Blog

29 articles

A map of Europe's dependence on US technology: cloud, software, AI and chips, alongside the leverage points Europe still holds in lithography and telecom.
SovereigntyCloud

Europe's Digital Dependence, Explained

This is the stakes, in one place. How deep does Europe's reliance on US technology run, why does concentration turn ordinary tools into systemic risk, and why is passing an audit not the same as being sovereign? This cornerstone ties the argument together and links to the detail behind each claim.

July 20, 20264 min read
A dial set between "open / dependent" and "sovereign / isolated", marked at a pragmatic middle labelled selective autonomy: control where it matters, open everywhere else.
SovereigntyGovernance

Sovereignty You Can Actually Operate

This is the method. Once you accept that dependence is real and compliance alone won't fix it, the question becomes operational: what do you actually control, how do you prove it, and how do you leave if you have to? This cornerstone turns the point of view into a how-to and links to the article behind each move.

July 20, 20264 min read
A prompt and its retrieved context flowing into a model, splitting one path to a foreign GPU outside the jurisdiction, the other to in-region EU inference that keeps the data home.
AISovereignty

Sovereign AI, Explained

This is our whitespace. Cloud dependence is a known story; AI is repeating it one layer up, faster and deeper. This cornerstone explains why "sovereign AI" is a real category and not a marketing label, and links to the article behind each claim.

July 20, 20263 min read
A boardroom dashboard of framework coverage, open gaps and trend, framing the shift from obligation to assurance.
ComplianceGovernance

From Obligation to Assurance: Board Accountability and Continuous Compliance

For years, compliance was something the board delegated and heard about once a year. Two EU laws ended that arrangement, by putting the board's own name on the liability. This final post is about what changes when compliance becomes a governance function the board personally owns.

July 9, 20265 min read
A repeatable, seven-step compliance gap-analysis loop laid out as a cycle.
ComplianceGovernance

A Practical Guide to Finding (and Closing) Your Compliance Gaps

Every compliance program eventually faces the same question, usually a few weeks before an audit: where are we actually exposed? This is the method to answer it calmly and repeatably, before the audit does it for you.

July 2, 20265 min read
A 12-month roadmap arc with six milestones (map, tier, fix sensitive, design exit, open standards, skills) under the line "Start on Monday. No rip-and-replace."
SovereigntyGovernance

A Pragmatic Sovereignty Playbook for the Next 12 Months

Seven posts of problem. This one is all solution. Here is what a European organization can actually do in the next year to reduce its dependence on foreign technology, without a rip-and-replace, without autarky, and without waiting for Brussels to build the alternatives.

June 25, 20268 min read
A layered reference-architecture shield inside an EU boundary, listing the seven pillars in order (jurisdiction/ownership, region-locked data, key custody, regional inference, cell isolation, tamper-evident audit, enforcement + test) with side notes on sovereign-by-design, privacy-by-default, resilience, and auditability.
ArchitectureSovereignty

A Reference Architecture for Sovereign-by-Default Platforms

Eight posts in, from the dependence map to the region lock, here's the synthesis: the minimum architecture that honestly earns the word "sovereign." Not a product pitch: a blueprint you can hold your own stack against.

June 25, 20267 min read
A single access-control requirement radiating out to GDPR, NIS2, DORA, ISO 27001 and SOC 2 badges under the banner map once, prove many.
ComplianceGovernance

The Overlap Dividend: How One Control Can Satisfy Five Frameworks

Here is the single most valuable idea in compliance, and most organizations leave it on the table: a large share of the work repeats. The same controls appear in law after law, which is why ENISA's own mapping table links NIS2 across ISO 27001, NIST CSF and ETSI EN 319 401. Do the work once, evidence it once, and claim it everywhere. That's the overlap dividend.

June 25, 20265 min read
A heavy chain and padlock labelled "egress fees lock-in" being cut with bolt-cutters, while an open door leads out to an open landscape; side labels read portability, open standards, interoperability, freedom to choose. Caption: your data, your apps, your choice.
Lock-inSovereignty

If You Can't Leave, You're Not Sovereign

Every sovereignty conversation eventually reaches the same question, and it's the one that actually matters: if you had to leave your provider next quarter (because of a price hike, a breach, a legal order, or a geopolitical shock), could you? And could you prove it?

June 18, 20267 min read
On the left, an open, composable architecture built from interlocking standard blocks (open-source core, open standards, portable formats, modular and interoperable, export) with a lit path leading out through a door. On the right, a cracked "lock-in monolith" (proprietary format, closed API, restricted access, high switching costs) hiding tight coupling and unknown dependencies. Caption: your data, your choice, anywhere.
Lock-inArchitecture

No Lock-In by Construction

In the companion post we argued the real sovereignty test is whether you can leave. This is the engineer's answer to the obvious follow-up: how do you build a system so that leaving is a rehearsed operation instead of a hostage negotiation, including leaving us?

