Sovereignty is not a server location
Sovereign AI does not hinge on where the server stands, but on control. Why sovereign-cloud offerings don't solve it, and how to test your exit readiness.
A French judge at the International Criminal Court can no longer book hotels, order anything online, or use a working credit card. Overnight, Nicolas Guillou’s digital life was erased.
What happened? He did his job, and the US government didn’t like it. So he was placed on the US sanctions list. Amazon, PayPal, Airbnb and the other US services closed his accounts immediately. Even European banks terminated their relationship with him, afraid of consequences for their US business. An EU citizen, on European soil, digitally wiped out. And Europe could only watch.
Today it is a judge. Tomorrow it could be a company. Or an entire state that declines to fall into line during the next round of geopolitical pressure.
I am not writing this out of ideology, but out of sober risk assessment. A few years ago I would not have thought it possible that I would one day think this fundamentally about the use of American software. But the last few years have shown how quickly rules, contracts and geopolitical assumptions that felt settled can turn out to be worth nothing. Economic dependencies are used as leverage, and laws with extraterritorial reach have long been a reality.
Why this weighs particularly heavily with AI
With AI the question sharpens, because AI works with the core of what makes a company: process knowledge, internal documents, decision logic, customer information. Anyone who uses these systems and feeds them their data is inevitably granting a great deal of insight.
And unlike with conventional software, being switched off is no longer a thought experiment. In June 2026 the US Department of Commerce applied export controls to the strongest models of one AI provider. The provider could not verify its users’ nationality in real time and therefore shut the models down for everyone, worldwide, from one day to the next. Eighteen days later the controls were lifted again and access returned.
You can dismiss that as an episode. I see it as confirmation of a principle: a model running through an American API is available exactly as long as an American authority considers that appropriate. Eighteen days is short. But anyone who ran a production process on that model during those eighteen days had a problem for eighteen days that they had no part in solving.
What we are being sold as the answer
The industry’s answer to all of this is called “sovereign cloud” and “sovereign AI”. Data centres on German soil, operated by Google and Microsoft. Politicians celebrate this as a win for digital sovereignty.
Except the server location changes nothing about the legal position. A US company processing data is subject to the US CLOUD Act, regardless of where the disk sits. That is not a thesis of mine. In June 2025, Microsoft France’s chief legal officer, Anton Carniaux, was asked under oath before the French Senate whether he could guarantee that data belonging to French citizens would never be handed to the US government without the approval of French authorities. His answer:
“No, I cannot guarantee that.”
He added that it had not happened so far. That is reassuring for as long as the interests run in parallel. Which is precisely when nobody is interested in sovereignty.
It gets similarly absurd when the providers are allowed to define what independence from them means. At the AI for Good Summit in Geneva, Microsoft’s Chief Responsible AI Officer offered a definition of sovereign AI that amounts, at its core, to systems reflecting local cultures, values and norms — while you carry on using global technology wherever that seems sensible.
She is right about one thing: sovereignty does not mean doing without cloud AI. And AI that respects local norms is a genuine topic. The definition is problematic all the same, because it puts the focus entirely on that partial aspect and sweeps the central question under the carpet.
Sovereignty means control, above all. Who decides when it matters? A model can reflect German norms perfectly and still be switched off by order from Washington. On export bans, on price rises, on disclosure orders, that definition says not a word. And this despite the fact that the case in which a government forced a provider to block its strongest models was cited as the starting point in the very same discussion. Microsoft is subject to exactly the same jurisdiction.
It fits the picture that at Gaia-X, Europe’s great sovereignty hope, AWS, Google, Microsoft and Huawei have seats at the table. We are conducting a sovereignty debate with precisely the actors we want to protect ourselves from.
The question that actually counts
Sovereignty does not necessarily mean hosting everything yourself. That is a misunderstanding that narrows the debate unnecessarily. The decisive questions are different ones: who controls the software, the keys and the operation? And how realistic is an exit?
If software, updates or access paths still depend on an external provider, the same dependency arises. In a German data centre too. Architecture decides more about sovereignty than the location of a server.
Being able to choose is not a stance but a measurable capability. Three questions are enough:
- How long would it take you to leave your most important AI service?
- Does operation continue if it is switched off tomorrow?
- Does the alternative genuinely exist, or does it only exist in the strategy paper?
Anyone who cannot answer those three does not have sovereignty. They have customer lock-in with a good feeling attached.
And this is not a question you answer once. An exit you have never tested is an assumption. Anyone who has never restored their backup does not have a backup.
What follows from this
Not that everything has to run on premises. For some systems there is simply no sensible local alternative; for others there very much is. It depends on what exactly you want to protect yourself against. Radical self-sufficiency is a different thing from protection against data leaving the building, and the two call for different architectures.
What follows is an obligation to make deliberate decisions. To know which critical data and processes depend on political or legal developments outside your own influence. And then to decide whether you want to carry that risk.
Trust in assurances and legal frameworks is, in case of doubt, no longer enough. Only an architecture that secures data sovereignty technically is dependable when it counts.
As long as our critical infrastructure, our cloud services and our AI are subject to the law of foreign states, we can be coerced. No data centre in Frankfurt changes that. No contract. No promise.
When do we start taking this seriously?
This piece draws together thoughts that first appeared in a series of LinkedIn posts between January and July 2026.