Larry Ellison and Oracle : US digital sovereignty and infrastructure power

Larry Ellison’s fortune and Oracle: digital sovereignty and infrastructure power. Credits: Ilan Costica / Wikimedia Commons — CC BY-SA 4.0.

Credits: Ilan Costica / Wikimedia Commons — CC BY-SA 4.0.

At 81, the Oracle cofounder is more than just a billionaire ranking: as of August 19, 2025, his net worth stands at $302 billion. The real story lies elsewhere: from data centers to AI safety rules, Lawrence J. Ellison (Larry Ellison) places Oracle at the heart of American digital sovereignty. From Project Texas to “Stargate,” infrastructure becomes an instrument of public power.

From Private Fortune To A Sovereignty Tool

Ellison’s trajectory reflects industrial patience. In 1977, he co-founded Oracle and owns about 41% of the company. In doing so, he created a software annuity through licenses and maintenance. He then reinvested that annuity into the cloud and AI. In 2025, Oracle stock gains nearly 50%, driven by AI-related compute and Oracle Cloud Infrastructure’s (OCI) aggressive positioning.

The shift is strategic: by tying itself to contracts of public interest. Oracle links the public interest (security, continuity, localization) and its private interest (capital spending in data centers, recurring revenue). Sovereignty becomes a market.

Oracle As An Arm Of The State: Project Texas And Sensitive Data

At the center of the state-platform relationship, Project Texas turns Oracle into a trusted third party for TikTok: isolation of U.S. services in the Oracle cloud and strengthened access controls, as described by TikTok’s US Data Security (USDS) team and discussed within the CFIUS (Committee on Foreign Investment in the United States) process. The goal: mitigate a perceived risk of dependence on a foreign power and ensure that data remains under U.S. jurisdiction.

This setup is not neutral: it outsources a quasi-sovereign function (securing and auditing a platform with a massive audience) to a private actor, while raising questions about independent assessment and democratic oversight.

Mini Timeline — TikTok/CFIUS And Oracle (2020–2025)

Sept. 2020: the White House announces a framework deal; Oracle becomes a prospective technology partner for TikTok in the United States (U.S. Treasury statement).
2021–2022: change of administration; review of the case under CFIUS. The project evolves toward an operational data isolation solution.
2022–2023: gradual rollout of Project Texas: hosting and access controls under Oracle Cloud for U.S. users (official TikTok USDS documentation).
Spring 2025: renewed talk of a sale of U.S. operations; Oracle remains a cloud provider and a candidate for a broader role, depending on the next political and regulatory decision.

“Stargate”: Industrial Policy Through Infrastructure

Announced as an accelerator for AI infrastructure in the United States, Stargate brings together Oracle and OpenAI; an additional 4.5 GW data center capacity deal is public. Beyond the numbers, the message is clear: reindustrialize through digital technology, secure the training and inference footprint, and bring back critical supply chains (energy, chips, colocation, networking).

The public lever is multifaceted: regulation (AI safety frameworks), public procurement (trusted cloud, FedRAMP), and technology diplomacy (export controls). Ellison is positioning himself at this intersection of industrial policy and private capacity.

Policies That Shape Compute Power

White House: AI Executive Order (October 30, 2023): first requirements for security and testing of advanced systems, interagency coordination, and safeguards for public use of AI.

NIST: AI Risk Management Framework 1.0: a voluntary framework for risk management (security, bias, rights), already adopted by some buyers.

OMB/FedRAMP (M-24-15): modernization of cloud security requirements in federal agencies; higher standards for certifications and the assurance chain.

CISA: Secure by Design: “security by design” guidance that influences public procurement and, in turn, the offerings of major cloud providers.

By combining these building blocks, Washington shapes demand and standardizes security. Oracle, an American company, benefits from a clear legal footprint under federal law. As a result, it gains a comparative advantage in sensitive deals.

Box — The U.S. Legal Framework For AI And Cloud

Executive: the October 30, 2023 Executive Order on safe and trustworthy AI (testing, reporting, and interagency coordination obligations).
Standards: NIST AI RMF 1.0 (risk governance: security, bias, rights), a basis for procurement and internal policies.
Public procurement: OMB/FedRAMP (M-24-15): stronger security requirements, continuous assurance chain for agency cloud services.
Cyberdefense: CISA – Secure by Design: secure-by-default obligations and responsible software practices.
Trade: BIS: export controls on advanced semiconductors (GPU/HBM) and critical equipment.
Transparency: role of the Government Accountability Office (GAO) and audits in monitoring federal data centers and digital policy.

