Government IT dependency is no longer just bad procurement. Britain’s reliance on foreign tech giants is a strategic security risk.
Britain has not merely outsourced government IT. It has allowed government IT dependency to become a structural weakness, outsourcing leverage, institutional memory, technical judgement and, in too many cases, the machinery of government itself.
For years, government IT dependency was treated as boring back-office plumbing: Microsoft for documents, Oracle for databases, Amazon Web Services and Azure for cloud infrastructure, and large outsourcing firms for delivery.
That complacency no longer survives contact with reality.
Since 2016, the world has changed. The Trump era did not create Britain’s weakness, but it exposed it. It reminded us that allies can become transactional, administrations can become volatile, and relationships once treated as permanent can suddenly become conditional.
A serious country does not build critical infrastructure on trust alone.
Foreign governments change. Courts intervene. Corporations restructure. Chief executives move on. Strategic interests shift. That same tension between sovereignty, capability and strategic dependency appears in foreign policy too, as I argued in Chagos, Diego Garcia and the £101 Million Question.
This is not anti-Americanism. It is basic statecraft.
Contents
- The bill is already enormous
- The contract price is only the visible cost
- Government IT dependency is a strategic security issue
- Data security is not just about server location
- Then there is the tax problem
- Failure is not an exception. It is part of the pattern
- Europe is beginning to understand this
- Open source is not magic. But it changes power.
- The test every contract should face
- The real cost is control
The bill is already enormous
The UK government’s own State of Digital Government Review says the public sector spent approximately £26 billion on technology in 2023.1Cabinet Office / DSIT, State of digital government review, published January 2025. The review states that the public sector spent approximately £26 billion on technology in 2023. GOV.UK.
The Public Accounts Committee says government spends at least £14 billion a year procuring digital services.2House of Commons Public Accounts Committee, Government’s relationship with digital technology suppliers, 2025. The Committee refers to at least £14 billion a year being spent by government on procuring digital services. UK Parliament.
The Register has reported that the UK public sector expects to spend around £9 billion on Microsoft products and services over five years, roughly £1.9 billion a year.3Lindsay Clark, “Faced with £40B budget hole, UK public sector commits £9B to Microsoft”, The Register, 7 August 2025. The Register.
That is before Oracle, AWS, Google, Salesforce, ServiceNow, Palantir, IBM, Fujitsu, Capgemini, Accenture, CGI, Sopra Steria, Atos, DXC, Kyndryl, Serco, Capita and the rest of the public-sector technology supply chain are properly considered.
This is not loose change. This is national infrastructure-scale spending.
Yet we still talk about it as if it were merely an IT budget. This is not the first time public money has been channelled through private delivery structures with weak democratic accountability. I explored a similar pattern in The Hidden Cost of Public-Private Partnerships, where public risk and private profit often travel together.
The contract price is only the visible cost
The direct cost is bad enough. The hidden cost may be worse.
Every failed project leaves wreckage behind it: a half-built system, a delayed replacement, a legacy platform kept alive years longer than planned, another emergency extension, another consultancy contract, and another supplier embedded even deeper into the public machine.
This is how dependency becomes permanent.
A department starts with email and office software. Then comes cloud storage. Then identity management. Then cyber security. Then workflow tools. Then analytics. Then AI add-ons. Then staff training. Then custom development. Then data formats. Then integrations. Then renewal.
That matters because AI is not neutral when its infrastructure, training data, deployment and commercial incentives are controlled by a handful of powerful firms. I explored that wider question in What the AI’s Think: Corporate Power, Ethics, and the Future of Artificial Intelligence.
Eventually, leaving is no longer a procurement decision. It is open-heart surgery.
That is vendor lock-in. Not as a theory, but as a business model.
The supplier does not need to win the next competition fairly. It simply needs to make escape more expensive than surrender.
The real danger of government IT dependency is that each renewal makes the next escape harder, more expensive and more politically risky.
Government IT dependency is a strategic security issue
The phrase “digital sovereignty” sounds polite. It sounds like something discussed at conferences by people in lanyards.
The better phrase is strategic security.
Because the question is not simply where the data sits. The question is who controls the system.
- Who controls the logins?
- Who controls the updates?
- Who controls the licence?
- Who controls the encryption keys?
