top of page
Search

Sovereign is better. Like healthy is better.

  • Writer: Claas
    Claas
  • Jul 30
  • 9 min read
Digital sovereignty has become something of an obligatory topic. It belongs to good professional form to be working on it and my impression is that this occasionally happens without a clear idea of what the work is meant to achieve. The topic is important, other organizations are doing something about it, so we start.

The debate resembles the one about nutrition. Sovereign is better, in the same way that healthy is better and nobody seriously disputes either statement. I certainly do not. The comparison holds because both are less about ideals than about informed trade-offs, and both are routinely argued as though they were about ideals.

Nobody expects a perfect diet. What separates people who eat reasonably well from people who do not is rarely discipline or purity. It is awareness: knowing roughly what you consume, being deliberate where it matters and staying relaxed about the rest. Applied to sovereignty, that produces a standard considerably lower than independence and considerably more useful. Dependencies you know about, have consciously accepted and could act on are a manageable position. The same dependencies, unexamined, are not.

Which leaves the questions worth asking. What counts as healthy, what counts as sovereign, and does the opposite automatically qualify as unhealthy or dependent? Where does it genuinely matter, where are compromises acceptable and when is fast food a reasonable answer?

I wrote about the term in January and argued that sovereignty is a political concept rather than a corporate objective and that what companies actually need is clarity about where decisions are made and which dependencies they accept. Half a year later that clarity has genuinely improved. Transparency is no longer the bottleneck, which moves the interesting question elsewhere. Once you can read the label, what do you do with it?
The labels got better

Nutrition "solved" its knowledge problem some time ago. Ingredient lists became mandatory, nutritional tables standardized, origin labels more detailed and an app can now scan a barcode and tell you within seconds how processed a product is and how much sugar hides behind a name that sounds like fruit. Anyone who wants to know what they are eating can find out (no comment if I think people actually do).


The transparency around digital dependencies has improved along similar lines and that deserves acknowledgment before any criticism. Contractual terms are more explicit about jurisdiction, processing locations are documented, providers publish transparency reports, and extraterritorial legal access is no longer a niche topic for lawyers.

Regulation is now adding formal categories. The Cloud and AI Development Act, proposed by the Commission in June 2026 as part of the Tech Sovereignty Package, introduces a four-level sovereignty assurance framework ranging from processing inside the EU up to full supply chain control without third-country influence. Level one would become the minimum for public sector suppliers. The legislative process is still running with adoption targeted for the end of 2027, so nothing is binding yet and the substance may well shift. What it already delivers is defined categories instead of adjectives, which the debate did not have before.

One detail in the Commission's own reasoning is worth noting. It estimates that roughly one percent of European public services would actually require the highest level. The maximalist reading of sovereignty is being relativized inside the regulation meant to enforce it.

Knowing is not deciding


What the improved transparency has changed in practice is less than you might expect. Amazon, Microsoft and Google account for roughly 70 percent of the European cloud market. European providers hold around 15 percent, down from 29 percent in 2017 and stable at that level since 2022. Sovereignty meanwhile features prominently in strategy papers, vendor questionnaires and board discussions, which is worth holding next to those market shares. Stated concern and purchasing behavior are clearly not the same thing here.

There is a useful precedent. Microsoft ran a genuinely isolated German cloud under Deutsche Telekom trusteeship, announced its discontinuation in 2020 and shut it down in 2021, citing limited demand and the operational constraints of the isolated setup. The offering existed, the declared interest existed, but the purchases did not. That is the organic aisle being removed because the shelves stayed full, and it should make everyone careful about how much weight to put on survey results.

Ideology is easier than judgment


Absolute positions are comfortable because they remove the need to judge individual cases.

Both topics share a structural problem, which is that a management question keeps turning into a moral one. The sovereignty version produces statements like "everything must be open source", "everything has to come from Europe" and "no US cloud under any circumstances", which are the direct equivalents of "sugar is poison" and "only organic is healthy". Absolute positions are comfortable because they remove the need to judge individual cases. They also make the actual decision harder, because a question of proportion has been converted into a question of virtue.

