different ideas capturing the same phrase, each operating at a different level, each with its own dynamics and failure modes. A regulator fixes national sovereignty problems. A procurement policy and legal team addresses organizational sovereignty. Both barely touch operational sovereignty, which requires infrastructure. Mixing them up, which almost everyone does, is like trying to fix a leaking pipe by repainting the kitchen.
The national sovereignty, which jurisdictions get to access, regulate, and occasionally compel disclosure of data generated within their borders or about their citizens. The national sovereignty is being backed by regulations such as General Data Protection Regulation (GDPR), which is “the European Union’s landmark privacy and security law“ or data localization. There are also constant EU-US data transfer disputes, which have the character of an argument between relatives who fundamentally disagree about something neither is quite willing to name directly, then China’s data laws, India’s data protection framework. All of them are real, important, and the receiver of most of the public attention that data sovereignty gets. This is an issue, because the next two layers matter as well and almost nobody is looking at them.
Organizational sovereignty is when a company or institution actually controls the data it generates and depends on, and when that control has been quietly transferred - through legal processes involving terms of service that nobody reads, to the vendors, platforms, and cloud providers it relies on. Most enterprises, if they observed the situation honestly, would find they technically own their data in the way that someone who has put everything in storage and lost the key nominally owns their furniture. Proprietary formats, API dependencies, and platform entanglements accumulate quietly until the data is technically yours but functionally theirs.
The sovereignty layer which is at the moment very far to reach is the operational sovereignty. It means that the infrastructure required to actually exercise data rights exists and is accessible in practice. A company can have perfect legal title to its data and carefully drafted rights to share and control it, but most of the time still find itself completely unable to act on those rights because the software, the connectors, the managed platforms that turn rights into reality either do not exist, or are accessible only to organizations with significant engineering budgets and someone on staff who knows what container orchestration is.
Therefore, this third layer is where the most significant failures are currently happening. It is also, not coincidentally, where the most important opportunities are waiting.
The deadline is approaching
Somewhere in Bavaria, there is a small manufacturer making a precision component that ends up inside a car you have probably driven. It is a company with about fifty employees. They have a parts database that runs on software from 2009. As of September 2026, they have a legal obligation to a regulator to demonstrate exactly how their data flows through the supply chain.
It is very hard for them to make that deadline. Not because they don’t want to comply but because the software required to comply - a connector (the technical term) a digital translator that sits between their old system and the shared data network their industry has built, actually costs more to set up than any reasonable accounting would justify. It’s simple: the law says they have the right to participate but the operational reality says they don’t have the infrastructure to do so.
The law says they have the right to participate but the operational reality says they don't have the infrastructure to do so.
This is not an isolated compliance failure. It is a structural condition, and Europe is its most visible example right now. Over the past decade, the European Union has built one of the most serious data governance frameworks in the world with GDPR, the Data Governance Act, the Data Act, the AI Act, the European Health Data Space. The people who wrote these rules were genuinely trying to get something hard right: who controls data, who can share it, under what conditions, with what protections. But across the supply chains, healthcare systems and public institutions where they apply, the gap between what the law permits and what organizations can actually do is, in many cases, massive. Consider a regional health clinic asked to share patient records through Europe’s new health data network. The legal right to share, under proper consent rules (avoiding the third party as Palantir), exists. What doesn’t exist is the connector - the piece of software that would translate between the clinic’s aging records system and the exchange network, enforce the consent protocols, and run reliably without anyone on staff who knows what it is.
The concentration of the almighty power
The internet was genuinely designed to be free and resist central control. Its early founders believed that decentralization was structural - that the network’s topology would naturally resist the accumulation of power. They were right about the infrastructure but they were, for some reason, not paying enough attention to the application layer built on top of it. What they built on top of it was Google, Facebook, and Amazon. A handful of platform companies came to mediate most of the economic and social activity flowing across the apparently open internet. The infrastructure was open but the layer above wasn’t. By the time the consequences became obvious, the platform companies were big enough to shape the regulatory environment designed to constrain them.
The data economy seems to be making the same mistake. The pipes that carry data between companies - the connectors, the protocols, the identity systems that make exchange possible - could be built as shared opensource infrastructure, owned by no one in particular. In parts of Europe, that’s exactly what’s happening. But the big tech companies have noticed these pipes exist and they have very good reasons - from their perspective, to own them instead. The fact that this would be bad for everyone else is, from their perspective, not really the point.
If the infrastructure layer of the data economy concentrates the way the application layer of the internet did - the consequences will be more severe. Not because AI is more powerful than search or social media - though it seems it might be - but because controlling the infrastructure through which data flows (imagine a monopoly of Palantir) means controlling the terms on which the entire economy operates.
Infrastructure has a long and consistent history of becoming permanent
The Treaty of Rome felt, to most people of that time, like a matter for trade lawyers and agricultural economists. The consequences for how Europe organized itself over the following half-century were considerably larger than the people arguing about tariff schedules had anticipated.
The data sovereignty debate feels, to most observers currently, like a regulatory and compliance matter - a concern for data protection officers, enterprise IT departments and the kind of person who likes to read Commission consultation documents for pleasure. It is not. It is a question about who controls the infrastructure through which economic value will flow in the next generation of the digital economy. It is a question about whether the organizations that generate - manufacturers, clinics, farmers, public institutions, small businesses across every sector, retain meaningful sovereignty over what they create, or whether that sovereignty is quietly transferred to the platforms they have come to depend on.
These questions are being decided now. Quietly and in a more consequential sense AS the infrastructure being built, the standards being adopted, and the platforms being deployed over the next few years (will) create arrangements that become progressively harder to undo. First difficult, then very expensive (both planetary and humanly), then effectively impossible. The decisions that feel temporary and technical and perhaps reversible have a strong track record of being none of those things. This is how infrastructure always works. It starts as a decision and ends as a fact.
The railways shaped the nineteenth century in ways the people arguing about how far apart the tracks should be, could not possibly have imagined. Electrification shaped the early twentieth in ways the engineers running the cables could not have imagined. The internet shaped the late twentieth in ways that are still working themselves out. The decisions about data sovereignty - who controls it, on what terms, governed by whose rules - are shaping the twenty-first.
And this is not a specialists' concern. The investor is choosing, right now, whether to back the infrastructure that serves everyone or the one that extracts from everyone. So is the employer whose operations depend on data she doesn't control, the employee whose livelihood runs on platforms that could reprice that livelihood tomorrow, and the decision maker who will one day have to explain why the window was open and nobody walked through it. Infrastructure decisions have always been someone else's problem until they became everyone's.
The concrete is being poured. What gets set in it is still, just barely, up for debate.
The author researched, fact-checked, and edited this piece, using AI tools for structural drafting and grammar checks along the way. All facts, figures, and quotes were independently researched and verified by the author.
The Infrastructure of the Commons is a biweekly publication on data sovereignty, agentic systems, AI governance, and the critical infrastructure decisions that will define the next decade.







