Digital sovereignty: control over your data, your meaning and your AI
Data in Europe is not sovereignty yet. Control is.

On 18 June 2025, a director of Microsoft France was asked a simple question under oath in the French Senate: can he guarantee that data of French citizens will not end up with American authorities without the French government's consent? The answer was as honest as it was uncomfortable: "No, I cannot guarantee that." With the addition that it had never happened.
With that single sentence, digital sovereignty changed from a policy term into a boardroom question. Not because the cloud is unsafe, and not because providers have bad intentions. But because the question of who ultimately has control over an organisation's data turns out not to have a technical answer. The answer is legal, contractual and architectural at the same time.
This article describes what digital sovereignty means in practice, why legislation makes it compulsory in 2026, and how an organisation regains control layer by layer, without tearing everything down.
What is digital sovereignty?
Digital sovereignty is an organisation's ability to decide for itself where its data lives, who can reach it, which logic runs on it and how it can leave again. It is not a location. It is control.
The most common reflex is: our data is in a European data centre, so we are sovereign. That is understandable, and it is only half the story. Location determines where the servers are. Jurisdiction determines whose law applies, and that follows the provider, not the data centre. An American provider falls under the American CLOUD Act, which gives authorities access under conditions to data the company manages, even when that data is in Europe. European data residency, such as the EU Data Boundary of large providers, improves the location. It does not change the jurisdiction.
Location versus jurisdiction
That does not mean every organisation should leave its cloud provider tomorrow. It means digital sovereignty is a deliberate choice per type of data, not a checkbox that is on by default.
Why digital sovereignty is on the agenda now
Three European laws turn sovereignty from a preference into an obligation, and the rise of AI raises the stakes higher than ever.
The Cybersecurity Act (NIS2). Since 15 August 2026, the Cybersecurity Act applies in the Netherlands, the Dutch implementation of the European NIS2 directive. Around 8,000 organisations in 18 sectors fall under it. They must register with the NCSC, take appropriate measures against risks to their systems, report serious incidents within legal deadlines, and the board carries ultimate responsibility for managing cyber risk. Securing the supply chain is part of that duty of care. Whoever does not know which providers, under which law, their own operations depend on, cannot carry that responsibility.
The Data Act. Since 12 September 2025, customers of cloud services have the right to switch: a notice period of at most two months, a transition period of at most thirty days, and at least thirty more days afterwards to retrieve data. From 12 January 2027, providers may no longer charge any switching costs at all, not even for outgoing data traffic. Leaving becomes a legal right. The law does not regulate whether leaving is technically possible. That depends on how your own environment is built.
The AI Act. The European AI Act is taking effect in phases. The transparency obligations have applied since 2 August 2026. The heaviest obligations, for high-risk systems, have been postponed via the Digital Omnibus to 2 December 2027, and for AI in regulated products to 2 August 2028. Postponement is not cancellation: organisations that use AI in decisions about people will face requirements on traceability, oversight and documentation.
And then there is AI itself. A question to an AI model often contains more sensitive context than a document ever did: a strategic consideration, a case file, a customer situation, condensed into a single prompt. Every question to an external model sends that context outside. Digital sovereignty is therefore no longer only about where data lives, but also about where that data is thought about.
The four layers of digital sovereignty
The four layers of digital sovereignty
Sovereignty is not a single switch. It consists of four layers, and each layer asks its own question.
- Data: where does it live, and under which law? The familiar layer: data storage in the EU, encryption, key management, access rights. Necessary, but not sufficient.
- Meaning: who owns the logic? The layer most often forgotten. The definitions, calculations and rules that turn raw data into business information are often hidden in a vendor's proprietary formats, in stored procedures or in reporting files. Whoever owns the data but cannot take the meaning along is not sovereign: the data is then a collection of numbers without explanation.
- AI: where does the model reason? Every question to an AI model shares context. The question is not whether AI may be used, but which reasoning may leave the building and which may not.
- Exit: can you leave? The Data Act gives the right, the architecture gives the ability. An exit that has never been practised is an assumption. An exit practised once a year is a fact.
Sovereignty is as strong as the weakest of these four layers. An organisation with its data under its own control, but its logic locked in with one vendor, has little to choose in practice.
