From Dependencies to Decisions: Sovereign Cloud in Perspective. Beyond the Hype and all or nothing.

In 2024, European cloud spending rose to $123 billion, with American hyperscalers accounting for more than 70% of the market. In Europe, regulations such as GDPR, NIS2, and DORA, combined with the US CLOUD Act and shifting geopolitics, are making organizations increasingly aware of their dependence on Big Tech and external influences that could directly disrupt their operations. The issue has moved beyond development and architecture teams. It is now being discussed at board level. Yet many organizations still struggle to translate that urgency into concrete action.

The availability of competing hyperscalers or European SaaS offerings is only part of the challenge. More often, organizations lack a clear and validated understanding of their dependencies, where those dependencies sit and which of them genuinely require action. Dependencies are fragmented across teams, embedded implicitly in architectures, and are rarely validated against operational reality. As a result, assumptions go unchallenged, risk discussions remain abstract, and decisions stall.

This blog series argues that sovereignty is not about eliminating dependencies. It is about understanding them, placing them in context, and making deliberate trade-offs. That starts with dismantling a false choice that dominates today's debate.

Why Full Digital Autonomy Is Unrealistic

Full European digital sovereignty sounds compelling, but in practice, it collides with reality at every layer of the stack.

Starting with hardware. For datacenters and chips, it is currently extremely difficult, if not impossible to build a European stack. Most components are produced in Asia (TSMC, Samsung), designed and developed in the US (Apple, Intel, NVIDIA, AMD) and enabled by critical European lithography (ASML). It is not a market that was built by a single country, but one that grew over decades. No single continent controls all aspects of the chain nor can replicate it in isolation. Hardware production is therefore a global industry with a complex supply chain and a fragile but functioning balance.

The Northvolt bankruptcy is a case in point. Despite enormous investments and strong political backing, Europe failed to establish autonomy in battery production, which is an important enabler for clean-tech and mobility. It illustrates that Europe still has big challenges to overcome in its ability to execute sovereign strategy.

The software layer is no different. For the software stack many organizations rely on American hyperscalers (Amazon, Google, Microsoft), and they do so for good reason. The scale, innovation pace, services and ecosystem maturity these platforms offer is exceptionally strong. Some organizations, like Netflix, have strategically locked-in - connecting their success to the success of these platforms. And many organizations are not just technically locked-in to these vendors, they have also invested years of training their personnel, optimizing their processes and implemented their governance and risk & compliance on it. Switching is not a technical migration. It is an organizational transformation, one that demands strong alternatives and massive investment in people, processes and architecture.

Autonomy is not pointless but full independence is fiction. The technology landscape is global by design, and pretending otherwise leads to strategies that are ambitious on paper and hollow in practice.

Acknowledging this is not defeat. It is the starting point for acknowledging that digital sovereignty is not black and white, but a starting point for objective conversations on where to accept dependencies and where to mitigate risks.

Digital sovereignty is not about eliminating dependencies. It is about understanding them, placing them in context, and making deliberate trade-offs.

Why Full Digital Autonomy Is Unrealistic

Full European digital sovereignty sounds compelling, but in practice, it collides with reality at every layer of the stack.

Starting with hardware. For datacenters and chips, it is currently extremely difficult, if not impossible to build a European stack. Most components are produced in Asia (TSMC, Samsung), designed and developed in the US (Apple, Intel, NVIDIA, AMD) and enabled by critical European lithography (ASML). It is not a market that was built by a single country, but one that grew over decades. No single continent controls all aspects of the chain nor can replicate it in isolation. Hardware production is therefore a global industry with a complex supply chain and a fragile but functioning balance.

The Northvolt bankruptcy is a case in point. Despite enormous investments and strong political backing, Europe failed to establish autonomy in battery production, which is an important enabler for clean-tech and mobility. It illustrates that Europe still has big challenges to overcome in its ability to execute sovereign strategy.

