Infographic titled 'Provable Sovereignty Defined' on a dark navy background with teal and cyan accents and white text. The top half is a left-to-right flow diagram: a Sovereign Entity, shown as a blue shield with a crown, sends Cryptographic Proof to a Decentralized Network, rendered as a hexagonal node web, which sends a Verified signal to an External Verifier, a person in a suit. The bottom half has three columns. Independent Authority, with a king and key icon, covers entities establishing unique identifiers and claims without central registry control, Self-Sovereign Identity, and a Controlled Root of Trust. Mathematical Certitude, with a lock and code icon, covers advanced cryptography and Zero-Knowledge Proofs for verification, provable claims without revealing data, and cryptographic signatures. Auditable Public Ledger, with a linked cube network icon, covers securing claims on a transparent, tamper-resistant, decentralized network, immutable records, and open verifiability by any party. The infographic conveys a framework where authority can be mathematically and publicly proven.
ANALYSIS

Provable sovereignty: inside the Geneva confidential computing proof of concept.

A completed proof of concept in Geneva combined Intel TDX confidential computing with Arqit's quantum-safe key distribution to test whether sovereignty claims, jurisdictional, cryptographic, and computational, could be technically demonstrated rather than only contractually promised. It shows what the technical layer of sovereignty can look like in practice, without claiming to certify sovereignty on its own.

By John Wroath, Editor

Published 29 July 2026

Disclosure: John Wroath, the author of this piece, is Editor of European Sovereign Infrastructure and Head of Demand Generation at nLighten, a European edge data centre platform, which operated the facility referenced in this proof of concept. This is a direct conflict of interest. It is disclosed here, prominently and near the top of the article, so readers can weigh the analysis that follows with that context in mind. This publication is editorially independent of nLighten; the role is disclosed here in the interest of transparency, and nothing in the piece is conditioned on that relationship.

A completed proof of concept in Geneva combined Intel TDX confidential computing with Arqit's quantum-safe key distribution to test whether sovereignty claims, jurisdictional, cryptographic, and computational, could be technically demonstrated rather than only contractually promised. It shows what the technical layer of sovereignty can look like in practice, without claiming to certify sovereignty on its own.

Why does sovereignty need a technical layer at all?

This publication's cover feature set out sovereignty as three layers that need to hold together: jurisdictional, which laws can reach the data; operational, who actually runs the infrastructure; and technical, whether those first two claims can be independently verified rather than simply trusted. The first two layers are largely questions of law and organisational structure, answerable, in principle, by reading contracts, ownership records, and staffing arrangements. The technical layer is different in kind: it asks whether a sovereignty claim can be checked by anyone, cryptographically, without needing to trust the provider's own account of itself. This is the layer that turns "we promise we're sovereign" into "here is how you can verify it yourself," and it is the layer this proof of concept was built to test.

What is confidential computing, and what does Intel TDX add?

Confidential computing addresses a gap that conventional encryption leaves open. Data can be encrypted at rest, sitting on disk, and encrypted in transit, moving across a network, but historically has had to be decrypted while actually being processed, the moment a system reads it into memory to do anything useful with it. That processing moment has long been the point at which even a well-encrypted system exposes the underlying data, to the operating system, the hypervisor, or anyone with sufficiently privileged access to the machine it runs on.

Intel Trust Domain Extensions, TDX, is a CPU-level technology that closes that gap by creating a hardware-isolated Trusted Execution Environment, called a Trust Domain, within which a virtual machine's memory and execution state stay encrypted and isolated even from the host system's own hypervisor and operating system. In effect, the infrastructure operator running the physical hardware cannot see inside the Trust Domain, even though it owns and operates the machine the Trust Domain runs on.

The feature that matters most for a sovereignty claim, however, is not the isolation itself but remote attestation: the ability for a customer, before ever sending sensitive data, to cryptographically verify exactly what software is running inside the Trust Domain and confirm that the hardware protections are genuinely active. Attestation is what turns "trust us" into "check for yourself," and it is the specific mechanism that lets a technical sovereignty claim be tested by an outside party rather than taken on faith.

What does Arqit's quantum-safe layer add on top of that?

