Britain cannot realistically build every single piece of technology it relies on. Nor, according to the experts we spoke to, should it try. But still, there’s a difference between using technology that’s developed abroad and becoming so dependent on a foreign provider that losing access to it could cause serious disruption.
This is an issue that’s becoming increasingly important as technology moves deeper into Britain’s critical infrastructure, public services and national security systems.
So, is Britain’s reliance on foreign technology becoming a national security risk? And if the answer is yes, what can Britain actually do about it?
The Real Risk Is Dependency, According To Experts
For several of the experts, the biggest problem isn’t foreign ownership itself. Rather, it’s the absence of alternatives and the access to these alternatives.
Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, argues that foreign technology can provide enormous benefits, including security capabilities that would be difficult and expensive to recreate domestically.
The problem, however, begins when a critical service becomes dependent on one supplier, technology or jurisdiction. John Harms, Head of Government Solutions at Quantexa, makes a similar point. According to Harms, keeping data in Britain doesn’t automatically make a system sovereign if the technology controlling that data remains dependent on an overseas provider. And that’s where things get rather complicated.
Indeed, this changes the question from whether or not the tech is British to whether or not Britain could function without it.
More from News
- Full Fibre Adoption Continues To Accelerate Across The UK
- OpenAI, Anthropic And Google Are Discreetly Building Their Own AI Standards Body – What Would That Actually Decide?
- How Have Digital Nomads Created A New Market For Businesses?
- England’s New Tourist Tax Has No National Cap – What Does That Mean For Hospitality Businesses?
- The EU Cyber Resilience Act Starts Today: Can Businesses Really Report A Cyberattack In 24 Hours?
- Can Binge-Watching Be Addictive By Design? Inside The State Lawsuit Against Netflix
- Could Australia’s Proposed Algorithm Rule Break The Current Echo Chamber That Is Social Media Today?
- PASS Announces Schedule Hero: AI-Powered Scheduling Built For Home Care
Some Experts Think Britain Needs An Exit Strategy
It’s not the glamorous option, especially when considered alongside the idea of building a giant British tech industry from the ground up. However, what’s more important is that it could be considerably more practical.
Evgenii Arsentev, CEO of AskDocDoc, argues that Britain should focus on making critical technologies replaceable rather than trying to recreate everything domestically. And that means open interfaces, portable data and tested alternatives.
His point is particularly relevant for governments and large organisations, which can spend years building processes around a particular provider. At that point, switching suppliers isn’t just a technical decision; it can mean replacing systems, retraining staff and rebuilding entire workflows.
Kim Larsen, CISO at Keepit, similarly argues that sovereignty starts with knowing exactly where critical data and workloads sit, who controls access to them and what happens if that access is suddenly removed. Essentially, you can’t build resilience around a dependency you don’t fully understand.
AI Is A Different Problem
AI could make this question a lot more difficult. Rob Demain, CEO of e2e-assure, argues that the UK’s dependence on foreign AI is particularly concerning because the most capable models are largely being developed by American companies, while Chinese models represent another major source of advanced AI.
For critical infrastructure, that creates a question about what happens if the AI being relied upon is suddenly unavailable, restricted or changed by the company or government behind it. Demain’s answer is to focus on the control layer. The AI that’s used to protect critical infrastructure, he argues, should be capable of running locally and under UK ownership and jurisdiction.
That doesn’t necessarily mean that Britain needs to build the world’s best foundation model tomorrow, but it does mean that critical systems shouldn’t become incapable of functioning without access to someone else’s model.
Is It Possible for Britain To Become Technologically Sovereign?
It’s tough to say, but probably not. Warren O’Driscoll, Head of Security Practice at NTT DATA UK&I, points out that Britain simply lacks the scale to achieve “top-to-bottom sovereignty”. Now, that doesn’t mean doing nothing.
O’Driscoll argues that investment should instead be targeted at areas where sovereignty matters most, particularly sensitive government operations and critical infrastructure, alongside sectors where Britain already has strong scientific and technological capabilities.
Matthew Barrington-Packer, Delivery Consultant across MOD, BAE Systems and Imperial College London, takes an even more operational approach to the issue. For him, sovereignty can’t remain an aspiration in government policy documents, because critical dependencies need owners, replacement decisions and deadlines. Ultimately, knowing that you have a vulnerability isn’t the same as fixing it.
So What Does Britain Actually Need?
Perhaps the answer isn’t sovereignty in the traditional sense at all. Raphaël Auphan, COO at Proton, argues that governments and businesses should audit their technology stacks, map their dependencies and establish fallbacks where necessary.
Matt Lloyd Davies, Principal Security Author at Pluralsight, makes the point that concentration is actually the central risk. A supplier being foreign can add geopolitical concerns, but relying heavily on one supplier is a vulnerability regardless of where that supplier comes from.
And so, the objective isn’t to stop using American, European, Asian or other international technology, but rather to make sure Britain can still operate if one of those relationships suddenly changes. In this case, the UK would have more choice, visibility, interoperability and the ability to switch if necessary.
Because Britain may never be technologically self-sufficient, and perhaps it doesn’t actually need to be. But if a country can’t replace a critical system, maintain it without outside (foreign) help or keep it running when an overseas supplier becomes unavailable, then the question of technological sovereignty stops being theoretical and starts becoming a major issue of resilience and national security.
Our Experts
- Kim Larsen: CISO at Keepit
- Evgenii Arsentev: PhD, Chief Executive Officer at AskDocDoc
- Raphaël Auphan: Chief Operating Officer at Proton
- Warren O’Driscoll: Head of Security Practice at NTT DATA UK&I
- Muhammad Yahya Patel: vCISO and Cybersecurity Advisor for EMEA at Huntress
- Andriy Dovbenko: Founder of UK-Ukraine TechExchange
- Rob Demain: CEO of e2e-assure
- Stuart Harvey: CEO of Datactics
- John Harms: Head of Government Solutions, Quantexa
- Jack Collier: Chief Growth Officer at io.net
- Matthew Barrington-Packer: Delivery Consultant (MOD, BAE Systems, Imperial College London) and Author of, “Just F*cking Ship It”
- Daniel Di Nardo: Network and Security Consultant at Intellibreach
- Matt Lloyd Davies: Principal Security Author at Pluralsight
- Lee Perkins: CEO at Civica
Kim Larsen, CISO at Keepit

