THE SCENARIO
The Republic of Nivara, a middle-income democracy of 45 million people, had pursued a deliberate policy of digital openness for two decades. Its trade agreements with the Meridian Bloc — three large economic zones that collectively controlled 68 percent of global cloud infrastructure — included generous provisions for cross-border data flows, standard contractual clauses, and mutual recognition of digital standards. Nivaran officials believed these arrangements would attract investment, accelerate AI adoption, and position their country as a regional technology hub.
In early 2026, a routine audit of Nivara’s national health data repository revealed something alarming. Over a seven-year period, nine Meridian Bloc technology firms had, through the legal architecture of those very trade agreements, extracted roughly 2.3 petabytes of citizen data — including biometric records, genomic sequences from a national health screening programme, crop yield data from state-subsidised farms, and real-time mobility patterns from public transport infrastructure. The agreements, Nivara discovered, contained no sunset clause on data use. The companies owned derivative datasets, trained foundation models on Nivaran cultural and linguistic data, and were under no obligation to share the value created. Nivara’s sovereignty had been traded away not through invasion or coercion, but through clauses buried in trade schedules its parliament had approved without a single amendment.
The Nivaran trade minister’s response — that the country could simply ‘build its own AI’ — was met with an uncomfortable reality. The Meridian Bloc had negotiated, as a condition of its trade agreements, that domestic cloud providers use Meridian-compliant chips, Meridian-recognised encryption standards, and Meridian-certified data centres. Nivara’s digital infrastructure was effectively a managed estate. Its sovereignty was not lost in a single moment of crisis. It had been surrendered in incremental, contractually binding, and fully legal transactions.
The Question
When every commercial agreement, every data-sharing framework, and every digital trade treaty is silently redrawing the boundaries of national sovereignty, how does a country assess whether it still controls its own digital destiny — and what can it do before the moment of discovery becomes a crisis?
The scenario above is a composite, but every element in it is drawn from actual provisions in existing trade agreements. The Comprehensive and Progressive Agreement for Trans-Pacific Partnership (CPTPP), the US-Mexico-Canada Agreement (USMCA), the Digital Economy Partnership Agreement (DEPA), and the EU’s General Data Protection Regulation (GDPR) each contain language that, combined, creates the architecture for what this article terms governance capture through data. The question is no longer whether data will be the currency of the next trade war. It is whether your country’s negotiators recognise that the war has already begun.
Part One: Data Sovereignty — The Fourth Dimension of Statehood
Traditional sovereignty rests on three pillars: territory, population, and government authority. The TEE Method™ — Territory, Exchange, Enforcement — provides a structured framework for analysing a fourth pillar that no Westphalian treaty anticipated: data sovereignty. This is not merely about where data is stored. It is about who controls the rules under which data moves, who profits from its use, and who can compel its disclosure.
“Data sovereignty is not a technical question about server location. It is a constitutional question about jurisdiction. When a country’s data lives under foreign law, its citizens live under foreign sovereignty — whether they know it or not.”
The first axis of the TEE Method — Territory — asks whether a nation’s data infrastructure exists within its legal jurisdiction. On its face, this appears straightforward. Yet the rise of hyperscale cloud providers has created what legal scholars call the ‘jurisdictional stack’: a single Google Cloud or AWS workload may route through data centres in three countries, pass through undersea cables owned by a fourth, and be subject to the qualified immunity provisions of a fifth via the CLOUD Act. The physical location of data is functionally irrelevant when the legal architecture that governs it belongs to another state.
Nivara’s experience illustrates the second axis — Exchange. The country’s trade agreements had, through standard contractual clauses (SCCs) and binding corporate rules (BCRs), created a one-way flow of value. Nivaran data moved outward to Meridian Bloc processors. Meridian AI models — trained partly on Nivaran data — moved inward as finished products. The exchange was nominally balanced in accounting terms. In sovereignty terms, it was structurally extractive. The TEE Method asks not just whether data moves across borders, but whether the value of that movement is symmetrically distributed.
