Blog
29 articles

Europe's Digital Dependence, Explained
This is the stakes, in one place. How deep does Europe's reliance on US technology run, why does concentration turn ordinary tools into systemic risk, and why is passing an audit not the same as being sovereign? This cornerstone ties the argument together and links to the detail behind each claim.

Sovereignty You Can Actually Operate
This is the method. Once you accept that dependence is real and compliance alone won't fix it, the question becomes operational: what do you actually control, how do you prove it, and how do you leave if you have to? This cornerstone turns the point of view into a how-to and links to the article behind each move.

Sovereign AI, Explained
This is our whitespace. Cloud dependence is a known story; AI is repeating it one layer up, faster and deeper. This cornerstone explains why "sovereign AI" is a real category and not a marketing label, and links to the article behind each claim.

From Obligation to Assurance: Board Accountability and Continuous Compliance
For years, compliance was something the board delegated and heard about once a year. Two EU laws ended that arrangement, by putting the board's own name on the liability. This final post is about what changes when compliance becomes a governance function the board personally owns.

A Practical Guide to Finding (and Closing) Your Compliance Gaps
Every compliance program eventually faces the same question, usually a few weeks before an audit: where are we actually exposed? This is the method to answer it calmly and repeatably, before the audit does it for you.

A Pragmatic Sovereignty Playbook for the Next 12 Months
Seven posts of problem. This one is all solution. Here is what a European organization can actually do in the next year to reduce its dependence on foreign technology, without a rip-and-replace, without autarky, and without waiting for Brussels to build the alternatives.

A Reference Architecture for Sovereign-by-Default Platforms
Eight posts in, from the dependence map to the region lock, here's the synthesis: the minimum architecture that honestly earns the word "sovereign." Not a product pitch: a blueprint you can hold your own stack against.

The Overlap Dividend: How One Control Can Satisfy Five Frameworks
Here is the single most valuable idea in compliance, and most organizations leave it on the table: a large share of the work repeats. The same controls appear in law after law, which is why ENISA's own mapping table links NIS2 across ISO 27001, NIST CSF and ETSI EN 319 401. Do the work once, evidence it once, and claim it everywhere. That's the overlap dividend.

If You Can't Leave, You're Not Sovereign
Every sovereignty conversation eventually reaches the same question, and it's the one that actually matters: if you had to leave your provider next quarter (because of a price hike, a breach, a legal order, or a geopolitical shock), could you? And could you prove it?

No Lock-In by Construction
In the companion post we argued the real sovereignty test is whether you can leave. This is the engineer's answer to the obvious follow-up: how do you build a system so that leaving is a rehearsed operation instead of a hostage negotiation, including leaving us?

Governing AI: the EU AI Act, ISO 42001, and the NIST AI RMF
The AI Act is the newest and fastest-moving layer of the compliance maze, so fast that its own deadlines shifted in mid-2026. That makes it the perfect case study for the two things this series keeps arguing: build on your existing controls, and never rely on a static answer.

Don't Let AI Become the Next Cloud Lock-In
Europe spent fifteen years becoming dependent on a handful of foreign cloud providers. It is now on track to do the same thing with AI, except faster, and one layer deeper. The good news: this time we can see it coming.

The Prompt Is the Data
Everyone accepts that you shouldn't store customer data in a foreign jurisdiction. Almost no one applies the same rule to the prompts they send an AI model, even though the prompt, and the context retrieved to answer it, often is the customer data. Sovereign AI that ships your prompts to a foreign GPU isn't sovereign. It's a data transfer with better marketing.

DORA in Depth: How Finance Turned Resilience Into Law
Most digital regulation asks "is your data safe?" DORA asks a harder question of the financial sector: "when your technology fails (not if), can you keep operating?" It's the clearest example in EU law of turning resilience into a legal obligation, and it's a template for how a sector law layers on top of general frameworks.

The Cyber Paradox: Sovereign Security on Dependent Ground
Europe has built genuinely good cyber defenders. The problem is where they stand.

Securing AI the Way Attackers Break It
Prompt injection is the number-one security risk in AI applications, and here's the uncomfortable part: it probably can't be fully fixed. So the job isn't to "solve" it. It's to build so that when it happens, almost nothing bad can follow.

Cybersecurity Laws and Their Control Baselines: NIS2, the CRA, and What to Adopt
Two EU cyber laws now sit on most organizations: one governs how you run security, the other how you build products. The relief is that both are answerable with a mainstream control baseline you may already run, plus a few targeted additions.

Sovereignty Is Not Autarky
The sovereignty debate keeps offering a false choice: cut yourself off from the world's best technology, or accept permanent dependence. There is a third option, and it's the only realistic one.

The Region Lock: Selective Autonomy, in Code
In the companion post we argued sovereignty is a dial, not a wall, a framing the EU's own Joint Research Centre backs, noting that digital sovereignty "must not be conflated with isolation or protectionism" (JRC, Open but Not Powerless, 2025). This is how you build the dial, and, just as importantly, how you prove it's actually connected to anything.

Privacy Laws and the Frameworks That Prove Them: GDPR and Beyond
GDPR turned "we respect privacy" into "prove it." This post is about the second half of that sentence: the frameworks and controls that turn a privacy promise into audit-ready evidence.

Compliant but Dependent: Why Europe Is Regulating Faster Than It Builds
You can pass every audit on the calendar and still not control your own infrastructure. Compliance and sovereignty are not the same thing. Confusing them is the most expensive mistake in European IT right now.

Who Can Actually Compel Your Data?
"Encrypted at rest" is the most reassuring phrase in enterprise IT, and one of the least informative. The question that actually decides your exposure is simpler and harder: who holds the keys, and who can be compelled to use them?

A Decade That Rewrote the Rulebook: EU Digital Regulation, 2016 → 2026
In 2016, an EU company's digital obligations fit in one directive. By 2026 they fill a shelf, and the shelf is still growing. Understanding the pattern matters more than memorizing the acronyms, because the pattern tells you something uncomfortable: compliance is never "done."

When Ordinary Tools Quietly Become Critical Infrastructure
Nobody decides to make a SaaS tool load-bearing for the economy. It just happens, one convenient choice at a time.

Designing Against the Monoculture: an Event-Driven Runtime
A single bad update once crashed 8.5 million machines in an afternoon. The bug was survivable. The architecture wasn't. Here's how to build so it can't happen to you.

Laws, Frameworks, Standards, Controls: How They Actually Fit Together
Half of all compliance confusion comes from four words used as if they were interchangeable. They're not, and once you separate them, the maze gets a lot smaller.

The Real Map of Europe's Digital Dependence
How deep does Europe's reliance on US technology actually run? Not as a slogan: as a number you can check.

Sovereignty by Architecture, Not by Promise
An EU data-center region is a postcode. It is not sovereignty. Here's the difference, and the architecture that actually closes the gap.

The Compliance Maze: Why "Are We Compliant?" No Longer Has a Simple Answer
A decade ago, "are we compliant?" had one owner and one answer. Today the honest answer is "compliant with what, in which capacity, as of which date?" That shift, from a question to a maze, is the most under-managed risk in European business.
