hello@tonishatagoe.com Abu Dhabi · London · Accra · New York
Digital Sovereignty

What Most People Get Wrong About Technology Dependency

<p>What Most People Get Wrong About Technology Dependency — A Sovereignty Briefing article drawing on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? by Tonisha Tagoe.</p>

THE SCENARIO

A mid-sized development bank in Southeast Asia adopted a comprehensive AI-driven credit scoring and risk management platform from a multinational technology provider. The platform promised to streamline lending decisions, reduce default rates, and meet international Basel III compliance standards. It was certified by global regulatory bodies, endorsed by correspondent banks, and implemented across the institution within six months. Two years into deployment, the bank’s internal audit team discovered something alarming. The platform’s risk models had been trained primarily on European and North American credit markets. They systematically underweighted critical local variables: informal economy participation, community-based lending patterns, agricultural income seasonality, extended family financial obligations, and rotating savings and credit association contributions. The system was not biased in the traditional sense — it was standardised for a different reality.

The bank’s leadership had not evaluated the platform for local applicability. They had assumed that international certification implied universal fitness. They had not tested the system against their own population data. When the national regulator flagged a systemic bias — rural borrowers were being denied credit at 23% higher rates than urban borrowers with equivalent financial profiles — the bank’s leadership faced a difficult truth. They were not using a tool that they governed. They were embedded in a system whose assumptions they did not own, could not modify, and could not exit without disrupting credit access for millions of citizens. The platform was not malicious. It was not intentionally discriminatory. It was standardised. And standardisation, when applied without sovereignty assessment, becomes a form of governance — one that operates beneath the level of institutional awareness.

What is your technology stack actually costing you — beyond the licence fee?

The dominant narrative around technology adoption presents a seductively simple binary: either you embrace modern platforms and reap efficiency gains, or you resist progress and fall behind. This framing is not merely incomplete — it is actively misleading. It obscures the deeper reality that every technology adoption is a sovereignty transaction, and most decision-makers are signing the contract without reading the fine print, because they do not know what fine print to look for.

Most entities will have a mixed technology profile — sovereign at some layers of the stack, dependent at others. The TEE Method™ does not require sovereignty at every layer, recognising that this is unrealistic for most entities. What it does require — and what this article explores in depth — is that every entity understands its stack position, governs it deliberately, and improves it progressively. The failure is not dependency itself. The failure is dependency that is invisible, ungoverned, and irreversible.

Part One: The Myth of Absolute Sovereignty and Absolute Dependency

The first and most damaging misconception about technology dependency is the assumption that it is binary — that an entity is either fully sovereign or fully dependent. This framing is conceptually tidy but practically useless. It creates paralysis in institutions that cannot achieve full sovereignty and equally dangerous complacency in institutions that believe they have achieved it.

A national government may own its data centres, control its network infrastructure, and employ its own software engineers — and still be dependent on a foreign foundation model provider for the AI systems that power its public services. A small startup may rely entirely on cloud infrastructure from a single provider — and still be sovereign in its data governance, its model selection, and its ability to switch providers if the terms change. The question is never “are we dependent?” It is always “where are we dependent, how deeply, and with what options for reducing that dependency over time?”

The TEE Method™ provides a structured framework for answering these questions through the Global AI Stack — an analytical model that decomposes technology dependency into seven distinct layers:

Stack LayerDefinitionSovereignty QuestionDependency Indicator
1. HardwarePhysical compute infrastructure, semiconductors, data centres, networking equipmentCan you acquire, maintain, or manufacture the physical infrastructure your systems require?Foreign-manufactured processors, leased data centre capacity
2. ConnectivityNetwork infrastructure, internet backbone, bandwidth provision, submarine cablesDo you control the networks and connectivity your systems depend on for operation?Single foreign provider for internet backbone, limited cable landing rights
3. DataTraining data, operational data, user-generated data, data storage and processingDo you own, govern, and control access to your data and the data your systems generate?Data processed on foreign servers, provider retains copies, no data sovereignty agreement
4. ModelsFoundation models, fine-tuned models, inference engines, algorithmic decision systemsCan you audit, modify, fine-tune, or build the models your systems use?Proprietary models with no access to architecture, training data, or weights
5. ApplicationsUser-facing software, APIs, integration layers, workflow toolsCan you customise, modify, replace, or build the applications that deliver AI services?No source code access, vendor-controlled feature roadmap, proprietary APIs
6. GovernancePolicies, oversight bodies, regulatory frameworks, compliance mechanismsDo you set the rules that govern AI use in your domain, or do you follow rules set by providers and other jurisdictions?Defaulting to provider terms, adopting foreign regulatory standards without local adaptation
7. TalentWorkforce capability, expertise retention, training pipeline, research capacityCan you develop, hire, and retain the talent needed to understand, govern, and build AI systems?Reliance on foreign consultants, inability to fill AI governance roles locally

