Different definitions and strategies: Moderated by Carolina Hayder, Cloudera, Trend Micro, Zoho, Retarus, and Genesys presented their own unique perspectives on digital sovereignty. Photo: Peter Knoll
“Digital sovereignty” is a concept currently in vogue in EU. But what exactly is it, how can it be achieved, and what measures need to be taken? TELI board member Peter Knoll attended an international panel discussion in search of answers.
Five companies, five approaches that differ significantly in some respects: At an event in Munich hosted by a well-known PR agency, a panel featuring representatives from major international IT corporations highlighted key aspects of digital sovereignty—defined as the right to act free from external interference.
Steffen Märkl, Director of Solutions Engineering (CEMEA) at Cloudera, was the first to speak. The US-based company specializes in big data, data management, and artificial intelligence (AI), integrating various open-source technologies in the process. “True sovereignty means maintaining absolute legal, operational, and technical control over the entire data and AI lifecycle,” said Märkl.
This encompasses four areas: data sovereignty (e.g., control of data under local laws), technical sovereignty (avoiding vendor lock-in through open source, open standards, and interoperability), AI sovereignty (development on one’s own infrastructure, protection of proprietary data, etc.), and operational sovereignty. By the latter, Cloudera means that administration, maintenance, and support must be carried out exclusively by authorized local personnel within trusted jurisdictions.
A four-pillar architecture
According to Steffen Märkl, a sovereign architecture within the EU must therefore rest on four pillars:
- the provider must have a local presence with staff in the EU
- there must be a “cloud-anywhere” platform featuring an open, hybrid architecture with a secondary abstraction layer
- and there must be unified governance
- and cryptographic sovereignty to ensure data remains under the customer’s control.
Autarky as a myth
In contrast, Dirk Arendt—Director of Government, Public, and Healthcare (DACH region) at TrendAI—warned against demands for regional isolation. Trend Micro specializes in security software; TrendAI collaborates with the US-based AI developer Anthropic to advance AI-native workflows, automation, and risk mitigation, integrating Anthropic’s large language model (LLM), Claude.
“Sovereignty means freedom of choice—not isolation,” said Arendt. He argued that complete technological self-sufficiency—isolating oneself from the global digital landscape—is “neither achievable nor desirable in an interconnected world.” The reality is not the “myth of autarky,” but rather self-determination. Freedom of choice exists among capable partners, and acting with self-determination is both possible and necessary.
Independence through ownership structure
Suvish Viswanathan, Regional Director DACH at Zoho, readily seized upon the topic of the Cloud Act to confidently position his company as an alternative to Microsoft Office. Zoho offers more than 60 products and 45 integrated applications.

Diverse requirements: According to Zoho executive Suvish Viswanathan, true digital sovereignty entails more than just having a data center in the EU. Photo: Peter Knoll
The India-based company is owner-managed, allowing it to operate with a long-term perspective—free from short-term investor influence—in line with its corporate motto: “People over profits.”
Suvish Viswanathan noted: “Data processed by a company registered in the US is automatically subject to US law—including potential requests based on the Cloud Act.”
Consequently, he argued, “it does not matter where the data center is located; the decisive factor is the legal jurisdiction, not the physical location.” Sovereignty arises where companies retain control over their data, processes, and technological decisions. A provider’s ownership structure, business model, and strategic independence can be just as relevant in this regard as technical or regulatory factors.
A stark contrast: safety awareness vs. actual safety
Nevertheless, only 47% felt “fully audit-ready.” “80 percent of decision-makers believe they have their email environment under control,” Oliver Paetz said, citing the study. Yet the reality is that roughly half use providers based outside Europe. The keys to sovereignty, he noted, are “observability and identity management”—far more than a European data center alone could offer.

100% digital sovereignty requires control over four areas, emphasizes Retarus product manager Oliver Paetz. Photo: Peter Knoll
In the final keynote address, Yasser Yoshua Wardasbi—Senior Manager for the European Sovereign Region (EMEA) at Genesys—spoke more about the lack of customer satisfaction with German public administration’s digital services than about the originally agreed core topic (though he did touch upon it). His thesis was that trust is fundamental to the political survival of democracy. The guiding question, he argued, is: “Will the digital service remain controllable and available—even in the face of extraterritorial pressure and geopolitical tensions?”
In the ensuing—and at times heated—discussion, several IT journalists present emphasized the importance of having a genuine alternative to major US corporations. There was a consensus that the use of LLM-based AI is not sensible or appropriate in every area; often, simpler methods—such as standard machine learning—suffice, consuming less computing power and, consequently, less energy.
All panelists agreed that monopolies pose a major threat to digital sovereignty, while acknowledging the significant hurdles—especially for international enterprises—involved in moving away from them.

