Summary
- Scotland’s digital and technology sector generated £5.7 billion of gross value added in 2022 and employed 60,000 people in 2024.
- Exports beyond Scotland were valued at £4.7 billion, although most went to the rest of the UK rather than international markets.
- Data localisation, cloud rules, cyber certification, AI assurance, and divergent regulation can force smaller exporters to duplicate infrastructure and compliance work.
The Scottish Government has identified data-localisation rules, cybersecurity certification, artificial-intelligence assurance, and regulatory fragmentation as growing barriers to technology exports, even as digital services account for a substantial share of Scotland’s trade beyond its borders.
An independent Trade in Services Report published by the government values Scotland’s digital and technology sector at £5.7 billion in gross value added during 2022, equivalent to 3.4% of the Scottish economy. Employment stood at approximately 60,000 in 2024, representing 2.2% of the workforce.
The sector exported £4.7 billion of services beyond Scotland in 2022, amounting to more than 82% of its gross value added. However, £2.9 billion went to customers elsewhere in the UK, while international exports were valued at £1.7 billion.
That distinction is important because a business serving England, Wales, or Northern Ireland operates within a largely common legal, currency, and regulatory environment. International expansion exposes the same company to differing rules on personal data, cloud hosting, cybersecurity, artificial intelligence, professional mobility, and platform access.
A large export figure hides concentration
Scotland’s technology sector includes telecommunications, computer services, information services, software, cybersecurity, systems design, and AI solutions. The official classification also includes video-game development, reflecting the limitations of industrial codes that do not map neatly onto contemporary digital markets.
Only around 18% of the sector’s economic output was retained within Scotland in 2022, while 51% was sold to the rest of the UK and about 30% internationally. That distribution shows a highly trade-dependent sector, although it also confirms that Scotland’s largest external market remains the domestic UK economy.
The report draws on UK-wide destination data to describe international demand because detailed Scottish service-export statistics are limited. Across the UK, the European Union and United States dominate computer and information-services exports, together accounting for a large proportion of the leading destination markets.
The EU offers geographic proximity and a large customer base, but Brexit has introduced barriers that do not apply to suppliers established inside the single market. The report concludes that UK businesses have gained access to some less restrictive non-EU markets while facing greater friction in the commercially important European market.
Trade in software and digital services can appear less exposed to borders than physical goods because no lorry or container crosses customs. In practice, regulation shapes the architecture through which a service is delivered, the locations where information may be stored, the staff permitted to support customers, and the evidence a supplier must provide before entering a market.
Compliance increasingly changes the product
Data-flow and localisation requirements can force providers to build separate hosting arrangements for different countries or customer groups. A software company operating one multi-tenant cloud platform may need additional infrastructure, contractual controls, and operating processes where customers require local storage or restrict cross-border support access.
Those changes raise fixed costs that are easier for multinational vendors to absorb than smaller Scottish exporters. A business may need several cloud regions, duplicated monitoring, separate legal advice, and country-specific documentation before generating meaningful revenue from the target market.
Cybersecurity products face another layer of friction through testing, encryption reviews, certification, incident-reporting obligations, and rules governing the movement of security telemetry. Managed detection services often depend on analysing logs across several customers and locations, so restrictions on transferring that information can require local security operations or fragmented tooling.
AI services sit across both sets of obligations. Providers must address data protection and hosting while also handling documentation, risk classification, transparency, bias testing, safety assurance, and conformity requirements that vary according to the system and jurisdiction.
The report notes that such rules can serve legitimate public interests, including privacy, resilience, safety, and accountability. The commercial problem arises where jurisdictions pursue similar objectives through incompatible processes, requiring exporters to repeat assessments without producing a corresponding improvement in protection.
Assurance could become an export capability
Regulation is not only a cost for Scottish technology businesses. Companies able to demonstrate robust security, responsible data use, and credible AI governance may gain access to customers in healthcare, financial services, government, energy, and other regulated industries.
Scotland already has research, financial-services, public-sector, and cybersecurity expertise that could support specialist assurance services. Testing, audit tooling, compliance automation, and secure cloud operations may become exportable products in their own right as regulatory obligations spread.
Building a market around assurance requires clarity over which standards customers and regulators will accept. A small provider gains little from completing one certification if every target country or large customer demands another overlapping framework.
Mutual recognition and regulatory cooperation therefore have a practical commercial effect. Agreements covering digital identities, cybersecurity certificates, professional qualifications, and data-transfer safeguards can reduce duplicated work without removing the underlying policy protections.
The report also points towards the importance of digital chapters in trade agreements, although negotiated language does not always determine how regulators, public procurers, or large customers behave in practice. Market access can remain constrained by sector rules, local certification, or conservative procurement even where a trade agreement supports cross-border data flows.
The evidence base remains uneven
Although the report was published in August 2026, its headline gross-value-added and trade figures relate to 2022, while the employment estimate is from 2024. The time lag reflects the difficulty of measuring service exports, but it means the figures do not capture the full effect of recent AI investment, changes in technology employment, or shifts in customer spending.
Industrial classifications also obscure differences between businesses. A telecommunications operator, software-as-a-service company, cyber consultancy, game developer, and AI supplier can all sit within the same broad sector while facing different customers, margins, export models, and regulatory barriers.
Better evidence would distinguish recurring cloud revenue from project services, show where Scottish companies ultimately earn international income, and identify which compliance costs prevent expansion rather than merely inconvenience it. Without that detail, policy risks offering generic export support to businesses whose obstacles are primarily technical or regulatory.
Even with those limitations, the report shows that Scotland’s digital economy depends heavily on markets beyond Scotland and that access cannot be separated from technology architecture. Hosting locations, security controls, model documentation, and regulatory reporting increasingly determine where a digital service can be sold.
The next stage of export policy will therefore require more than promoting Scottish technology overseas. Progress will depend on reducing avoidable regulatory duplication, helping smaller companies interpret market requirements, and ensuring that domestic rules support systems capable of operating across borders rather than locking suppliers into one jurisdiction.






