ANALYSIS

Can a blockchain protocol answer Europe's sovereignty question? Testing ICP's subnet model.

The Internet Computer Protocol structures itself into subnets, node groups that can be geographically and jurisdictionally bounded, with a live Swiss subnet and an EU-bounded subnet already operating. That answers part of the sovereignty question convincingly. It does not resolve who ultimately governs those subnets, a dependency worth weighing as carefully as any corporate ownership structure.

By John Wroath, Editor

Published 28 July 2026

Disclosure: this publication's own website runs on Caffeine, a development platform built on the Internet Computer Protocol (ICP). This is a direct conflict of interest. It is disclosed here, prominently and near the top of the article, so readers can weigh the analysis that follows with that context in mind. Nothing in the piece is conditioned on that relationship, and the governance critique later in the article applies to the same protocol this publication depends on.

Most blockchain networks make a vague decentralisation pitch and leave it there. The Internet Computer Protocol is a useful test case precisely because it does something more structured: it makes an explicit, jurisdictionally bounded sovereignty argument, with live subnets confined to specific legal regimes. That makes it possible to test the claim against the same three-layer model this publication has applied to every other sovereignty assertion, and to do so without hedging either way.

What does ICP claim, specifically?

The architecture is factual and worth stating plainly before any verdict is applied to it. ICP runs on independently operated node machines housed in independent data centres. Those node machines are grouped into subnets, and the subnets are connected to one another via chain-key cryptography, a mechanism that lets any subnet verify the outputs of any other without re-executing its computation. Within a subnet, execution is replicated: every node computes the same result, and a node that diverges is detected and disregarded by the rest.

On top of that architecture sits the sovereignty claim that distinguishes ICP from generic decentralised infrastructure. An operator can configure a subnet restricted to specific node providers, specific geographic locations, or specific jurisdictions. DFINITY, the foundation that develops the protocol, frames these as sovereign subnets. This article cites that framing plainly without adopting it as this publication's own verdict; the job of the sections that follow is to test it.

The reason this is worth testing carefully, rather than dismissing as marketing, is that the claim is structured. A subnet can be configured to refuse nodes outside a stated jurisdiction, which is a verifiable property of the system if the configuration is honoured and the node onboarding process is genuine. That is a meaningfully different assertion from a generic DePIN network saying its nodes are distributed globally, which tells a buyer almost nothing about jurisdictional exposure. The earlier piece in this edition on AI sovereignty and federated infrastructure gestured toward exactly this distinction; this article is the named, concrete case study that piece pointed at.

Where has this actually been built, not just proposed?

Two concrete, named examples are live today, and both deserve to be stated factually.

The first is an EU-bounded subnet, live since December 2023, positioned around GDPR-aligned hosting. DFINITY announced it through PRNewswire on 18 December 2023 as a subnet configured to keep node operation within European jurisdiction, aimed at workloads with GDPR residency requirements. Whatever view one takes of the marketing, the subnet exists and runs.

The second is the Swiss Subnet, launched in January 2026 at Davos, with 13 node providers across Swiss cantons and Liechtenstein. It is marketed explicitly against FINMA and GDPR requirements, with the claim that data never leaves Swiss or Liechtenstein jurisdiction. The subnet.ch site sets out the framing in DFINITY's own terms.

One precision matters here and is kept precise throughout this article: Switzerland is not an EU member state. The Swiss Subnet answers a Swiss sovereignty question, governed by Swiss law and FINMA regulation, which is a different question from an EU sovereignty question governed by EU law and the Commission's framework. A reader evaluating ICP for EU sovereignty purposes should not treat the Swiss Subnet as though it answers the same question the EU-bounded subnet does. The two subnets answer two different jurisdictional questions, and conflating them would be the kind of imprecision this publication exists to push back against.

How does this map onto the three-layer model, and onto SEAL specifically?

The three-layer model set out in this publication's cover feature, jurisdictional, operational, technical, gives a direct structure for testing ICP's claim. Each layer can be assessed on its own, and the assessment below does exactly that.

Jurisdictional layer, corresponding most closely to SOV-2 in the SEAL framework. Geographically bounded subnets are a genuine, verifiable answer to the jurisdictional question, in principle, if two conditions hold: the nodes are truly confined to the stated jurisdiction, and the operators are legitimate independent entities genuinely resident there. The EU-bounded subnet and the Swiss Subnet are both configured to satisfy this, and the configuration is a property of the system rather than a promise. This is a real answer, not a rhetorical one, and it is more than most conventional cloud providers can point to, since a hyperscaler's region does not by itself constrain which legal entities can be compelled to produce data held there.

Operational layer, corresponding to SOV-4. Node providers are independent legal entities, which is a plausible answer to who runs it day to day, provided they are individually vetted, auditable, and genuinely independent of one another rather than independent in name only. The Swiss Subnet's 13 node providers across Swiss cantons and Liechtenstein are named and identifiable, which is more than can be said for the pseudonymous wallet addresses that operate most DePIN networks. The diligence question a buyer should still ask is whether that independence is structural or merely contractual, the same question the SEAL article's S3NS case raised about ownership versus operation.

Technical layer, spanning SOV-3 and SOV-6. Chain-key cryptography and replicated execution are a genuinely interesting technical answer to verifiability. A subnet's outputs can be cryptographically verified by anyone without re-running the computation, and a diverging node is detected and disregarded by the protocol itself rather than relying on an external auditor. This is arguably a more mature answer to can control be proven than most conventional cloud providers offer today, where attestation is typically a contractual and audit-cycle matter rather than a property of the system. This is the strongest part of ICP's case, and it is credited plainly: on the technical layer, the protocol does something conventional cloud does not.