“Sir Richard Dearlove is right to flag the risk, however, there’s no quick fix here. Similar to the situation across Europe, Britain won’t become independent of global hyperscalers overnight. That’s the reality we’re all working with.
“What’s changing is that awareness and the tools to manage this risk are catching up: new technologies, new vendors, and regulation are all moving in the right direction, giving organisations more options than they had even a year ago.
“And fortunately, the wake-up calls that we have had in recent years can be responded to: we can get to work on protecting critical infrastructure today, even if we do still have technological dependencies.
“It’s essentially about governance: It’s less dramatic, slightly more dull, but knowing exactly where your critical data and workloads sit, who controls access to them, and what happens if that access is suddenly cut off, is the best data protection right now. Sovereignty starts with control over your own data, not with abandoning the infrastructure you depend on for better or worse.”
Evgenii Arsentev, PhD, Chief Executive Officer at AskDocDoc

“Sovereignty arguments usually fixate on who owns the hardware. The sharper question for anyone running critical services is substitutability: if your main supplier changed terms, raised prices or went dark on Friday, what would still be running on Monday?
“For most organisations the honest answer is nothing, because the dependency was never on a product, it was on a whole way of working that grew around one vendor’s tools. That is a supply risk before it is a foreign policy one. I would not spend public money rebuilding a domestic copy of everything. I would spend it on making swaps possible: open interfaces, portable data, and at least one tested alternative for anything the country cannot do without. Dependence you can exit in a week is not a national security risk. Dependence nobody has ever tried to exit is.”
Raphaël Auphan, Chief Operating Officer at Proton