June 18, 20267 min read
The EU AI Act risk pyramid, from prohibited and high-risk systems down to minimal-risk AI.
ComplianceAI

Governing AI: the EU AI Act, ISO 42001, and the NIST AI RMF

The AI Act is the newest and fastest-moving layer of the compliance maze, so fast that its own deadlines shifted in mid-2026. That makes it the perfect case study for the two things this series keeps arguing: build on your existing controls, and never rely on a static answer.

June 18, 20266 min read
Two padlocks side by side: "Cloud lock-in (10 years)" and a larger, faster-closing "AI lock-in (18 months)" wrapped in cables labelled API dependence, data gravity, fine-tuning and agents, with a time-to-lock-in strip showing AI lock-in arriving far sooner.
AILock-in

Don't Let AI Become the Next Cloud Lock-In

Europe spent fifteen years becoming dependent on a handful of foreign cloud providers. It is now on track to do the same thing with AI, except faster, and one layer deeper. The good news: this time we can see it coming.

June 11, 20268 min read
A prompt plus retrieved context flowing into a model, then splitting two ways: one path to a foreign GPU / inference environment (out of jurisdiction, data leaves your control), the other to an EU-region inference environment (data stays within your jurisdiction). Below, a source text is turned into an embedding vector and then reconstructed back into readable text, showing embeddings still reveal source information.
AIData & privacy

The Prompt Is the Data

Everyone accepts that you shouldn't store customer data in a foreign jurisdiction. Almost no one applies the same rule to the prompts they send an AI model, even though the prompt, and the context retrieved to answer it, often is the customer data. Sovereign AI that ships your prompts to a foreign GPU isn't sovereign. It's a data transfer with better marketing.

June 11, 20268 min read
The five DORA pillars shown as columns standing on a financial-resilience base.
ComplianceGovernance

DORA in Depth: How Finance Turned Resilience Into Law

Most digital regulation asks "is your data safe?" DORA asks a harder question of the financial sector: "when your technology fails (not if), can you keep operating?" It's the clearest example in EU law of turning resilience into a legal obligation, and it's a template for how a sector law layers on top of general frameworks.

June 11, 20266 min read
A glowing EU shield of EDR, MDR and SOC capabilities standing on cracked ground whose foundations are labelled US cloud, identity backplane, and telemetry. The shield is only as sovereign as the dependent ground beneath it.
CybersecuritySovereignty

The Cyber Paradox: Sovereign Security on Dependent Ground

Europe has built genuinely good cyber defenders. The problem is where they stand.

June 4, 20268 min read
An AI model core surrounded by concentric defensive rings (sanitize, fence untrusted data, least privilege, output filter, verifier, monitor) with a red "untrusted content / potential injection" stream breaking apart against the outer layers.
AICybersecurity

Securing AI the Way Attackers Break It

Prompt injection is the number-one security risk in AI applications, and here's the uncomfortable part: it probably can't be fully fixed. So the job isn't to "solve" it. It's to build so that when it happens, almost nothing bad can follow.

June 4, 20267 min read
Two pillars, organizational security under NIS2 and product security under the CRA, resting on a shared ISO 27001 and NIST CSF 2.0 control baseline.
ComplianceCybersecurity

Cybersecurity Laws and Their Control Baselines: NIS2, the CRA, and What to Adopt

Two EU cyber laws now sit on most organizations: one governs how you run security, the other how you build products. The relief is that both are answerable with a mainstream control baseline you may already run, plus a few targeted additions.

June 4, 20265 min read
A spectrum dial running from "Open / dependent" on the left to "Sovereign / isolated" on the right, with the marker set in a pragmatic middle position labelled "Selective autonomy: control where it matters, not isolation everywhere." Supporting notes: strategic control where it matters, trusted partnerships, operational resilience, innovation without lock-in.
SovereigntyLock-in

Sovereignty Is Not Autarky

The sovereignty debate keeps offering a false choice: cut yourself off from the world's best technology, or accept permanent dependence. There is a third option, and it's the only realistic one.

May 28, 20267 min read
Diagram of a tenant tagged region = eu-west and "region locked". Inside the chosen EU region, data (encrypted storage), compute (isolated workers) and AI inference (private inference) all stay together, contained by construction; a US region lane is greyed out and blocked by policy. Supporting notes: data residency, sovereignty by design, transparency, enforcement in code, trusted infrastructure.
ArchitectureData & privacy

The Region Lock: Selective Autonomy, in Code

In the companion post we argued sovereignty is a dial, not a wall, a framing the EU's own Joint Research Centre backs, noting that digital sovereignty "must not be conflated with isolation or protectionism" (JRC, Open but Not Powerless, 2025). This is how you build the dial, and, just as importantly, how you prove it's actually connected to anything.