The third axis — Enforcement — is the crux of the emerging trade war. A country may legislate data sovereignty in its domestic law, but without the practical capacity to enforce those laws extraterritorially, the legislation is aspirational. When the Meridian Bloc’s firms refused Nivara’s request to delete derivative datasets, Nivara discovered that its data protection authority lacked the technical capability to audit a foreign model’s training data. The law said one thing. The technical reality said another. Enforcement capacity — not legislative ambition — is the true measure of data sovereignty.
Part Two: Cross-Border Data Flows and the Architecture of Dependence
The tension between data localisation and data liberalism has defined digital trade policy for a decade. On one side, the US and EU have pushed for freer cross-border data flows through agreements like the EU-US Data Privacy Framework. On the other, countries such as India, China, Brazil, and South Africa have implemented data localisation mandates, requiring copies of citizen data — and in some cases all data — to be stored within national borders. This binary, however, obscures a more dangerous dynamic: the creation of what the TEE Method calls structural dependence.
Structural dependence arises when a country’s digital economy becomes technically impossible to operate outside the ecosystem of a foreign platform. Consider Vietnam’s manufacturing sector, which relies on Siemens’s MindSphere IoT platform for factory operations, or Indonesia’s logistics industry, built on Alibaba Cloud. These are not contractual relationships that can be renegotiated at renewal time. They are infrastructural dependencies — the digital equivalent of a country whose railway gauge was designed by a foreign power.
“A country that cannot route its own data, train its own foundation models, or audit the algorithms that govern its citizens has not entered the digital economy. It has been embedded within it — as a supplier of raw material, not an architect of value.”
The TEE Method’s Exchange axis evaluates this through three criteria: symmetry of data flows (do both parties derive comparable strategic value?), portability (can the country exit the arrangement without catastrophic economic disruption?), and legacy rights (what happens to data already shared when agreements end?). Most current trade agreements score poorly on all three. CPTPP Article 14.11, for example, prohibits data localisation but contains no portability mechanism. A country that joins CPTPP effectively cedes control over data movement without any guarantee that it can later reclaim that control.
The emerging battleground, however, is not cross-border data flows in the traditional sense. It is cross-border model flows. When a foundation model trained on one country’s data is deployed in another, the sovereignty implications are significantly more severe than the transfer of a raw dataset. The model contains compressed, weighted representations of the source data — and when it is deployed, it extracts new inferences about the target population that the deploying country cannot audit, challenge, or control. Trade agreements have not yet begun to address this distinction. They treat data and models as interchangeable. They are not.
Part Three: Platform Dominance and Governance Capture Through Data
The term platform dominance is conventionally used to describe market power in the commercial sense. The TEE Method applies it in a sovereignty context: platform dominance occurs when a foreign-controlled digital platform acquires the capacity to shape domestic governance outcomes through its control over data, algorithms, or infrastructure.
This is not hypothetical. In 2024, a European data protection authority attempted to audit a US social media platform’s algorithmic content moderation during a national election. The platform refused, citing conflicting obligations under US law and the EU’s own Digital Services Act — a legal standoff that the authority ultimately lost. The election proceeded with an algorithm the regulator could not inspect, trained on data the regulator could not access, making decisions that the regulator could not reverse. That is governance capture through data.
The mechanism operates through four channels:
- Regulatory asymmetry — Platforms operating across jurisdictions exploit the slowest regulator. A data protection authority in a 10-million-person country lacks the resources to challenge a $2 trillion company. Trade agreements that include investor-state dispute settlement (ISDS) provisions compound this by allowing companies to sue states for regulatory changes that affect their business models.
- Data network effects — Each additional user generates data that improves the platform’s algorithms, which attracts more users, which generates more data. Cross-border data flows supercharge this cycle, creating winner-take-most dynamics that no national market can replicate on its own.
- Infrastructure lock-in — Once a country’s government services, healthcare system, or educational institutions are built on a foreign platform’s cloud infrastructure, the switching costs become prohibitive. The platform becomes a sovereign actor within the state’s own administrative systems.
- Information asymmetries — Platforms know more about a country’s population than the country’s own government does. This includes not just personal data but aggregate insights about economic activity, social cohesion, public health trends, and political sentiment.
The TEE Method’s Enforcement axis addresses this through the concept of extraterritorial enforcement capacity. A country that cannot inspect a foreign platform’s algorithmic systems, cannot compel the deletion of data processed abroad, and cannot verify compliance with its own laws has, in practice, outsourced its enforcement function to the platform’s home jurisdiction. Governance capture is complete not when the state stops making laws, but when it becomes technically unable to enforce them.