“In today’s world, digital sovereignty is no different from actual sovereignty. Sir Richard Dearlove is right: British businesses are over-reliant on technology owned by other jurisdictions. Proton’s research shows 74% of European firms fear a US “kill switch” cutting them off from their digital tools. Over half (54%) say they couldn’t survive a single day without them. This isn’t an abstract fear. Proton’s Tech Watch found that 88% of the UK’s publicly listed companies run their email on US infrastructure, directly exposed to US law.
“When an economy goes offline at another government’s whim, that isn’t just a business continuity issue, it’s a national security vulnerability. The answer isn’t necessarily British-built everything, but jurisdiction matters. As a Swiss, European company that employs engineers across the continent, including in the UK, Proton operates under laws that no Washington or Beijing administration can override. More broadly, government and British businesses must audit their tech stacks, map their dependencies, and build fallbacks in case a supplier’s politics change. This isn’t about isolationism but instead having options when the supply chain stops being neutral.”
Warren O’Driscoll, Head of Security Practice at NTT DATA UK&I

“Compared to trading blocs such as the USA, China and even the EU, the UK lacks technology manufacturing industrial capacity and is heavily dependent on providers from other shores for key infrastructure to support services including cloud, compute, security and AI. And we have a lot to lose if things go awry: our economy is built around services, which depend on digital technologies. As UK businesses roll out AI, achieving a level of sovereignty will become ever more important both to protecting economic growth, and to averting disruption to critical services.
“On the positive side, strengthening our sovereign AI capabilities could enable us to generate more value from our advanced scientific, digital and research sectors: the government is right to warn that digital inventions and innovations coming out of the UK are too often monetised in countries with stronger domestic digital infrastructures and production. Occupying the regulatory middle ground between the US and the EU, the UK can take a more flexible approach – avoiding either the EU’s regulatory rigidity or the USA’s ‘sell it first, build and regulate later’ approach, and putting it in a strong position to host digital innovators and cutting-edge research.
“So intelligently-targeted spending on sovereign AI could boost national resilience, growth and investment. These investments should be proportionate to risk – prioritising sovereignty in sensitive government operations and critical national infrastructure, for example. They should also favour high-potential sectors – focusing on fields such as biotechnologies and advanced engineering, in which we have lacked the secure, domestic capacity to scale new technologies.
“It’s important to be realistic here. The UK lacks the scale to achieve anything like top-to-bottom sovereignty, and £1.1 billion is tiny by comparison with the sums being invested elsewhere: we’ll have to accept that some elements of AI sovereignty cannot be achieved. Nonetheless, it is a helpful and positive signal as to the government’s direction of travel; we can only hope that the new administration continues on this journey.”
Stuart Harvey, CEO of Datactics

“The most important concern around digital sovereignty is about who has access to data and how this is regulated.
“The biggest challenge isn’t only the dependence on external technology providers, but also whether control is retained over the quality, governance and lineage of the data that underpins businesses and national security.”
“At its core, digital sovereignty ensures that sensitive national data is protected under national laws and oversight that is managed with clear accountability. Building UK AI capabilities is a strategic move to reduce the structural risk of relying on platforms where access can be withdrawn at any moment.”
Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress

“Britain’s reliance on foreign technology can create national security risks, but we need to be careful not to confuse foreign ownership with insecurity.
“The bigger issue is dependency. The UK benefits enormously from global technology and from trusted international partners. In some cases, major overseas technology providers offer security capabilities and resilience that would be difficult or costly to reproduce domestically.
“The risk arises when a critical public service becomes so dependent on one supplier, technology or jurisdiction that we have no realistic alternative if that service is disrupted, compromised or becomes unavailable. So, the answer isn’t simply to “buy British”. We need to identify our critical technology dependencies, scrutinise supply chains, diversify where appropriate and make sure organisations have credible contingency and exit plans.
“Ultimately, resilience comes from having options. We should be able to benefit from the best global technology without becoming so dependent on any single supplier, country or technology that its disruption becomes our crisis.”
Andriy Dovbenko, founder of UK–Ukraine TechExchange

