On February 10, 2026, Pakistan’s national digital authority signed a memorandum of understanding with the DFINITY Foundation to build what both sides call a “sovereign cloud” on the Internet Computer Protocol, according to DFINITY’s own announcement and a follow-up analysis published on Medium. The plan includes a dedicated Pakistan Subnet on the protocol, meant to host government software and AI-powered national systems that run independently of foreign cloud providers like Amazon or Microsoft. By March, Pakistan’s first government application built on this infrastructure, a national messenger platform, had completed a month of live operation, marking a shift from pilot project to something actually running in production.
What “sovereign cloud” is actually solving for
The pitch is straightforward: keep sensitive government and citizen data physically and legally inside the country, on infrastructure the government does not have to trust a foreign company to operate, while still getting the tamper-resistance and distributed-verification properties that come with blockchain-style architecture. That is a real and growing concern for governments generally, not just Pakistan’s. A country running its national identity, health, or messaging systems on a foreign-owned cloud is, in a meaningful sense, renting its own digital sovereignty.
This is happening at the same time several other countries are deep into a very different kind of digital infrastructure buildout: mandatory digital identity. Estonia, the long-running example, now runs eID cards across essentially its entire population, integrated into voting, healthcare, and daily commerce, and has recently begun assigning digital “AI ID codes” to AI agents themselves, extending the identity system beyond people. Estonia’s own privacy advocates have raised a real and specific criticism for years: any government agency with an investigative function reportedly has access to a wide swath of retained data, a structure that several civil liberties observers say does not fully account for basic data protection norms taken for granted elsewhere in the EU. Every EU member state is now required to offer a standardized Digital Identity Wallet to citizens and residents.
The pattern worth watching
Pakistan’s move and the Baltic digital-ID buildout are not the same story, but they are the same phenomenon from two directions. One is a government trying to own its own infrastructure rather than lease it from abroad. The other is a government trying to own its citizens’ identity data rather than leave it scattered across private systems. Both are framed, correctly, as questions of sovereignty and control. Neither framing automatically resolves the harder question underneath: control by whom, and checked by what.
A sovereign cloud that a government fully controls is not automatically safer for the people whose data sits on it than a foreign-run one, it just changes who has to be held accountable, and how. A digital ID system that makes daily life more convenient is not automatically compatible with the data protection standards a democracy claims to uphold, as Estonia’s own advocates have argued. The technology in both cases is genuinely useful. Whether it strengthens or narrows the room ordinary people have to live outside a government’s direct line of sight depends entirely on the legal guardrails built around it, guardrails that, in both Pakistan’s case and Estonia’s, are still being written in real time.
Sources: DFINITY Foundation, “Pakistan Digital Authority and DFINITY Partner for Sovereign Cloud Infrastructure and AI Software Systems”; The Swop via Coinmonks, “Pakistan x Internet Computer: A Real Sovereign Cloud Signal”; Identity Week, “Estonia scaling the ‘Digital Republic’ amid threats”; Liberties.eu, “Here’s How Privacy Is Violated in Estonia”; Biometric Update, “Estonia’s AI agent ID plan raises new questions about digital identity”.
Leave a Reply