— or rather, what looks like control is often just ownership

April 2025. The Iberian peninsula loses power. Spain, Portugal, parts of southern France – one of the largest blackouts in European history. The grid is gone for hours in some regions, days in others.

When power goes out for long enough, diesel reserves run down. Standard reserves last 24 to 72 hours. Beyond that, every operator depends on resupply. And resupply, during a regional crisis, doesn’t happen on first-come-first-served terms.

Most countries have critical infrastructure designations. When supplies are restricted – fuel, materials, response capacity – critical infrastructure gets priority. Probably hospitals, then government, then the operators classified as essential – the order depends on the country.

Colocation facilities often sit on national critical infrastructure registers. On-prem data centers typically don’t.

The companies that looked less sovereign on paper turned out to be more sovereign when conditions tightened. The ones who looked more sovereign discovered that ownership didn’t produce priority.

The mechanism: a company that had kept power under its own roof, owning everything, would in a long enough crisis find itself waiting in the same queue as everyone else. A company that had colocated – given up direct ownership of power – would, structurally, be ahead of that queue.

This isn’t a quirk of one event. It’s a structural pattern that most sovereignty conversations get wrong.

Sovereignty isn’t about who owns the asset. It’s about whether the outcome holds when conditions shift.

Two kinds of sovereignty are at stake. Asset sovereignty is who owns and operates the infrastructure. Outcome sovereignty is whether the operation holds when conditions shift. They can pull against each other.


The conventional view is reasonable. And sometimes wrong.

The intuitive assumption is straightforward: ownership equals control, and control equals sovereignty. The Iberian case shows the first half of that equation isn’t always true.

Most of the current sovereignty discourse runs on this assumption. Repatriate workloads. Build your own. Reduce dependencies. Each step toward more direct ownership feels like a step toward more control – and therefore more sovereignty.

But some threats exceed what direct ownership can defend against. The on-prem operator with their own diesel reserves looks like they have control over their power. In a long enough crisis, they don’t. What looked like control becomes a waiting position. Asset sovereignty stayed intact. Outcome sovereignty didn’t.

This doesn’t reverse the conventional view. It refines it. Sometimes ownership produces control. Sometimes it doesn’t. The question is whether the threat you’re defending against is one your own resources can actually meet.

Of course control is sovereignty – that’s the whole point. The headline asks a real question. Here’s the specific answer: what looks like control is often just ownership. And ownership by itself isn’t control.


This isn’t only about power.

The same pattern appears across other domains.

Insurance markets pool risk across thousands of insureds, backed by other insurers and the broader financial system. Self-insuring against catastrophic loss relies on one balance sheet. The delegation to insurance markets produces solvency protection against truly large events that no individual enterprise can match.

Managed detection and response providers share threat intelligence across thousands of customers. When a novel attack hits one, the indicators are protecting all the others within hours. An internal security operations centre, no matter how sophisticated, faces each new threat alone. The delegation produces detection that scale makes possible and that no single enterprise can replicate.

Content delivery networks pool traffic and defence capacity across thousands of customers. A single enterprise running its own origin infrastructure couldn’t build hundreds of edge locations, couldn’t absorb a terabit-scale attack alone. The delegation produces global reach and attack resilience that direct ownership structurally couldn’t achieve.

The pattern works under specific conditions. The delegated system has to be built on rules – laws, regulations, or industry standards – that actually create protection. The protection has to come from being big enough that no single company could replicate it. And the threat has to be one your own resources can’t handle alone.

When all three are true, delegating produces outcome sovereignty that asset sovereignty couldn’t.


Where this leaves us

The takeaway isn’t delegate everything or own everything. It’s that the choice between the two depends on what threat you’re actually defending against.

For threats too big for you to handle alone – physical disruption, large-scale attack, catastrophic loss – connection to something bigger produces outcome sovereignty that ownership can’t match. For threats about jurisdiction, confidentiality, or strategic exposure, asset sovereignty may be exactly right.

The question is whether your current sovereignty posture matches the threats you actually face.

Three things worth doing

  • Examine your most expensive ownership decisions. Are those decisions defending against the threats they were designed for, or against threats that have shifted?
  • Examine your dependencies. Are those delegations connecting you to systems with real protection at scale, or just to other single points of failure?
  • Examine the threats you’re not defending against. Those are the threats where the delegation question matters most.

Asset sovereignty isn’t the same as outcome sovereignty. The first is who owns. The second is who keeps running when conditions stop holding.


This argument was first developed for an internal masterclass held on April 16, 2026, where it was presented as part of a broader exploration of how organizations should think about whether ownership always equals sovereignty. The published version reflects subsequent conversations and refinements. A companion piece, Mind the Depth (of Sovereignty), takes up the harder question underneath this one.

Originally published on LinkedIn