Europe in Search of its Digital Sovereignty
Enterprises and public-sector organisations increasingly view the issue of digital sovereignty from a risk-based perspective, reflecting a broader unease about diminishing control over increasingly complex and interconnected digital ecosystems.
In the public debate, digital sovereignty often focuses on data protection and data location. However, sovereignty considerations should cover many more aspects. PAC has taken a closer look at what these are, conducted an EU-wide CxO Survey* on the topic, and published the key findings in a new SITSI report.
How to define digital sovereignty
Sovereignty considerations can be observed around the world but are particularly pronounced in Europe.
The European Commission’s recently developed Cloud Sovereignty Framework defines criteria, sovereignty evaluation and assurance levels (SEALs), and a scoring methodology for assessing the sovereignty level of cloud services across strategic, legal, operational, and technological dimensions. Vendors and customers have started to align themselves with the framework, with an eye to future public procurement.
The number and variety of aspects to be considered under the framework underlines that digital sovereignty is not a specific technology or a single piece of legislation. In a broad sense, digital sovereignty refers to the idea that states, companies, and public authorities should always
- be able to shape their digital transformation in accordance with their own values and goals;
- have control over the digital technologies they use and the data they process.
Drivers of digital sovereignty
Geopolitical instability, supply chain disruptions, growing dependence on non‑European cloud, software, and AI vendors, and regulatory pressure, in particular, drive sovereignty concerns, which can be divided into three major blocks:
- unauthorised data access or abuse;
- technological and/or commercial;
- operational resilience (“survivability” in the event that digital services are no longer available)
PAC’s CxO Survey* has shown that concerns are pronounced across all areas:
Digital sovereignty should not be digital isolation
The need for digital sovereignty should not be met with digital isolation. European organisations continue to seek the innovative power, scalability, and efficiency offered by global cloud and AI ecosystems. Consequently, most organisations will adopt hybrid approaches rather than pursue “full sovereignty”.
“Driving innovation and developing new data-based business models without compromising digital sovereignty” was a major driver for 87% of PAC’s CxO Survey* participants.
The challenge lies in striking the right balance between maintaining transparency, control, and flexibility on the one hand and enabling data- and AI-driven innovation on the other, all while keeping costs reasonable – the latter being clearly the CxO Survey* respondents’ biggest concern.
How to determine the need for digital sovereignty
Given the many aspects to consider, it is difficult to make universally applicable statements about the sovereignty requirements of individual industries, processes, or workloads. No organisation has only critical workloads, just as hardly any organisation has no critical workloads at all.
For a full picture of an organisation’s sovereignty needs, it is therefore essential to carefully classify the sensitivity and sovereignty needs of individual data and workload categories. AI systems, in particular, are potentially subject to specific ethical, legal, and regulatory frameworks, such as the EU AI Act. Moreover, requirements related to ethical data use and accountability increasingly become competitive differentiators.
Strategies between ideology and pragmatism
Current strategies regarding digital sovereignty are diverse and range between
- “ideology” – be prepared for the highly unlikely but potentially very impactful “black swan” event; and
- “pragmatism” – be prepared for widely known and predictable events like hacker attacks, regulatory violations, industrial espionage, etc.
Most scenarios are expected to involve hybrid approaches, as supporting digital sovereignty typically has to strike a balance between the degree of sovereignty, the access to innovative power and global scalability, and costs.
Vendors’ approaches to sovereignty
As heterogeneous as the aspects of digital sovereignty are vendors’ approaches to dealing with this heterogeneity. There are multiple strategies to provide the highest possible – or most reasonable – degree of sovereignty.
- European and local cloud providers are positioning themselves as potentially sovereign alternatives to the global hyperscalers; partly with additional on-site and “air-gapped” options.
- In-house, colocated, and private hosting models are experiencing a kind of revival. However, they normally do not offer the same levels of global scalability, feature richness, and innovative power as the global hyperscalers.
No 100-percent sovereignty
From a European perspective, 100% technological sovereignty that includes chips, hardware, software, etc. can hardly be reached in the foreseeable future. Consequently, the global hyperscalers have adopted various strategies to meet European organisations’ specific sovereignty requirements, including the announcement of dedicated billion-Euro investments:
- They offer extended control mechanisms for customers and/or managed services partners.
- They have established dedicated local entities with local management teams.
- They have launched dedicated (1:1) sovereign cloud variants outside of the usual public cloud regions – hosted by European third parties or on-premises.
- “Air-gapped” models work without constant connection to the vendor’s cloud regions.
Open source-based technology is considered a way to break free from the dependence on proprietary software applications and untransparent AI models but comes with potential disadvantages such as hidden total cost of ownership, limited features and functions, poor interoperability, etc. Nevertheless, an increasing number of organisations are moving away from proprietary software to open-source alternatives, others have made open source the core architecture of new AI developments.
For all these approaches, real-life examples can be found in PAC’s Market View:
New PAC report
PAC’s latest Market View, “Europe in Search of its Digital Sovereignty“, highlights why organisations must carefully assess the sovereignty requirements of individual workloads and data categories before defining their strategy.
New upcoming PAC RADAR
PAC will soon launch a new vendor benchmark in this area: a new PAC RADAR will closely examine vendors’ capabilities to help customers maintain or regain their digital sovereignty, resilience, and sustainability without compromising innovation and efficiency.
*PAC’s CxO Survey on Digital Sovereignty
As part of our research on digital sovereignty, PAC has conducted a dedicated quantitative CxO Survey. 550 decision-makers in organisations from all industry sectors, and of all sizes, in Austria, France, Germany, Spain, Italy, Benelux, and the Nordics (Sweden, Denmark, Finland) participated.
The study, carried out and published in collaboration with T-Systems, IBM, Genesys, AWS, Orange Business, and Arvato Systems, was meant to serve as a barometer for where and to what extent EU-based organisations face sovereignty-related concerns and challenges, how they prioritise technology investments, and what expectations they have of their IT partners.