May 28, 20268 min read
GDPR at the centre with spokes to ISO 27701, ISO 27001 and the NIST Privacy Framework, plus a health-sector tag for the EHDS.
ComplianceData & privacy

Privacy Laws and the Frameworks That Prove Them: GDPR and Beyond

GDPR turned "we respect privacy" into "prove it." This post is about the second half of that sentence: the frameworks and controls that turn a privacy promise into audit-ready evidence.

May 28, 20265 min read
Infographic contrasting an "Audit Passed" shield with a system still wired to a foreign-controlled cloud. "What an audit proves" (documented controls, incident response, risk assessments, encryption in place) versus "what it doesn't" (foreign legal exposure, vendor lock-in, provider outage risk, external key control). Caption: compliance checks the box; sovereignty removes the dependency.
SovereigntyCompliance

Compliant but Dependent: Why Europe Is Regulating Faster Than It Builds

You can pass every audit on the calendar and still not control your own infrastructure. Compliance and sovereignty are not the same thing. Confusing them is the most expensive mistake in European IT right now.

May 21, 20268 min read
Diagram of the key boundary. Left, provider-controlled: the provider holds the encryption key, so a foreign legal order produces readable data. Right, customer- or EU-entity-controlled: the customer or an EU entity holds the key, so the same order yields only ciphertext, nothing to hand over. Caption: control the key, control the risk.
Data & privacyArchitecture

Who Can Actually Compel Your Data?

"Encrypted at rest" is the most reassuring phrase in enterprise IT, and one of the least informative. The question that actually decides your exposure is simpler and harder: who holds the keys, and who can be compelled to use them?

May 21, 20267 min read
A rising timeline from 2016 to 2026 with milestone markers for GDPR, NIS, NIS2, DORA, the AI Act, CRA and eIDAS2.
ComplianceSovereignty

A Decade That Rewrote the Rulebook: EU Digital Regulation, 2016 → 2026

In 2016, an EU company's digital obligations fit in one directive. By 2026 they fill a shelf, and the shelf is still growing. Understanding the pattern matters more than memorizing the acronyms, because the pattern tells you something uncomfortable: compliance is never "done."

May 21, 20266 min read
Infographic: a single routine software update propagates a fault across airports, healthcare, banking, offices, broadcast and cloud services, ending in 8.5 million affected devices, illustrating the path from convenience to embedding to concentration to criticality.
CloudCybersecurity

When Ordinary Tools Quietly Become Critical Infrastructure

Nobody decides to make a SaaS tool load-bearing for the economy. It just happens, one convenient choice at a time.

May 14, 20268 min read
Infographic: how correlated failure happens (software homogeneity, privileged execution and unstaged updates combine into a continent-scale failure) contrasted with designing for resilience using independent cells, isolation and an event-driven runtime so failures stay local and systems stay available.
ArchitectureCybersecurity

Designing Against the Monoculture: an Event-Driven Runtime

A single bad update once crashed 8.5 million machines in an afternoon. The bug was survivable. The architecture wasn't. Here's how to build so it can't happen to you.

May 14, 20268 min read
A layered diagram showing how a law, a framework, a standard and a control fit together, from obligation down to the evidence that proves it.
Compliance

Laws, Frameworks, Standards, Controls: How They Actually Fit Together

Half of all compliance confusion comes from four words used as if they were interchangeable. They're not, and once you separate them, the maze gets a lot smaller.

May 14, 20266 min read
Infographic map of Europe showing digital dependence on US technology (€264bn annual outflow, 70% US cloud market share, 80% of software spend, and 40-vs-3 AI models) alongside European leverage in ASML lithography and 5G telecom.
SovereigntyCloud

The Real Map of Europe's Digital Dependence

How deep does Europe's reliance on US technology actually run? Not as a slogan: as a number you can check.

May 7, 20269 min read
Split infographic. Left, data residency: your data sits in an EU region but a foreign jurisdiction can still issue a legal access request to the provider. Residency is geography, not governance. Right, data sovereignty by architecture: customer-controlled keys, encryption by design, isolated EU region, and EU-governed operations mean EU law governs the stack; sovereignty is whose laws govern the data.
ArchitectureData & privacy

Sovereignty by Architecture, Not by Promise

An EU data-center region is a postcode. It is not sovereignty. Here's the difference, and the architecture that actually closes the gap.

May 7, 20268 min read
An organization at the centre of a maze whose walls are labelled GDPR, NIS2, DORA, the AI Act, CRA, ISO 27001 and SOC 2, with one clear path threading through.
ComplianceGovernance

The Compliance Maze: Why "Are We Compliant?" No Longer Has a Simple Answer

A decade ago, "are we compliant?" had one owner and one answer. Today the honest answer is "compliant with what, in which capacity, as of which date?" That shift, from a question to a maze, is the most under-managed risk in European business.

May 7, 20267 min read