Ayşenur Kasap, MAs in EU Studies and International Security
Simona Petrulyte, MA in EU Studies
“Governments of the Industrial World, you weary giants of flesh and steel, I come from Cyberspace… You have no sovereignty where we gather.” (John Perry Barlow, 1996)[1]. When Barlow, as a cyber-liberitarian, published his Declaration of the Independence of Cyberspace, he captured an emerging vision of a digital realm immune to the heavy hand of state power. Thirty years later, that vision appears increasingly difficult to defend in realistic terms. Unlike traditional domains of global governance, such as trade or aviation, cyberspace has failed to solidify a global regulatory framework so far. Instead, sovereignty has been reasserted and reconfigured within this regulatory vacuum. We are not witnessing the convergence of a global digital order, but its fragmentation into competing legislative pathways.
This is not merely a binary struggle between Washington and Beijing; it is a complex, multi-polar realignment of the relationship between state authority, market, and the individual. By comparatively examining the domestic legislative frameworks of the United States (U.S.), the European Union (EU), and China, this analysis maps emerging models of digital governance and explores their implications for the evolving global digital order. To compare these legislative frameworks systematically, the analysis is organised around three analytical layers: data governance, platform and algorithmic governance, and security and sovereignty. These represent the principal legislative arenas through which contemporary states exercise authority over the digital sphere. Rather than providing an exhaustive review of domestic legal systems, this paper compares key legislative pathways that reveal the dominant governance logic across three analytical layers of digital governance.
Taken together, these layers reveal three broad governance logics around which the emerging digital order increasingly appears to oscillate among these actors: market-led security model, state-centric security model, and rights-based regulatory model. As these powers codify their digital futures, digital governance is increasingly becoming a contest over the legislative organisation of sovereignty. While the U.S. relies on a fragmented patchwork of sector-specific regulations, the EU champions a rights-based regulatory model through comprehensive extraterritorial norms that prioritize individual privacy, often at the cost of higher compliance burdens for global firms. Conversely, China is no longer solely advancing a state-centric security model. Its domestic legislative framework reinforces state authority over data and digital infrastructures, whereas recent international initiatives indicate a growing interest in participating more actively in the institutional architecture of global data governance. This ambition is exemplified by the launch of the World Data Organization (WDO) in Beijing on 30 March 2026. According to its founding vision, the initiative seeks to promote greater interoperability and lower cross-border compliance burdens, offering an alternative approach to global data governance [2].
In this light, our cases are selected not merely as geopolitical equivalents, but as distinct configurations of state–market–security relations, illustrating how digital governance oscillates across different ends of a conceptual pendulum. In doing so, the analysis challenges the common assumption that states grouped under similar political categories necessarily converge in their governance logics. By bringing the EU into comparison with the U.S. and China, it further reveals that even liberal democracies exhibit significant divergence in how they structure the relationship between state power and the digital sphere within the global market. Ultimately, a comparative legislative analysis of these three actors provides a necessary perspective to envisage the emerging digital landscape. As outlined in the comparative matrix (see Figure 1), this divergence is not merely regulatory; it marks a fundamental reconfiguration of where sovereignty in the digital sphere is located.
Data Layer (Ownership, Privacy & Extraction Logic)
The politics of data ownership and control reveals not convergence, but an uneven fragmentation of authority over one of the digital economy’s foundational resources: user-generated data. This fragmentation reflects contestations over authority, security, and the boundaries of state and market power in the digital age. Consequently, data governance is not strictly a matter of privacy regulation, but a struggle over the political economies of data extraction, access, and sovereign control.
In the U.S., data governance has been strongly shaped by national security priorities, particularly in the post-9/11 era, during which surveillance and intelligence-gathering capacities expanded significantly. Regarding a momentum toward stronger privacy protections, the U.S. still lacks a comprehensive federal data protection framework. Instead, its regulatory approach relies on a combination of sector-specific privacy laws, intermediary liability protections such as Section 230, and predominantly ex post enforcement mechanisms. These regulatory intervention typically occurs after harmful practices are identified through agencies such as the Federal Trade Commission (FTC). Together, these features have facilitated the emergence of a market-driven, platform-centric data ecosystem in which major technology firms are able to aggregate and monetize personal data at an unprecedented scale.