Consider how this works in practice. Nobody who eats sensibly has banned pizza. A glass of wine with dinner, a bratwurst in the stadium or at the Christmas market, chips on a Friday evening: none of that makes a diet unhealthy and treating each instance as a lapse is reliably how people abandon the whole project. What matters is the pattern over months, not the individual meal.

The same logic applies to technology decisions. For most organizations, using a hyperscaler, a proprietary platform or a US-based service is not a lapse. It becomes a problem when it happens everywhere, without examination, until no realistic alternative remains. The pragmatic question is where the benefit justifies the price, which requires knowing both.

Most sovereignty programmes I have seen aim at the wrong target here. Running your own mail infrastructure to reduce jurisdictional exposure while the entire pricing logic sits in a standard platform that only the vendor fully understands is the digital equivalent of buying organic milk for your instant coffee. Each individual decision is defensible and the pattern makes no sense. The dependencies that matter most are rarely in the infrastructure layer. They sit in decision logic, in data ownership, in business logic buried in configuration, and in know-how that lives with vendors rather than inside the organization.

What awareness looks like


The useful version of this is less about eating well and more about knowing how to eat. Someone who can read ingredients, cook a decent meal and judge when convenience food is the right answer is in a different position from someone who eats well by accident or badly by default. That capability creates options, and options are what sovereignty means in practice: choosing deliberately, understanding consequences, having alternatives, being able to switch, and accepting or reducing risk on purpose.

At the risk of building the kind of maturity model I usually complain about, the levels are recognizable enough to be worth naming.

  • Digital malnutrition. "We do not really know where our data is." No reliable transparency about flows, contracts or dependencies. More common than most CIOs would admit publicly.
  • Digital ready meals. "One provider handles everything for us." Convenient, often functional, and entirely dependent on that provider's roadmap, pricing and continued interest in the segment.
  • A balanced diet. "We use standard solutions, we know our dependencies and we can steer them." Documented exposure, priced exit options, deliberate acceptance of most of it.
  • Cooking where it counts. "We build ourselves specifically where it creates advantage." Selective in-house capability in the areas that differentiate, standard products everywhere else.

The interesting part is that the third level holds most of the value and requires no dramatic technology decisions at all. It requires knowing what you have. Almost nobody needs the fourth level everywhere, in the same way that almost nobody needs to bake their own bread to eat well.

Some things are not available

Availability is where preferences stop mattering, and this constrains decisions more than the debate usually admits. When AWS launched its European Sovereign Cloud in Brandenburg in January 2026, it came with around 90 services against more than 240 in the commercial EU regions, two availability zones, and without CloudFront, GPU instances and most Bedrock models. There is a certain irony in two availability zones falling short of the German BSI recommendation on geographic redundancy, which means the sovereign option can fail a domestic resilience requirement that the standard option satisfies. For a range of workloads this is not a more expensive version of the same thing. It is a different thing that cannot do the job.

The model layer shows the pattern more sharply. Mistral is the only European provider with commercial-grade frontier models, reached roughly 400 million dollars in annual recurring revenue in early 2026 and has raised in the order of six and a half billion euros in total. Set against valuations of roughly 850 billion dollars for OpenAI and 965 billion for Anthropic, the resource asymmetry is difficult to argue away, and independent assessments consistently place European models behind the leading US and Chinese systems on complex multi-step reasoning. For the large majority of enterprise use cases that gap is irrelevant. For a specific minority it is decisive, and those tend to be the use cases with the highest expected value.

"You can want the local option and still not be able to buy it."

The decision this forces is uncomfortable in a familiar way. You can want the local option and still not be able to buy it, which means the honest choice is between accepting the dependency and dropping the ambition, rather than between two comparable products.

