Digital sovereignty: why regulating AI is not enough
Digital sovereignty is no longer a concept reserved for cybersecurity specialists or geopolitical forums. In the age of artificial intelligence, it concerns the functioning of economies, the security of infrastructure, the ability of democracies to decide their own technological future and, increasingly, people’s everyday lives.
Roberto Baldoni is one of the scholars who have contributed most to bringing these issues from the field of computer science into public policy and international relations. Honorary Professor of Computer Science at Sapienza University of Rome, he has worked extensively on distributed and dependable systems, cybersecurity and the security of digital infrastructure. He was the founder and first Director General of the National Cybersecurity Agency and Deputy Director General of the Department of Information for Security, with responsibility for cybersecurity. Today he is Senior Advisor for Technology and Cybersecurity Policy to the Italian Ambassador to the United States.
On the sidelines of the event “Digital Sovereignty in the Age of AI”, hosted at Politecnico di Milano, we interviewed him about the concrete meaning of digital sovereignty for Europe, the technological dependencies created by globalisation, the relationship between regulation and industrial capacity, and the role that universities and research centres can still play in a landscape dominated by large platforms, cloud services, data centres and artificial intelligence models.
For Baldoni, the starting point is clear: over the past century, energy has been the critical resource par excellence; today, while energy has not ceased to be critical, the entire technological stack underpinning the digital transformation has also become so. And the decisive question is how far democracies are able to govern it, without retreating into unrealistic forms of autarky.
Professor Baldoni, the title of the event refers to “digital sovereignty in the age of artificial intelligence”. What does this mean in concrete terms for an advanced democracy, and for European democracies in particular?
It means treating the entire technological stack, from energy and critical minerals to semiconductors and data centres, from telecommunications to artificial intelligence models, as a critical resource.
In the last century, energy was the critical element par excellence. Over time, however, the digital transformation has made the entire technological stack the backbone of our society: for the economy, of course, but also for relationships and everyday life.
Why is this technological stack so different from the strategic resources of the past?
The complexity is very different from that of oil supply in the last century. In that case, we had linear, relatively simple supply chains that made it possible to support national supply chains.
Today, after globalisation, we have globalised supply chains. And each of the layers I mentioned has its own supply chain in turn. The complexity is immense: a political decision taken by a country, even one very far away, in a particular sector can have an impact on a country on the other side of the world.
This is where strategic autonomy comes into play. In an interconnected and interdependent world, the degree of digital sovereignty also depends on how a country is positioned within global supply chains. The more involved it is in these chains, the greater its negotiating power.
Within this negotiation over strategic resources, where does Europe stand today? How far have we come?
Unfortunately, Europe is in a poor position today. During globalisation, it delegated, and often moved abroad, many industrial capabilities. At this point, however, there is a need for strong industrialisation geared towards artificial intelligence models: data centres for training, data centres for managing prompt traffic, infrastructure for generating new models, for generating agents and for orchestrating them.
We have moved from a strong industrial system, that of the 1980s, to a predominantly regulatory system.
Why is a purely regulatory approach not enough?
Regulation follows two fundamental rules: it is extremely complex to regulate what you do not produce and it is extremely complex to regulate what you do not understand.
When we think about regulations such as the AI Act, at least the part introduced after the advent of ChatGPT, we need to consider this problem: you cannot fully regulate what you do not understand. We still do not really know how these statistical machines work. It is as though we had regulated electricity before understanding Maxwell’s equations.
One day, someone will explain to us in greater depth how these machines work, and then we will certainly be able to regulate them better.
Does this mean that artificial intelligence cannot be regulated today?
No. This does not mean that what we already understand cannot be prohibited or regulated today.
I am thinking, for example, of social scoring applications, facial recognition, bias in training data, and the watermarking of content generated with artificial intelligence, including images. These are aspects that were part of an initial version of the AI Act and must be safeguarded. Other parts, however, should be thoroughly reconsidered.
In this scenario, when we talk about digital sovereignty, we are not necessarily talking about closure or protectionism. In what sense?