The first insight from this framework is that sovereignty is rarely uniform across layers. An institution may be strong in data governance and talent but weak in hardware and models. Another may have strong application customisation capabilities but complete dependency at the governance layer. The mixed profile is the norm, not the exception. The question is whether the institution knows its profile and governs it accordingly.

The second insight is that dependency at lower layers of the stack constrains sovereignty at higher layers. If you do not control the hardware, you cannot fully control what runs on it. If you do not own the data, you cannot fully govern the models trained on it. Dependency compounds upward through the stack, which is why early intervention at the infrastructure level has outsized strategic importance.

Part Two: The Composites — How Dependency Manifests Across Institutions

The following illustrative composites are drawn from observable patterns across multiple real contexts. They represent the lived reality of institutions around the world that adopted without testing. Each profile demonstrates how dependency manifests differently depending on the entity type, the layers of the stack involved, and the governance gaps that allowed unmanaged dependency to develop.

The Financial Regulator. A national financial regulatory authority in an emerging economy adopted an AI-driven market surveillance system from a multinational fintech provider. The system monitors trading activity, flags anomalous patterns, and generates enforcement recommendations. At the application layer, the regulator appears to be in control — it configures parameters for suspicious activity detection, receives alerts, and issues directives based on the system’s output. But the model layer reveals a different picture entirely. The anomaly detection algorithms were trained on trading data from developed financial markets — New York, London, Tokyo — and systematically misidentify patterns common in emerging markets. High-frequency small-value transactions common in informal remittance corridors are flagged as suspicious. Agricultural commodity cycle patterns that would be normal in a commodities-dependent economy trigger false alerts. The regulator cannot modify the models without vendor engagement, cannot audit the training data to determine what biases have been encoded, and cannot determine what the model has been optimised for — efficiency, revenue protection, regulatory compliance, or some proprietary combination. The regulator has outsourced its judgment to a black box that was built for a different financial reality.

The National Health Service. A public health system in Sub-Saharan Africa adopted a diagnostic AI platform for tuberculosis screening, funded by an international development organisation. The platform was tested on reference datasets and achieved impressive accuracy metrics. In the field, performance degraded significantly — the training data over-represented certain demographic groups and under-represented local population characteristics. More critically, the health service discovered that it did not own the data generated from its own screenings. Every chest X-ray processed, every diagnosis generated, every outcome recorded — all that data flowed back to the provider to improve the next version of the model. The provider had the data. The provider had the model. The provider controlled the improvement cycle. The health service had the dependency. The development organisation that funded the deployment had moved on to its next project. Ten years later, the health service was more dependent than when it started — because the manual diagnostic capacity that had existed before the AI deployment had been allowed to atrophy.

The Public University. A public university in Latin America standardised on a major AI platform for all academic services — admissions processing, curriculum design, student assessment, research assistance, and administrative operations. The platform’s pedagogical models embed specific assumptions about learning that are not culturally neutral: individualised assessment, competitive grading curves, outcome-measurable progress. The university’s distinctive educational philosophy — which emphasised collaborative learning, community knowledge production, and holistic student development — gradually converged toward the platform’s defaults because the platform’s metrics became the university’s metrics. Faculty who questioned the platform’s pedagogical assumptions were flagged as “non-compliant with quality standards.” Course evaluations that used the platform’s criteria systematically favoured teaching approaches aligned with the platform’s design. The university had not been conquered. It had been standardised — and the standardisation had been invisible because it happened through the everyday use of tools that seemed neutral.

