All articles
SovereigntyGovernanceArchitecture

Sovereignty You Can Actually Operate

This is the method. Once you accept that dependence is real and compliance alone won't fix it, the question becomes operational: what do you actually control, how do you prove it, and how do you leave if you have to? This cornerstone turns the point of view into a how-to and links to the article behind each move.

Ilke Tosunoğlu
Ilke TosunoğluJuly 20, 20264 min readUpdated July 20, 2026
A dial set between "open / dependent" and "sovereign / isolated", marked at a pragmatic middle labelled selective autonomy: control where it matters, open everywhere else.

The sovereignty debate keeps offering a false choice: cut yourself off from the best technology in the world, or accept permanent dependence. There is a third option, and it is the only realistic one. Call it selective autonomy: sovereign capacity where it genuinely matters, openness everywhere else, and the ability to tell the difference.

Autarky (the strawman) Selective autonomy (the goal)
Aim Build everything yourself Control what matters; stay open elsewhere
Scope The whole stack Sensitive workloads and chokepoints
Cost Enormous, slow, often worse Targeted, achievable now
Posture Closed Open but not powerless

Not autarky: sovereignty is a dial

The realistic objective is not a European wall. Europe already proves the point: it is deeply dependent in cloud and AI, yet holds one of the most asymmetric chokepoints on earth in lithography. That is sovereignty as leverage, not isolation, and the lesson scales down to every organization. You do not need to own the whole stack; you need control where control is decisive. The full argument, and the workload-tiering tool that operationalizes it, is in Sovereignty Is Not Autarky.

Location is not control

The most common mistake is treating an "EU region" as sovereignty. Residency answers where the bytes sit; sovereignty answers whose laws govern them and who can be compelled to hand them over. Under the US CLOUD Act, a demand served on a US-headquartered provider reaches data it controls anywhere in the world, Frankfurt and Dublin included. The architectural answer, customer-held keys, encryption, no-egress isolation, and an EU operating entity, is what turns a promise into a property of the system. Read Sovereignty by Architecture, Not by Promise and its companion Who Can Actually Compel Your Data?.

Sovereign security needs sovereign ground

A related trap sits one layer down. Europe fields genuinely strong security vendors, but the high-value control planes, cloud-native security, hyperscale telemetry, identity, run overwhelmingly on US infrastructure, and European tools frequently run on the very systems they are meant to protect. Sovereign security has to include the ground it stands on. That is the argument of The Cyber Paradox.

The truest test: can you leave?

Sovereignty is a capacity, and the capacity that matters most is the ability to walk away. A provider you cannot leave has sovereignty over you, whatever colour the badge. Public-cloud adoption is near-universal; tested exit plans are not. From 12 January 2027 the EU Data Act prohibits all cloud switching and egress charges (Data Act, Art. 29), removing the financial moat, but the effort, the proprietary APIs and untested failover, is still yours to solve. Why the exit is the real test is in If You Can't Leave, You're Not Sovereign.

The 12-month plan

None of this requires ripping out what works. The pragmatic sequence: map dependencies and concentration, tier workloads by the sovereignty they actually need, fix the sensitive tiers first with customer-held keys, design a tested exit, prefer open standards where they're ready, and treat skills as critical infrastructure. The full playbook, with the EU's SEAL assurance ladder and what not to do, is in A Pragmatic Sovereignty Playbook.

Where this leads

The stakes are the first pillar, Europe's Digital Dependence, Explained. The sharpest new front, sovereign AI, is the third, Sovereign AI, Explained.

To put the sensitive tiers on sovereign ground, explore the Soveryne Cloud Foundation, or get in touch and we'll help you tier your workloads. If we're not the right fit for a given tier, we'll say so.