If you want to read the Digital Sovereignty Series, start here: mguenther.nl/series

Designing Digital Sovereignty for a World That Won't Hold Still
Don’t solve your current sovereignty problem. Three examples to make this concrete. An organization fine-tuning AI models on European customer data finds the regulatory ground shifting – GDPR transfer rules, CLOUD Act exposure and new AI Act obligations together pushing those models and pipelines toward EU jurisdiction. The training infrastructure built in 2023 wasn’t designed for that constraint. The remediation isn’t a configuration change; it’s an architecture rebuild. A European enterprise places R&D and strategic plans in a US-headquartered cloud provider’s EU region. The data sits in Frankfurt or Dublin. The contract specifies EU jurisdiction. But the parent company can be compelled by its home government to provide access – and the enterprise has no visibility into whether, when, or how often that happens. A sub-sea cable cut between mainland Europe and Scandinavia reroutes traffic through paths with significantly higher latency and reduced bandwidth. The infrastructure is still running. The DR strategy assumed those links would behave the way they did when it was designed. They don’t anymore. Three different scenarios, three different surfaces – legal, access, operational. But the same underlying pattern: the conditions the architecture was designed for keep changing, and what was a solid solution at procurement quietly becomes tomorrow’s liability. ...