Two approaches can be envisaged. The first is to take the AI stack, meaning the entire technological stack, and rebuild it “at home”, with local supply chains. But this is not simple and, above all, it is extremely costly.
Global supply chains developed around the principle of minimising costs for users. The moment a decision is made to produce everything within a given territory, costs rise. Nor is it necessarily the case that the result will be better in terms of quality, because scale is a fundamental factor, both for quality and for costs.
So strategic autonomy is not the same as technological autarky?
Exactly. For certain specific areas linked to national and European security, it is certainly necessary to build technological stacks that are as independent as possible. But for the civilian sphere, I believe another approach is important, one that brings all democracies together. This is what I call the trusted technologies approach.
The idea is that supply chains should be located within countries that share certain fundamental values, starting with freedom.
What makes a technology “trusted”?
A decisive aspect is contestability. If a company supplies me with a certain product, which I then use to build a service or a final product, it is essential that the company operates within a democratic legal system. I must be able to challenge its product, I must be able to carry out audits, and there must be a judge to whom I can turn.
In my view, these elements are no longer optional. During the pandemic, and still today, we have seen that dependence on systems that do not share these fundamental values can become a risk for society as a whole.
Is it realistic to imagine this alliance among democracies at such a fragmented geopolitical moment?
Naturally, saying this at a time like the one we are living through is complex. Democracies themselves are deeply divided. But we must work beyond political cycles, with a longer-term vision.
I believe that in every democratic country there are men and women who think in this way, and we must try to bring them together before the divisions become so deep that each of us goes our own way.
If everyone goes their own way, scale is reduced. And if scale is reduced, there is a risk of losing the technological challenge to autocracies, China first and foremost.
Is this a challenge that concerns Europe alone?
No. It would not be Europe alone that lost it: in the long term, the United States would also risk losing it.
The United States would hold out longer because it is stronger technologically, structurally and financially. But compared with the vertical integration of a government such as China’s, it is difficult to stay the course and win the challenge across every layer of the technological stack and in every sector.
We are at Politecnico, and there are many students in the audience. What role can universities and research centres play? And what skills will be needed?
The most honest answer is also somewhat negative. For several years, research has partly moved away from universities and public research centres.
This process began with the cloud at the end of the last century, and today it creates many problems in the talent pipeline. Some American companies are organising in-house postdoctoral programmes specifically for the people they hire.
What, then, remains for academia?
Academia remains extremely important for several reasons. First of all, it is one of the few independent auditors of these new technologies, particularly artificial intelligence. It can define important benchmarks for comparing how different models and technologies work, against parameters ranging from ethical aspects to other assessment criteria.
Moreover, universities remain the place where long-term research can be carried out. Some concepts, from neural networks to transformers, took decades to mature. They are not the results of research that is immediately productive. In this sense, universities, and Politecnico as one of the emblems of technology at national and European level, can certainly play their part.
It is clear, however, that compared with forty years ago, the research landscape is much more complex.
Should artificial intelligence still be thought of primarily as research?
We need to understand that artificial intelligence is an industrial factor. Naturally, it includes a research component, as is also the case in the automotive sector, and in AI this component is much larger. But in Europe, it is essential to understand that artificial intelligence is not only research: it is industry, it is the transformation of industrial society.
Sometimes we think of a kind of “CERN for AI”, and this may also be an interesting prospect. But we must remember that we have real problems to address. And these problems concern the artificial intelligence industry.
Digital sovereignty, then, does not coincide with the illusion of producing everything within one’s own borders. Rather, it is the ability to understand where critical dependencies lie, which supply chains cannot be left to cost considerations alone, and which technologies must be trusted, contestable and verifiable. In the age of artificial intelligence, this ability becomes a form of political autonomy.
For Europe, the challenge appears twofold. On the one hand, it must continue to defend its democratic values in the technological sphere as well. On the other, it must once again build industrial capacity, infrastructure, skills and scale. Because regulation remains necessary, but it is not enough. And because, as Baldoni suggests, you cannot fully govern what you do not produce and do not understand.