QimTech

Digital Sovereignty: Beyond the Current Geopolitical Buzz

Through interviews with executives from leading Swiss and European cloud providers (OVHcloud, Exoscale, Hidora), we share our vision of digital sovereignty. Read our analysis to learn how the new legal frameworks are changing the landscape and where technological dependencies come into play.

Digital sovereignty is not about hosting everything locally or seeking total independence. Above all, it is about understanding what we depend on, to what extent that dependence is acceptable, and how to maintain our ability to act if circumstances change.

A few key ideas stand out:

  • Sovereignty is multidimensional: it encompasses infrastructure, software, applicable law, and operational control.
  • The goal is not “100 percent self-sufficiency,” but rather managing critical dependencies.
  • A so-called “sovereign” cloud does not eliminate all risks: data residency, operational autonomy, and legal dependency must be distinguished from one another.
  • The right answer is often an architectural one: hybridization, supplier diversification, and open standards help build resilience without sacrificing innovation.

👉 Our article on the sovereign cloud can shed some light on this specific topic.

What is digital sovereignty, and why is it a key factor in resilience?

At a time when geopolitical tensions are awakening minds, sovereignty is back at the top of the priority list.

On Friday, June 12, under orders from its government, Anthropic (an American AI provider) abruptly cut off access to one of its models overnight.

CLOUD Act, Data Act, European certifications, pricing conditions of major software publishers, supply chain dependencies: these are all topics that now require corporate management to look at their architecture for what it is—a strategic choice, and no longer merely a technical one.

Digital sovereignty is neither a defensive reflex nor a marketing argument; let us avoid widespread “sovereign-washing“—it is a structural function.

Just like energy supply, transportation, or healthcare, digital technology is an infrastructure over which an organization, an administration, or a country must retain control for its critical activities.

Everything in this discussion relates to risk management, and I sincerely hope this topic will not stop the day the world appears stable again. Because digital sovereignty is not a fear-driven reflex in response to current events.

In the vast majority of cases among our clients, the right architecture is neither a

  • 100% sovereign cloud,
  • nor entirely on-premises,
  • It is a permanent balance.

The challenge consists of practicing this hybridization without letting operational complexity take over, and reducing vendor lock-in through, for example, technical abstraction layers. It is this balance that prevents confinement within a single dependency and allows, as the context evolves, for adjusting the weight of each component rather than suffering a abrupt change of direction.

Here, we will discuss the impact of digital dependencies incorporated into your strategy and the evolving legal frameworks that govern them.

To explore this topic further, I also spoke with three executives and founders of Swiss and European cloud companies:

The 4 Dimensions of Digital Sovereignty

What do we mean when we talk about sovereignty? Depending on the speaker, the word covers very different realities. It is a deeply subjective question. One thing is certain: sovereignty is not an ON/OFF switch.

  • Some believe that sovereignty must be exercised from start to finish.
  • Others will simply say that a data center located within the country, operated by a locally registered company, and outside the scope of the CLOUD Act, is sufficient.

Between these two extremes lies a whole spectrum of sensibilities.

In reality, sovereignty can be broken down into at least four dimensions: hardware, software, legal, and operational. Each organization must place its cursor according to its risk profile, sector, and regulatory obligations.

The Material Dimension

The hardware dimension, first, meaning the control of the physical infrastructure. How far can we go?

At the extreme, certain players master a remarkable portion of their industrial chain. OVHcloud, for example, assembles its own servers in its factory in Croix, and has designed and manufactured its liquid cooling systems for over twenty years.

At the other end of the spectrum, no European player engraves its own processors: chip manufacturing remains largely in the hands of TSMC in Taiwan, and general-purpose CPU design is held by Intel, AMD, and ARM.

AI has made certain dependencies much more visible, particularly around GPUs. It would be illusory to claim that Europe currently possesses an equivalent alternative to NVIDIA for large-scale AI use.

➡️ Material sovereignty is therefore rarely absolute; however, it would be just as dangerous to view this situation as permanent. New initiatives are emerging—let’s prepare for the alternatives of tomorrow.

