Digital sovereignty: Detoxify!
In June 2026, Washington cut off global access to an AI model within days, before restoring it. What this episode reveals about the true nature of digital sovereignty, and what really needs to be audited in a data platform.
Temps de lecture estimé : X min
In eighteen months, artificial intelligence has moved from the experimental stage to the boardroom, often arriving via shadow IT before being officially adopted. And in its wake, one word has taken over tenders, marketing brochures, and public speeches: " sovereign ".
In June 2026, the temporary suspension of Anthropic's Fable 5 model outside the United States, by order of the U.S. Department of Commerce, made concrete what had seemed inconceivable six months earlier: the possibility of a "kill switch" triggered by Washington on a technological component already integrated into organizations worldwide. Access was restored a few weeks later, but the point had been made.
Yet AI has invented little in this regard. It has acted as a catalyst. The dependencies it highlights have existed for decades: American software, Chinese equipment, Taiwanese components, and extraterritorial jurisdictions.
At Ascend, we claim the word "sovereign" for our Harnest platform, even if it remains fallible.
All the more reason to give it a rigorous definition, contrary to a market that has largely stripped it of its meaning.
The false debate between provider nationality and data localization
In my discussions with CIOs, legal departments, and executives, two schools of thought emerge:
The first advocates for vendor-based sovereignty: a sovereign solution must be French or European, period.
It has the merit of simplicity and aligns with public policies on digital sovereignty. However, it hits an industrial reality: a French software vendor may build its product on infrastructure, components, and models that are not. The nationality of the logo says little about the chain of dependencies hidden behind it.
Our partner Outscale by Dassault Systèmes makes every effort to break free from its dependencies, but acknowledges that its strategy is limited to diversification; buying only European components is, to date, impossible.
The second considers that the vendor's nationality matters less than the location of the data and the jurisdiction that applies to it.
This view is more nuanced: it asks the right question—where is the data stored, and under what law? But it stops halfway. Data physically hosted in Europe can still be subject to extraterritorial laws, notably the U.S. Cloud Act.
And above all, it ignores a factor that legal and financial experts know well: economic exposure carries as much weight as legal exposure.
Both positions have merit. Both are, in my opinion, incomplete.
Three dependencies that define your level of sovereignty
In my view, an organization's sovereignty relies on a combination of three types of dependencies.
- Legal dependencies. Which jurisdictions is your company subject to, based on its locations, operating licenses, or stock market listings? The law applicable to your data goes far beyond the question of where it is stored.
- Economic dependencies. Which markets, currencies, or operating authorizations do you depend on? Take a large European bank whose data is hosted in France on French infrastructure. It conducts significant business in the United States, finances itself in dollars, and holds an American banking license. Faced with an injunction from a U.S. court, its choice would be simple: hand over the requested data or jeopardize its right to operate across the Atlantic. The location of its servers would change nothing.
- Technological dependencies. European companies operate largely using American software, Chinese equipment, and Taiwanese components. This dependency is structural. No one will break free from it in the short term.
Framed in these terms, the question changes its nature. Sovereignty ceases to be a binary attribute that you either possess or you don't. It becomes a continuum on which every organization occupies a position, and on which it can progress.
Total sovereignty is an illusion. Stagnation would be a surrender.
Acknowledging the depth of our dependencies leads some to a comfortable fatalism: since we will never be fully sovereign, what is the point? This all-or-nothing reasoning is the best ally of stagnation.
The credible strategy can be summed up in one word: detoxification. Progressive, methodical, and committed to for the long term. In practical terms, it relies on three movements:
- Stop adding new dependencies when a sovereign alternative of equivalent value exists
- Gradually prioritize the most sovereign solutions with every renewal, every call for tenders, and every new project
- Step-by-step reduction of existing exposures, starting with the most critical ones
This transition will take years, likely decades. Every technological choice then becomes a trade-off: am I reducing my dependency, or am I worsening it?
What this changes for your non-financial data
Let's apply this reasoning to a concrete case: non-financial data for European companies.
This data is among the most sensitive within an organization. It exposes supply chains, operational performance, strategic investments, and vulnerabilities.
It constitutes a governance asset in its own right, and its location is a critical issue in itself.
Let's be clear: placing this data on sovereign infrastructure will not eliminate the dependence of European banks and companies on American technology. They will remain equipped for a long time with software that falls under neither our laws nor our control.
But nothing, absolutely nothing, justifies a new data platform replicating an avoidable dependency. For the systems we are building today, a sovereign alternative exists. Choosing it is simply a matter of consistency.
For executive management, legal departments, and boards of directors, this translates into four questions to ask any non-financial data platform:
- Where is the data hosted and processed?
- Which jurisdictions does it fall under, directly or through extraterritoriality?
- Which providers are involved in the technology stack?
- What are the legal risks associated with all these dependencies?
Sovereignty is thus becoming a component of data governance. It is a purchasing criterion, an audit criterion, and a risk management criterion.
This is the choice we made when designing Harnest as a sovereign non-financial ERP: hosted, operated, and governed in Europe, with complete traceability of the processing chain.
A trajectory, not a label
The debate over IT and data sovereignty will not be settled by a flag on a logo or a datacenter address. It will be settled by each organization's ability to map its dependencies, prioritize them, and reduce them, decision by decision.
Sovereignty is not a state that you proclaim.
It is a trajectory that you steer.