- Who controls the support contract?
- Who controls the audit trail?
- Who can change the price?
- Who can terminate access?
- Who can be compelled by foreign law?
- Who carries liability when things fail?
If the answer to too many of those questions points outside the UK, then Britain has a problem.
Not a branding problem. Not a procurement problem. A state-capacity problem.
That state-capacity problem links directly to a wider question I raised in Can We Really ‘Tear Down’ Bureaucracy for Efficiency?: whether stripping back public institutions actually improves delivery, or simply leaves government more dependent on outside suppliers.
- Could the UK continue running critical public services if relations with a foreign power deteriorated?
- Could it maintain systems if a supplier restricted support?
- Could it resist foreign legal pressure placed on a cloud or software provider?
- Could it patch, rebuild or migrate core public systems without the original vendor?
- Could it inspect proprietary systems deeply enough to know what they are doing?
For too much of the public sector, the honest answer may be: not quickly, not cheaply, and not safely.
That is not sovereignty. That is dependency wearing a headset and calling itself digital transformation.
Data security is not just about server location
The public is often reassured that data is safe because it is stored in a UK data centre, or because a contract says UK GDPR applies.
That is not enough.
A UK data centre can still run on a foreign-controlled platform. A UK subsidiary can sign a contract while the intellectual property, operational control, support system or parent-company obligations sit elsewhere. A cloud region can be physically in Britain while the provider remains subject to foreign law.
The serious question is not simply: where is the server?
The serious questions are:
- Who owns the platform?
- Who controls the software?
- Who has administrative access?
- Who can see the logs?
- Who provides the updates?
- Who owns the intellectual property?
- Which courts matter?
- Which foreign laws apply?
- Who can switch it off?
Until those questions are answered honestly, public-sector “cloud sovereignty” risks becoming little more than sovereignty-flavoured marketing.
The same underlying danger appears in the politics of personal data. In From Likes to Lies, I looked at how data can be used not merely to observe citizens, but to shape opinion and influence democratic behaviour.
Then there is the tax problem
There is another awkward question.
How much public money flows into multinational technology suppliers, only for profits, licensing income, intellectual property charges or intra-group fees to be structured in ways that minimise UK tax?
This must be phrased carefully. Legal tax planning is not the same as illegal evasion. But the public-interest problem is obvious.
The taxpayer pays the contract. The supplier books the revenue. But where is the profit declared? Where is the intellectual property held? Where do the licence payments go? Which company carries the liability? Which jurisdiction gets the tax?
TaxWatch has estimated that seven large US-based technology groups may have made almost £15 billion of profit from UK customers in 2021, while complex structures significantly reduced their UK tax exposure.4TaxWatch, “Seven large tech groups estimated to have dodged £2bn in UK tax in 2021”, 2023. TaxWatch.
So the taxpayer may pay twice: once through the public contract, and again through lost tax revenue.
Then perhaps the taxpayer pays a third time when the system fails, the licence increases, the migration becomes impossible, or the legacy platform has to be kept alive because nobody in government can safely turn it off.
Failure is not an exception. It is part of the pattern
The mythology of outsourcing says private suppliers bring discipline, efficiency and expertise.
Sometimes they do.
But Britain’s public-sector IT record is littered with delays, overruns, resets, emergency extensions, abandoned projects and legacy systems that become more expensive with every year they are not replaced.
The Register has reported that only 15 commercial staff with direct digital procurement expertise were dedicated to dealing with the government’s largest technology suppliers, despite around £14 billion of annual central government technology spending.5Lindsay Clark, “Just 15 buyers are in charge of £14B in UK central government tech spending”, The Register, 6 June 2025. The Register.
That should terrify people.
It suggests that the British state is entering negotiations with some of the most powerful technology companies on Earth while lacking the internal capacity to properly challenge, replace or escape them.
When that happens, the supplier is not merely a supplier. It becomes the adult in the room.
Europe is beginning to understand this
The UK does have guidance encouraging open source and open standards.6Government Service Manual, “Be open and use open source”, GOV.UK. The guidance encourages government teams to use open standards, consider making source code open and avoid locking users into a single supplier. GOV.UK.
But guidance is not law. Guidance is not industrial strategy. Guidance is not internal capability. Guidance is not a migration plan.
