Synchronicity can be revealing. When unrelated stories co-incide, sometimes they illuminate each other in surprising ways, despite not sharing a causal link. Two industry white papers recently arrived in my inbox. 

The first covers the hot-button topic of our uncertain age: digital sovereignty, in an era not just of disruptive technology, but also the tearing up of political orthodoxy. How to maintain control when everything is in flux, and our allegiances are either challenged, or forced upon us by external circumstance?

And the second is a report on agentic AI from Economist Enterprise, the strategic insights wing of The Economist Group, publisher of the respected magazine. In that white paper’s analysis, organizations are not just being pulled apart by agentic AI, but are also pursuing the technology relentlessly, despite the damage it is apparently causing.

In short, we want to seize back control of our technology and data, says one – then let agentic AIs tear the business to shreds instead, says the other. So, what is going on?

Sovereignty 

The first white paper, The Digital Sovereignty Revolution, comes from UK cloud provider Civo. Updating 2025 research with new findings, it says that businesses are being hit with a costly “sovereignty tax” due to what it calls their “forced dependency” on US cloud giants.

Civo surveyed 1,000 UK IT leaders and found that two-thirds of them would now consider switching cloud providers to regain control over their data and infrastructure, while 77% are “deeply concerned about the exposure of their data infrastructure to geopolitical risk”.

The report does not pull its punches, saying:

Despite this desire to exit, the number anticipating becoming more deeply entrenched in US hyperscalers’ systems has more than doubled over the past year, due to a combination of technical lock-in and anti-competitive practices.With AI accelerating the need for data residency and 39% of firms hit by US hyperscaler outages this past year (costing some over £1 million), an overwhelming 90% of UK firms are now demanding government intervention to back homegrown tech.

This may be a problem, I suggest. The British government is known for making bold public statements about the UK’s innovation powerhouse, while ceding policy control to US hyperscalers and AI vendors, sometimes against the advice of homegrown start-ups (see diginomica, passim). So, expecting Whitehall to start pulling business from US cloud providers, as the French government has done recently, may be a forlorn hope.

That said, Parliament has at least attempted a definition of sovereignty in this context. In March, the House of Commons Library published its own research briefing on digital sovereignty ahead of a Westminster Hall debate. It described it as “the agency and capacity of any organisation to make intelligent, informed choices to shape its digital future by design.”

The Civo report continues:

Sovereignty is now a strategic priority for 73% of organisations, up from 61% [in Civo’s 2025 research]. But this isn’t just talk; it’s driven by the extraterritorial reach of foreign law, new AI security threats, and a broader sense of creeping dependency on Big Tech. A strategic shift is underway, but here lies the problem: while 66% of leaders say they’d switch providers to gain greater control, many simply don’t know that credible UK choices already exist, when, in reality, they do. The market exit options appear narrower than they are, undermining the UK’s ability to future-proof its digital infrastructure and digital sovereignty.

Clearly, these findings favor Civo itself, but we can forgive the company that, as the research is both statistically valid and amplifies many a backroom conversation that I have heard from cloud users and business leaders. The white paper continues:

With the trust gap widening and 43% of IT leaders now unsure how Big Tech handles their data, the extraterritorial reach of the US Cloud Act only amplifies those concerns. The market is calling for change. Security and infrastructure leaders need more than another short-term hyperscaler fix.

US vendors would pitch that they recognize customers’ fears and offer them remedies in the form of  UK and European divisions and data centers. But that is not how Civo sees things. It says:

Some hyperscalers are promoting ‘sovereign clouds’ with little or no jurisdictional control, a practice that Clara Chappaz (former Minister of Digital for France) refers to as ‘sovereignty washing’. While Europe has made progress toward establishing more clearly defined frameworks, organizations need to go beyond vendors’ rhetoric about sovereignty and determine their own meaning for digital sovereignty concerning their data, infrastructure, and compliance obligations.

It concludes:

With US platforms capturing 80% of the market, what was once seen as commercial pragmatism [reliance on US cloud giants] is now exposed as structural risk. Trust isn’t enough; this is a strategic imperative. The UK must now consider digital infrastructure a national resilience challenge that cannot be extricated from its global geopolitical context.

Taxing question

Like other non-US vendors in recent months, those are boldly political statements. But that is hardly surprising in 2026. Whatever your own political affiliations may be – whether you are Republican or Democrat, or left or right of center in UK or European terms – one thing is undeniable: the current US government has politicized the technology sector to an unprecedented degree and turned AI into an expression of the doctrine of American exceptionalism. The recent AI Action Plan and its accompanying Executive Orders from Trump 2.0 make that very clear.

So, what is the “sovereignty tax” that Civo describes, beyond being a neat bit of vendor messaging. The white paper says:

What was once discussed hypothetically is now emerging as a documented consequence of relying on foreign cloud infrastructure. The Sovereignty Tax is not an official term, a regulated concept, or a single, calculable fee, but rather one that encapsulates the cumulative cost of delaying taking control.

