Keeping servers within national borders does not place them under national control.
A medical record can be created in Riyadh, stored in Bahrain, processed by an algorithm trained in the United States, and managed through a European subsidiary. Which state truly controls it? The conventional answer attributes the data to the individual, company, or government that generated it. In practice, ownership matters less than control. Real power belongs to whoever is able to access, process, transfer, restrict, or legally compel the disclosure of the information.
Health, defense, biometric, judicial, and civil registry data require stricter protection than ordinary commercial information. Governments must invest in interoperable regional cloud capabilities, open standards, independent auditing, and the ability to maintain essential services should a foreign provider revoke access. Above all, data sovereignty must extend beyond storage to encompass the entire chain: collection, classification, computation, access, sharing, and deletion.
In the 21st century, control over a territory will increasingly depend on control over the data that reveals its people, institutions, and resources.
Those who cannot guarantee where their data will end up do not fully govern their own territory. And with that data, literally anything can be done.
https://strategic-culture.su/news/2026/08/13/the-invisible-geography-of-israeli-power/