Confidential computing protects data while it is being processed. It does not, on its own, address a longer-horizon risk that sovereignty-conscious organisations increasingly have to plan around: so-called "store now, decrypt later" attacks, in which an adversary intercepts and stockpiles encrypted data today, betting that a sufficiently powerful quantum computer will be able to decrypt it years from now, once one exists. For data with a long sensitivity horizon, government records, health data, anything sovereignty rules are typically written to protect, that future risk is not hypothetical enough to ignore.

Arqit's Symmetric Key Agreement platform addresses this by brokering shared symmetric encryption keys directly between endpoints, rather than relying solely on the public-key cryptography techniques that a future quantum computer is expected to be able to break. Keys can be rotated for every session, and the underlying symmetric cryptographic primitives are the kind that established guidance, including US National Security Memorandum 10 and related NSA requirements for classified systems, has pointed toward specifically because they are considered robust against quantum attack in a way conventional public-key exchange is not. Layered on top of TDX's confidential processing, this addresses a different part of the sovereignty question: not just who can see the data now, but who might be able to decrypt it a decade from now.

Attestation is what turns a sovereignty claim from a promise a provider makes about itself into something a customer can check for itself.

John Wroath

What did the Geneva proof of concept actually test?

The proof of concept, anchored in a European-operated facility in Geneva, combined these two capabilities to test whether all three layers of the sovereignty model could work together and be independently verified, rather than simply asserted in a contract. Confidential computing with Intel TDX provided the computational layer, isolating processing and making it independently attestable. Arqit's quantum-safe key agreement provided the cryptographic layer, protecting the data itself against both current and anticipated future decryption threats. European operation of the underlying facility provided the jurisdictional layer, the same layer this publication's cover feature and CLOUD Act analysis have examined in general terms, here anchored to a specific, named location.

It is worth being precise about what this proves and what it does not. A proof of concept demonstrates technical feasibility in a controlled setting. It establishes that these components can be combined and that the resulting claims can be attested to, rather than merely stated. It does not, on its own, constitute a commercial service, a claim about production-scale performance, or a certified sovereignty rating for any of the parties involved.

What would it take to move from proof of concept to something SEAL could recognise?

This publication's SEAL decoder set out how the EU Cloud Sovereignty Framework actually scores providers: against eight weighted objectives, each with its own floor, assessed in the context of an actual tender rather than in the abstract. A technical demonstration like this one is directly relevant to two of those objectives in particular, data and AI sovereignty and technology sovereignty, since both ask whether control and processing integrity can be verified rather than assumed. But relevance is not the same as a rating. SEAL scoring happens against a specific procurement's defined floors, assessed by the purchasing body, not awarded by a proof of concept published on a vendor's or publication's own initiative. The honest way to describe the relationship is that this work facilitates a stronger technical answer to those objectives, when and if it is put in front of an actual SEAL assessment. It does not itself constitute or claim a SEAL rating for any party.

Why does this matter beyond one facility?

The specific combination tested in Geneva, confidential computing plus quantum-safe key agreement plus European operation, is one instance of a broader shift this publication has traced across its first edition: from sovereignty as something asserted through contracts and corporate structure, toward sovereignty as a property that can be independently tested. This publication's piece on AI sovereignty and federated infrastructure raised the same theme from a different angle, arguing that verifiability, not just distribution of control, is what makes a sovereignty claim trustworthy at all. A single proof of concept in one European city does not settle that broader argument. It does show, concretely, what taking the technical layer seriously can look like when a jurisdictional claim, a cryptographic claim, and a computational claim are made to work together rather than sit as three separate, unconnected promises.


End of article

Related reading

COVER FEATURE

What is European Sovereign Infrastructure? A working definition.

European Sovereign Infrastructure is digital infrastructure, including data centres, networks, and cloud platforms, that operates under European jurisdiction and control. It means three things hold at once: European law governs the data, European entities run the facilities and hold the keys, and technical measures make that control verifiable rather than merely promised.

John Wroath

ANALYSIS

AI needs a sovereign layer too. Can federated infrastructure deliver it?

AI raises sovereignty stakes beyond cloud alone: training data provenance, model weight custody, and GPU supply chains all carry jurisdictional exposure that cloud sovereignty frameworks were not built to answer on their own. Federated infrastructure is one credible response, and Europe is already building it institutionally.

John Wroath

Primary sources

Disclosure: Provable sovereignty: inside the Geneva confidential computing proof of concept. is published as part of Edition 01 of European Sovereign Infrastructure. The publication is editorially independent. No source cited in this article had sight of the copy before publication.