Standardisation, when applied without sovereignty assessment, becomes governance. The platform’s assumptions become the institution’s assumptions — not through malice, but through the quiet logic of infrastructural default. The most effective form of control is the one that the controlled do not perceive as control.

TEE Method™

Part Three: The Red Flag Checklist for Technology Dependency

The following ten-question checklist helps institutions assess whether they are operating with healthy managed dependency or dangerous unmanaged dependency. The questions are designed to be answerable without technical expertise — they test governance awareness, not technical knowledge. If three or more items apply, the institution is in a danger zone that requires immediate governance intervention.

  • Your organisation cannot produce a complete inventory of every AI system it currently uses without launching a dedicated audit exercise — meaning that some systems are operating below the level of leadership awareness.
  • You have no documented understanding of how your data flows through third-party AI systems — what data is collected, where it is stored, who has access to it, and under what legal framework it is processed.
  • No one in your organisation can explain, at a level sufficient for governance decision-making, how your primary AI platform reaches its conclusions — the system is a black box to those who are responsible for governing it.
  • Your contracts for AI services include no data sovereignty provisions, no explicit exit clauses, and no knowledge transfer requirements — meaning you have no contractual basis for leaving the provider.
  • You cannot estimate the cost — financial, operational, reputational, or strategic — of switching to an alternative provider for any major AI system in your portfolio.
  • Your AI systems have never been independently audited for fairness, bias, or local applicability by an evaluator who has no stake in the system’s continued deployment.
  • Training data generated by your institution’s operations flows back to the AI provider without your explicit, informed consent and without your retaining ownership of the derivative data products.
  • Your leadership team cannot name the three highest-risk AI dependencies in your institution from memory — they would need to commission a report to find out.
  • No individual or body in your organisation has been assigned explicit responsibility for monitoring and managing technology sovereignty — it is everyone’s concern and therefore no one’s responsibility.
  • Your procurement process for AI systems does not include a mandatory sovereignty assessment as a gate before deployment — technology adoption decisions are made on functionality, cost, and convenience alone.

If three or more of these items describe your institution, you are operating with unmanaged dependency that represents a material strategic risk. The risk is not that a single system will fail in a dramatic, visible way — though that is possible. The more likely risk is that the cumulative architecture of dependency will constrain your institution’s strategic options gradually, quietly, and irreversibly, until the options you thought you had are no longer available.

Part Four: The Progressive Sovereignty Path

The TEE Method™ does not demand that every institution achieve sovereignty at every layer of the stack simultaneously. Such a demand would be unrealistic and counterproductive — it would create paralysis in institutions that cannot achieve full sovereignty and guilt in those that are making genuine progress. Instead, the TEE Method™ demands progressive improvement: a deliberate, documented, and governed trajectory toward greater sovereignty over time.

The path has four stages, each building on the previous:

Stage 1: Discovery. Conduct a comprehensive AI inventory across the entire institution. Map every system, every data flow, every provider relationship, every contractual dependency, every informal tool adoption that has not been formally approved. This stage alone typically reveals that 60-80% of AI dependencies were previously unknown to institutional leadership — not because anyone was hiding them, but because no one had asked the question. Discovery is not a technical exercise. It is a governance intervention that makes the invisible visible.

Stage 2: Assessment. For each identified AI dependency, apply the TEE Diagnostic Grid™. Score sovereignty across all seven layers of the Global AI Stack. For each layer, determine: are we sovereign (we control this layer and can make independent decisions), strategically dependent (we have chosen this dependency and govern it actively), or vulnerably dependent (we depend on this layer without knowing the terms of that dependency)? Assessment produces a dependency map — a visual representation of the institution’s technology universe that reveals the architecture of dependency that previous adoption decisions have created.

Stage 3: Prioritisation. Not all dependencies can or should be addressed simultaneously. Prioritise based on three factors: strategic criticality (how central is this system to the institution’s core mission?), risk level (what is the consequence of this dependency failing or being exploited?), and feasibility of intervention (how much effort and resource would be required to reduce or restructure this dependency?). The high-priority targets are consistently: systems that process sensitive data, systems that are single points of failure for critical operations, systems with high switching costs that lock the institution in, and systems whose providers have demonstrated behaviour that threatens institutional or national sovereignty.

