In this project, we study the data centre geopolitics, sovereignty vs dependency, and hybrid warfare exposure of the digital infrastructure where the Global South is treated as a testing ground. This project builds the governance instruments needed to distinguish real control from its illusion. Using Anthropic’s MOU with Rwanda as an example, which signalled cooperation, we cannot identify who controls the stack, what legal regime applies, how incident response works, whether workloads are segmented, and how one country’s compromise could cascade into others through shared services, supply chain, hosted dependencies, etc.
Given Africa’s progress in digital transformation, African countries are a neocolonial target, in the sense of resource extraction logic applied to compute, data, energy, natural resources with the climate consequences externalised onto host countries. This concern is consistent with broader warnings that foreign-controlled digital infrastructure deepens dependency, weakens regional bargaining power, and exposes host countries to surveillance and regulatory arbitrage.
OBJECTIVE
With this project, we want to understand what a true sovereignty aware infrastructure means. This means analysing how we can navigate the current global challenges to design one that increases trust and not dependency or cross-border collaborations, identifying operational tools to materialise policy claims. The project stands on three foundational questions:
- What risks does foreign-built AI and data infrastructure introduce into a host country, and how do those risks propagate?
- When does hosting AI workloads in-country actually strengthen sovereignty, and when does it simply relocate dependence onto foreign-owned infrastructure sitting on domestic soil?
- How can AI and data centre infrastructure be used as instruments of grey-zone conflict against a host country, and what does exposure look like below the threshold of armed attack?
“Sovereign AI”, “sovereign compute” and “data sovereignty” are increasingly invoked as policy goals, but it’s failing the operational test. A datacentre physically located in-country may still run on foreign-owned hardware, foreign-controlled software stacks, foreign cloud orchestration, and foreign legal jurisdiction over the operator. So the sovereignty claim is only geographic by nature.
Without a true test of sovereignty, policy conversations conflate service oriented architectures and co-location with control. The result is power concentration and infrastructure spending that produces dependency, threatens privacy and human rights, and raises the question of why is this a pre-condition that no one agreed to.
The three questions are facets of the same problem: foreign-built AI and data infrastructure introduces systemic risk that is not captured by existing governance instruments. Because that gap between cooperation signals and true sovereignty is what allows extractive conditions like dependency and exposure, creating grey-zones.