By contrast, China’s data governance framework integrates privacy regulation with state security and industrial policy objectives. The Personal Information Protection Law (PIPL, 2021) regulates the collection and processing of personal data, while the Data Security Law (DSL, 2021) establishes state authority over data classification and cross-border data flows. While these legal frameworks may appear structurally
similar to the GDPR at first glance, China’s data governance model operates on a fundamentally different data protection logic. Whereas the GDPR is designed to strengthen individual rights vis-à-vis corporate actors, PIPL and DSL embed personal data within a broader state-centric framework that prioritizes national security, economic development, and regulatory control over digital infrastructures. In this model, data is not solely treated as a protected individual asset, but as a strategic resource subject to state-defined classification, localization requirements, and regulated access under national security provisions. Consequently, personal data protection is integrated into, and at times constrained by, broader objectives of political stability and state sovereignty.
On the other end of the spectrum, the EU has emerged as a leading regulatory power in global data governance through the General Data Protection Regulation (GDPR), which has set de facto global standards for a privacy-first data protection regime since it entered into force in 2018. A defining feature of the GDPR is its extraterritorial scope, applying to the personal data of individuals in the EU regardless of where the data processor is established. The EU’s data governance architecture extends beyond the GDPR to include the Data Governance Act and the Data Act. Together, these instruments constitute a multi-layered regulatory framework that simultaneously aims to protect individual privacy, enable data sharing, and rebalance data-driven markets. This influence has not been driven solely by formal regulatory diffusion but also by structural market incentives. Major technology firms, operating across jurisdictions, have been compelled to internalize European standards in order to maintain access to the EU market, while several states have mirrored core elements of its regulatory architecture in their own legal systems. Further, this dynamic reflects more than regulatory influence and is commonly referred to as the “Brussels Effect”, capturing how the EU’s economic scale translates legal norms into global compliance expectations, effectively positioning the EU as a rule-maker in digital governance beyond its territorial boundaries [3]. Unlike the U.S. market-oriented model and China’s state-centric approach, the EU seeks to reconcile fundamental rights with the economic value of data by constructing regulated data-sharing mechanisms and common European data spaces. However, this reveals a structural paradox: while the EU positions itself as a global norm-setter in data governance, much of the underlying digital infrastructure remains controlled by U.S. and Chinese technology firms. This tension raises a broader analytical question of whether durable normative power can be maintained under conditions of technological and infrastructural dependence.
Platform and Algorithmic Layer (Epistemic Control)
Platform governance exposes a second and more politically sensitive layer of contestation: the control of visibility, speech, and epistemic authority in digital space. Across different jurisdictions, platform governance increasingly revolves around a common concern, the governance of algorithmic visibility, yet authority over these systems is allocated in markedly different ways: primarily to private platforms in the U.S., to the state in China, and to regulatory institutions in the EU.
In the U.S., online speech has largely been governed by private platforms rather than detailed statutory regulation. Supported by the liability protections of Section 230 of the Communications Decency Act (1996), technology companies have been afforded broad discretion to shape how content is moderated, ranked, and recommended. However, this ‘laissez-faire’ approach is increasingly being challenged by security imperatives of the Trump government; the 2026 Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security marks a shift toward a hybrid model, introducing a voluntary framework for collaboration that integrates NSA-led classified benchmarking. This effectively subjects frontier AI models to specialized security assessments, signaling that the U.S. is moving toward an ‘innovation-security’ synthesis that prioritizes national resilience over corporate autonomy.