Stage 4: Action. Execute a progressive sovereignty plan with specific, measurable milestones and clear accountability. For each prioritised dependency, the plan must specify: the desired sovereignty outcome at each phase, the specific actions required to achieve that outcome, the individual or team responsible for each action, the timeline with defined checkpoints, the success criteria against which progress will be measured, and the contingency plan if actions fail to achieve their intended results. Action is not a one-time project — it is an ongoing governance practice that is revisited and revised as the technology landscape evolves.

Action Plan: Building Sovereignty Awareness in 90 Days

The following action plan provides a practical pathway for institutions to move from unaware dependency to active governance. It is designed to be executable without massive budgets or extensive technical expertise — it requires political will, governance discipline, and the questions that the TEE Method™ provides.

TimeframeActionDeliverableSuccess Criteria
Week 1Establish a technology sovereignty working group with representatives from technology, legal, procurement, operations, and governance functions. Assign an executive sponsor with authority to mandate cooperation across departments.Chartered working group with named members and executive sponsorGroup meets, agrees scope, identifies first priority systems
Week 2Launch a rapid AI inventory across all departments. Use a standardised template to capture: system name, provider, purpose, data inputs, data outputs, contract type, contract expiry, and known dependencies. Include both formally adopted systems and informally adopted tools.Complete AI asset register with provider mapping and dependency classificationRegister identifies at least 90% of AI systems in use
Month 2Apply the TEE Diagnostic Grid™ to the five highest-risk AI dependencies identified in the inventory. Score each dependency across all seven stack layers. Document findings and recommended priority actions for each.Five completed TEE assessments with dependency scores and action recommendationsAssessments are reviewed and validated by an independent party
Month 3Present the full dependency map and governance plan to institutional leadership. Secure approval for priority interventions, resource allocation, and ongoing monitoring. Establish quarterly sovereignty review cycle.Approved technology dependency governance plan with budget, timeline, and accountability frameworkPlan is adopted, resources allocated, next review scheduled

Part Five: Why the Window for Action Is Open — But Not Indefinitely

The prevailing narrative in the technology industry — that the architecture of AI dependency is already set, that the platforms are locked in, that the window for governance has closed — is not supported by the evidence. AI has transformed a fraction of the world. It has reached a minority of the world’s population. The majority of governments have not yet made their critical technology procurement decisions. The majority of institutions have not yet committed to platforms they cannot exit. The window for sovereignty-conscious adoption and governance remains open.

But it will not remain open indefinitely. Every adoption decision that is made without sovereignty assessment closes options for the future. Every contract that is signed without data sovereignty provisions, exit clauses, and knowledge transfer requirements establishes dependency that becomes more expensive to break over time. Every system that is deployed without testing entrenches assumptions that become harder to challenge as institutional capacity for independent judgment atrophies.

The institutions that will have sovereign technology options in ten years are the ones making sovereignty-conscious decisions today — not because they are rejecting technology, but because they are adopting it with awareness, governing it with discipline, and maintaining the capacity to adapt as their circumstances and the technology landscape evolve.

The Closing Question

The technology industry would have you believe that your only choice is which provider’s ecosystem to join. The TEE Method™ offers a different choice: to understand your dependency before you deepen it, to govern the systems you use rather than being governed by them, and to maintain the strategic option of building your own path forward.

Here is the question that every leader must answer, not with words but with governance structures that outlast their tenure:

If your institution’s primary technology platform changed its terms, pricing, ownership, or strategic direction tomorrow — would you have a sovereign alternative ready to deploy? If not, what are you doing today, this week, this quarter to build one?

This article draws on the TEE Method™ framework from SOVEREIGN: Who Owns the Future? by Tonisha Tagoe — a comprehensive guide to understanding, assessing, and governing technology dependency in the age of unexamined intelligence.

Keep Reading

Related Articles

Get in Touch
LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…

LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…