← Back to blog
Typographic composition of the term Sovereignty

AI Vocabulary

Sovereignty: does the word guarantee what it is made to say?

Digital sovereignty means the ability to control one's data and the infrastructure that processes it, without depending on a foreign power. Applied to a product, the word covers very different realities: hosting in Europe, a European publisher, or immunity from extraterritorial legislation. Those are three distinct things.

The three questions behind the word

Where is the data physically stored and processed? That is the simplest and the most often advertised. A data centre in a given country is a verifiable fact.

Who controls the company operating that centre? A European subsidiary of a non-European group hosts in Europe and remains subject, through its parent, to other obligations.

Which law applies to the company and its officers? That is the most important question and the least addressed, because the answer depends not on geography but on legal attachment.

Why hosting is not enough

Certain legislation allows an authority to require a company within its jurisdiction to hand over data it holds, wherever stored. The server's location is no obstacle to a demand addressed to the company itself.

This explains the appearance of more demanding arrangements, where the operator is an independent European-law entity with separate staff and governance.

Such structures exist and their exact reach is debated. A firm wanting a firm position on this point must examine the legal attachment of every link in the chain, not only of the provider it contracts with.

The particular case of models

One point is rarely raised and it is decisive: even with European hosting and a European publisher, the model called may be developed and operated elsewhere.

The question must therefore be put at the level where it arises: which model is called, by whom is it operated, and under which jurisdiction? An answer covering hosting alone leaves the question entire.

What the word does not cover, and is credited with

Three expectations are commonly attached to it in error.

That it guarantees confidentiality: a sovereign arrangement applies the same access rules as any other, and its operating staff have the same technical access.

That it excludes any demand from an authority: it shifts the question towards national and European authorities, which also have powers of compulsion.

That it implies compliance with data protection law: those are two distinct subjects, and a non-compliant sovereign arrangement is entirely possible.

What it does not solve

Sovereignty says nothing about security. A poorly administered sovereign arrangement is less safe than a well-run foreign one, and observed incidents stem far more often from configuration errors than from demands by authorities.

It says nothing either about professional secrecy inside the firm: barriers between teams arise identically whatever the provider's nationality.

And it has a cost, in price and in features, to be weighed against the risk actually covered.

Why it matters to a lawyer

Because it is a powerful commercial argument, often aimed at the most cautious organisations, and it covers very unequal levels of commitment.

The three questions above are enough to settle it, and they take a minute. A provider answering all three is describing a position; one answering the first while believing it has answered all three has not understood the question.

← Back to blog