Part Four: The Global AI Stack and Multilateral Alignment
The final domain of the emerging data trade war is the global AI stack — the layered architecture of chips, foundation models, training data, fine-tuning platforms, and deployment infrastructure that constitutes the production system for artificial intelligence. No single country controls all layers. The United States dominates chips (Nvidia, AMD, Intel) and foundation model development (OpenAI, Anthropic, Google DeepMind, Meta). China controls key segments of hardware manufacturing (Taiwan Semiconductor Manufacturing Company — TSMC, though headquartered in Taiwan) and has rapidly scaled its own foundation model ecosystem (DeepSeek, Baidu, Alibaba, Zhipu AI). The EU leads in regulatory frameworks (AI Act, GDPR) but lacks native foundation model and chip champions. Most of the Global South is a consumer of every layer.
This stratification is the central strategic vulnerability for non-aligned nations. The TEE Method’s Territory axis analyses the AI stack not as a technology market but as a sovereignty architecture. A country that deploys a US foundation model on Chinese cloud infrastructure via European middleware is potentially subject to the legal jurisdiction of all three. When each jurisdiction’s laws conflict — as US export controls on AI chips (October 2022, October 2023, and subsequent updates), China’s data security laws, and the EU’s AI Act increasingly do — the deploying country is not protected by any of them. It is exposed to all of them.
“The AI stack is the new trade route. The countries that control its layers will set the terms of digital sovereignty for the next generation — and the frameworks being negotiated today, from the Global AI Summit declarations to the proposed UN AI governance resolutions, will determine who sits at the table and who is merely on the menu.”
Multilateral alignment — the fourth axis of the TEE Method, operating across all three pillars — is the only viable response. No single country outside the major AI powers can build a complete sovereign stack. But a coordinated bloc can. Consider the following:
- Shared data trusts — A coalition of like-minded nations can pool training data — in health, agriculture, climate, and linguistics — to create sovereign foundation models that no single member could afford independently. The African Union’s Data Policy Framework and ASEAN’s Digital Masterframework 2025 both gesture toward this model but lack binding commitments and enforcement mechanisms.
- Interoperable encryption and standards — Rather than adopting either US or Chinese standards, a multilateral bloc can develop its own cryptographic and data interoperability standards, negotiating from a position of collective market size rather than individual vulnerability.
- Joint enforcement capacity — A shared digital enforcement agency, funded by member states and equipped with technical auditing capability, can level the playing field against hyperscale platforms that currently exploit the enforcement gap between jurisdictions.
- Collective bargaining in trade agreements — The CPTPP and DEPA were negotiated by blocs. But the blocs were dominated by the data-exporting powers. A sovereignty-conscious bloc — the Global South plus Europe, minus the platform powers — could rebalance trade terms, mandating symmetric data value sharing, sunset clauses on derivative data use, and enforceable portability rights.
Sovereignty Test Matrix
Apply the TEE Method™ to assess your country’s position. Score each domain from 1 (fully dependent) to 5 (fully sovereign). A total below 15 out of 25 indicates critical vulnerability.
| Domain | TEE Axis | Assessment Criteria | Score (1–5) |
|---|---|---|---|
| Cloud & Infrastructure | Territory | Can the country operate core government and economic services without foreign-owned cloud infrastructure? Are there sovereign alternatives? | |
| Data Value Capture | Exchange | Does the country retain proportional value from data that crosses its borders? Are derivative datasets subject to renegotiation? | |
| Regulatory Reach | Enforcement | Can the country inspect, audit, and compel compliance from foreign platforms operating within its jurisdiction? | |
| AI Stack Control | Territory / Exchange | Does the country have sovereign access to foundation model training, deployment, and governance? | |
| Multilateral Leverage | Enforcement | Is the country part of a coordinated bloc with shared standards, pooled data, and joint enforcement capacity? | |
| Total | Out of 25 |
Red Flag Checklist
If three or more of the following apply to your country, immediate sovereignty assessment is recommended using the full TEE Method™ framework.
