Digital Sovereignty and the Architecture of Extraction
We are deeply grateful to James Siguru Wahutu, Rhiannon Neilsen, and Spencer Overton, for generously sharing their expertise and guidance throughout the development of this brief.
Control over data is of the utmost importance to people and countries around the world, given the immense power that data, and the control over it, carries. The rules and authority that decide who gets that control are what we refer to as data governance. This brief argues that data governance is the foundational layer of digital harm. Before AI bias, platform manipulation, or synthetic media can be meaningfully addressed, the issue of who owns, stores, processes, and profits from a population's data, and under whose legal framework, must be resolved. Regulating outputs without regulating inputs treats the symptoms while leaving the infrastructure of harm intact.
The brief also examines the largest regulatory regimes attempting to address this problem, the American, the European, and the Chinese, and finds that digital sovereignty is fundamentally a question of structural power, and that meaningful prevention requires building legal authority, physical infrastructure, enforcement capacity, and collective forms of data governance that give populations greater control over their own data. For atrocity prevention practitioners, the implication is that the downstream harms this field already monitors, from bias and homogenization to deception and manipulation, each depend on an underlying data architecture that remains largely unregulated.