“In a recent piece in a UK national newspaper, Sir Richard Dearlove, the former head of MI6, warned that foreign states have their ‘fingerprints all over our critical national infrastructure’. I’ve taken some time to digest those comments, and I think they raise a question Britain needs to answer: how much control do we have over the technology we would depend on in a crisis?
“My view is that technological dependence becomes a national security risk when we lose the ability to act independently. If we cannot repair a system, replace a critical component or keep a service running without an overseas supplier’s support, that has consequences for our security.
“Ukraine gives this debate a very practical context. The Russian cyberattack on the Viasat satellite network began approximately an hour before the full-scale invasion in February 2022. Britain should take that experience seriously when assessing the resilience of its own communications and critical infrastructure.
“Ukraine’s experience also shows why access to engineers, production capacity and the ability to adapt technology quickly matter so much. Buying a finished product is only part of the equation. You need the people and capabilities to keep it effective as circumstances change.
“Through UK–Ukraine TechExchange, I see considerable potential to connect Ukrainian defence innovation with British investment, engineering and manufacturing. We should be developing those partnerships with a long-term ambition: building capabilities that both countries can sustain, improve and rely on.
“For Britain, that means giving promising defence and technology companies a clearer route from trials to meaningful contracts. It means procurement decisions that take maintenance, supply chains and operational control as seriously as the purchase price. And it means testing whether alternatives actually work before we need them.
“Foreign ownership alone does not make a technology unsafe, and Britain will continue to need international partners. But we should understand exactly where our dependencies leave us exposed and invest in the capacity to address them.
“What stays with me after Dearlove’s comments is this: sovereignty has to be something we can exercise under pressure. We need to know that the systems we rely on will remain available, and that we have the skills and resources to respond when they fail.”
Rob Demain, CEO of e2e-assure

“The dependency to worry about now is AI. The most capable models are American and the companies that build them set the guardrails, hold back capability and Washington can pull access entirely. The alternative on the open market is Chinese. China is giving open-weight models because distribution is the strategy. So the real choice facing UK critical infrastructure is American models we don’t control or Chinese models we can’t put in an assurance chain.
“Britain has no answer of its own today, despite earmarking £750m for a national super computer. That won’t be fixed quickly, so the practical step is sovereignty at the control layer: AI used to defend critical infrastructure should run locally, under UK ownership and jurisdiction, on infrastructure that keeps operating if a foreign government changes its mind. That is buildable today. A British AI model is a longer project.”
John Harms, Head of Government Solutions, Quantexa

“Using international technology is not, in itself, a national security risk. The real danger is dependency. If critical public services become so reliant on a single provider that the government loses control of its data, cannot easily switch suppliers or risks disruption if that technology becomes unavailable, then it becomes a question of national resilience.
“Keeping data on British soil doesn’t automatically give Britain technological sovereignty. What matters is retaining control, visibility and freedom of choice.
“The answer isn’t to shut out global technology companies. The government should build open, interoperable technology ecosystems that allow it to choose the best technology while avoiding dependence on any one provider. True technological sovereignty means Britain can benefit from global innovation without ever becoming so reliant on a supplier that it loses the freedom to choose.”
Jack Collier, Chief Growth Officer at io.net

“Three American companies – Amazon, Microsoft, and Google – own nearly all of the UK’s cloud infrastructure. Britain talks about AI leadership, but the country’s work to train and deploy AI models runs on machines owned by these global providers. There’s no British alternative to keep them honest.
“The UK’s only homegrown public cloud provider, UKCloud, went bust in 2022 after American giants opened UK data centres and undercut them on price. In September 2025, the Ministry of Defence handed Google a £400 million “sovereign cloud” contract. A month later, HMRC awarded Amazon a £500 million contract as the sole bidder after rivals pulled out.
This creates a national security problem. Britain is increasingly dependent on foreign companies for infrastructure storing critical data. There’s also an economic cost – British businesses, startups and research projects pay high and unpredictable computing costs to the same hyperscalers, raising the price of experimenting with AI and turning ideas into viable products.”
Matthew Barrington-Packer, Delivery Consultant (MOD, BAE Systems, Imperial College London) and Author of, “Just F*cking Ship It”