On the other hand, China represents the most explicit fusion of algorithmic governance and state power. At the platform layer of China’s digital governance, the Algorithmic Recommendation Regulation (2022) mandates that visibility infrastructures remain aligned with state-defined standards of social stability. This proactive logic extends into the AI domain via the Cyberspace Administration of China’s (CAC) Generative AI Measures (2023), complemented by the AI Technology Ethics Review Measures (2026) and AI Anthropomorphic Interactive Services Measures (2026), which collectively govern the entire lifecycle of model training and human–AI interaction. Unlike the functionally differentiated regimes found elsewhere, China’s framework treats data, algorithms, and AI as a unified domain of regulatory oversight. Orchestrated by the CAC, this convergence of security, industrial policy, and informational control transforms technological infrastructure into an explicit extension of state sovereignty.
By contrast, the EU seeks to strengthen public oversight through an unprecedented regulatory toolkit designed to address multiple dimensions of digital power. The Digital Services Act (DSA, 2024) focuses on the governance of online visibility by imposing transparency and accountability obligations on content moderation and algorithmic recommendation systems, thereby shaping how information is curated and encountered in digital spaces. The Digital Markets Act (DMA, 2024) targets the structural concentration of economic power by regulating large “gatekeeper” platforms and limiting practices that reinforce market dominance, such as self-preferencing and ecosystem lock-in. Complementing these, the AI Act (2026) which came into effect with a phased transition process, introduces a risk-based framework for artificial intelligence systems, classifying applications according to their potential impact on safety and fundamental rights and imposing stricter obligations on high-risk use cases. Taken together, these instruments constitute a comprehensive attempt to govern not only platform behaviour, but also the informational, economic, and technological infrastructures that shape digital society.
Security and Sovereignty Layer (Authority & Enforcement)
Without doubt, the overarching aim of digital governance appears in the layer of security and sovereignty, where authority over infrastructure, data flows and technological dependencies is ultimately defined. It is widely acknowledged that the optimism surrounding the vision of a borderless cyberspace in the 1990s, simultaneously, has given way to renewed debates over territorial sovereignty. Consequently, debates in digital governance have increasingly centred on the tension between the traditional understanding of territorial sovereignty and emerging post-territorial approaches referring to a digital sphere of influence where states project authority not through physical geography, but through extraterritorial laws and cloud infrastructures[4]. However, reconciling these competing imperatives reveals the central paradox of contemporary digital governance. However, reconciling these competing imperatives reveals the central paradox of digital governance. While major powers pursue divergent, often fragmented legislative pathways regarding individual privacy and platform control, they share a common underlying drive: an imperative to safeguard domestic security while maintaining structural integration within the global market.
The US operates through a hybrid configuration in which security powers embedded in surveillance legislation coexist with an increasingly explicit strategy of technological containment and industrial policy. In the U.S., security governance prioritizes intelligence capabilities and technological leadership. FISA Section 702 (2008) regulates the access of intelligence agencies to electronic communication data for foreign intelligence purposes. Similarly, the CLOUD Act (2018) expanded the state’s ability to access data for national security purposes, while the CHIPS and Science Act (2022) reflects an industrial strategy aimed at securing technological competitiveness and reducing strategic dependencies.
By contrast, China presents the most centralized model approaching digital security as an extension of the state-centric governance model. It approaches digital security as an extension of state sovereignty. The Cybersecurity Law, National Intelligence Law, and Counter-Espionage Law establish extensive state authority over digital infrastructures and data, while industrial policies reinforce technological self-reliance. Rather than separating cybersecurity, national security, and political authority, China´s governance model treats these objectives as a unified state-led strategy. This legal triumvirate constitutes a layered and symbiotic framework: the Cybersecurity Law establishes infrastructural sovereignty by regulating the technical parameters and data flows of the digital ecosystem. The National Intelligence Law creates an expansive jurisdictional mandate for data access by effectively integrating all digital actors into the state’s intelligence apparatus. Concurrently, the Counter-Espionage Law provides a punitive shield against external interference, broadening the definition of ‘national security’ to encompass virtually any form of cross-border information exchange. Collectively, these statutes transcend simple state control; they represent a comprehensive security architecture where technical regulation, institutional obligation, and penal enforcement are inextricably intertwined.
