The global digital supply mesh is built on connctions. Every time an organization uses technology developed, operated or financed by someone else, it connects to the supplier of that technology in some way or form. This is not an unfortunate side effect of the Mesh. It is the mechanism through which much of its value is created.
The Upside: Specialization & Reuse Create Value
Specialization allows different actors to become exceptionally good at solving individual technological problems. A company does not need to manufacture its own processors, develop its own database, build a global network, or train its own foundation model. It can use NVIDIA for accelerated computing, PostgreSQL for databases, AWS for scalable infrastructure, Stripe for payments, or OpenAI for AI capabilities, benefiting from billions invested and decades of specialized expertise elsewhere.
Reuse multiplies this effect. A small development team can combine Linux, Kubernetes, open source libraries, cloud infrastructure, payment services and AI APIs into a product without recreating any of them. Global scale spreads the enormous cost of developing and operating these technologies across millions of users, while abstraction makes them accessible through increasingly simple interfaces.
Together, specialization and reuse increase innovation speed, efficiency, scalability and productivity. Organizations can focus their own investment on what differentiates them while building everything else on investments already made by others.
The Downside: Connectedness Creates Risk
But dependency has another face. If an organization relies on someone else's technology, infrastructure or expertise, it also depends on that component remaining secure, available, legally accessible and economically replaceable.
Digital sovereignty is therefore not one single dependency problem, but needs to mitigate six different risks that can emerge across the mesh.
Cyber Vulnerability. The risk that vulnerabilities in software, hardware, infrastructure, or their dependencies can be exploited to compromise systems or data.
Operational Disruption. The risk that critical digital capabilities become unavailable or degraded, interrupting the processes that depend on them.
Loss of Expertise. The risk that an organization loses the knowledge and skills required to understand, operate, maintain, or change critical technology.
Regulatory Exposure. The risk arising when technology, data, or providers fall under laws and regulatory authorities that can affect how they may be accessed or operated.
Kill Switch. The risk that access to critical technology, services, software, or infrastructure can be restricted or withdrawn.
Vendor Lock In. The risk that changing a technology or provider becomes prohibitively difficult or costly because of accumulated technical, contractual, operational, or organizational dependencies.
You Cannot Have One Without the Other
Jekyll and Hyde are, like in the original novel, not two different systems. They are two consequences of the same system. The specialization, reuse, abstraction and interconnectedness that create enormous economic value also create the inter-connectedness from which sovereignty risks emerge.
The challenge is therefore not to eliminate dependencies, but to manage their risks without losing their benefits. And that is where digital sovereignty gets difficult. See the next chapter.