“Dearlove is right about the risk but the diagnosis usually stops too early. Having spent twenty years delivering programmes across UK defence and critical infrastructure, I’d argue our biggest sovereignty weakness isn’t which foreign kit sits in the stack — it’s how slowly we replace anything. British infrastructure operators know where their dependencies are; what they lack is the institutional will to act on that knowledge.
“Replacement programmes get agreed by every committee and committed to by none, deferred year after year as “under review.” A sovereignty strategy is only as strong as its delivery dates. The practical fix is unglamorous: name each critical dependency, name its replacement decision, and put an owner and a hard date on it. Sovereignty isn’t declared in policy papers. It’s shipped, system by system.”
Daniel Di Nardo, Network and Security Consultant at Intellibreach

“In my opinion, Sir Richard Dearlove’s warning underscores a very real cybersecurity risk. If one of the foreign states has influence or control over the critical infrastructure, it is a significant security concern for the United States, not only technological but also geopolitical. States should ensure that their critical infrastructure is protected from being taken advantage of by foreign governments.
“This hazard can be mitigated by implementing a least-privilege access rule, conducting constant identity checks, and having an approval process in case of privilege escalation. In addition, it is essential to have a plan for rolling back or revoking access if something goes wrong or an unauthorized breach occurs. The strategy to prevent cyber intrusion and respond to it is vital for each country.
“Thus, the expert’s words are important for the U.S. government in assessing the potential risks of foreign states and their involvement in the development of critical infrastructure technologies. Without proper control and management, technology can be taken over by foreign agents, which will inevitably lead to destabilization and geopolitical risks.”
Matt Lloyd Davies, Principal Security Author at Pluralsight

The risk is real, but “foreign technology” and “loss of sovereignty” aren’t the same thing. Critical infrastructure will always rely on global suppliers. The real question is whether those dependencies leave the UK unable to operate, maintain, replace, or recover essential services without external cooperation.”
“The national security concern is concentrated dependency, not foreign origin on its own. If a critical service depends heavily on a single overseas supplier, component, cloud platform, or remote support model, that can create strategic leverage even without a cyberattack.”
“That’s as much a resilience issue as a cybersecurity issue. The key question isn’t “is this a threat” but whether the UK understands its critical technology dependencies and has credible alternatives if a supplier, country, or technology suddenly becomes unavailable.”
“This isn’t a uniquely British problem. The EU is having a near-identical debate right now. About two-thirds of European cloud services run through three US companies, and the European Commission has just launched its own Tech Sovereignty Package. Even Germany (usually the sensible one!) admits in its own surveys that most companies want independence from US providers but don’t have it. Most advanced economies are built on the same small set of hyperscalers and suppliers, and everyone is now working out what that means.”
“Concentration is the core risk regardless of who the supplier is. That said, adversary-owned dependency does carry an added layer on top of ordinary concentration risk: the possibility of deliberate leverage or disruption, not just accidental failure or commercial disruption. Concentration risk exists either way; the adversarial case adds intent to the equation.
The answer isn’t technological isolation, it’s better visibility of supply chains, stronger scrutiny of technology used in critical infrastructure, control over remote access, diversification where dependencies are too concentrated, and contingency planning that’s actually exercised.”
“Sovereignty should mean retaining meaningful operational choice. The UK doesn’t need to build everything domestically, but for genuinely critical systems, it should know what it depends on, where control sits, and what happens if that dependency fails.”
Lee Perkins, CEO at Civica

“This is a concern, but we need to keep a sense of perspective. Every day, people rely on technology to access healthcare, local services, education and emergency support. If critical systems – or the data behind them – become overly dependent on decisions made outside the UK, that creates a vulnerability we can’t ignore.
“At the same time, that does not mean rejecting global technology. International providers bring expertise, investment and security capabilities that are often hard to match. Britain should continue building its own digital capability while working closely with trusted partners. Public bodies need a clear understanding of where their data sits, how systems connect and who is involved in the supply chain. Greater transparency, interoperability and flexibility are just as important as security in building long-term resilience.”