Conversely, the EU frames security through resilience and strategic autonomy rather than intelligence dominance. The NIS2 Directive and the Cyber Resilience Act strengthen baseline cybersecurity obligations across critical infrastructure and digital products, shifting security governance towards system-wide risk prevention and operational resilience. Meanwhile, the European Chips Act addresses a structural vulnerability in semiconductor supply chains by reducing dependency on external producers and reinforcing Europe’s technological autonomy. As EU’s main paradox introduced under the data governance layer, the European Chips Act serves as a strategic admission of this vulnerability; while the EU seeks to define global standards for data and AI, it remains heavily reliant on external players for the foundational hardware, such as advanced semiconductors designed in the U.S. or manufactured in the Taiwan/China nexus, that powers this ecosystem. Indeed, the European attempt to reconcile market integration with normative and security ambition (e.g., Gaia-X) remains a contested process, caught between the desire for digital sovereignty and the persistent reality of external infrastructural reliance [5]. Consequently, no matter how robust a region’s data governance framework is, it remains inherently constrained if it lacks sovereignty over the physical supply chains that underpin the entire digital architecture.
Consequently, the comparison throughout this paper suggests that the defining feature of contemporary digital governance is not the emergence of entirely distinct legislative models, but the growing convergence of strategic objectives pursued through divergent governance logics. While the U.S., China, and the EU follow distinct legislative pathways, these models are not mutually exclusive. Rather, each increasingly combines security, economic competitiveness, and regulatory authority. What distinguishes these actors is not the presence of these objectives, but the governance logic that takes precedence within their legislative architectures. Across data, platform, and security layers, legislation serves a common purpose: strengthening state capacity to govern data, information systems, and critical infrastructures.
Yet, these ambitions remain fundamentally constrained by the technological environment. Semiconductor production, cloud infrastructures, and cross-border data flows continue to rely on global networks that no single actor can fully control. This reveals a central paradox of the emerging digital order: states seek greater authority over the digital sphere while remaining dependent on technological systems that transcend national borders. The pursuit of digital sovereignty has not diminished this interdependence; rather, sovereignty and interdependence have evolved simultaneously as the defining tension of our era.
Examining these domestic legislative pathways reveals how each actor navigates this tension. The U.S. relies on technological leadership and market-driven innovation reinforced by national security; China complements its state-centric model through institution-building and standards coordination; and the EU projects regulatory influence through legally binding standards backed by market access. Future competition will likely concern not only technological innovation or regulatory influence, but the ability to govern infrastructures that remain inherently global. In this light, the metaphor of the “digital pendulum” requires reconsideration: it no longer captures a temporary movement between models, but an enduring tension between sovereign ambition and structural interdependence. This tension is unlikely to be resolved through either full convergence or complete decoupling. Thus, the central challenge of digital governance will not be determining which model prevails, but whether competing systems can sustain their ambitious claims to sovereignty while remaining dependent on the shared, global infrastructures that bind them together.
- [1] Barlow, J. P. (1996), A Declaration of the Independence of Cyberspace, Electronic Frontier Foundation https://www.eff.org/cyberspace-independence
- [2] The Innovation Informatics Editorial Team, China (2026). World Data Organization launched in Beijing to advance global data governance. The Innovation Informatics, 2:100042. https://doi.org/10.59717/j.xinn-inform.2026.100042
- [3] Bradford, A. (2012). The Brussels Effect (SSRN Scholarly Paper No. 2770634). Social Science Research Network. https://papers.ssrn.com/abstract=2770634
- [4] Paul De Hert & Johannes Thumfart, The Microsoft Ireland Case and the Cyberspace Sovereignty Trilemma. Post-Territorial Technologies and Companies Question Territorial State Sovereignty and Regulatory State Monopolies, 5 (BRUSSELS PRIVACY HUB, Working Paper No. 11, 2018).
- [5] Adler-Nissen, R., & Eggeling, K. A. (2024). The Discursive Struggle for Digital Sovereignty: Security, Economy, Rights and the Cloud Project Gaia-X. JCMS: Journal of Common Market Studies, 62(4), 993–1011. https://doi.org/10.1111/jcms.13594
Photograph: JESHOOTS.COM

