Brazil’s emerging Brazilian Cloud initiative is moving beyond data residency to test whether critical infrastructure can continue operating when foreign suppliers, software or external connections disappear.
Brazil has a problem shared by almost every government pursuing technological sovereignty: you can put the data inside your borders, but that does not mean you control the technology running underneath it.
A Cloud platform can sit inside a Brazilian data centre while depending on foreign software, overseas management consoles, proprietary licensing and technology suppliers operating under another country’s jurisdiction. Pull one of those connections and the supposedly sovereign infrastructure may suddenly look considerably less sovereign.
Brazil now wants to find out exactly how much control it really has.
The country’s emerging Brazilian Cloud initiative is attempting to redefine digital sovereignty around a harder test than data residency. Instead of demanding that every processor, platform and software component is Brazilian, the project is asking whether critical systems can continue operating when an external supplier, service or connection disappears.
It is sovereignty measured by what happens when something gets switched off.
That distinction matters as governments become increasingly dependent on hyperscale Cloud platforms and AI infrastructure controlled by a relatively small group of global technology companies. The explosion of generative AI has only deepened those dependencies, adding GPUs, model platforms, orchestration software and increasingly complex infrastructure stacks to an already concentrated technology ecosystem.
Brazil’s answer is not technological isolation. It is controlled dependence.
The concept was tested during the first market consultation for the Brazilian Cloud, involving the Ministry of Management and Innovation in Public Services (MGI), federal technology company Serpro, the Brazilian Agency for Industrial Development (ABDI) and the National Bank for Economic and Social Development (BNDES).
Serpro is providing technical support to the initiative, helping establish requirements and develop a methodology for determining what sovereignty actually looks like inside a modern Cloud environment.
The starting point is that technological independence and technological self-sufficiency are not the same thing.
Wilton Mota, President, Serpro, argues that Cloud sovereignty cannot be reduced to a binary choice between sovereign and non-sovereign infrastructure. Nor can it be determined simply by asking where data is physically stored.
Instead, Serpro is examining control across three dimensions: data, operations and technology.
“This involves identifying, among other aspects, who has access to the keys, who manages the environment, to which jurisdictions it is subject, what its external dependencies are, and whether the operation can be maintained in the event of an interruption,” said Mota.
That immediately raises uncomfortable questions for conventional sovereign Cloud strategies.
A government may require information to remain inside national borders, but what happens if administrators depend on software hosted overseas? Who controls the encryption keys? Can the platform still be managed if an external connection disappears? What happens when a licensing agreement ends? Can workloads move elsewhere or has proprietary technology effectively locked them in?
Brazil’s existing Government Cloud already imposes requirements around data residency and operations within national territory. The Brazilian Cloud is intended to go further by building domestic capacity to develop, maintain and evolve critical parts of the technology stack.
The objective is not to purge foreign technology. That would be extraordinarily difficult in an industry built around global semiconductor, software and infrastructure supply chains.
Instead, Brazil wants to identify the dependencies it cannot avoid and reduce the ones it considers dangerous.
Under the Market Listening Support Handbook, the future platform should allow technologies, particularly software, to be developed, maintained and evolved by Brazilian institutions and teams.
That makes software control central to the strategy.
Serpro has already spent years working across multiple public Cloud environments. Alexandre Improta, strategic projects manager at Serpro’s Data Center, said the organisation began operating in this model in 2019 and now works with technologies from different providers.
“This experience integrates the technical references used in the discussion of the Brazilian Cloud. The goal is to establish mechanisms that allow the use of external technologies while maintaining control over elements considered critical to the operation,” said Improta.
In practice, that means designing an infrastructure capable of surviving supplier changes.
Two requirements are particularly important: interoperability and national capability.
The architecture is expected to use open standards, allow migration between environments and support equipment from different vendors. These sound like familiar enterprise technology principles, but in a sovereign Cloud they become geopolitical safeguards.
