Actico_Element_16-9_Verauf eb-mb-rb_300

07.09.2026|

Digital Sovereignty: Why the Freedom to Change Course Is a Strategic Priority 

  • Blog
Technology decisions now involve a broader set of considerations. Performance, innovation, scalability and cost still matter. But legal, regulatory and geopolitical factors are becoming increasingly relevant to cloud and AI strategies.

For regulated financial institutions, this adds another dimension: understanding how critical business processes depend on the technologies behind them — and preserving the ability to act as conditions evolve. That makes digital sovereignty a management priority. 

The issue is not technology. It is dependency.

Cloud and AI operate within global technology ecosystems. Using them inevitably creates dependencies on providers, platforms and legal jurisdictions. None of this is new. What has changed is the weight these dependencies now carry in business decisions. 

Cloud and AI also introduce different dimensions of digital sovereignty: 

  • Cloud underpins critical business processes, creating technical and operational dependencies as well as exposure to different legal jurisdictions.  
  • AI adds another layer as it becomes more deeply embedded in business processes. Organisations may depend on specific models, providers and computing infrastructure, while transparency and availability become increasingly important considerations. 

When external factors change the equation

These dependencies become more relevant as external conditions change — whether through new regulation, geopolitical developments or decisions made by governments and technology providers. The US CLOUD Act and export controls illustrate how developments beyond an organisation’s direct control can affect the use of technology in Europe.

DORA adds a regulatory dimension. Since early 2025, financial institutions have been required to maintain documented exit strategies for ICT services supporting critical or important functions, with appropriate testing and review. The ability to prepare for a potential provider exit is therefore no longer simply a matter of good practice; it is part of the regulatory framework.

For organisations, the objective is not to eliminate every dependency. It is to know which ones matter, understand how they could affect critical business processes and preserve options where they are needed most.

What digital sovereignty looks like in practice

Data location alone does not create sovereignty. What matters is the degree of control an organisation retains. Four questions bring that into focus: 

  • Who can legally access our data?  
  • What AI models and providers do our processes depend on? 
  • Can we move applications and data without disrupting operations?  
  • Can critical processes continue if a provider, service or jurisdiction becomes unavailable?  

The real test comes when business as usual no longer applies. 

Designing for the freedom to change course

We see digital sovereignty as an architectural principle, not a binary choice between providers or technology stacks. Our approach is to preserve meaningful choice where it matters most. That can mean running cloud services on European infrastructure or designing AI capabilities so organisations are not locked into a single AI provider. 

We think of this as Sovereignty Architecture: making critical dependencies visible, preserving options and building flexibility into the architecture from the outset. Digital sovereignty is not about eliminating dependency. It is about deciding which dependencies to accept — and making sure those decisions remain yours. 

ACTICO CEO Hans-Jürgen Rieder

“Digital sovereignty is not an end in itself. It enables companies to capture the efficiency gains of digitalisation while preserving their ability to act independently as geopolitical, regulatory or technological conditions evolve.”

Hans Jürgen Rieder, CEO ACTICO