Over a decade ago I saw this first-hand, with customers of QuarkXPress, the software once used to lay out most of the world’s books, magazines and newspapers. Many of them made a perfectly rational decision: they froze. They stayed on an old version and stopped upgrading, to avoid paying for changes they didn’t feel they needed. And for a while it worked beautifully. They owned their software, their files, their machines, and depended on no one’s release schedule but their own. That felt like sovereignty, and they had it.

But standing still doesn’t stay simple. Apple kept releasing new versions of macOS, and at some point the frozen application no longer ran on them. So the operating system had to be frozen too. And a frozen OS pinned the hardware, because new Macs wouldn’t run the old one. One decision to stand still had quietly become three.

Then the ground moved. PDF/X-4, the ISO standard for print-ready files (ISO 15930-7), was becoming an expected format in modern print workflows – and only a later version of QuarkXPress offered this output capability. To produce it, a frozen customer needed the new application, which needed a newer OS, which needed a new Mac. The upgrade they’d deferred to keep their setup unchanged had compounded silently. Years of accumulated dependencies had turned a manageable change into an expensive, all-at-once migration.

Their sovereignty hadn’t been taken. It had aged away. What made them sovereign one year had, a few years on, quietly removed the very thing it once gave: they could no longer do the one thing sovereignty is supposed to guarantee, which is to act on their own terms. Nobody attacked them. No vendor locked them in. The world simply moved, and they had optimized for standing still.

The one supplier you can never fire

We picture the threat to sovereignty as something from outside: a vendor who locks us in, a regulator who shifts the rules, an adversary who cuts us off. But the frozen customer was beaten by their past self – the one supplier you can never fire. It made what looked, at the time, like the sovereign choice, and then it was gone: no budget, no roadmap, unreachable, accountable to nothing, still binding everything you now run. And the decisions it left behind are one form of what we call technical debt.

And there’s a second way past-you does this, one that doesn’t need the world to move at all. Think of a writer who, back in 1999, set out to publish independently on the web. There was no WordPress yet, no Markdown, and HTML was still thought of as code, not a way to write. So he did the sensible thing for the time: he built his own system, and wrote in his own rich, WYSIWYG format – one that did exactly what he wanted. For years it served him beautifully. Every year he thought: why change, it all works. He owed nothing to any platform.

The bill came later. Two decades on, with a thousand pages of work inside it, the system had grown too old to maintain – and because that homegrown format is understood by nothing except the code he wrote himself, he is stuck. He can leave, but only by paying: rebuilding the whole thing from scratch, by hand, migrating decades of work into something the rest of the world can read. A standard format would have turned much of that into a conversion problem rather than a manual reconstruction: export, convert, import, done. He never fell off a moving standard, as the frozen customer did. He simply never stood on one. Opposite mistakes, the same place: work the rest of the world can no longer read without a toll.

You can be stranded because you invented a private language. You can be stranded because you stayed on yesterday’s common language. And even today’s common language can move — which is why who governs it matters.

That is what lock-in often is – not a cage, but a cost, set by a version of you no longer here to help pay it.

And it happens in the hardest infrastructure too

Banks felt it in November 2025. The coexistence period for MT and ISO 20022 ended, making ISO 20022 the standard language for cross-border payments – a change the industry had agreed years earlier, in 2018. Institutions that had stayed on MT could no longer continue unchanged.

Or take the devices and apps that signed in to Microsoft 365 the old way, with Basic Authentication – a username and password sent straight to the server. For years it just worked: the scanner that emailed invoices, the line-of-business app wired up once and forgotten, the mail client someone configured years ago and never touched again. None of it was broken. None of it needed attention. That was the point – it sat quietly in the corner doing its job.

Then Microsoft, closing a long-standing security hole, began switching Basic Authentication off. Modern authentication – OAuth – had become the way you were expected to connect, and the old method was on its way out. Beginning in late 2022, it was disabled across the legacy protocols regardless of usage, and the things still relying on it didn’t slow down or warn anyone. They stopped. The scanner couldn’t send. The app couldn’t sign in. The method they depended on was simply no longer accepted, and anything that hadn’t moved to modern auth couldn’t connect at all. The last of it is still being phased out now.