Vendor lock-in is no longer simply a procurement problem when the workloads involved support government operations or critical public services. Dependence on one proprietary platform can become dependence on a particular company, jurisdiction and technology ecosystem.
Brazil therefore wants sovereignty to vary according to the importance of the workload.
A relatively low-risk application may tolerate dependencies that would be unacceptable for a system supporting essential government services. As criticality increases, so does the required ability to operate, recover, audit, modify and ultimately replace parts of the infrastructure.
But Brazil is also attempting something harder: turning the abstract language of technological sovereignty into numbers.
Serpro has developed what it calls the Sovereignty Gradient, an assessment methodology dividing sovereignty into three areas. Data sovereignty accounts for 30% of the score, technological sovereignty another 30% and operational sovereignty 40%. Fifteen criteria feed into the index.
The heavier weighting given to operations is significant.
A platform can satisfy residency requirements and still leave its operator dangerously dependent on someone else to keep it running. Operational sovereignty asks a more basic question: if outside assistance disappears tomorrow, can the service continue?
Serpro is trying to prove the answer rather than accepting contractual assurances.
According to Improta, its verification procedures have expanded dramatically, from approximately 70 tests to around 500. Practical assessments had uncovered situations where requirements appeared to have been satisfied on paper but failed to hold up during testing.
One of the most revealing techniques is brutally simple.
Disconnect it.
The Disconnection Test, described during a public hearing on the Brazilian Cloud by Gildomiro Bairros, engineering manager of platforms and Cloud solutions at Serpro, puts a solution into a laboratory environment and cuts its external connection.
Engineers then see what survives.
Can essential services continue operating? Can administrators still control the environment? Does some apparently local component suddenly stop working because it needs to communicate with a remote platform?
“A solution that relies, for example, on a console located outside the national data center or on a permanent external connection for its administration presents a dependency that needs to be considered in the sovereignty assessment,” said Bairros.
It is effectively a technological stress test for sovereignty.
The same principle becomes even more complicated when AI enters the equation.
Governments racing to build sovereign AI capacity frequently focus on compute: how many GPUs they possess, where the hardware is installed and who operates the data centre.
Brazil’s approach suggests that is only part of the equation.
A GPU sitting on national territory is still embedded in a wider technology stack encompassing software, libraries, management platforms and other components required to turn silicon into usable AI infrastructure. Sovereignty therefore depends on understanding the entire stack and determining which components could be replaced without bringing the system down.
The proposed Brazilian Cloud would use public infrastructure located in Brazil and be operated by a public company. Licensing conditions are also expected to allow the platform to continue operating, being maintained and evolving even after the relationship with a private technology partner ends.
That tackles another form of dependence that can be harder to see than foreign hardware: contractual lock-in.
Owning infrastructure means relatively little if the software required to operate it becomes inaccessible when a commercial relationship terminates.
There are limits to Brazil’s ambitions.
Hardware is not currently the central target. The initiative excludes, at this stage, purchasing ICT and networking infrastructure as well as contracting hosting, colocation or housing services. Its focus is the software platform and Brazil’s ability to develop, maintain and evolve it.
That may prove to be the most pragmatic part of the strategy.
No major economy can easily reproduce the global semiconductor and Cloud supply chains that underpin modern computing. Attempting complete technological autarky would be enormously expensive and potentially counterproductive.
But governments can decide where dependence becomes unacceptable.
That is the bigger experiment taking place inside the Brazilian Cloud.
Instead of treating sovereignty as a label that can be attached to infrastructure because the servers happen to sit inside national borders, Brazil is trying to treat it as an engineering property — something that can be tested, scored and potentially broken.
The question is no longer whether foreign technology exists inside the stack. It almost certainly will.
The question is what happens when that technology is no longer available.
If Brazil can still operate the platform, move workloads, administer critical systems and keep public services running, dependence remains manageable.
If pulling one external connection brings everything to a halt, the servers may be in Brazil.
The sovereignty is somewhere else.


