Europe Does Not Become Sovereign Because Its Cloud Is European
Digital sovereignty is not a procurement label. It is the ability to remain in control when everything around you stops being predictable.
This article responds to the position paper “Impuls zur Stärkung digitaler Souveränität in Deutschland und Europa” by Fritzi Köhler-Geib, Claudia Plattner and Kristina Sinemus. The paper makes an important and timely case for strengthening Europe’s technological capability through investment in chips, cloud and datacentres, AI, quantum computing, robotics, financing and coordinated public demand. Its central ambition is right: Europe must regain strategic options in the technologies on which its economy, public sector and security increasingly depend.
But from a CISO perspective, the debate needs one critical addition. Digital sovereignty is not achieved merely by building or procuring European technology. It is achieved when institutions can still control, defend, audit, operate, recover and, where necessary, leave that technology under adverse conditions.
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
Europe is right to worry about digital dependency.
It is right to invest in chips, cloud infrastructure, artificial intelligence, quantum computing, robotics and European technology companies. It is right to question whether a continent that depends heavily on non-European infrastructure providers can remain economically competitive, politically autonomous and operationally resilient.
The emerging debate on digital sovereignty has finally moved beyond vague rhetoric. Recent proposals increasingly focus on concrete measures: pooled public procurement, European cloud providers, AI investment, strategic technology funding, industrial policy, scale-up financing and more integrated European markets.
That is progress.
But there is a problem at the centre of the debate.
Too often, digital sovereignty is still treated as a question of origin.
Is the provider European?
Is the data centre located in Europe?
Is the company registered in an EU member state?
Is the cloud branded as sovereign?
These questions matter.
But they are not enough.
A European provider can still be operationally dependent on foreign hyperscalers, foreign chip supply chains, foreign security tooling, foreign identity systems, foreign cryptographic components, foreign capital or foreign software ecosystems.
And a non-European provider can, in some circumstances, be used in a controlled and resilient way if the customer retains meaningful control over identities, encryption keys, data, logging, recovery, architecture and exit options.
The wrong question is:
Is this technology European?
The more important question is:
Can we still control, defend, audit, operate and leave this technology when the political, legal, commercial or cyber environment turns hostile?
That is the real test of digital sovereignty.
Sovereignty Is Not Autarky
Europe will not become digitally sovereign by building a technological wall around itself.
No country or region controls every layer of the digital stack. Not the United States. Not China. Not Europe.
Semiconductors depend on global supply chains. Cloud infrastructure depends on specialised hardware, energy grids, networking equipment, software ecosystems and highly concentrated manufacturing capabilities. AI depends on compute capacity, data, talent, open-source communities, model architectures and research networks that cross national borders.
The goal should not be complete independence.
The goal should be strategic freedom of action.
That means Europe must know where dependencies exist, decide which dependencies are tolerable, reduce those that create unacceptable risk and ensure that critical services can continue even when suppliers, jurisdictions or networks become unreliable.
This is not protectionism.
It is resilience engineering at geopolitical scale.
The Missing Half of the Sovereignty Debate
Most digital sovereignty programmes focus on technology development, market access, financing and public procurement.
All of these are necessary.
But they are only one half of the strategy.
The other half is security architecture.
Without security architecture, Europe may successfully create European alternatives that remain fragile, opaque and difficult to leave. It may replace one dependency with another. It may create national or European monopolies that look sovereign on paper while becoming dangerous single points of failure in practice.
Digital sovereignty requires more than suppliers.
It requires control.
That control must exist across at least six layers.
1. Data sovereignty
Where is the data stored?
Who can access it?
Who can copy it, analyse it, train on it, disclose it or hand it over under legal pressure?
Data residency is not enough. An organisation may store data in Frankfurt, Paris or Helsinki and still lose control if privileged administrators, support personnel, legal authorities or underlying platform services can access it from elsewhere.
Real data sovereignty requires transparent access paths, enforceable legal safeguards, technical controls and verifiable evidence.
2. Identity sovereignty
Who controls identities?
Who controls privileged access?
Who can create accounts, reset credentials, bypass controls, use break-glass access or administer the underlying platform?
Identity has become the control plane of the modern enterprise.
If an organisation does not control its identities, it does not control its cloud. If it does not control privileged access, it does not control its data. If it cannot independently revoke access, it cannot claim operational sovereignty.
A sovereign cloud without customer-controlled identity governance is not sovereign.
It is outsourced administration.
3. Cryptographic sovereignty
Who controls the keys?
Who operates the HSM?
Who owns the root of trust?
Who can decrypt data now, later or under exceptional circumstances?
This is where many sovereignty claims collapse.
Encryption is often presented as proof of control. But encryption only creates sovereignty when the customer controls the keys, the key lifecycle, the access policies and the recovery mechanisms.
A cloud provider that manages the customer’s keys may offer strong security.
