Glossary
The language needed to distinguish authority from dependency did not exist.
This glossary builds it: new instruments, restored definitions, and the operational vocabulary the field was missing.
Explore the Duology
Diagnosis, exposure, and the instruments to reclaim control.
Meet the Author
Thirty years inside the machine. Now naming what it does.
Read the Reviews
Peer-reviewed by the people this book was written for.
The Operational Vocabulary
At least eighteen definitions of digital sovereignty from the world’s leading advisory firms, and not one would survive the Survivability Condition. The language of the field was manufactured to describe managed dependency as progress.
This glossary replaces it with instruments that distinguish enforceable authority from revocable permission.
If the vocabulary does not expose the dependency, the vocabulary is part of the dependency.
Digital Sovereignty Today is Dion Wiggins’s personal blog, publishing ~5 posts a day on real-world events, developments, and shifts in digital power as they happen.
Sign up for the newsletter to be notified when it launches.
The glossary is currently being populated from definitions in Volume 1 and 2. More to come shortly.
AI Hegemony
A condition in which dependence on external AI systems and infrastructures is rendered legitimate and desirable. Authority over models, compute, updates, and decision processes remains external, while consent is secured through institutional narratives of safety, progress, and inevitability that frame alignment as responsible governance.
—
It stabilises external control by allocating legitimacy upstream of political contestation. Dependence is normalised as innovation, preserving the appearance of sovereign choice while foreclosing meaningful refusal.
Consolidated Fragility
The structural condition in which apparently distributed digital systems rest on a highly concentrated set of shared infrastructures, control planes, providers, standards regimes, network chokepoints, and supply-chain inputs. Although services appear geographically distributed and technically redundant, operational capacity remains concentrated in a limited number of underlying nodes. Disruption, coercion, or destruction affecting a small number of those nodes propagates failure across otherwise unrelated sectors, economies, and institutions.
—
In the context of digital sovereignty, consolidated fragility describes the condition in which operational continuity depends on infrastructures or authorities that lie outside the jurisdictional control or physical protection of the state itself. The condition emerges when efficiency, scale, and standardisation concentrate critical capabilities into shared platforms, amplifying systemic exposure under stress while maximising performance and reducing cost under stable conditions.
Consolidated fragility is distinct from systemic risk. Systemic risk is the cascading failure that occurs across a system. Consolidated fragility is the underlying structural concentration that makes such cascading failure possible; it is embedded in the architecture long before any failure propagates.
Control Plane Check List
An analytical checklist that locates authority by identifying who can execute, alter, or terminate a system at each control layer. It maps control over identity, authentication, compute allocation, orchestration, updates, billing, and enforcement rather than relying on stated ownership, contracts, or governance artefacts.
—
It determines whether authority survives loss of permission in practice. Where any layer cannot operate, change, or recover without external approval, that control plane is ceded. The checklist turns sovereignty claims into an executable test by showing who can act, who can refuse, and who holds the final veto.
Convenience Sovereignty
The appearance of digital sovereignty produced by uninterrupted service, stable conditions, and frictionless operation, where continuity is mistaken for control despite authority resting on an external actor’s ongoing permission, pricing, policy, or discretionary access.
—
Convenience sovereignty cannot be verified under duress by definition. It exists only while withdrawal is hypothetical. The moment access is suspended, terms are altered, licences revoked, capacity throttled, or timelines imposed that cannot be resisted or exited within sovereign tolerance, the claim collapses.
It is not a sovereignty variant, stage, or compromise. It is a misclassification error that treats operational comfort as authority. Where enforcement power, recovery time, or continuity can be unilaterally dictated by an external party, sovereignty does not exist. It has merely not yet been challenged.
Digital Sovereignty
The ultimate enforceable authority, and the practical control to carry that authority into effect, of nations, organisations, communities, and individuals (collectively, the sovereign) over the data and operational survivability, execution, governance, and recovery of digital systems.
—
This authority and control must be visible, auditable, independently verifiable, structurally secured, operationally demonstrable, and enforceable by the sovereign, with capacity proportionate to the sovereign’s scale and the criticality of the system. This capacity includes the skills, expertise, and operational knowledge required to exercise sovereign authority, which must be retained, directed, and substitutable under the sovereign’s own control.
It is a strategic capacity that must be exercised without external permission, not contingent on external authority, and carried into effect through the ability to build, operate, permit, constrain, deny, restore, migrate, substitute, or exit execution.
This capacity is compatible with voluntary participation in shared systems, markets, treaties, or standards only where entry, exit, enforcement, and remedy remain under the sovereign’s own control within a defined operational boundary and where such participation does not degrade or subordinate sovereign authority during operation. Such participation cannot be unilaterally altered, revoked, or weaponised by an external actor.
It must be enforceable under the sovereign’s own legal jurisdiction, such that disputes, interventions, audit rights, and remedies can be compelled in the sovereign’s own courts and enforcement systems, within the sovereign’s own time tolerance, and without reliance on foreign arbitration, extraterritorial law, or external discretionary authority that can prevent or indefinitely delay enforcement. Self-determination must be preserved without any form of externally imposed observation, whether overt or covert, embedded as a condition of access, operation, compliance, recovery, or continued use.
Digital sovereignty exists only where that authority and control remain effective without critical reliance on, or exposure to, any external actor, platform, vendor, jurisdiction, infrastructure, contractual condition, economic mechanism, or control path through which execution, continuity, recovery, substitution, migration, or exit can be constrained, degraded, or denied.
It fails wherever any external actor retains the capacity to withdraw, override, delay, compel, surveil, or block sovereign operation, or to impose economic, contractual, or licensing conditions that render execution, continuity, recovery, substitution, migration, or exit non-viable, by any means and through any mechanism, whether technical, legal, commercial, or operational.
Digital Sovereignty Debt
The accumulated future risk incurred when a state, institution, or society deliberately externalises control over critical digital systems in exchange for short-term efficiency, speed, or capability.
—
Digital Sovereignty Debt arises when authority over identity, system operation, lifecycle control, or escalation is delegated to external actors or foreign jurisdictions, reducing the capacity to refuse, override, exit, or recover without permission. This condition is observable in the loss of credible escalation authority and the inability to independently suspend, reconstitute, or disengage from dependent systems.
Digital Sovereignty Debt is non-monetary in nature and is not a measure of error, intent, or political values. It accumulates through lawful, consensual, and economically rational decisions and compounds over time via routine lifecycle events such as renewals, updates, integrations, and dependency deepening. Unlike technical debt, which can be reduced through refactoring, investment, or optimisation within a controlled system, Digital Sovereignty Debt accumulates through the loss of control itself and cannot be retired while authority remains externalised. As this debt accumulates, exit degrades from an operational capability into a formal right.
Digital Sovereignty Debt falls payable under conditions of misalignment, conflict of law, political rupture, or systemic shock, often at the moment when repayment is least feasible. It is frequently exacerbated by monopoly power, commercial extraction incentives, geopolitical overreach, and scale asymmetries between dominant platform providers and smaller or dependent firms. Unlike financial debt, it cannot be refinanced, inflated away, or resolved through regulation alone. Once exit and compulsion are structurally lost, repayment requires rupture rather than reform.
Digital Sovereignty Half-Life
The period over which a system’s effective authority, enforceability, and exit capability degrade by half under normal operating conditions as dependencies accumulate, in the absence of deliberate structural intervention.
—
It defines how long sovereignty remains materially exercisable before control shifts from being asserted to being assumed, regardless of intent, competence, or governance quality. Sovereignty half-life varies by control domain, architecture, and dependency profile.
Half-life is not a measure of progress, maturity, or optimisation. It is a measure of how long sovereignty survives exposure to pressure before it can no longer be meaningfully exercised.
Governance Substitution
Governance substitution occurs when formal governance mechanisms persist after operational authority has been structurally displaced.
—
Regulatory activity, oversight procedures, and enforcement instruments continue to operate in form, but no longer possess the capacity to compel, override, or refuse at the point where misalignment occurs.
Under conditions of governance substitution, authority migrates upstream into externally controlled infrastructure, platforms, contractual regimes, or foreign jurisdictions, while governance remains downstream, confined to procedural compliance and delayed sanctions.
Governance substitution is not regulatory weakness or institutional failure. It is a structural misalignment between where authority is exercised and where governance is formally performed.
Kill Switch
Any mechanism, technical, legal, or contractual, that allows a remote party to instantly revoke, disable, or terminate access to critical infrastructure, data, or services.
—
Kill switches can be embedded in software, hardware, service agreements, or legal frameworks, and triggered by vendors, governments, or regulators to enforce compliance or exert geopolitical leverage. While colloquial in origin, the concept also aligns with analyses of infrastructural power in law and political economy, where control over service continuity functions as a form of governance.
Latent Digital Sovereignty
Latent digital sovereignty occurs when a state retains formal legal authority and active governance over digital systems after the operational capacity to refuse, override, or withdraw from those systems has already decayed.
—
Authority persists in law and procedure, but no longer functions as control at the point where escalation would be required. Under conditions of latent digital sovereignty, governance activity continues while refusal authority has migrated upstream into system architectures, platforms, contractual regimes, or external control planes. The loss is typically unrecognised until misalignment or crisis exposes the inability to act without external permission or institutional rupture.
Latent digital sovereignty is not a political choice or regulatory weakness. It is a structural condition in which sovereignty survives as presumption rather than executable authority.
Performative Authority
The expression of governance, compliance, or sovereignty through policy, process, certification, or oversight structures that produce auditable artefacts without altering where control resides. It generates signals of order and accountability under stable conditions but collapses under withdrawal because no mechanism exists to compel, override, or sustain control.
—
Performative authority cannot be verified under duress by definition. It holds only while signalling is accepted as control. The moment authority must be exercised without permission, and no mechanism exists to compel, override, or sustain control, the claim collapses.
Permission Choreography
A governance mechanism through which substantive authority is converted into procedural display. Control over identity, compute, updates, money, and law is exercised through compliance regimes, audits, certifications, contracts, and procurement rituals rather than through ownership of control planes.
—
It preserves the appearance of sovereignty while relocating operational control elsewhere. By defining legitimacy through process rather than authority, it renders compliance governable and refusal illegible, allowing dependency to deepen without registering as loss of control or governance failure.