Nvidia: In the era of AI, an acceptable dependency or the Achilles' heel of your sovereignty?

"An assumed Achilles' heel. No credible alternative today. We manage it, we do not deny it."
Matthieu Robin
Founder and CEO of Hidora
Hidora

The software dimension next.

The structuring choice is that of standards.

Building your architecture on open-source components, such as Kubernetes, PostgreSQL, or OpenStack, ensures true portability and the abilityto switch to other providers.

Building on proprietary ecosystems, on the other hand, gradually shifts technological decision-making power to the vendor.

To take a concrete case, Exoscale’s SKS relies on Karpenter, an open-source project supported by the Cloud Native
Computing Foundation (CNCF): this choice of open standards gives clients the freedom to change providers.

In contrast, a proprietary autoscaler—whose code and roadmap remain the sole property of the provider—creates a level of lock-in whose cost is often not fully appreciated until it’s time to move on.

➡️ In practice, software sovereignty means retaining the ability to switch away from a solution.

What is your red line: the one thing you will never do, even if it costs you clients?

"Locking in a client. Concretely: open APIs and standards, no proprietary formats that make it costly to leave, no hidden exit fees. Reversibility is not a marketing argument; it is a design constraint. The day staying with us becomes a fatality rather than a choice, we have failed."
Antoine Coetsier
Co-founder and COO of Exoscale
téléchargement

The Legal Aspect

The legal dimension is probably the most meaningful for legal departments and CISOs. The decisive criterion is not the location of the data center, but the jurisdiction that can, ultimately, demand access to the data.

Since 2018, the U.S. CLOUD Act has authorized U.S. authorities to request data held by any U.S.-controlled company, regardless of the country where that data is physically stored. A European entity that is wholly owned by a U.S. parent company therefore remains legally subject to this requirement (AWS Sovereign Cloud, for example, remains subject to it).

And the European Data Act, applicable since September 2025, requires cloud providers to do exactly the opposite: prevent any illegal access by a third-party government.

➡️ Choosing a supplier also means choosing the law that governs it.

The Operational Dimension

The operational dimension, finally:

  • Who holds the encryption keys, who can regenerate them, and who manages them?
  • Do administrators have privileged access to the data? Where are they located? Under which jurisdiction do they operate?
  • Where is the SOC that monitors the platform located?

In certain regulated sectors, such as finance, healthcare, or defense, these issues are no longer merely theoretical: they are the subject of specific contractual provisions, sometimes accompanied bycitizenship requirements for authorized personnel.

The Genevan provider Hidora illustrates this requirement with its Hikube platform, whose workloads are natively distributed and synchronously replicated across three Swiss data centers in Geneva, Gland, and Lucerne. The complete loss of one site is absorbed automatically, and the data never leaves Swiss territory at any time. It is at this level that sovereignty is proven, or cracks.

I have voluntarily simplified the criteria grid because other objectives rely on strategic sovereignty, data & AI, supply chains, security & compliance, or environmental sustainability.

Initiatives such as “ Digital Resilience Initiative ” help us measure our organizations’ level of technological dependence using a transparent methodology. For many companies, the challenge is not to immediately find the perfect strategy, but rather to get started so they can understand which risks are acceptable and which are not.

➡️ My belief: It’s never either A or B—on-premises or cloud-based. The best architecture is almost always a hybrid approach. It involves designing the information system and implementing governance on a case-by-case basis, workload by workload. It’s not glamorous, but that’s the reality on the ground.

What digital sovereignty strategy should you adopt based on your infrastructure?

In the field, I’ve noticed that two broad categories of companies are emerging. Each faces different challenges, but they share the same need: to plan for their digital autonomy.

Cloud-first

These organizations are already deeply anchored with an American hyperscaler. The challenge is not to leave everything; that would be unrealistic and unnecessary. The challenge is to have a credible plan B in case of a “kill switch.”

This plan B must contend with five risks:

  • geopolitical exposure,
  • loss of negotiating power,
  • innovation lag,
  • market concentration,
  • capacity constraints.

What would this scenario look like in practice?