EU–U.S. Comparison: Standards, Sovereignty, And Public Procurement

Regulatory approach
European Union: the AI Act follows a risk-based model, with targeted bans, stronger obligations for high-risk systems, and innovation sandboxes. Phased implementation between 2025 and 2026, under national authorities and a European AI Office.
United States: no equivalent federal framework law; the Executive Order (10/2023) sets guardrails and delegates to agencies (NIST, CISA, OMB) the production of standards and public-sector compliance.

Cloud, localization, and portability
EU: NIS2 tightens security and incident reporting obligations. DORA imposes operational resilience on the financial sector and oversight of critical cloud providers. The Data Act enshrines switching and interoperability for services (anti-lock-in) starting in September 2025. The EUCS scheme (cloud certification, ENISA) is in finalization and could include legal sovereignty requirements (immunity from non-EU law). Transatlantic transfers rely on the Data Privacy Framework (2023), which may be reviewed by the CJEU.
United States: FedRAMP/OMB structures federal cloud procurement and security; data localization mainly depends on contract clauses and sector-specific regimes.

Public procurement and competition
EU: stronger requirements for trusted cloud and portability/interoperability clauses to avoid contractual lock-in. The DMA and competition law aim to curb the structural power of major players.
United States: guided by technical standards, framework contracts, and audits, with a logic of performance and security rather than localization.

Energy and environment
EU: the energy efficiency directive (2023 recast) introduces reporting obligations for data centers and sufficiency indicators (e.g., efficiency, water). CSRD standards strengthen the publication of climate impacts.
United States: monitored by the DOE/LBNL, local mechanisms (utilities, PPAs), and eligibility for certain incentives depending on the state.

Convergences And Divergences
• Convergence on security by design, auditability, and risk management.
• Divergence on legal sovereignty: the EU formalizes territorial control and reversibility requirements; the United States favors an agency-centered and contractual approach.

Energy, Water, And Public Finance: The Democratic Cost Of Gigawatts

Data center electricity demand has tripled over ten years and could still double or triple by 2028, according to the Department of Energy (LBNL 2024 report). At the local level, projects require heavy grid connections, water, and tax incentives.

The democratic question: who pays? Between regulated rates, subsidies, and grid upgrades, part of the cost is socialized. However, direct jobs remain limited. Budget transparency, environmental conditionality, and independent assessment become criteria of legitimacy.

Trade And Technology Diplomacy: Chip Controls, Securing Supply Chains

Sovereignty also depends on control of silicon. Since 2022, the Bureau of Industry and Security (BIS) has tightened export controls on advanced chips (GPU and HBM) to certain destinations, in order to limit access to cutting-edge training capacity. These geopolitical measures are reshaping the supply of chips, servers, and memory. And therefore the cost and pace of infrastructure deployment.

A Democratic Debate That Needs Structure

Infrastructure power calls for counterpower. Several efforts are needed:

  1. Public accounts: publish, ex ante and ex post, the costs and benefits of sites (energy, water, taxation), based on common standards (DOE, LBNL).
  2. Process: oversee projects through audits and public consultations, and harmonized cyber requirements (NIST, CISA, FedRAMP).
  3. Platform transparency: require independent reports on security, data use, and model impact. Especially for services of “general interest” (information, health, and education).
  4. Public procurement: avoid contractual lock-in through multicloud and open standards.

The GAO has long called for tighter governance of federal data centers: a useful benchmark for the AI era.

Style And Networks: The Art Of “Being At The Table”

A Republican supporter, Larry Ellison has cultivated access to decision-makers. He backed Donald Trump, took part in AI-related announcements, and served on Tesla’s board (2018–2022). His method: combine political alliance, a technical pitch (cost, performance, security), and execution capacity (rapid data center rollout). The result is interdependence: the state needs credible operators; Oracle needs a stable public framework to invest at scale.

What The “Ellison Case” Reveals

Digital sovereignty is not decreed; it is built. By establishing itself on the infrastructure layer (compute, storage, networking), Oracle is betting on the form of power that now matters most: control over available compute time, under U.S. law. For citizens, the stakes are high: freedoms (data governance), public finances (site costs), climate (data center footprint), competition (avoiding concentration). Only under these conditions can Ellison’s bet be seen as a public good as well as a private success.

Biographical Highlights

Full name: Lawrence Joseph Ellison
Birth: August 17, 1944, New York
Oracle: cofounder (1977), CEO until 2014, executive chairman and CTO since 2014
Ownership: about 41% of Oracle
Net worth: $302 billion (August 19, 2025, Bloomberg index)
Notable facts: purchase of Lānaʻi (2012); America’s Cup victories (2010, 2013); launch of SailGP (2019)

This article was written by Pierre-Antoine Tsady.