But it does not necessarily offer full cryptographic sovereignty.
Europe must treat key management, PKI, HSM capabilities, certificate ecosystems and post-quantum cryptography as strategic infrastructure.
Not as implementation details.
4. Operational sovereignty
Who runs the service during a crisis?
Who patches it?
Who detects an attack?
Who responds at 03:00 on a Sunday morning when an identity system, cloud control plane or AI platform has been compromised?
Sovereignty cannot exist without operational capability.
A provider may be European, but if it lacks mature incident response, 24/7 monitoring, threat intelligence, forensic capacity, vulnerability management, crisis communications and recovery procedures, it may be less sovereign in practice than a well-controlled international provider.
Operational sovereignty means being able to defend the service.
Not merely to buy it.
5. Supply-chain sovereignty
What sits underneath the service?
Which chips, operating systems, firmware components, open-source libraries, APIs, development tools, AI models, managed services and subcontractors are involved?
The cloud is not a single product.
It is an ecosystem of dependencies.
The same applies to AI platforms, robotics, quantum systems and critical digital services. A European technology provider may still rely on foreign chips, foreign operating systems, foreign control software, foreign model weights, foreign security products or foreign developer ecosystems.
This does not make European providers irrelevant.
It makes transparency essential.
Europe needs dependency maps, software bills of materials, supplier-chain visibility, hardware assurance and security assessments that look beyond the legal entity at the top of the contract.
6. Exit sovereignty
Can you leave?
Can you recover?
Can you migrate critical workloads, data, identities, keys and logs within a defined timeframe?
Can you continue operating if a provider fails, is sanctioned, is acquired, becomes politically inaccessible or suffers a catastrophic cyber incident?
The ability to exit is one of the clearest indicators of sovereignty.
A system that cannot be left is not a platform.
It is a dependency.
The Cloud Debate Is Too Binary
One of the strongest ideas in the current sovereignty discussion is the use of common public-sector cloud procurement, European framework agreements and standard landing zones. These measures could create demand, improve interoperability and give European providers an opportunity to scale.
But the debate becomes dangerous when it turns into a simplistic choice between “European cloud” and “US cloud.”
This is the wrong architecture.
Europe does not need a binary cloud strategy.
Europe needs a risk-based cloud strategy.
Some workloads should remain in highly controlled European environments because they involve classified information, national security, sensitive government operations, critical infrastructure, citizen identity, highly sensitive personal data or strategic industrial intelligence.
Other workloads may be safely operated in international cloud environments when strict technical and contractual controls exist.
The distinction should not be ideological.
It should be based on data classification, operational criticality, legal exposure, recovery requirements, supplier risk and the consequences of loss of control.
A strong sovereign cloud strategy should therefore require:
- customer-controlled identities and privileged access;
- independent logging into customer-controlled security operations;
- verified data residency and administrative access transparency;
- encryption with customer-controlled or independently governed keys;
- tested backup and recovery outside the primary provider environment;
- standardised data portability and migration mechanisms;
- full subcontractor and supply-chain transparency;
- contractual incident-response obligations;
- mandatory exit planning and migration exercises;
- resilience testing against provider failure, ransomware and control-plane compromise.
A landing zone without these controls is not a sovereignty architecture.
It is simply a faster way to consume cloud services.
Europe Cannot Build Sovereignty Without Cybersecurity
One of the largest blind spots in many digital sovereignty strategies is the absence of cybersecurity as a strategic technology domain in its own right.
Europe talks about cloud.
But who secures the cloud?
Europe talks about AI.
But who secures the models, the data, the prompts, the agents and the training pipelines?
Europe talks about robotics.
But who secures the firmware, the remote access, the safety controls and the machine-to-machine interfaces?
Europe talks about quantum computing.
But who prepares the cryptographic infrastructure for the day when current encryption becomes obsolete?
Digital sovereignty cannot be achieved if Europe remains dependent on external capabilities for:
- identity and access management;
- privileged access management;
- endpoint detection and response;
- SIEM, SOAR and threat intelligence;
- cloud security posture management;
- software supply-chain security;
- PKI, HSM and cryptographic services;
- AI security and model assurance;
- OT and robotics security;
- digital forensics and incident response;
- secure-by-design engineering tools.
A European cloud provider using foreign identity systems, foreign security analytics, foreign cryptographic modules and foreign endpoint protection may still be valuable.
But it should not be marketed as fully sovereign.
Sovereignty must be measured across the stack.
Not at the logo level.
The AI Problem Is Not Only About Building Models
Europe’s ambition to build frontier models, industrial AI systems and shared AI platforms is understandable. The idea of creating European alternatives to dominant AI platforms is politically attractive and economically necessary.
But AI sovereignty is not achieved when Europe owns a model.
It is achieved when Europe can govern the entire AI lifecycle.
