Skip to content

Why Westminster Doesn’t Get Digital Sovereignty

A candid photo from the audience of a parliamentary committee meeting in Portcullis House, Westminster, showing a notebook with handwritten questions on digital strategy next to a water glass and a UK Parliament visitor lanyard.

There is a distinct kind of modern exhaustion that comes with trying to engage in civic life as someone who actually cares about where data lives, how infrastructure functions, and why outsourcing our entire digital existence to a handful of American tech monopolies is a catastrophically bad idea.

Recently, using an open letter template provided by the Open Rights Group, I sat down and wrote to my local Member of Parliament. The core purpose of the letter wasn’t just to vent about corporate monopolies or data tracking, it was a direct, formal invitation to an upcoming cross-party briefing in Portcullis House. The event, hosted by a group of cross-party MPs alongside technical experts and privacy advocates, was designed to have an honest conversation about practical digital sovereignty, open-source resilience, and how the UK government can break its deep-seated addiction to Big Tech across banking, healthcare, communications, and transport.

I wasn’t expecting a handwritten manifesto on the merits of self-hosting or a detailed breakdown of Linux kernel security. But I did hope that someone in the constituency office might glance at the event details, recognise that public infrastructure dependencies are a growing vulnerability, and perhaps even send a staffer along to take notes.

Instead, the reply that eventually landed in my inbox completely ignored the invitation, bypassed the event entirely, and pivoted straight into a pre-packaged ministerial script about artificial intelligence.

Reading through the response, it quickly became obvious that the actual message hadn’t been digested by a human who understood the context. Rather than addressing public infrastructure, data localisation, or the dangers of corporate vendor lock-in, the letter assured me that “…the Government has committed to extremely robust digital sovereignty measures across the board.” To prove this, it pointed proudly to a “…£500 million investment in a sovereign AI fund to back our brilliant AI entrepreneurs and start-ups” and highlighted plans to invest “…up to £2 billion in public compute,” including a brand-new national supercomputer in Edinburgh.

To anyone who spends their free time managing local Docker containers, configuring Proxmox nodes, or trying to keep personal and community data away from foreign cloud monopolies, the disconnect is staggering. Throwing hundreds of millions of pounds at commercial AI startups and centralised supercomputers doesn’t solve the UK’s dangerous reliance on Big Tech for essential public infrastructure, it just subsidises a newer, flashier brand of corporate vendor lock-in.

When local councils, NHS trusts, and emergency services are permanently tethered to Microsoft 365, AWS, and Google Cloud, funding venture-backed proprietary AI models is the digital equivalent of rearranging deck chairs on a sinking ship. True digital sovereignty isn’t about trying to out-scale Silicon Valley at their own game using taxpayer-funded venture capital. It is about architectural independence, open standards, and the freedom to audit, modify, and host the software our society actually runs on.

Unsurprisingly, there was zero mention of open-source software, local infrastructure resilience, or the Portcullis House briefing I had specifically asked them to attend. The reply simply wrapped up with a reassuring note reminding me that “…sovereignty is not about isolationism,” leaving me to wonder if anyone in Westminster realises that running your own Nextcloud instance or securing your own network isn’t isolationist, it’s just basic digital hygiene.

The reality is that political institutions are structurally optimised for high-level buzzwords and venture-capital optics rather than unglamorous, foundational engineering. They want ribbon-cuttings for supercomputers, not audits of opaque cloud contracts.

Until policymakers finally understand that digital sovereignty means giving public institutions the freedom to run their own infrastructure on hardware and software they actually control, the rest of us will just keep quietly backing up our data to local ZFS pools, hardening our home labs, and keeping our systems secure ourselves.

Join the conversation