A Frankfurt data centre is not enough
Most “EU data” assurances answer the wrong question. They tell you where your data sits. They do not tell you who can reach it.
When a vendor promises your data stays in Europe, they are answering a question of geography: residency. It is a real and necessary thing. But it is not the question that decides whether your data is actually yours. That question is sovereignty, who can compel access to it, whose law governs it, and who controls the capability built on it. A Frankfurt data centre operated by a US-headquartered company satisfies the first and quietly fails the second.
This distinction sounds like a lawyer's footnote. It is in fact one of the most consequential strategic decisions an enterprise will make this decade, because the data and the AI capability you build on it are becoming your single most valuable asset, and you are deciding, often without noticing, whether you own that asset or rent it from someone who can take it back.
The mechanism: extraterritorial reach
The reason residency is not sovereignty has a name, the US CLOUD Act, and no contract clause cures it.
Under the US CLOUD Act, a US-headquartered provider can be compelled by US authorities to produce data in its custody regardless of where in the world that data is stored. A European region does not change the provider's nationality, and Standard Contractual Clauses, the usual contractual comfort, cannot override a foreign government's lawful demand on a company subject to its jurisdiction. This is not hypothetical: asked under oath by the French Senate whether he could guarantee French citizens' data was safe from US authorities, a Microsoft France executive reportedly answered that he could not. And the reflex runs deeper than anyone admits: Adobe's award-winning 2024 showcase of European customer experience, at Danish pharma giant Novo Nordisk, frames its regulated-data protections through HIPAA, an American healthcare statute, with GDPR nowhere in the story. Europe's flagship deployments are answering to the wrong continent's law, and it went through an entire award season unremarked.
So the control a residency promise appears to give you is, on the dimension that matters most, an illusion. The chart makes the gradient concrete: moving from a US region to an EU region of the same US provider improves very little. Real control arrives only with operational sovereignty, a provider that cannot be compelled by a foreign government, and supply-chain sovereignty: a stack of model, data, and compute you actually own or can fully audit.
A Rindogatan-modelled control index. Residency alone, an EU region of a US-headquartered provider, barely moves control, because the provider's home jurisdiction still reaches the data. Real control arrives only with operational and supply-chain sovereignty. Directional, not survey data.
Why a business leader should care
This is not a compliance argument. It is a strategy argument, about control, competitive advantage, and not handing your crown jewels to a jurisdiction you do not answer to.
Set the regulatory checklist aside for a moment; the rules are being amended even as you read this, and most boards rightly delegate them. The argument that should reach the board is simpler and sharper. Your customer data, your proprietary processes, and increasingly the AI models trained on them are the assets that differentiate you. If a foreign government can compel them, a foreign vendor can change the terms on which you access them, and a foreign jurisdiction governs them, then you do not control your own advantage. You are renting it.
This is the strategic core of European AI sovereignty, and it is the opposite of a confrontational posture. It is the ordinary commercial logic every leader already applies to their most valuable assets: own what differentiates you, control what you cannot afford to lose, and do not build your future on a dependency whose keys someone else holds. Sovereignty is not about where the server is. It is about who is in control when it matters.
“Your data can sit in a Frankfurt data centre and still answer to a foreign government. Residency moves the bytes; it does not move the control. Sovereignty is the difference between owning your most valuable asset and renting it from someone who can take it back.”
The three levels of sovereignty
Treat sovereignty as a ladder, not a binary, and place each workload on the rung its value demands.
Residency is the bottom rung: your data is in the EU, but a foreign provider's jurisdiction still reaches it. Operational sovereignty is the middle: the entity operating your data and AI cannot be compelled by a foreign government, typically a European provider, or a structure that legally insulates the operation. Full sovereignty is the top: you control the supply chain end to end, open-weight models you can host, data that never leaves your perimeter, compute you can point to, so there is no external party who can compel, observe, or cut off the capability.
Not every workload needs the top rung. Public, non-sensitive work can live happily lower down, and the frontier labs are extraordinary where the data is not. But your crown jewels, personal data, proprietary IP, the decisions that define the business, belong at the top, on infrastructure you control. The mistake is treating a residency promise as if it bought you the whole ladder.
What sovereignty actually requires
Four moves to turn “sovereign” from a marketing word into an architecture.
Map your data and AI workloads by what you cannot afford to lose, not by where they happen to run today. Personal data, proprietary IP, and business-defining decisions are the crown jewels; everything else is negotiable.
Put the crown jewels on infrastructure that is operationally and supply-chain sovereign: open-weight models on European or self-hosted compute, where the inference and the data never leave a perimeter you control. Use US platforms as a data and activation layer if you wish, but never as the home of the asset itself.
Then ask every “sovereign cloud” vendor the only question that settles it: can you, or your parent, be compelled by a non-EU government to access or hand over this data, yes or no? If the honest answer is yes, you have residency, not sovereignty. Architect for the honest answer, and you own your future instead of renting it.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.