Probably not an abrupt cutoff. The prospective Europe 2031 scenario, published by a collective of European researchers, imagines it more insidiously: a licensing regime that rations access to cutting-edge services by country categories, with priority allies, capped volumes, and rising prices for others.

Fiction, certainly. But the mechanism already exists: American export controls on semiconductors operate precisely by country tiers. A credible plan B must therefore anticipate gradual degradation as much as sudden failure.

Concretely, this can involve:

  • hybridizing the infrastructure by placing critical workloads on a sovereign European or Swiss cloud,
  • the deployment of DRP/PRA on an alternative infrastructure,
  • or the implementation of mechanisms for data portability and reversibility.

⚠️ The goal is not to replicate the entire environment, but to ensure that critical functions remain operational under any scenario.

On-premises

Many organizations still view hosting their infrastructure in-house as a form of sovereignty by default. This approach still offers real advantages:

  • proficiency with equipment,
  • data locality
  • and operational oversight.

But you’re closing the door on agility, flexibility, and, above all,innovation.

In the age ofartificial intelligence, buying GPUs to install in your server room isn’t always the best solution—neither financially nor operationally. Technological dependence, skills, innovation, capacity, and operational resilience: these are all risks that in-house solutions shift rather than eliminate.

A European or Swiss sovereign cloud allows organizations to benefit from cloud agility (GPU as a Service, ML platforms, on-demand scalability) while retaining their digital autonomy. Without massive investment, without American dependency.

And here, there is a concrete opportunity waiting to be seized.

Stop being held hostage by an hypervisor vendor

Since the acquisition of VMwareby Broadcom for $69 billion in late 2023, the virtualization market has been turned upside down. Perpetual licenses have been eliminated. The catalog of more than 160 products has been reduced to just a few subscription packages. Prices have doubled, tripled, or even increased tenfold in some cases. AT&T has publicly denounced a 1,050% price increase. The minimum number of cores per license has risen from 16 to 72, making access prohibitively expensive for smaller organizations.

Sovereign clouds are credible alternatives to on-premises environments, carrying far less risk than an external foreign cloud.

This is a strategic opportunity. Migrating to solutions based on open standards on a Swiss cloud is a way to break free from dependence on an American hypervisor that plays games with its licensing packages, while gaining access to solutions that aren’t necessarily more expensive.

➡️ Turning forced dependence into chosen autonomy—that’s what I call good risk management.

U.S. “Sovereign Clouds”: What Progress Has Been Made, and What Are the Limitations?

Hyperscalers are currently adapting to Europe; the AWS European Sovereign Cloud is probably the best evidence of this.

In January 2026, AWS made it available with a first region established in Germany. A German legal entity, operations entrusted exclusively to EU-resident personnel, infrastructure physically and logically separated from other regions, 7.8 billion euros committed.

The effort is real, and the controls are too: independent assessments place the offering at a strong level regarding operational sovereignty, security, and compliance. For many workloads requiring European data residence and operational autonomy, it is a credible and useful answer.

The limit is not technical; it is structural. The European entity remains 100% owned by Amazon, an American corporation. As long as ultimate control lies outside the Union, the legal and strategic dimensions remain exposed: the US CLOUD Act (for example) authorizes American authorities to demand data held by any company under US control, regardless of the storage location. Legal and strategic sovereignty is not respected for this reason.

This is also a good reminder: an announcement is not a verdict. AWS indicates it has never transferred European client data to US authorities since 2020. This is plausible. But the absence of a request to date does not guarantee one tomorrow, and for the most sensitive data—healthcare, defense, critical infrastructure—a residual legal risk can be enough to rule out a vendor.

Here is a good example of this: an email exchange between Anton Carniaux of Microsoft and the French Senate:

Mr. Dany Wattebled, rapporteur: “Mr. Carniaux, as director of public and legal affairs, you represent Microsoft France to public decision-makers. Can you guarantee before our commission, under oath, that French citizens’ data entrusted to Microsoft via the UGAP will never be transmitted following an injunction from the US government without the explicit
agreement of French authorities?”

