For the better part of a decade, the debate about digital sovereignty in Australia has circled a single, seemingly technical question: where does the data physically sit? Governments wrote data-residency clauses into procurement contracts, cloud providers built local regions to satisfy them, and everyone assumed that if the servers were on Australian soil, the country was in control. A new analysis published on the ASPI Strategist argues that this framing was always a comfortable distraction, and that the artificial intelligence era has finally forced the harder truth into the open.
The harder truth, as the piece frames it, is that location was never the point. What matters is who controls the system and, ultimately, who can switch it off. A dataset stored in a Sydney data centre offers little protection if the software running on top of it, the models it depends on, and the licences that keep it operating are all governed by decisions made in another country. Sovereignty, in this reading, is not about geography at all. It is about dependency, and about whether a foreign supplier or a foreign government can quietly withdraw a capability that Australian institutions have come to rely on.
An old lesson in new clothes
The reason the ASPI analysis calls this an old lesson is that Australia has been here before with earlier waves of technology. Utilities, telecommunications and critical infrastructure all taught the same thing: control over an essential service is a form of power, and outsourcing it to a party whose interests may not align with yours creates a vulnerability that no amount of local hosting can fix. The novelty of AI is not the principle but the speed and the scale. Large language models, the cloud platforms that serve them and the specialised chips that train them are concentrated in the hands of a small number of mostly American firms, with a rising challenge from China. That concentration means the leverage sits a long way from Canberra.
The argument lands with particular force because the mechanisms of control are often invisible until they are used. A supplier can change pricing, alter terms of service, restrict access to a model, or comply with an export control or sanctions regime in its home jurisdiction. Any of those moves can degrade or disable a service that an Australian bank, hospital or government agency treats as core infrastructure. The data never leaves the country, yet the capability evaporates. That is the scenario data-residency rules were never designed to catch, and it is the one the AI age makes most likely.
Two ways to read the risk
There is a competing view, and it deserves a fair hearing. The major cloud and AI providers argue that deep integration with global platforms is precisely what gives Australia access to frontier capability it could never build alone. On this reading, trying to wall off a sovereign stack is expensive, slow and self-defeating, because it cuts the country off from the very models and compute that make AI useful. Interdependence, the argument runs, is a feature rather than a bug, and the answer is stronger contracts, clearer service guarantees and trusted partnerships rather than a retreat into autarky.
The sovereignty camp does not dispute that Australia benefits from global platforms. Its point is narrower and, in a sense, harder to rebut: benefiting from a capability and being able to lose it at someone else’s discretion are two different conditions, and prudent governments plan for the second even while enjoying the first. The disagreement is really about how much resilience is worth paying for, and where the line sits between sensible risk management and costly duplication. That is a judgement call, not a technical fact, which is why it has proven so difficult to settle.
What it means for Australia
For Australian policymakers, the practical stakes are becoming concrete rather than theoretical. The federal government has stood up a national AI framework and an office to coordinate policy, and the country is in the middle of a data-centre construction boom pitched partly on the promise of sovereign capability. Yet as FluentSea has reported, much of that build-out amounts to hosting other people’s systems rather than controlling one’s own, and the distinction is exactly the one the ASPI analysis is pressing. A data centre humming away near Tailem Bend or in western Sydney is a real asset, but it is not sovereignty if the intelligence running inside it is licensed, updateable and revocable from abroad.
The financial and public sectors are where this bites hardest. Regulators such as APRA already require banks and insurers to manage concentration risk in their technology suppliers, and the logic extends naturally to AI. If a handful of foreign models underpin fraud detection, customer service and credit decisions across the economy, then a disruption to any one of them becomes a systemic event rather than a single firm’s problem. Government service delivery carries the same exposure, which is why the recent tightening of rules around automated decision-making in agencies such as Centrelink matters well beyond its immediate context. The question of who can switch a system off is, in the end, a question about who can switch off a service that citizens depend on.
What comes next
The analysis does not pretend there is a clean fix, and neither should anyone reading it. Building a fully sovereign AI stack is beyond Australia’s means and probably beyond its needs. The more realistic agenda is a portfolio of measures: diversifying suppliers so no single provider holds a chokehold, negotiating contractual protections that survive a change of political weather offshore, investing selectively in domestic capability where the strategic exposure is greatest, and mapping exactly which critical services would fall over if a given model or platform disappeared. None of that is glamorous, and none of it fits neatly into a procurement checkbox, which is part of why it has been neglected.
The value of reframing the debate is that it points policy at the right target. For years the sovereignty conversation in Australia has been answerable with a map, showing where the servers sit. The AI age asks a question a map cannot answer, about control and the power to withdraw it. If the country absorbs that lesson properly this time, the next round of investment and regulation will be measured not by how much data lives onshore, but by how much of the system Australia could keep running if a partner decided to walk away.
Sources: ASPI Strategist.


















































