We live in the age of interdependence. No nation — big, small, powerful or weak , nukes or no nukes — can truly sustain itself in isolation. A lesson that was recently reminded to the world’s most powerful nation, The United States.
Interconnectedness is not a new phenomenon, in fact since human beings first organized themselves into families, tribes, and communities, survival has depended on cooperation and mutual reliance. But what has changed is the depth and complexity of global integration.
It has expanded uncontrollably since Adam Smith first prophesied the logic of specialization and exchange that underpins today’s global supply chains, in The Wealth of Nations.
But it is also true that from the inception of the concept of “nations state”, all nations act in what they perceive to be their own interest.
Therefore in this interconnected world, great powers are exploiting these networks of dependence in pursuit of their strategic interests. It has become a tool of coercion and influence — a phenomenon so widespread and consequential that it now has its own name: “weaponized interdependence.”
Yet we — the smaller nations — are not helpless in this reality, only vulnerable to our own stupidity. In other words, how a nation assesses its dependencies must include a critical evaluation of the vulnerabilities that can be exploited against it during periods of competition or crisis.
We are not advocating a retreat from globalization — that would be a stupid course of action, and one that is neither practical nor desirable. But we must understand, manage, and mitigate our dependencies before they harden into strategic liabilities.
One such dependency Sri Lanka seems to be sleepwalking into is its digital identification project. We are building — or, more accurately, allowing India to build — our **Sri Lanka Unique Digital Identity (SL-UDI) **project. It is being built on India’s Modular Open-Source Identity Platform (MOSIP) and will collect biometric data, including facial, fingerprint, and iris scans, for unique identity verification, alongside an “e-Locker” mobile app for digital service delivery. The project is officially described as funded by an Indian grant, but the reality is that India is financing only about 50 percent of it — roughly LKR 10.4 billion of a total project budget of approximately LKR 20 billion.
India has already begun building in dependency, requiring the selection of an Indian firm as Master System Integrator (MSI) as a condition of the grant itself. Most alarmingly, procurement is being run through India’s National Institute for Smart Government (NISG), among five shortlisted Indian companies — Infosys, TCS, Protean eGov, RailTel, and Bharat Electronics. Why is it not a global tender where even Sri Lankan IT firms - some of the worlds leading such as MIT, WSO2, IFS, Virtusa - are also allowed to compete for. This process has already drawn criticism from the Department of Registration of Persons (DRP) — the line department responsible for the project, which has itself built a functioning e-NIC system that is more than 80 percent complete, with roughly LKR 5.5 billion already invested.
In this century, sovereignty is no longer defined solely by the traditional pillars of territory, population, and government — it has extended into the digital domain. Networks, platforms, and digital infrastructure are now strategically significant, arguably as much as, if not more than, physical borders and critical national assets. Among these digital assets, data is the most crucial. Digital sovereignty is therefore not merely a technological concern; it is a matter of national security, political autonomy, and economic resilience.
Nations that lack control over their digital ecosystems risk exposing themselves to external influence, surveillance, coercion, and disruption. At the heart of digital sovereignty lies the issue of privacy — and here we do not mean merely individual rights. The collection, storage, and control of personal and national data is itself a matter of strategic vulnerability. Allowing a foreign power to dominate or control sensitive national data — and the digital infrastructure that collects, stores, processes, and manages that data — carries profound implications for national sovereignty. In Sri Lanka’s case, such dependence would effectively grant unprecedented leverage to the single most consequential external power in its strategic environment: India.
The issue is not whether India is a friend or partner today, but the enduring reality that states pursue their own national interests, and that relationships between states evolve as circumstances change. History repeatedly demonstrates that strategic dependencies, once established, can be transformed into instruments of influence, pressure, and coercion when interests diverge. From this perspective, permitting any foreign power to acquire dominant control over critical digital infrastructure and sensitive national data creates a vulnerability that future governments may find difficult to reverse. Such dependence risks placing key elements of Sri Lanka’s digital sovereignty beyond its own control, creating opportunities for external actors to shape political, economic, and strategic outcomes in ways that serve their interests rather than Sri Lanka’s.
In an era of weaponized interdependence, the prudent question is not whether such leverage could be used, but whether Sri Lanka can afford to create the conditions that make its use possible. A sovereign state must therefore ensure that critical national data, and the infrastructure that supports it, remain subject to effective national oversight, regulation, and control.
China’s proposed solution to this dilemma — unlike the Indian model, which creates long-term technological and operational dependencies — offers full financing alongside local ownership and implementation. Under this model, the development, operation, and management of the project would be undertaken by Sri Lankan engineers and companies, with no direct foreign involvement in the design, coding, or day-to-day operation of the system. China’s contribution would be limited primarily to financing and the provision of equipment.