Mr. Anton Carniaux: “No, I cannot guarantee it, but, once again, that has never happened.”

Added to this is a structural legal tension:

  • The European Data Act, which takes effect in September 2025, requires cloud service providers to prevent any unlawful access by authorities in a third country.
  • The CLOUD Act requires the opposite.

U.S. suppliers find themselves caught in the middle, and their customers along with them.

Hyperscalers should not be excluded from the European digital strategy. They must be repositioned within an architecture where no single dependency becomes critical.

It is important to keep in mind that a sovereign cloud offered by a U.S. provider does indeed reduce many operational and residency risks, which is valuable. However, by its very nature, it does not eliminate legal and strategic dependence.

The first is a concrete and legitimate improvement.

The second is a commitment involving architecture and a contract, of a different nature.

➡️ Making the right choice means knowing which of the two a given workload actually requires.

👉 Our use case on migration to AWS might be of interest to you.

An IT Director tells you "you are too small for my critical production". What do you reply to him?

"The real threat is not choosing genuinely sovereign actors for your critical assets. Sovereignty is no longer an operational or technical issue, but a strategic one for all organizations."
Helen Wohlfahrt-Kuhn
Directrice Générale Corporate Allemagne, Pologne et Suisse d'OVHcloud
LOGO-850-ovh-cloud

What role do Swiss and European cloud services play in digital sovereignty?

Let’s be honest: European players don’t yet have all the capabilities of American or Chinese hyperscalers.

OVHcloud, Europe’s largest cloud provider, holds less than 2% of the global market share, compared with 32% for AWS and 23% for Azure. The gap is enormous.

But it’s a virtuous cycle. If European companies and organizations trust these cloud services:

  • they will use their services,
  • will generate profits,
  • will enable them to invest more in order to become more competitive.

What threatens the sovereign cloud the most: hyperscalers or the cautiousness of Swiss IT Directors?

"I would say the cautiousness, not out of ill will, but because the debate lacks clear reference points for decision-making. Many IT Directors, particularly in Switzerland, navigate between frameworks designed for the EU, the EUCS, the new European sovereignty framework, and their own Swiss obligations, without a common interpretation grid. The market needs pedagogy and objective criteria adapted to their context more than new slogans."
Antoine Coetsier
Co-founder and COO of Exoscale
téléchargement

And we must not underestimate what already exists. Many European services rely on open standards rather than proprietary ecosystems. In terms of portability, interoperability, and reversibility, this is a significant competitive advantage. Less vendor lock-in.

The Swiss Federal Council has made digital sovereignty one of the three priority areas of its 2026 strategy. Customer requests from European companies tripled in the first half of 2025.

And yet, some companies I meet are still cautious, citing a lack of maturity or reliability among Swiss and European cloud providers.

I often hear people say, “Yeah, but OVH—those data centers that burned down…”

No cloud service is infallible, and that’s no one’s fault. Mistrust keeps European players small; their small size fuels mistrust; and this dependence reinforces itself until it becomes a bargaining chip in the hands of others.

Even the largest and best-designed platforms experience major incidents.

  • In October 2025, AWS suffered a major outage in its US-EAST-1 region lasting approximately fifteen hours, with well over a hundred services affected and tens of millions of reports worldwide.
  • A week later, a configuration change in Azure Front Door caused an outage of about nine hours on Azure and Microsoft 365.
  • In July 2024, a faulty CrowdStrike update paralyzed millions of Windows endpoints.

These are not arguments against any specific vendor; they are reminders that size does not equal immunity.

👉 You might be interested in our articles on cloud security and specific security solutions.

What will tip the market faster: a European law or the next hyperscaler outage?

"Massive outages and 'kill switches' make us aware of our dependencies. Combining organizational conviction, strong regulation, and public procurement that must massively support European cloud and AI players will truly tip the market."
Helen Wohlfahrt-Kuhn
Directrice Générale Corporate Allemagne, Pologne et Suisse d'OVHcloud
LOGO-850-ovh-cloud

The approach is architectural, and that is exactly where the expertise lies. Resilience doesn’t come from the logo on the data center; it comes from the design:

  • redundancy,
  • multi-region.