Then there is the price


Food shows how selective people actually are about premiums. Almost nobody buys everything organic. Most people who care pick two or three categories where it seems worth it, eggs or meat or whatever their particular concern happens to be, and buy the rest at normal prices without feeling conflicted about it. The premium gets spent where the perceived benefit is highest. That selective logic is largely missing from sovereignty discussions, which tend to apply the premium everywhere or nowhere. The numbers themselves are reasonably documented by now. Microsoft's Delos and Google's S3NS sit in the range of 15 to 20 percent, AWS GovCloud at around 20 percent, while Oracle's EU Sovereign Cloud charges nothing extra. For the AWS European Sovereign Cloud, one independent comparison across storage, compute, serverless and database services found a consistent 15 percent premium, while another sample came out marginally cheaper than Frankfurt. That contradiction is instructive rather than annoying, because it suggests the list price is not the real cost driver. Reduced service availability, additional integration work and a thinner partner ecosystem land in the project budget instead.

Sometimes the calculation runs the other way. My county Schleswig-Holstein reports more than 15 million euros in annual licence savings against nine million euros of one-off investment in 2026, having moved around 30,000 machines to LibreOffice as the mandatory standard, with Nextcloud replacing SharePoint step by step and Linux still in piloting rather than general rollout. That is an encouraging case and I would resist turning it into a template. Comparing one-off project cost against recurring licence cost flatters migrations, because the parts that hurt appear in neither figure: productivity during transition, training, workarounds, the long tail of incompatible documents and the specialist applications nobody remembered. The state itself is explicit that roughly 20 percent of workplaces outside the tax administration are not migrated, precisely because of those dependencies.

What makes the price question genuinely hard is that the benefit resists quantification. You pay a measurable amount now against a scenario that may not occur, and if it does occur, it will probably occur to your successor. Maximum sovereignty is not free and is not sensible everywhere, which is an economic statement rather than a political one.

Not everyone is choosing


One distinction gets lost regularly. For someone with coeliac disease, gluten-free is a medical requirement rather than a lifestyle position, and discussing it as a preference misses the point entirely.

Parts of the economy are in that situation. Public administration, critical infrastructure, defence and parts of healthcare and financial services face requirements that are either binding already or heading that way, which is exactly what the Cloud and AI Development Act formalizes. For those cases, cost and convenience are secondary because the alternative is not permitted.
The confusion in the current debate comes from addressing both groups with the same arguments. For everyone else this remains a trade-off with a price tag, and framing it as an obligation produces either resentment or symbolic compliance.

Where the comparison breaks

Two limits are worth stating plainly.

  • The first is that nutrition works mainly at the level of the individual, while digital dependency has geopolitical, economic and security dimensions reaching well past the single organization. A company can make entirely sensible individual decisions and still form part of a critical national dependency. The aggregate outcome is not the sum of the rational choices, which is a familiar problem in economics and an unfamiliar one in IT strategy. No vendor assessment, however well run, captures it.

  • The second is the feedback loop. Poor nutrition produces consequences you experience yourself, reasonably soon, which occasionally changes behavior. Digital dependency produces consequences that appear rarely, arrive late and land on whoever holds the role when the situation escalates. That asymmetry probably explains why better information has changed so little. The person paying the premium and the person carrying the risk are frequently not the same person, and transparency does not fix an incentive problem.

What is worth doing

None of this argues against engaging with the topic. Knowing what you consume is better than not knowing, and the organizations handling this well have done the unglamorous work. They know which dependencies they have, which would be painful to unwind, what an exit would realistically cost, and which ones they have consciously decided to accept.

"An accepted dependency that someone has documented, priced and assigned to an owner is a managed risk. The same dependency, unexamined, is just something that happens to be true about your company."
That last part carries more weight than any individual technology choice. An accepted dependency that someone has documented, priced and assigned to an owner is a managed risk. The same dependency, unexamined, is just something that happens to be true about your company.
Sovereignty in any strict sense remains unavailable to companies, and it was never the realistic goal.

Awareness is the achievable version: knowing what you consume, knowing what the alternatives cost, being deliberate where the consequences would genuinely hurt, and staying able to change the menu when you need to. Nobody manages a perfect diet either, and the people who eat well are not the ones who tried.


 
 
 

Comments


bottom of page