This guest post reflects the views of the author and does not necessarily represent the views of KuppingerCole Analysts. It is provided for informational purposes only and should not be interpreted as independent research, analysis, endorsement, or advisory services by KuppingerCole Analysts.
Over the past few years, "digital sovereignty" has become one of the defining themes in discussions about digital identity. Depending on the conversation, it might mean data residency, cloud infrastructure, national identity systems, AI regulation, or simply ensuring that critical digital infrastructure remains under local control.
None of those goals are inherently at odds with the internet. What concerns me is the increasingly common assumption that digital sovereignty somehow replaces the need for interoperability. It doesn't.
If anything, the opposite is true.
The Internet Has Never Required Uniformity
The internet has never depended on everyone making the same policy decisions. It has depended on independently governed systems finding ways to communicate despite making different decisions. That distinction has always been important, but it becomes even more important as governments, industries, and enterprises develop their own trust frameworks.
One of the recurring lessons from standards work is that technical standards are often expected to solve problems that are fundamentally about governance. They can't.
A protocol can define how to exchange a credential. It can define how to communicate metadata or express an authorization decision. What it cannot do is determine whether one government should trust another government's identity system, whether one regulator should recognize another regulator's assurance model, or whether two organizations should accept each other's risk posture.
Those are policy decisions. Standards provide a common language for communicating the outcome of those decisions.
That distinction becomes particularly relevant when people talk about internet fragmentation. The conversation often assumes there are only two possible futures: either everyone converges on a single global approach, or every jurisdiction builds its own isolated ecosystem.
Neither seems especially likely.
Standards Translate Between Trust Frameworks
The internet has always accommodated diversity. Organizations have different security policies. Industries have different compliance requirements. Countries have different legal obligations. Those differences existed long before we started using the term "digital sovereignty." What made the internet successful was not eliminating those differences but allowing systems to interoperate despite them. Federated identity has generally worked on the same principle.
Federation never required every organization to have identical identity proofing practices. Certificate authorities operate under different policies and governance frameworks while using common certificate and validation standards. Even something as familiar as email depends on independent operators applying different policies while using common protocols and message standards.
I've started thinking about standards less as mechanisms for creating uniformity and more as translators between independently governed systems.
That isn't as elegant as a single global trust framework, but it is much closer to how the internet has evolved over the past forty years. We establish common ways to represent information, exchange evidence, and evaluate claims while leaving room for organizations to make their own decisions about what they will ultimately trust.
I suspect this is where identity architecture is heading as well.
Designing for a More Diverse Internet
European initiatives such as the EUDI Wallet are advancing an ambitious vision for cross-border digital identity while operating within a distinct regulatory environment. Other regions are making different choices based on their own legal, commercial, and societal priorities. Sovereignty requirements can create legitimate constraints on data movement, infrastructure, and trust relationships. The objective is not unrestricted interoperability, but sufficient interoperability within clearly defined legal, security, and policy boundaries. Those differences are real, but they are not necessarily failures of interoperability.
The more interesting question is whether systems designed under different assumptions can still exchange enough information and evidence to make their own trust decisions.
That is where open standards continue to matter.
Interoperability should not be measured by whether every deployment looks the same. It should be measured by whether independently governed systems can understand one another well enough to accomplish useful work without forcing everyone into a single trust model.
Digital sovereignty changes who establishes trust and under what rules. It does not eliminate the need to communicate those decisions across organizational or national boundaries.
If anything, it raises the bar for interoperability. The future internet is unlikely to be less diverse than today's. The real challenge is ensuring that diversity does not become isolation.