A jurisdictionally-bounded subnet's day-to-day operation may sit in Switzerland or the EU, but the protocol-level authority that can alter what runs on it does not sit exclusively there.

John Wroath

The governance question nobody's marketing material leads with.

This is the section that has to carry equal weight to the one above, and it does. The technical and jurisdictional merits are real, and so is the governance concentration that sits above them, and a rigorous sovereignty assessment has to hold both in view at once.

Every subnet, however jurisdictionally bounded its node providers, remains governed by the Network Nervous System, or NNS. The NNS is a single on-chain DAO that can vote to upgrade, reconfigure, or halt canisters anywhere on the network, including on a subnet configured as sovereign. What this means in practice is that a jurisdictionally-bounded subnet's day-to-day operation may sit in Switzerland or the EU, but the protocol-level authority that can alter what runs on it does not sit exclusively there. The operational layer can look clean while the authority above it is concentrated elsewhere, which is structurally the same pattern this publication identified in the S3NS case in the SEAL article: an operationally clean layer sitting beneath a concentrated governance or ownership layer.

The governance concentration data is worth stating factually. Published analyses indicate that the DFINITY Foundation, a Swiss non-profit, holds a substantial share of long-locked voting power in the NNS, with cited estimates running as high as 40 percent. DFINITY has published its own response to this criticism, which should be read as the subject's self-assessment of its own governance risk rather than as independent commentary, the same standard this publication applied to provider self-assessments in the SEAL article. The point here is not to single out DFINITY; it is to note that a governance layer concentrated in a single foundation is a dependency a sovereignty assessment has to weigh, in the same way the SEAL framework's SOV-1 asks where decisive strategic authority sits.

There is a further jurisdictional wrinkle worth being precise about. The DFINITY Foundation is Swiss, and the Swiss Subnet is built to satisfy Swiss jurisdiction. But Switzerland is not an EU member state, so a Swiss-concentrated governance layer is not neutral from an EU vantage point either. A reader evaluating ICP for EU sovereignty purposes is being asked to place protocol-level authority in a jurisdiction that, while close and aligned, is not the one their regulator sits in. That is not a fatal objection, but it is a real one, and it is the kind of precision the definition-of-done for this article requires: do not conflate Switzerland with the EU anywhere in the assessment.

There is also a smaller trust-set point that sits alongside the governance question and is distinct from it. Some subnets run with as few as 13 nodes, which is a narrower validator set than most hyperscale cloud regions rely on. This is a resilience question rather than a jurisdictional one: a small validator set is more exposed to correlated failure, whether through coincidence, compromise, or coordination, than a large one. It does not undermine the jurisdictional claim, but it is a separate consideration a buyer weighing ICP against conventional cloud should hold in view, because resilience and sovereignty are related but not identical axes.

So does ICP answer the sovereignty question?

A direct, structured answer rather than a hedge.

On the operational and jurisdictional layers, the subnet model answers the sovereignty question better than generic DePIN networks do. A configured, jurisdictionally bounded subnet with named, identifiable node providers is a meaningfully stronger answer than a permissionless network of pseudonymous operators, and it is stronger than what most conventional cloud providers can point to on the jurisdictional layer alone. On the technical and verifiability layer, chain-key cryptography and replicated execution answer the can control be proven question arguably better than conventional cloud does today, and that is credited plainly.

On the governance layer, the answer is: not yet. The NNS remains a single on-chain authority that can alter what runs on any subnet, and the concentration of long-locked voting power in a single Swiss foundation is a dependency a rigorous sovereignty assessment has to examine separately from the operational layer beneath it. This gap is structurally similar to the S3NS case examined in this publication's SEAL article, where an operational layer that looked clean sat beneath a concentrated ownership and governance layer. The lesson there applies here: an operationally clean layer does not by itself answer the question of who holds the authority above it.

What would change this assessment is nameable. Broader, demonstrably diversifying NNS voting power over time, with the concentration in any single foundation declining rather than holding, would directly address the governance-layer gap. And governance mechanisms that let a jurisdictionally-bounded subnet meaningfully resist a global protocol-level change it did not consent to, rather than being subject to it by default, would close the structural parallel with the S3NS case. Neither of those is a small change, and neither is currently in place. Until they are, ICP answers more of the sovereignty question than its generic DePIN peers, and less of it than its own marketing implies.


End of article

Related reading

COVER FEATURE

What is European Sovereign Infrastructure? A working definition.

European Sovereign Infrastructure is digital infrastructure, including data centres, networks, and cloud platforms, that operates under European jurisdiction and control. It means three things hold at once: European law governs the data, European entities run the facilities and hold the keys, and technical measures make that control verifiable rather than merely promised.

John Wroath

ANALYSIS

AI needs a sovereign layer too. Can federated infrastructure deliver it?

AI raises sovereignty stakes beyond cloud alone: training data provenance, model weight custody, and GPU supply chains all carry jurisdictional exposure that cloud sovereignty frameworks were not built to answer on their own. Federated infrastructure is one credible response, and Europe is already building it institutionally.

John Wroath

Primary sources

Disclosure: Can a blockchain protocol answer Europe's sovereignty question? Testing ICP's subnet model. is published as part of Edition 01 of European Sovereign Infrastructure. The publication is editorially independent. No source cited in this article had sight of the copy before publication.