That includes:
- the provenance and legal status of training data;
- the protection of sensitive industrial and public-sector data;
- model integrity and resistance against poisoning;
- secure retrieval-augmented generation;
- protection against prompt injection;
- prevention of model and data exfiltration;
- secure agent permissions;
- monitoring of autonomous actions;
- explainability and accountability;
- independent testing and red teaming;
- audit trails for high-impact decisions;
- clear responsibility when systems fail.
A European AI platform without strong security controls could become one of the largest concentration risks Europe has ever created.
The future risk is not only that Europe depends on foreign AI.
The future risk is that Europe builds centralised AI infrastructure without the governance maturity required to control it.
Quantum Sovereignty Starts With Post-Quantum Security
Europe’s investment in quantum computing is strategically important.
But the urgent security question is not only who develops quantum computers.
It is who prepares for them.
The cryptographic systems protecting government records, healthcare data, financial transactions, military communications, industrial secrets and long-lived personal data may be vulnerable to future quantum capabilities.
The risk is not theoretical.
Adversaries can collect encrypted information today and decrypt it later.
This is the “harvest now, decrypt later” problem.
A credible sovereignty strategy must therefore include a European post-quantum cryptography programme focused on:
- cryptographic inventories;
- identification of systems with long-term confidentiality requirements;
- migration roadmaps;
- hybrid cryptographic architectures;
- quantum-safe procurement standards;
- European PKI and HSM capability;
- supplier requirements for post-quantum readiness;
- testing and certification of future-proof security products.
Europe cannot claim quantum sovereignty while remaining unprepared for the cryptographic consequences of quantum computing.
Public Procurement Can Become Europe’s Strongest Lever
The state is not just a regulator.
It is one of Europe’s most powerful technology customers.
Public procurement can create market demand, reference customers, predictable revenues and scale opportunities for European providers. This is especially true in cloud, AI, cybersecurity, digital identity, data platforms and critical infrastructure.
But public procurement should not only reward European origin.
It should reward controllability.
The most valuable procurement criteria would focus on:
- technical transparency;
- data portability;
- interoperability;
- customer-controlled identity;
- customer-controlled cryptography;
- independent logging;
- evidence of resilience;
- supply-chain visibility;
- tested exit capability;
- vulnerability disclosure;
- incident-response maturity;
- secure software development;
- compliance with European security baselines.
This would create a market in which sovereignty becomes measurable.
Not rhetorical.
Europe Needs a Sovereignty Security Framework
Europe does not need another broad declaration about digital independence.
It needs an operational framework that can be applied to cloud providers, AI platforms, critical software, public-sector systems, infrastructure services and strategic suppliers.
A European Sovereignty Security Framework should define minimum requirements across five areas.
A common sovereignty baseline
A mandatory baseline for critical cloud, AI, data and infrastructure services covering identity, encryption, logging, backup, recovery, supply-chain transparency, incident response and exit readiness.
A dependency risk register
A structured register for governments, critical infrastructure operators and major public-sector organisations that records dependencies by supplier, country, legal jurisdiction, component, data type, identity system, cryptographic control, subcontractor and recovery capability.
Security-by-design procurement
A procurement model that makes operational control, resilience and portability explicit award criteria rather than optional contractual language.
A European cybersecurity technology initiative
A focused programme to strengthen European capabilities in IAM, cryptography, cloud security, security operations, software assurance, AI security, robotics security and threat intelligence.
Mandatory exit and crisis exercises
Critical services should be tested against realistic failure scenarios:
- provider insolvency;
- sanctions or legal restrictions;
- cyberattack on the cloud control plane;
- compromise of privileged identities;
- loss of cryptographic keys;
- ransomware;
- major supplier outage;
- forced migration from a strategic provider.
A sovereignty strategy that has never been tested under stress is not a sovereignty strategy.
It is a PowerPoint strategy.
The Real Test
Europe should absolutely invest in its own technologies.
It should build cloud capacity, AI capability, chip expertise, quantum leadership and robotics ecosystems. It should improve financing, reduce fragmentation, simplify scale-up pathways and use public demand more strategically.
But Europe should not confuse industrial policy with operational sovereignty.
A European provider is not automatically sovereign.
A European data centre is not automatically sovereign.
A European AI model is not automatically sovereign.
Sovereignty is created when an organisation retains the ability to make decisions, enforce controls, defend itself, recover from failure and change course.
The real question for every strategic technology decision should be simple:
Can we still operate this safely if the provider fails, the legal environment shifts, the supply chain breaks, the cloud is attacked or the relationship ends?
When the answer is yes, sovereignty becomes real.
When the answer is no, Europe has not reduced dependency.
It has only changed its branding.
Publication Note & Disclaimer
This article was originally published on LinkedIn on January 30, 2026 and may have been edited or updated for publication on this site.
It reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion