Chapter 4 (full draft): Three Experiments for Digital Sovereignty
Lessons from China, Europe, and the Gulf
I first understood the meaning of digital sovereignty not in a policy paper, but in an ordinary conversation about dependence on a different aspect.
Talking to my family in India recently, they were worried about cooking gas supply due to the Strait of Hormuz shutdown from the Iran war. Restaurants were closing or rationing supplies. Households were adapting to a very difficult situation. It struck me then. What happens if such a thing happens to our digital environment? i.e., if we couldn’t send emails, process payments, or operate critical machinery or tools suddenly because of a similar geopolitical situation.
If a nation’s data, applications, payments, hospitals, schools, startups, and government services all run on infrastructure owned elsewhere, how truly independent is that nation?
At first, the question felt nebulous. It felt like a problem that could be addressed by diplomats, regulators, or technology committees. But the visions of artificial intelligence reshaping cloud computing changed the way I looked at them completely.
I remembered standing in front of a data center facility in Ashburn, VA. Looking at the long gray wall and the large security gate, it seemed just like a warehouse. When I reimagined this with the visions of AI taking over the world, it seemed something very different suddenly. It looked like a nervous system of a nation. It reminded me of ports, highways, power grids, and telecom networks, the type of invisible systems that determine whether an economy can move, grow, compete, and protect itself.
Different countries reached this realization in different ways, shaped by their own histories and anxieties. China, e.g., due to its historical shadow war with the US, realized very early that it had to build its own digital fortress.
Europe had a different outlook. It focused on privacy and protection of its citizens and chose rules, rights, and governance.
The Gulf, on the other hand, recognized that partnerships were key in developing a sovereign digital structure for preserving the future of oil-dependent economies.
Each path tells a story about fear, ambition, and institutional character. They are not flawless but have various lessons on offer. At the very least, this puts India on notice.
I want to be clear about something: this isn't a call to copy anyone's homework. India can't just take China's model, or Europe's, or the Gulf's, and paste it onto our own map. We're not any of them, and honestly, that's the whole point.
We have a democracy that is vibrant but at the same time chaotic; a federal structure that forces consensus instead of commandment; a private sector that's incoherent but competitive rather than state-managed; and a digital public infrastructure, the secret sauce that is a mystery to the rest of the world on how we built it. Does it look messy and rough? Of course. But it doesn’t mean we cannot be as successful as the other regions. It just presents a different starting point, that's all.
Bottom line, India cannot simply adopt another nation’s template. It should discover its own approach. So, this chapter is not a search for a perfect blueprint. It is a walk through three national experiments, each with its own challenge, compromise, and consequence while presenting India an opportunity to decide what road it must build for itself.
China: Sovereignty Through Supreme Control
The heavy doors of the secret inner briefing room at Zhongnanhai (a compound that houses the offices of and serves as a residence for the leadership of the Chinese Communist Party (CCP) and the State Council) closed behind the table where seven men sat around. At the center was the general secretary.
There was a projection screen showing a map of global supply chain vulnerabilities.
The Catalyst: The ZTE and Huawei Shock
A senior minister stood at the podium. He pointed to a certain area on the screen and shouted. "Ninety percent of our advanced enterprise software runs on American databases. Our banks rely on IBM and Oracle. Our councils run on Windows." And then he argued while flashing a timeline of the 2018 ZTE sanctions and the subsequent blacklisting of Huawei [1]. "U.S. is weaponizing vague, non-technical national security risks as a political tool to unfairly suppress legitimate Chinese commercial competitors "
The room went quiet. These incidents illustrated a clear lesson for everyone at the table: dependence on US technology is a critical risk and threat to national security. Something had to be done.
The Debate: Pragmatism vs. Nationalism
This has been an ongoing debate for years within the Party’s economic planning committees.
Liu He (Former Vice Premier & Economic Czar): A Harvard-educated economist who served as China's top economic adviser and chief trade negotiator with the United States argued for a cool-headed response to US sanctions. The same was the case with Wang Qishan (former vice president), who spent decades integrating China into the global financial system.
But the general secretary was eventually won over by the counterfaction advocating for a stricter national security posture. This faction included Wang Huning (the party's chief ideologue) and Chen Wenqing (head of the Political and Legal Affairs Commission).
The meeting ended with President Xi Jinping's mandate for technological self-reliance He did not care about the short-term economic friction. He was very clear; history did not favor nations that outsourced their core sovereignty.
The Directive: "Xinchuang" is Born [2]
There were two major policy wings to the directive
Xinchuang Policy: China aims to achieve technological self-reliance by replacing foreign technology in government and critical sectors by 2027.
Document 79 and “Delete A” Strategy: A secret directive issued in 2022, aka the “Delete America strategy," mandated the replacement of foreign software and hardware with domestic alternatives in state-owned enterprises and government entities again by 2027.
Although it was codenamed Xinchuang, the IT application innovation, people inside the room knew the true goal: de-Americanization.
The Execution
Before the meeting adjourned, specific orders were carved out. The Ministry of Finance was told to open a bottomless vault of subsidies for local tech firms. The Ministry of Industry and Information Technology was ordered to draft a secret blacklist of foreign vendors.
Jan Zhe was reading the diktat in her accountant’s office at the state-owned offshore drilling company. The circular didn't use the word "ban." It used the word "encouraged," i.e., state-owned enterprises were encouraged to complete migration to domestic database and operating-system alternatives by the end of the fiscal year. Jan had been in state enterprise long enough to know what "encouraged" meant. She formulated an immediate plan to switch from Oracle Financials to Yonyou’s BIP product.
Hao Yu’s experience was more disconcerting than threatening. She suddenly saw a large increase in orders from domestic companies for her semiconductor testing firm. The orders had tripled inside two quarters, and three of the new accounts were state-linked fabs she'd pitched unsuccessfully for years. What had changed was a set of decisions made in a room she'd never be invited into, decisions that could, with the same silence they arrived with, reverse themselves
China was cutting the cord with US companies, willing to spend whatever it took to build a digital fortress.
The result was the emergence of technology giants capable of operating at global hyperscale: Alibaba Cloud, Tencent Cloud, Huawei Cloud, and Baidu AI Cloud. Today these companies power much of China's online economy, from providing digital services to government agencies, banks, manufacturers, e-commerce platforms, and healthcare systems to the AI models being trained on top of them. Cloud infrastructure became an extension of national industrial policy, not a byproduct of market competition.
From a Chinese administrator’s point of view, this approach worked. The country no longer depends on American cloud companies to run its digital economy. Much of its AI work now happens on local infrastructure. The government also has strong control over important computing systems. Chinese companies continue to spend huge amounts of money on chips, networking equipment, AI hardware, and cloud software.
Yet these achievements came with substantial cost.
However, it came with a cost. Over time, China’s internet became increasingly separated from the rest of the world because of what is known as the Great Firewall. Google, Facebook, and Twitter were no longer available. Many other global digital services have also become hard or impossible to use. Information became more limited. Working with people across borders became harder. Foreign startups often struggled to enter China, and Chinese startups often struggled to grow outside China. Innovation still happened, but mostly inside China’s own closed digital world.
The price to be paid was not only economic. They were social and intellectual. It was another opportunity for the state to exert its authoritative control over its citizens, and political censorship became more routine while scientific collaboration became more constrained and academic openness diminished.
China demonstrated that technological sovereignty can certainly be achieved. But it also demonstrated that sovereignty bought through isolation carries significant long-term costs.
India should learn from China's perseverance but not from its seclusion.
Europe: Sovereignty Settled Down for Regulation
I understood Europe’s approach in a very different way. I once watched a friend in Europe hesitate before clicking “accept” on a website. It was not because the button was confusing. It was because she genuinely wanted to know where her data was going, who would use it, and whether she had any say after giving it away. That small moment stayed with me. In Europe, digital sovereignty was not just about keeping foreign companies away. It was about protecting ordinary people and giving them some control over their own digital lives.