Nobody who got caught had done anything wrong, exactly. They’d done nothing – which, once the ecosystem moved, turned out to be the one thing you couldn’t afford to do.

Different layers, same mechanic.

What each of them did was let the boundary between themselves and the world become exceptional. Some froze on yesterday’s common language, some on their version, their system, their design, one on a private language of his own. Each of them would have said, and it felt, and truly was, sovereign. Different routes, same destination: every year fewer systems could meet them where they stood.

This is uncomfortable, because the instinct runs the other way. We treat two things as the essence of sovereignty: the more it’s mine, and the more freely I get to choose. Both feel like control. Both, past a point, can become the opposite.

The freedom to pick your own private format quietly spends your future freedom to leave. And “mine” is not the same as sovereign: plumbing only you understand can turn independence into isolation – and isolation, the moment you need to move, is the weakest place to be.

Distinctive in what you make, ordinary in how you move it

The two things don’t behave alike. What you make – your words, your designs, your decisions, your data – is where distinctiveness is the whole point. How you store and move it – the format, the protocol, the encoding, everywhere it touches the outside world – is the opposite: not a place to be original, but a place to be utterly ordinary, speaking what everyone else speaks, so you can reach them and leave. The ones who stay sovereign are unmistakably themselves in the substance and boringly conventional in the pipes. The ones who get stuck did it the other way around.

Unless

Which brings us to the word the title has been holding back. Sovereignty ages into loss of control – unless you keep speaking a language the world still reads. That is what a standard is: a compromise, agreed by many voices, about how things will be done. A compromise agreed by others will often chafe – it is hardly ever shaped exactly to you, it limits the individual and it limits you. That is the price. But it is also exactly what keeps your sovereignty from aging, because a language many people agreed on is one many people keep speaking – and thus giving you more ways to be read and more ways to leave.

Which standard, though?

Still, “use a standard” is useless advice on its own, because almost everything calls itself one. The real question isn’t whether something is a standard. It’s who governs its future.

A format governed by an independent body – ISO, the IETF, the W3C – has its future decided in the open, by many parties, so no single one of them can quietly change it or take it away. A format controlled by a single vendor may be excellent and everywhere, but one company holds the pen, and its roadmap answers to its business, not yours. And a format governed by no one but you is the narrowest case of all, because the party who controls its future is a version of you who has already stopped maintaining it.

Owning the format yourself puts you in the last category, not the first – which is why it does not by itself make you sovereign, and why the compromise you resented turns out to be the thing protecting you. Not perfectly – standards get revised, and some are eventually retired too. But their evolution is shared across an ecosystem rather than held by one implementation, and the path they took is far more likely to remain documented.

The same question fits anything you keep – your files, the way your apps talk to each other, the tools that run your systems. If whoever governs this format changed it or disappeared tomorrow, could you still open your own work and take it elsewhere? The standards that make the answer yes have a family resemblance. Communication standards. Exchange standards. Data standards. Every one of them is about reaching other people and systems – handing something over, being understood, staying connected. Sovereignty feels like it should mean drawing in, needing no one. But the ones that keep you sovereign are the ones that keep you open.

Keeping the door open

Freezing feels like the sovereign move. So does building your own, and so does defining things your own way, answerable to no one else’s terms. All three feel like control. And all three turn on a single question, asked of every format, protocol and tool you rely on: if whoever governs this changed it, or walked away, would you still be all right? The people who stay sovereign answer it early. The rest let a past version of themselves answer it for them.

Somewhere a bank is still paying to re-plumb what it could have migrated years ago. Somewhere an enterprise is still bolting another adapter onto an authentication system it kept because it felt like control. Neither was beaten by an enemy. Each is paying a supplier it can never fire – an earlier self that either chose its own way, or clung to the common one after it moved, and then walked away.

You don’t hold on to sovereignty by building higher walls. You hold on to it by never being stranded – by depending on things that outlive any single owner, and keeping your work in reach of the rest of the world. The standards you once resented, the compromises shaped by other people, are not the bars of the cage. They’re what keeps the door open.

Originally published on LinkedIn.