Digital sovereignty is a scale, not a switch
Not every dataset needs the same level of control. A public product catalogue has different requirements than donor data, patient records, personnel data or the board's strategic plans. Protecting everything at the highest level makes it unaffordable. Leaving everything at the lowest level means taking risks nobody consciously chose.
| Level | What it means | Suited for |
|---|---|---|
| 1. European cloud with agreements | Data in the EU with a large provider, with a processing agreement and encryption | Regular business data without special sensitivity |
| 2. Own tenant | The environment runs in your own cloud tenant, with your own administration and your own keys | Organisations that want to decide who manages and who has access |
| 3. Portable meaning and a practised exit | Logic in open, readable form, independent of one platform; exit practised yearly | Organisations that want to turn dependency into freedom of choice |
| 4. Private AI on own hardware | The AI model reasons on your own servers; questions and answers never leave the building | The most sensitive data and reasoning |
The levels stack: whoever works at level 4 has the lower levels in order too. And the choice is made per type of data, based on a data classification, not for the whole organisation at once. How the hosting options relate to these levels is listed with the pricing.
Why the meaning layer makes the difference
The most powerful step towards digital sovereignty is often not a migration, but the liberation of meaning. As long as definitions and calculations are locked into one platform, every platform choice is irreversible, and a switch is a multi-year project. When meaning lives in an open, governed layer, with recorded definitions, owners and agreements between teams, the platform underneath becomes interchangeable. Meaning is then the constant, the platform the variable.
That changes the negotiating position completely. An organisation that can take its logic along chooses a provider because it is the best, not because leaving is too expensive. In a company brain built that way, the meaning layer is the foundation: every employee, every system and every AI assistant works from the same recorded meaning, and that meaning belongs to the organisation itself, always exportable.
Private AI: the last layer in your own hands
For the most sensitive reasoning there is one way to be certain it never leaves the building: the model runs inside the building itself. With private AI, the AI model runs on physical servers the organisation manages itself, often on hardware that is already there. Questions, context and answers stay within your own walls. No external service sees the prompt, no foreign jurisdiction reaches the conversation.
Private AI works best in combination with a governed meaning layer. A model that runs on your own hardware but does not know what "revenue", "active customer" or "outstanding" means in this organisation gives fast but unreliable answers. A model that reasons from recorded definitions gives answers that can be traced back to the source.
To be fair: private AI asks more than a subscription. It involves physical hardware, installation, management and maintenance. It fits where the sensitivity of the data justifies that investment: special personal data, confidential strategy, organisations that fall under the Cybersecurity Act, and organisations whose customers, donors or regulators demand certainty. For the rest of the data, the lower levels of the scale suffice.
Where do you start with digital sovereignty?
Digital sovereignty is not reached in one project, but in five manageable steps.
- Classify what is sensitive. Not all data deserves the same level. A simple division into four classes, from public to strictly confidential, determines where the effort goes.
- Map the dependencies. Which providers, under which law, touch which data and which processes? This overview is, incidentally, exactly what the duty of care under the Cybersecurity Act asks for.
- Make the meaning portable. Take definitions and calculations out of hidden procedures and proprietary formats, and record them in an open, governed layer with an owner per concept.
- Choose the level per layer. Regular data at level 1 or 2, critical logic at level 3, the most sensitive reasoning at level 4.
- Practise the exit. Once a year a controlled test: can a core component really be moved, and how long does that take? The answer says more about sovereignty than any contract.
Each step is small and builds on the previous one, just like the growth path of a company brain.
Frequently asked questions about digital sovereignty
Is data in a European data centre automatically sovereign? No. The location determines where the data is, the provider's jurisdiction determines whose law applies. An American provider falls under American legislation such as the CLOUD Act even with European data centres.
Do we have to leave American cloud providers? Not necessarily. For much data, a European environment with good agreements is appropriate. What matters is that the choice is made deliberately per type of data, and that leaving remains possible when needed.
What does the Cybersecurity Act mean for digital sovereignty? The law has applied since 15 August 2026 to around 8,000 organisations. The duty of care also covers supply chain security, and the board carries ultimate responsibility. Insight into your own digital dependencies is therefore no longer a choice but an obligation.
What does the Data Act change? Customers of cloud services have had the right to switch since 12 September 2025, with fixed maximum terms. From 12 January 2027, switching costs, including costs for outgoing data traffic, are prohibited.
What is private AI? An AI model that runs on physical servers under your own management, so that questions, context and answers never leave the organisation. It is used for the most sensitive data and reasoning.
Who is private AI suited for? For organisations where the sensitivity of the data justifies the investment in their own hardware, installation and maintenance. Because every situation is different, the possibilities are discussed per organisation.
Digital sovereignty is not where your data stands today, but whether you can decide yourself where it stands tomorrow.
The most sensitive questions deserve a model that thinks within your own walls
Sources
Every claim in this article can be checked at the source.
- 1
- 2
- 3
- 4
- 5