This attitude towards digital privacy and protection is inherent in European culture and mindset. European history features regimes that used mass surveillance and data tracking to identify and oppress citizens. This created a cultural memory were keeping personal information private is seen as a crucial defense against tyranny. [3]
That instinct shaped how Europe responded to the same digital sovereignty problem.
Unlike China, Europe was already part of the open global internet. Its markets were open, and American technology companies had already become very powerful before European cloud companies could reach the same size. So, Europe did not try to build a wall around its digital economy or create national champions in the same way China did.
Instead, Europe responded in a different way. It focused on building rules and guardrails curtailing American corporations' access to its citizens' data by protecting privacy, keeping big platforms in check, managing how data is used, protecting consumers, and making digital markets fairer.
The best example is GDPR, the General Data Protection Regulation. It became one of the most important privacy laws in the world and forced technology companies everywhere to take personal data more seriously.
All good so far. European regulators proved capable of shaping global technology behavior. Until the realization struck that regulation alone could not create infrastructure.
This realization eventually produced Gaia-X.
I remember first reading about Gaia-X and thinking, “This sounds exactly like the kind of thing Europe should be able to do well.” The idea was simple enough to understand. Europe did not want every company, hospital, factory, university, and government office to be completely dependent on a few American cloud giants. It wanted a trusted European way to share and store data, where users would know who held their data, what rules applied to it, and whether it could move safely between different providers.
On paper, it sounded very attractive. Gaia-X was not meant to become one giant European cloud company. It was supposed to create a federated system, where many cloud providers and data services could connect through common standards. In plain English, the dream was this: a German manufacturer, a French hospital, an Italian energy company, and a Dutch research lab should be able to share data securely without losing control over it.
Hans Schnieder, a mid-sized factory owner in Stuttgart, was reading the report from a consulting company that had proposed modernizing its digital systems. It said the machines can become smarter and more efficient if they share production data with suppliers, logistics partners from France, and AI companies from the US. More than getting excited about the potential, he worried about the risks in typical European mentality. What if his data ends up with a competitor? What if a foreign cloud provider changes the terms later? What if the law changes and he is stuck? Doubts emerged about Gaia-X before it came out of the drawing board.
The founding members of the Gaia-X initiative tried to address this concern. i.e. to convince Hans that he would not have to choose between innovation and control. He could use cloud services, share data, join digital supply chains, and still have clear rules around trust, transparency, and sovereignty. That was the emotional appeal of Gaia-X. It spoke to a very European concern: progress is welcome, but it must come with guardrails.
Around the table sat a German factory association, a French cloud company, an Italian energy group, a Dutch research institute, a Spanish regulator, a Polish cybersecurity official, and two lawyers from the European Commission at the inaugural Gaia-X execution meeting in Brussels. Everyone began with the same friendly sentence: “We all agree Europe needs digital sovereignty.” For the first twenty minutes, the room felt hopeful. Then the real questions began. The German side wanted strong industrial data rules while the French company argued for safety nets for European cloud providers. The Dutch institute only cared about open standards, and the Spanish regulator was most interested in consumer safeguards. The cybersecurity experts from Warsaw sought enforcement of strict certification requirements. The EC lawyers requested language that could be enforceable in courts all over the world. By the second day, nobody was arguing about Gaia-X. They were all arguing against each other for different versions of it. There was the promise, a simple one, but Europe had too many voices, too many interests, and too many layers of approval for the execution to move rapidly.
You can see this type of pattern emerge if you put a few smart people in a room with their own agenda and interests to solve a common problem. The initial sessions will feel full of energy and enthusiasm. Consensus may quickly emerge on big philosophical concepts such as trust, openness, interoperability, and sovereignty. Then the real trouble begins, and people ask who will own what, who will pay, whose standard will be used, who will certify the system, and who will be liable if something goes wrong.
The weeks turned into months. New working groups appeared, which formed review boards. The activity was limited to the boardroom discussions, deadlines slipped, and no actual code was being produced. Everyone was getting frustrated; there were incidents of ugly bureaucratic maneuvering. According to internal reports published by POLITICO, a French board member managed to essentially "wrest control" of communications away from the project's own chief executive. [4]
There was another awkward twist. European cloud providers wanted a strict "walled garden" to reclaim digital sovereignty. However, massive European corporate buyers (like BMW and Deutsche Telekom) heavily relied on US tech and insisted that American hyperscalers be included. [5] In late 2021, Yann Lechelle, the CEO of Scaleway, announced that the company would not renew its Gaia-X membership, complaining that the "pure intent of Gaia-X is unlikely to be achieved" because the organization's definition of "sovereignty" had been watered down to accommodate US tech giants. Rather than persist with negotiations to solve the battle for strict European exclusivity, they chose to walk away entirely. [6]
Over time, Gaia-X wasn’t going to solve the hard infrastructure problem. It did not create a European Hyperscaler that could compete with the scale, product depth, engineering speed, and capital spending of the American giants. It was at best a trust and governance framework. It helped Europe define how data sharing should work, what transparency should mean, and how cloud services could be judged against sovereignty principles. That mattered in some sense. It gave policymakers, companies, and regulators a shared language as an escape route.
This is the simple lesson I took from Gaia-X. Europe spent a lot of time designing the fence around the house. It cared about the gate, the locks, the cameras, the access rules, and who was allowed to enter. All of that mattered. A house without a fence can be unsafe. But Europe forgot the harder part: someone still had to build the house itself.
For India, this is the warning. We should absolutely care about the fence. We need rules for interoperability, transparency, privacy, and accountability. We need gates, locks, and clear security. But we cannot mistake perimeter security for ownership. If India wants real digital sovereignty, it must also build the house: the cloud, the data centers, the operating teams, the engineers, the financing, and the customer base that make sovereignty real in everyday life.
The Gulf: Sovereignty Through Strategic Partnerships
In 2023, a partnership was announced to build the first hyper-scale data center in Egypt, and first for Middle East and Africa region [7] It was part of the Vision 2030 developed by Saudi’s young deputy crown prince, Mohammed bin Salman, in 2016. Vision 2030 explicitly places technology, AI, and cloud infrastructure at the epicenter of this transformation.
For nearly three-quarters of a century, Saudi Arabia operated on a simple formula: pump oil, generate wealth, and fund a massive public sector. The state provided citizens with lifetime security, heavily subsidized utilities, and tax-free living. But by the mid-2010s, that formula cracked. They were staring down a dreaded future.
Global commodity markets took a violent downturn, causing crude oil prices to plunge from over $100 a barrel down to less than $30. GCC’s financial reserves began depleting rapidly. This served as a catalyst that triggered them to embark on a long journey to break down the Golden Chains of Oil.
They couldn’t follow the previously discussed models. They didn’t have China’s scale. They didn’t possess Europe’s well-developed internal market. So, they had no choice but to partner. Instead of pushing global hyperscalers out, Gulf governments invited them in, but with a purpose. The idea was not simply to buy cloud services. It was to make the hyperscalers build real capacity inside the region.
Together, several companies contributed different pieces of the same puzzle. AWS brought broad infrastructure and developer services. Google brought data, AI, analytics, and sovereignty controls. Microsoft brought enterprise cloud, productivity, government relationships, and AI adoption. Oracle brought database and business-system continuity. The Gulf used all of them to compress time. Instead of spending fifteen years building everything alone, it used foreign platforms to accelerate cloud adoption immediately.
But the Gulf did not just open the door and let the hyperscalers do whatever they wanted. The governments wanted partnerships, but they negotiated hard to retain proper control. Knowing the Prince’s authoritative style of functioning from a business interaction I personally had with him many years ago, I can imagine how this would have gone. “You are welcome here to do business with us,” they would have asserted, “but this cannot just be a sales opportunity for you. Our data must be in the region. Our regulators must know how the systems are run and our people must be trained such that when you leave, there should be enough capability in this region to operate it on our own, if needed.” That was the real bargain.
It was a smart strategy to use foreign expertise to accelerate capability while building domestic capacity in parallel, thus avoiding permanent dependence.
This approach has reduced time-to-market while preserving long-term strategic flexibility. Whether it ultimately succeeds in helping them meet their goals remains unknown until another few years. A friend of mine, Ajeesh, who works in an IT company in that region, has seen the initial buildup by foreign hyperscalers and eventual knowledge transfer. But he still doesn’t feel in full control. He can only operate using the tools provided to him by these international organizations; he can’t develop a fundamental capability on his own. So, one thing is for sure. Domestic technological capability cannot simply be purchased or rented; it must eventually be developed. So, we shall see where they eventually land.
At any rate, the most important thing is that countries such as Saudi Arabia and the United Arab Emirates recognized that digital infrastructure would become essential to economic diversification beyond oil. Rather than merely hoarding and dealing in consumer goods, Saudi Arabia has leveraged Vision 2030 to turn itself and its allies into an independent tech corridor. By investing in regional AI hubs, sovereign clouds, and large data center projects, including huge hyperscale projects in Egypt, the Kingdom is trying to turn its location into a digital crossroads that connects Europe, Asia, and Africa.
The Gulf experiment does demonstrate an important principle. Strategic partnerships need not imply permanent dependence if accompanied by deliberate capability building.
India: Sovereignty Through Scaling and Awareness
Three Insights for India
If studied together, these three experiments reveal three vastly different approaches that took different pathways and shall likely produce different end results.
China coerced autonomy for its digital operating system, took a rigid, autocratic approach to it and is likely to achieve the goal while alienating the rest of the world. Europe strived for automation, looked for consensus, cooperation, and compromise from everyone, and is likely to only build the fence and never own the house. The Gulf chose speed, using partnerships to advance quickly while never intending to fully own what it built.
Each model has its own pros and cons while reflecting unique national circumstances. None of these can be directly imitated in India.
India’s context is quite different. Unlike China, India values its open democracy and collaboration with other countries. Unlike Europe, it has a scale and collective spirit that can drive things to conclusions. And unlike the Gulf, it has homegrown talent that can do almost anything on its own. This has been proven already in other areas. Aadhaar and UPI are just a few examples. India has repeatedly shown that ambitious digital public infrastructure can move from vision to nationwide deployment. Its diaspora leads engineering teams inside nearly every major global technology company.
What remains missing is the national zeal for complete digital sovereignty.
The Indian Edge
India, therefore, begins from an unusually favorable position with a massive domestic market, an entrepreneurial technology sector, world-class engineering talent, growing AI demand, existing digital public infrastructure, experience in operating XXXL-scale systems, strong democratic institutions, and finally, a powerful and influential diaspora in the IT sector.
These ingredients did not exist together for China twenty years ago when they started. Europe will never have all these elements. Gulf may have some or perhaps even all of them but not on this massive scale.
So, India's challenge is therefore not capability. It is determination. Can the nation align around infrastructure whose returns may take a decade to fully materialize? Can the administration provide the space and opportunity for public and private organizations to come together and make this happen?
The objective should not be to merely build another cloud company. It should be to build the digital foundation upon which future generations of Indian companies, researchers, governments, and citizens can innovate without asking permission from infrastructure they do not control. The countries discussed in this chapter have already spent billions of dollars conducting experiments in digital sovereignty. India has the privilege of learning from each of them.
The next chapter turns from international experience to the practical question that follows naturally:
If India were to build its own hyperscaler, what would it take?
[2] https://ginterfaces.com/the-silent-tech-purge-chinas-plan-to-replace-all-western-software-by-2027/
[3] https://hgs.com/blog/data-privacy-world-war-ii-shaped-the-evolution-of-privacy-laws/
[5] https://lawcat.berkeley.edu/record/1257873/files/37-2-Full-Issue-r-2-9.pdf
[6] https://www.politico.eu/article/chaos-and-infighting-are-killing-europes-grand-cloud-project/