Back to Blog Lobby

From Privacy to Sovereignty: How PETs Are Evolving to Enable Digital Sovereignty

From Privacy to Sovereignty: How PETs Enable Digital Sovereignty

We’ve spent years in the Privacy-Enhancing Technologies (PETs) space. The label is accurate, and the name is functional. These are technologies that enable sensitive data to be used and computed on while remaining protected, allowing organizations to derive value from data and models without exposing them.

But increasingly, the “privacy” label feels too narrow for the much broader range of use cases these powerful technologies can enable.

Privacy is fundamentally about control: who can access information about us, how it can be used, and under what conditions. In that sense, privacy can be viewed as sovereignty at the level of the individual.

But in the digital realm, the same technologies that protect the use of sensitive individual data can also protect the use of sensitive data and digital assets at the enterprise and national levels.

Enterprises need sovereignty over their sensitive data, models, intellectual property, AI workloads, keys, and policies including when those assets are used on infrastructure they do not own.

Nations need sovereignty over strategic data, AI capabilities, and critical digital operations even while depending on global technology supply chains, commercial infrastructure, and collaboration with allies.

At each level, the fundamental challenge is remarkably similar:

How do you benefit from an ecosystem you do not fully control without surrendering control over what is yours?

Digital Sovereignty Is Becoming a Business Imperative

This question is becoming increasingly urgent.

Organizations today operate across public clouds, SaaS platforms, specialized AI infrastructure, external models, technology providers, partners, and national borders. They increasingly depend on digital infrastructure that they neither own nor fully control.

At the same time, shifting geopolitics, the rapid acceleration of AI, supply-chain volatility, concerns over technology-provider jurisdictions, and extraterritorial legal reach are changing how organizations think about these dependencies.

This is driving the growing focus on Digital Sovereignty.

For an organization, Digital Sovereignty is fundamentally about retaining control and authority over its digital assets and operations, even when the underlying infrastructure is not fully under its control.

And sovereignty extends well beyond data residency. It encompasses control over data, models, AI workloads, intellectual property, cryptographic keys, and policies. It includes the ability to determine who can access these assets and under what conditions, and the operational freedom to move workloads, change providers, collaborate across boundaries, and respond to disruption without surrendering control.

According to Gartner’s 2026 Hype Cycle for Digital Sovereignty, 70% of senior business executives now view technology sovereignty as a critical priority. It is easy to understand why. Maintaining control over sensitive data, models, and intellectual property is becoming a board-level imperative precisely as organizations become more dependent on infrastructure and ecosystems outside their direct control.

Sovereignty Has Traditionally Meant Infrastructure

Most people still tend to equate sovereignty with physical location and ownership: a private data center, a dedicated cloud region, sovereign infrastructure, or a walled estate you could point to on a map and say, “everything in here is under my control.”

That approach provides one form of sovereignty. But it also creates an increasingly difficult tradeoff:

Organizations can embrace public cloud, global technology providers, and specialized AI infrastructure to gain scale, innovation, and access to the latest capabilities while accepting greater external dependencies.

Or they can seek sovereignty through isolation, limiting where workloads can run and which technologies they can use.

Scale and innovation on one side. Control and sovereignty on the other.

Moving toward one has traditionally meant giving ground on the other.

And the problem is becoming more complicated. Sovereignty concerns today extend beyond where a server is located to who manufactures the hardware, who operates the infrastructure, which jurisdiction governs the provider, who controls the cryptographic keys, and who may have the technical or legal ability to access sensitive assets.

But sovereignty does not necessarily require eliminating these dependencies or trusting every party involved with everything. An organization may trust a provider to operate its infrastructure, deliver compute, and maintain availability, without having to trust that provider with access to its sensitive data, models, or intellectual property or with the ability to surrender those assets to another authority.

This raises a different and more nuanced question:

What if sovereignty were not about whether we trust the infrastructure, but about precisely what we need to trust it for?

From Infrastructure Sovereignty to Workload Sovereignty

This is where PETs begin to play a much larger role.

PETs make it possible to introduce granularity into trust: to rely on infrastructure for the functions it needs to perform, while cryptographically protecting sensitive assets from access that is neither required nor authorized.