It is a price exacted from organizations that continue to build critical systems on platforms they cannot fully govern. It results in unpredictable costs, limited negotiating power, restricted portability, incomplete data visibility, operational disruption and exposure to legal or policy decisions made outside the UK.

But a tax normally comes with figures attached. The report offers:

In the past year, 39% of UK IT leaders experienced outages originating from US hyperscalers, with 15% experiencing them several times. Among those hit by outages, 29% reported a direct financial cost, 40% now report risk exposure above £50,000, and five percent report costs exceeding £1 million.

This is the toll most organizations are already paying without seeing it on an invoice. Every year, proprietary API dependencies deepen, egress fees make exits more expensive, and migration complexity compounds. The scale of the trap is visible in the data: three-quarters of IT leaders doubt their ability to exit a major US provider, with some even questioning their ability to do so at all. Organizations are not simply choosing to stay; in many cases, they have lost the practical ability to leave.

Of course, a UK or European cloud service might experience outages too, but nonetheless, what’s the conclusion here? Civo’s report argues:

For UK organisations, this is now a board-level issue. Sovereignty is integral to business continuity, innovation, customer trust, and competitiveness. US tech policy dictates that access to hyperscaler platforms can be restricted or withdrawn for reasons outside a customer’s control, so a single policy change can have serious repercussions for the entire UK digital economy.

Agentic chaos?

So, according to Civo, enterprises are desperate to seize back control and put decision-makers back in the driving seat. Human agency is critical, and sovereignty is vital, right? Not according to Economist Enterprise, which can afford to step back and observe real-world business behavior, while having no skin in the game – in cloud services terms, at least. According to its own white paper, Power Without Control – Rethinking Cybersecurity for the Age of Agentic AI:

AI agents are breaking things and organizations know it. [But] they are deploying more anyway.

A staggering 98% of organizations have already experienced a disruptive agent-related incident, it continues:

Inside most large organizations today, an AI agent is making decisions, accessing data and taking actions that nobody is fully tracking. Not because leaders are unaware; 90% say they are deploying agents faster than their security teams can evaluate or govern them, but because competitive pressure to adopt agents outpaces the infrastructure to control them.

In the agentic era, failure is inevitable. Driven by the appeal of hyper-productivity and the rush to keep up with competitors, agent deployment has entered overdrive during the last year. That is now sparking frequent incidents and disruption from accidents like deleted code bases as well as opening new entry points for malicious actors.

The challenge is that the very capabilities agents need to deliver the biggest gains – freedom to move across data and tooling environments, take actions, and interact with each other [one might describe that as the agentic equivalent of sovereignty] – necessarily heighten information insecurity. Nearly 90% believe they are deploying agents faster than they can evaluate, govern or secure them.

In this brave new world, the threat is no longer at the perimeter, says the Economist Group, but has been moved inside the enterprise – largely due to relentless AI hype, it seems, and the associated promises of productivity gains that, in many cases, refuse to appear. (The Productivity Paradox has been well known for decades).

The white paper explains:

Conventional cybersecurity postures emphasise protecting the perimeter from outside actors. While that remains important, agents are bringing disruption from within, such as complex emergent behaviours and cascades from agent-to-agent interactions. Survey respondents are just as worried about their agents acting out of intended scope as they are about external exploitation. Regulatory investigations, supply chain continuity, brand reputation and revenue impacts are the top four business areas at risk from agentic incidents, according to our survey.

My take

So, enterprises want strategic, operational and human sovereignty, and they want sovereign data and IT systems, and yet most are rushing to give agentic AIs sovereignty over their business in the meantime.

Even for a world-weary and, some might say, cynical IT journalist – I prefer ‘critical thinker’, thank you – it is hard not to feel profoundly depressed by the synchronous findings of these reports. Of deepest concern are the Economist Group statements “In the agentic era, failure is inevitable”, “competitive pressure to adopt agents outpaces the infrastructure to control them”, and “driven by the appeal of hyper-productivity and the rush to keep up with competitors, agent deployment has entered overdrive.”

What they tell us, once again, is that organizations are not being driven by common sense and good governance, but almost entirely by hype and marketing noise, based on AI’s promise of instant productivity wins and cost savings. Yet survey after survey tells us that those productivity benefits often fail to materialize, and costs are rising, not falling. Tokenomics has replaced traditional economics, and hyperscalers are taking more and more of our money.

I’ve said before that I think excessive tech evangelism can be one of the most destructive force on Earth at present, one that can no longer be separated from geo-politics and climate change, and which is amplified by tech CEOs’ ability to talk up their valuations on social platforms. And I see no evidence to the contrary from either of these reports.