- ☐ Your country’s national health, education, or financial data is stored predominantly on cloud infrastructure owned by a single foreign firm.
- ☐ Your country has signed a trade agreement containing data flow provisions that prohibit data localisation without a parallel sovereignty impact assessment.
- ☐ No domestic AI foundation model exists, and no joint initiative with peer nations to develop one is underway.
- ☐ Foreign platforms operating in your country have declined — or been legally unable — to comply with domestic regulatory requests in the past 24 months.
- ☐ Your country’s data protection authority has fewer than 50 full-time staff; the largest platform operating in your jurisdiction has more than 5,000 engineers.
- ☐ Trade agreements your country has ratified include investor-state dispute settlement (ISDS) provisions that cover data-related investments.
- ☐ There is no domestic legislation defining data sovereignty as a matter of national security, distinct from privacy or consumer protection.
- ☐ Your country imports more AI models than it exports data — and no mechanism exists to audit what those models encode about your population.
- ☐ Undersea cable landing rights in your country are exclusively held by entities subject to foreign intelligence or data access laws (e.g. the US CLOUD Act, China’s Data Security Law, or the UK Investigatory Powers Act).
- ☐ Your country’s digital trade negotiators outrank your data protection authority in treaty formulation — or your data protection authority is not at the table at all.
Threshold: If three or more items apply, the country’s data sovereignty profile requires urgent remediation, beginning with a full TEE Method™ assessment and the development of a Sovereign Data Strategy within 12 months.
Action Plan: Reclaiming Digital Sovereignty
For countries that have identified sovereignty vulnerabilities — whether through the matrix above, the red flag checklist, or real-world experience — the following action plan provides a structured response pathway.
| Phase | Timeframe | Actions |
|---|---|---|
| Assessment | Months 1–3 | Conduct full TEE Method™ audit of cloud infrastructure, data flows, trade agreement obligations, and AI stack dependencies. Publish unclassified findings. Identify critical dependencies that cannot be sustained beyond 24 months. |
| Legislative | Months 3–9 | Enact data sovereignty legislation that distinguishes data sovereignty from data privacy. Mandate sovereignty impact assessments for all new trade agreements. Require data value-sharing provisions in cross-border transfer approvals. |
| Infrastructure | Months 6–18 | Establish or designate sovereign cloud infrastructure for government data. Negotiate data centre co-location agreements with peer nations. Develop certification frameworks for sovereign-compliant providers. |
| Coalition | Months 6–18 | Form or join a multilateral data sovereignty bloc. Agree on shared standards, pooled training data for foundation models, and joint enforcement mechanisms. Commit to collective renegotiation of data provisions in existing trade agreements. |
| Enforcement | Months 9–24 | Establish a Digital Sovereignty Enforcement Agency with technical auditing capability, extraterritorial investigation capacity, and the statutory authority to compel platform compliance. Fund at minimum the equivalent of 0.05 percent of GDP. |
| AI Stack | Months 12–36 | Launch sovereign foundation model initiative, either nationally or through the bloc. Prioritise domains of strategic vulnerability: health, agriculture, climate, and critical infrastructure. Ensure open-weight access for all member states of the coalition. |
The Question, Revisited
The scenario that opened this article — Nivara’s slow-motion loss of digital sovereignty through a series of legally sound, technically innocuous, and politically popular trade agreements — is not a dystopian fiction. It is the trajectory on which dozens of nations are currently moving. The next trade war will not be declared. It will be discovered, in an audit report, in a regulatory standoff, or in a moment of geopolitical crisis when a country realises that it can no longer control the data on which its citizens, its economy, and its security depend.
The question — the same one that opened this analysis — has not changed. It has become more urgent.
When every commercial agreement, every data-sharing framework, and every digital trade treaty is silently redrawing the boundaries of national sovereignty, how does a country assess whether it still controls its own digital destiny — and what can it do before the moment of discovery becomes a crisis?
The answer lies in structured assessment, coordinated action, and the recognition that data sovereignty is not a niche concern of privacy advocates. It is the defining strategic question of the digital age. The countries that answer it now will write the rules of the next trade war. The countries that do not will discover, like Nivara, that the war has already been lost — in plain sight, in broad daylight, with their own signatures on the treaties that surrendered it.
This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future?