AI

The Splinternet: How Data Is Fragmenting

What is the Splinternet? How geopolitics and AI agents are fragmenting the internet and what organizations need to know about where their data is going.

Liam Lawson
August 21, 2026

For most of the past twenty years, the internet was treated as a single, open, globally shared resource. You built something, put it online, and anyone anywhere could access it. That model is changing, faster than most organizations realize.

The concept has a name: the Splinternet. It refers to the fragmentation of the internet into separate, sovereign, and increasingly incompatible digital ecosystems, driven by geopolitics, regulation, and the arrival of AI agents that are raising the security stakes for everything connected to the public web. Understanding what is happening and why is becoming a strategic question for any organization that depends on digital infrastructure, which at this point means nearly all of them.

Three Forces Driving the Fragmentation

Zachary Smith, CEO and co-founder of Datum and the founder behind two significant infrastructure exits including Packet, acquired by Equinix for $335 million, has been building network infrastructure for decades. Speaking on a recent episode of The AI Report podcast, Zac outlined three converging forces that are fundamentally changing how the internet works.

The first is that data is going everywhere. As AI models, agents, and distributed software become the norm, data is no longer sitting in one place. It moves between devices, cloud services, AI providers, and edge locations constantly. The infrastructure that worked when most applications were centralized is struggling to keep up with that reality.

The second is the explosion of providers. Ten years ago, the cloud market was largely dominated by Amazon, Google, and Microsoft. Today that landscape includes hundreds of specialty services: platforms built specifically for AI workloads, database services, payment tools, authentication providers, and deployment platforms. The average application now pulls from dozens of these simultaneously, which means every organization is managing a tangled web of dependencies across providers with different security practices, different reliability guarantees, and different data handling policies.

The third force, and the one Zac describes as underappreciated, is geopolitical. Germany already requires that certain categories of data about German citizens be stored physically within Germany. France is investing in AI infrastructure independent of US providers. China and Russia have operated nationally controlled internet environments for years. And within the United States, certain content is only legal in specific states, requiring different handling depending on where a user happens to be located.

Those rules are coming to more industries and more regions. The gap is how prepared organizations will be when they arrive.

The Private Internet Already Exists

One of the less visible aspects of this fragmentation is how much of the internet is already private.

Most people interact only with the public web, the part you access through a browser. But a significant portion of total internet traffic never touches the public web at all. It moves through direct connections between networks, data centers, and cloud providers at meet me rooms, physical buildings where different networks exchange traffic directly. Financial services, inter-cloud data transfers, enterprise-to-vendor communications, and media distribution pipelines already largely operate on this private layer rather than the open internet.

Zac uses the Visa network as a frame for where more of the internet is heading. Visa runs on a curated, secure network where every participant, whether a bank or a merchant terminal, has been vetted and must meet security requirements before connecting. The result is a system that handles enormous transaction volume reliably because access is controlled. His argument is that AI agents are pushing more of the broader internet in this same direction.

When a business deploys an agent that can access systems, send messages, and take actions on behalf of users, letting that agent roam freely on the open internet creates a significant risk. The natural response is to contain it: build a private environment where the agent can only communicate with specific, approved systems and nothing else. Zac believes we will see every person and every company eventually running their own version of that kind of private network, not just enterprises.

What Organizations Need to Think About

For most businesses, these trends raise practical questions that did not really exist five years ago.

Where is your data actually living? As applications spread across more services and more geographies, the answer is often less clear than it should be. Data that enters one service may be stored, copied, or processed by infrastructure in places with very different legal rules.

Which services are you using to handle data from customers in regulated countries? If you serve users in Germany or France, the tools you use to store and process their information may need to operate within the EU. In healthcare or financial services, those requirements are tighter still.

What happens to your data when an agent acts on it? AI systems that move information between tools and services can expose data to providers that were never part of the original plan. The more independently an agent operates, the more important it becomes to define and enforce where it is allowed to go.

None of these are new categories of risk. What is new is how fast data is now moving across more services, more agents, and more jurisdictions than before, making them harder to track without making deliberate decisions about how your systems are built.

Watch the full conversation with Zac on The AI Report podcast.

Stay up to date with the latest AI news and analysis. Subscribe to The AI Report.

Join the Newsletter
Inchide fereastra