And when it matters:

  • multi-cloud,
  • disaster recovery plans that have actually been tested,
  • diversification of suppliers,
  • layers of abstraction that maintain a portable workload.

A localized fire and a control plane failure at a hyperscaler both point to the same principle: design for failure; never assume that a single vendor or a single region will always be there.

European and Swiss sovereign clouds naturally fit into this framework as a credible second pillar for critical workloads.

Other organizations see sovereignty as a strategic axis to preserve their freedom and ensure alignment with their values.

How Is Europe Building Its Digital Sovereignty?

The idea of building a European cloud powerhouse is not new. In 2020, France and Germany launched GAIA-X, a consortium meant to lay the foundations for a sovereign European cloud ecosystem.

GAIA-X: The Limitations of an Initial Approach

Strategic ambiguity: no one really knew what GAIA-X was. A European hyperscaler? A standards label? A governance framework? Everyone projected their expectations onto it, and the compromise diluted the ambition.

Co-optation: AWS, Microsoft, Google, and even Huawei and Alibaba joined the consortium. When the annual GAIA-X conference is sponsored by the very companies it is supposed to protect against, there is a problem. The CEO of Scaleway even advanced the thesis that American hyperscalers had infiltrated the project to slow it down from within. Whether one believes it or not, the result speaks for itself.

Bureaucracy: years of conceptual documents, zero services delivered. Forrester ultimately described GAIA-X as a “static entity.” The founder of Nextcloud summarized it even more bluntly in 2025: “GAIA-X is dead, taken over by American hyperscalers. The original goal is no longer there.”

➡️ GAIA-X is a textbook example of what happens when you let the wolf into the sheepfold. Nevertheless, it has shifted mindsets and now serves as a springboard toward a more sophisticated approach and new reasons to collaborate, and Europe has taken this opportunity to change its methods.

EUCS: Toward a European Certification for Cloud Services

Let’s start with the EUCS (European Union Cybersecurity Certification Scheme for Cloud Services), the European cybersecurity certification scheme for cloud services established under the Cybersecurity Act.

The idea is simple yet powerful: a single, Europe-wide framework to certify suppliers’ cybersecurity levels, featuring:

  • three levels of coverage (Basic, Substantial, High)
  • and, in its early versions, a “High+” tier that imposed sovereignty requirements (headquarters in the EU, data stored in Europe) for reaching the top tier.

Why it matters: NIS2 and the Data Act allow member states to require their essential entities to only use EUCS-certified providers. The certification would then become the gateway to public contracts and regulated sectors.

Let us be honest about the turbulent areas: the sovereignty requirements of the High+ level were removed from the project in March 2024, under pressure from certain member states and lobbies. France, Italy, and Spain are pleading to reintegrate them.

Cloud Sovereignty Framework: A Practical Approach to Measuring Cloud Sovereignty

At the same time, the European Commission has gone a step further by creating its Cloud Sovereignty Framework, detailed on June 1, 2026, which goes beyond mere labels or declarations of intent: it measures sovereignty based on evidence, through 8 objectives built on 48 verifiable criteria:

  • strategy,
  • jurisdiction,
  • data governance,
  • operations,
  • supply chain,
  • technology,
  • security and compliance,
  • sustainability

The New European Plan

The political aspect followed on June 3, 2026, when the Commission presented its technological sovereignty package. The goal is clear: to build a European technology stack so that, in its own words, “no one has the power to shut it down.”

The initial assessment is grim:

  • More than 80 percent of the digital products, services, and infrastructure used in the European Union come from outside the EU;
  • About 70% of the European cloud market is held by three U.S. providers (AWS, Azure, and Google Cloud).
  • According to estimates by the Europe 2031 group, approximately 5% of the world’s AI computing power is hosted in Europe, compared with nearly 80% in the United States.

As for the European cloud landscape, it is made up of dozens of players of varying sizes, with no single player dominating the market.

Does Europe need a single cloud champion or dozens of players?