Predictably, concerns will be raised about the security implications of using Chinese technology. We do not believe such concerns should be dismissed; rather, they deserve careful consideration. But the critical issue is not the nationality of the equipment itself — it is the degree of national control, transparency, and oversight embedded within the system. If the architecture, software development, integration, and maintenance of the system remain under Sri Lankan control, local engineers would retain — and therefore bear the responsibility for — the ability to conduct security audits, inspect source code, identify vulnerabilities, and verify that no unauthorized access mechanisms or backdoors exist. The ultimate safeguard, then, would be the competence and vigilance of Sri Lanka’s own technical professionals — a standard we believe is on par with, if not exceeding, international norms.
This stands in contrast to models in which critical digital infrastructure is designed, developed, and maintained by foreign entities on foreign frameworks, where the host nation may possess only limited visibility into the system’s internal workings and correspondingly limited ability to independently verify its security. From the perspective of digital sovereignty, the central question should not be whether the foreign partner is East or West, friend or rival — but whether it is Sri Lanka that retains meaningful control over the infrastructure, data, and technological capabilities upon which its future sovereignty increasingly depends.
China’s proposal also offers Sri Lanka something beyond favorable financing terms: strategic leverage. The mere existence of a credible alternative partner strengthens Colombo’s negotiating position by reducing its dependence on any single external actor — an opportunity to hedge, using competition among major powers to secure better terms, stronger safeguards, and greater respect for Sri Lanka’s sovereign preferences.
This is not an argument that China is some uniquely benevolent actor in the international system. States do not conduct foreign policy out of charity, and China is making this offer because it serves Chinese interests, not Sri Lankan ones. That reality should be accepted, not denied, and used as the foundation of sound statecraft. The relevant strategic calculation is not whether China is good or India is bad, but how each power’s interests — relative to Sri Lanka, and relative to each other — translate into risk.
On that score, geography matters. India’s proximity gives it an enduring and immediate ability to shape developments inside Sri Lanka that no other external power can replicate. China, despite its undeniable interests in the Indian Ocean Region, operates from far greater distance, and its ability to directly influence Sri Lanka’s political, economic, and social outcomes remains correspondingly constrained. All dependencies carry risk, but not all are equally vulnerable to weaponization — a dependency on China is simply less exposed to that risk than a comparable dependency on India. In that sense, Sri Lanka would be choosing the lesser of two evils, so to speak.
One might reasonably conclude, at this point, that this paper is advocating for China — and that judgment would not be unfair. Of the two proposals currently on the table, we assess that the Chinese model gives the least cause for concern relative to the Indian one. Ultimately, however, this debate is not about choosing India over China, or China over India. It is about choosing Sri Lanka.
The central lesson of the twenty-first century is that power increasingly flows through networks of dependence rather than through traditional instruments of coercion alone. States that fail to recognize this reality risk surrendering elements of their sovereignty not through conquest, but through convenience, complacency, and poorly considered partnerships. The question before Sri Lanka is therefore not whether foreign assistance should be accepted, but whether that assistance strengthens or weakens the nation’s ability to retain control over its most critical strategic assets.
Digital identity infrastructure is not merely another government project. It will become the foundation upon which future governance, public services, financial systems, commercial transactions, and citizen records are built. Whoever holds influence over that infrastructure holds influence over a critical component of Sri Lanka’s future sovereignty. For this reason, the decisions made today will carry consequences that extend far beyond the tenure of any government or the duration of any bilateral relationship.
Sri Lanka should therefore approach the SL-UDI project through a simple principle: maximize national control, minimize strategic dependency, and preserve the ability to independently manage, secure, and govern its own data and digital infrastructure. Any proposal — whether originating from India, China, the West, or any other partner — should be evaluated against that standard alone. By that measure, the Chinese proposal appears to offer a more favorable balance of risk and sovereignty than the current Indian model, because it places greater emphasis on local ownership, implementation, and control. Whether one ultimately agrees with that assessment is secondary to the broader point: Sri Lanka must never allow critical national infrastructure to evolve into a strategic vulnerability.
Small states cannot eliminate dependency. Such a goal is neither realistic nor desirable in an interconnected world. What they can do is ensure that their dependencies are diversified, manageable, and resistant to coercion. Wise statecraft lies not in rejecting globalization but in navigating it prudently. In an era of weaponized interdependence, sovereignty belongs not to the nation that stands alone, but to the nation that remains master of the dependencies upon which it relies.