In doing so, PETs can change the sovereignty equation by allowing control to move from the infrastructure to the workload itself.

Instead of relying solely on the infrastructure operator to enforce protection, controls can be embedded cryptographically into the data, models, and workloads themselves.

Control can travel with the workload.

This means sovereignty no longer needs to be determined solely by who owns the data center or operates the cloud. Organizations can reduce the degree to which they must trust the infrastructure, network, or service provider hosting their workloads.

Sensitive data and models can remain protected during active use. Access can be cryptographically constrained. Keys release can remain under the organization’s control. Policies can govern where and under what conditions workloads execute.

This creates the possibility of something fundamentally different:

Sovereignty without isolation.

Organizations can use distributed and multinational infrastructure, collaborate across institutional and national boundaries, and benefit from external technology ecosystems while retaining stronger control over their critical digital assets.

AI Makes Sovereignty Even More Urgent

Nowhere is this more important than AI.

Organizations increasingly want access to the strongest models and the most advanced specialized compute. Much of that capability resides on public cloud infrastructure and within technology ecosystems they do not own.

At the same time, AI workloads bring together some of an organization’s most valuable digital assets: proprietary data, sensitive prompts, models, algorithms, business logic, and intellectual property.

Keeping everything within organization-owned infrastructure may provide greater control, but it can also restrict access to compute, models, innovation, and scale.

The alternative should not have to be surrendering control.

PETs can enable organizations to use external AI infrastructure while maintaining cryptographically enforced protections over their data, models, and workloads.

This is particularly important for AI sovereignty because the organization that operates the infrastructure does not necessarily need to be the organization that controls the workload.

The provider can operate the infrastructure while the customer retains control over its data, models, keys, policies, and access decisions.

That separation could become fundamental to how Sovereign AI is built.

One Principle, Three Levels of Sovereignty

Seen through this lens, the evolution of PETs is perhaps less surprising.

At the individual level, PETs protect personal information and enable privacy, helping individuals retain control over how their data is used.

At the enterprise level, the same technologies can protect proprietary data, models, intellectual property, and workloads enabling organizations to operate across infrastructure and organizational boundaries without surrendering control.

At the national level, they can help protect strategic data and AI capabilities while allowing governments and institutions to use global technology ecosystems and collaborate across national boundaries.

The technology may differ depending on the use case, but the underlying principle is the same:

Enable use without surrendering control.

Privacy was one of the first and most important manifestations of that principle.

Digital Sovereignty is the broader one.

From PETs to SETs?

We have seen this evolution developing for some time, but the market increasingly appears to be arriving at the same conclusion.

Analysts who have followed these technologies for years are now explicitly connecting them to sovereignty. Gartner’s 2026 Hype Cycle for Digital Sovereignty rates Fully Homomorphic Encryption as Transformational and Confidential Computing as High Benefit, and lists Duality among the vendors in this space.

Gartner also makes an important observation: absolute technological sovereignty is an unachievable goal for most organizations. Sovereignty is therefore a spectrum that organizations need to actively manage.

That makes the role of these technologies even more important.

If sovereignty cannot realistically mean owning every component of the technology stack, manufacturing every processor, operating every data center, and eliminating every external dependency, then organizations need another mechanism for maintaining control across those dependencies.

This is why the “PETs” label has started to feel a size too small.

Privacy-Enhancing Technologies describes a specific purpose for protecting data, It says much less about the much broader job they are increasingly needed to  perform.

Protecting data and models from exposure is not only about privacy. It is about control, resilience, operational freedom, and the ability to use critical digital assets beyond infrastructure, organizational, and national trust boundaries without giving up authority over them.

Perhaps we should start thinking about PETs as something broader: 

Sovereignty-Enabling Technologies – SETs.

Technologies that allow individuals, organizations, and nations to participate in increasingly interconnected digital ecosystems while retaining control over what is theirs.

Or, put more simply:

Operate anywhere. Collaborate across boundaries. Remain in control.

So, are PETs evolving into SETs?

We’d be interested to hear what you think.

Sign up for more knowledge and insights from our experts