"We can have several bakeries on a single street; if the bread is good, everyone is happy."
Matthieu Robin
Founder and CEO of Hidora
Hidora

The new plan relies on four pillars:

  • A Chips Act 2.0 for semiconductors,
  • A Cloud and AI Development Act (CADA) which aims to approximately triple data center capacity in Europe over five to seven years and introduce a single European method to evaluate the sovereignty of cloud and AI offerings in the same logic as the Cloud Sovereignty Framework,
  • An open-source strategy,
  • a roadmap that bridges the digital and energy sectors, since data center electricity consumption is now part of the equation.

Europe is starting from far behind: no European organization will entirely turn away from American hyperscalers in the short or medium term, and a complete exit is neither realistic nor the objective.

➡️ My take: After the GAIA-X disappointment, we’re finally heading in the right direction. We’re moving away from controversial slogans and labels toward measurable, comparable criteria(the CSF) and concrete legislative tools—the June package. If sovereignty requirements are included in the EUCS, Europe will have a harmonized instrument that clearly distinguishes a certified, sovereign cloud from a “sovereign-washed” cloud, providing real clarity for businesses and government agencies.

There are also concrete successes to display. Recently, the ECB chose OVH for the sovereign infrastructure of the digital euro. That matters.

For a positioning anchored in Switzerland, this is also where the data residence argument hits the mark: a provider operating entirely under Swiss jurisdiction naturally ranks high on the legal and operational dimensions that these frameworks now evaluate.

Qim Info helps you turn digital sovereignty into a framework for decision-making

Digital sovereignty is neither a political whim, nor a passing fad, nor a commercial argument. It is an architectural discipline, a risk governance, and an investment in resilience.

Ultimately, the issue is neither ideological nor technological. It can be summed up in one sentence: For every critical activity in your organization, do you know who holds the switch—and what it would cost you to take it back?

If the answer is well-documented, tested, and quantified, you’re on the right track, regardless of your provider. If it isn’t, the issue warrants attention.

At Qim info, we’ve found that most organizations aren’t lacking in technology. What they lack most are methods for objectively assessing their dependencies and making informed decisions.

Our role is less about recommending a supplier and more about helping our clients develop a strategy tailored to

  • their constraints,
  • their risks,
  • their ambitions.

This often involves more hybridization, open standards, and diversification, but rarely involves one-size-fits-all solutions.

At the Qim info Center of Expertise, we support our clients in this approach to infrastructure planning: assessing critical workloads, structuring hybrid environments, evaluating vendors, and building pragmatic digital autonomy—not a dogmatic one.

FAQ

What is the difference between digital sovereignty and data sovereignty?

The main difference lies in the scope: digital sovereignty is broader and includes data sovereignty.

  • Digital sovereignty = maintaining control over one’s overall digital environment.
  • Data sovereignty = maintaining control over one’s data and how it is used.

Examples:

  • “Are we too dependent on a single cloud provider to run our IT system?” → an issue of digital sovereignty.
  • “Who can access our data, from which country, under which jurisdiction, and can we retrieve or delete it?” → the issue of data sovereignty.

Is a sovereign cloud enough to guarantee digital sovereignty?

No. A sovereign cloud can strengthen digital sovereignty, but it is not enough to guarantee it.

The reason is simple: digital sovereignty is not just about where data is hosted. It refers to an organization’s actual ability to maintain control over its digital environment and to operate without excessive dependence on a third party.

Does hosting data in Switzerland guarantee data sovereignty?

No. Location matters, but the real issue is effective control over the data: access, uses, jurisdiction, encryption, reversibility…

How can a company’s level of digital sovereignty be assessed?

The Swiss Confederation recommends, in particular, watching:

  • legal and technical review;
  • control over data and encryption keys;
  • dependence on a single supplier;
  • the option to switch providers or repatriate services and data;
  • a master’s degree in architecture;
  • the internal capabilities needed to manage the system;
  • the availability of alternatives;
  • resilience in the event of a crisis or geopolitical change.

Picture of Clément Raussin
Clément Raussin

Head of the Cloud & DevOps Solutions Department at Qim info

Contents