The European Union has moved further in treating interoperability and digital independence as strategic public infrastructure. The Interoperable Europe Act entered into force on 11 April 2024, creating a legal framework to strengthen public-sector interoperability across the EU.7European Commission, Interoperable Europe Act. The Act entered into force on 11 April 2024 and aims to strengthen public-sector interoperability across the EU. European Commission.
This does not mean the EU has mandated that every government system must be open source. It has not.
But it does show a different direction of travel: open standards, reuse, interoperability, shared public-sector solutions, less dependence on single-vendor ecosystems, and more awareness that public administration itself now rests on digital infrastructure.
Britain, by contrast, risks being left in the worst possible position: dependent on foreign proprietary platforms, but without the legal discipline, public procurement strategy or domestic industrial base needed to escape them.
This fits a broader pattern in British politics: the country often depends on things it then pretends it can do without. I made a similar argument about labour, public services and economic reality in Could Britain Survive Without An Immigrant Workforce?.
Open source is not magic. But it changes power.
Open source is not a cure-all.
Bad open-source projects can fail. Open code still needs skilled maintainers. Security still needs funding. Public bodies still need discipline, governance, documentation and competence.
But open source changes the balance of power.
- It allows systems to be inspected.
- It allows code to be reused.
- It allows suppliers to compete on support rather than ownership.
- It reduces lock-in.
- It preserves knowledge.
- It gives government somewhere else to go.
- It means public money can create public assets, rather than simply renting private black boxes forever.
If public money pays for a public system, the public sector should not be trapped inside a private system it cannot inspect, repair, reuse or leave.
The test every contract should face
The answer is not to ban foreign suppliers. That would be unrealistic and probably damaging.
The answer is to treat critical digital systems as strategic infrastructure.
Every major public-sector technology contract should face a Strategic Dependency Assessment before award or renewal.
That assessment should ask:
- Who owns the supplier?
- Which foreign laws apply?
- Where is the data stored and processed?
- Who controls access?
- Who controls the encryption keys?
- Where are profits booked?
- Where is the intellectual property held?
- Which company carries liability?
- Which subcontractors are involved?
- Can the system be migrated?
- Can the data be exported in open formats?
- Can the public sector operate the service if the supplier fails, withdraws, is sanctioned, is compromised, or becomes politically exposed?
- Does government retain enough internal expertise to challenge the supplier?
If those questions cannot be answered clearly, the contract should not be treated as routine procurement.
It should be treated as a strategic risk.
The real cost is control
The visible bill is already huge.
The hidden bill is larger.
But the deepest cost is not financial.
It is the loss of control.
The real cost of government IT dependency is not merely the contract price. It is the loss of control.
A state that cannot independently operate, inspect, secure, migrate or replace the systems through which it pays benefits, collects taxes, manages health records, runs courts, controls borders and coordinates public services has surrendered something far more important than a procurement budget.
It has surrendered operational sovereignty.
The British state should not award critical digital contracts unless it can answer three simple questions:
Who controls the system?
Who can turn it off?
Where does the money go?
Until those questions are answered, Britain is not modernising government.
It is renting it.
Sources & References
- 1Cabinet Office / DSIT, State of digital government review, published January 2025. The review states that the public sector spent approximately £26 billion on technology in 2023. GOV.UK.
- 2House of Commons Public Accounts Committee, Government’s relationship with digital technology suppliers, 2025. The Committee refers to at least £14 billion a year being spent by government on procuring digital services. UK Parliament.
- 3Lindsay Clark, “Faced with £40B budget hole, UK public sector commits £9B to Microsoft”, The Register, 7 August 2025. The Register.
- 4TaxWatch, “Seven large tech groups estimated to have dodged £2bn in UK tax in 2021”, 2023. TaxWatch.
- 5Lindsay Clark, “Just 15 buyers are in charge of £14B in UK central government tech spending”, The Register, 6 June 2025. The Register.
- 6Government Service Manual, “Be open and use open source”, GOV.UK. The guidance encourages government teams to use open standards, consider making source code open and avoid locking users into a single supplier. GOV.UK.
- 7European Commission, Interoperable Europe Act. The Act entered into force on 11 April 2024 and aims to strengthen public-sector interoperability across the EU. European Commission.