The software layer is no different. For the software stack many organizations rely on American hyperscalers (Amazon, Google, Microsoft), and they do so for good reason. The scale, innovation pace, services and ecosystem maturity these platforms offer is exceptionally strong. Some organizations, like Netflix, have strategically locked-in - connecting their success to the success of these platforms. And many organizations are not just technically locked-in to these vendors, they have also invested years of training their personnel, optimizing their processes and implemented their governance and risk & compliance on it. Switching is not a technical migration. It is an organizational transformation, one that demands strong alternatives and massive investment in people, processes and architecture.

Autonomy is not pointless but full independence is fiction. The technology landscape is global by design, and pretending otherwise leads to strategies that are ambitious on paper and hollow in practice.

Acknowledging this is not defeat. It is the starting point for acknowledging that digital sovereignty is not black and white, but a starting point for objective conversations on where to accept dependencies and where to mitigate risks.

“Autonomy is not pointless but full independence is fiction.”

Why Accepting the Status Quo Is Equally Risky

Understanding these complexities can lead to a fatalism: since we cannot gain full independence, just accept the status quo. This feels pragmatic. In reality, it is complacency dressed as realism, and it leaves organizations exposed to risks they have chosen not to see.

Geopolitical risks exist. When the US imposed sanctions, Microsoft blocked the International Criminal Court's Chief Prosecutor from accessing its services. There was no technical failure and no contractual breach. A political decision in Washington directly disrupted a critical workflow in The Hague. Separately, the Dutch government blocked the sale of Solvinity to US-based Kyndryl. Keeping DigID, a government-regulated identity service, outside the reach of US legislation.

Current geopolitical unpredictability such as trade tensions, conflicts and sanctions are already felt by many organizations. The Strait of Hormuz closure is affecting global markets, proving that heavy dependency on a single region or provider can quickly lead to global stagnation and faster than most contingency plans anticipate.

Regulation is tightening. NIS2, DORA and GDPR cannot be ignored. Not acting on these means finding yourself out of step with regulatory requirements that are only becoming stricter.

Ignoring dependencies and complexities does not make them disappear. It makes them invisible, and invisible risks are the most dangerous kind.

Finding the Middle Ground

Sovereignty is not binary. It is a spectrum of choices about which dependencies are acceptable, which require mitigation and which are genuinely critical.

A public marketing website has fundamentally different sovereignty requirements than a system for patient health records, banking data or a government identity service. All may be vital to the organization, however risk profiles vary, and so should strategies covering sovereignty be.

Running multiple providers, deployment models and technology stacks is not a failure to consolidate. It is a pragmatic response to a complex landscape. The key is to make these choices conscious and deliberate rather than accidental or inherited.

For the same reasons most companies would never build their own power plant, most should not pursue full autonomy. Sovereignty should be about orchestration and control. Know which dependencies and risks matter. Know what happens if they are disrupted. Know what alternatives exist.

This means applying sovereignty at the workload level, not as a blanket policy. Each workload has its own data classification, regulatory context, operational requirements, and risk tolerance. For some, sovereignty must be part of the core architecture. For others, an exit strategy is sufficient. For some, the current dependency may be an acceptable risk.

Finding the middle ground is not a grey compromise. It is a realistic view that acknowledges complexities but still allows for action where it matters.

What Organizations Actually Need

Still most organizations lack the foundation to act, even if they acknowledge the middle ground. They may agree that sovereignty requires conscious choices, but they cannot make those choices without first answering a deceptively simple question: what do we actually depend on?

Most organizations do not have a clear, validated picture of their dependencies. Not because they haven't tried, but because dependencies are fragmented, implicit, and layered. They span infrastructure, platforms, identity, data flows, licensing, and even personnel skills, and they rarely live in a single document or team. And even where insights exist, lack of strategy often leaves individual teams making isolated judgement calls on risk.

Digital Sovereignty blogseries visual 1

So, moving from extreme viewpoints to a workable middle ground, and from unknown risks to understanding dependencies, we can now look ahead to what organizations actually need. Answering what we depend on is only the beginning. The next step is to understand what kind of control is actually at stake.

In the next article, we explore this through three dimensions of sovereignty: data, operational and technical, before moving toward a pragmatic framework for turning visibility into decisions.