He does something most executives won't. He pulls apart three words that get used interchangeably by people who should know better. Privacy protects individuals. Security protects data. Sovereignty protects your ability to make decisions when the ground moves. Then he drops the line that should have cleared the room: an organization can be fully compliant and still structurally dependent.

Nine words. The whole problem.

He lists the questions nobody in the building can answer. Who reaches our data in a real emergency. Which countries' courts have a say we never agreed to. Can we leave our provider without setting the business on fire. Is our data quietly training a model we'll later rent back at a markup.

Good questions. They are also the CLOUD Act, described in full and named nowhere.

And then - this is the part - the article walks up to the door it built and knocks politely. The prescription is to put sovereignty "on the executive agenda." To have the Chief Data and AI Officer ask the hard question. To review contracts and architectures through the lens of autonomy.

The hero of the story is an executive who asks, before signing, what happens if we have to migrate in a few years. The room goes quiet. Everyone agrees it's an excellent question. They pick the more flexible vendor and go home feeling sovereign.

Here is the trouble. A better question is still just a question.

A subpoena has never once been deterred by a slide titled "Vendor Risk." A foreign court does not adjourn because your CDAIO raised a thoughtful concern in Q3. Multi-cloud is not independence — it's spreading your dependence across three landlords who all answer to the same judge. And the contract that protects you is a promise the provider makes about its own conduct, right up until a law it cannot refuse tells it to do the opposite, quietly, and forbids it from telling you.

You cannot govern your way out of a warrant.

Compliance describes how things behave while everyone is cooperating. Sovereignty is what's left when they stop. Those are not the same property, and no volume of contract language converts one into the other. The only thing that survives the exact moment Bergson is describing - the moment the context changes - is architecture. Either the provider can read your data and hand it over, or it mathematically cannot. There is no clause that lives in between.

So the question is not whether sovereignty belongs on the executive agenda. He's right that it does. The question is what you put on the agenda next to it. A governance review, or an architecture where the answer to "who can access our data in extreme situations" is a number you can actually prove.

The number is zero.

Bergson wrote the diagnosis. It's a good one. The prescription just can't be a meeting.

The Data Sovereignty Illusion: Does Your Organization Really Control the Data It Depends On? - CDO Magazine


Originally published by Ross Norrie, founder of SkyeConnex, on LinkedIn.

Published June 1, 2026 · More from the SkyeConnex blog