Sovereignty is becoming a strategic management task

Why organisations need to create greater control, transparency and resilience within their digital ecosystems

“Digital sovereignty is becoming a matter of strategic survival”

In this interview, Timon Schmotz from Materna explains how geopolitical uncertainties, strict regulation and the desire for technological independence are setting new standards for cloud architectures, the use of AI and security strategies. He highlights where the biggest blind spots lie today – from opaque service chains to proprietary lock-ins – and explains why true sovereignty can only be achieved through clear control over data, operational structures and processes. 

Many companies increasingly view digital sovereignty as a business-critical attribute. In your view, what is the most important driver: geopolitical uncertainties, regulatory pressure or the desire for greater technological autonomy?
From our work with clients, we see that all three drivers reinforce one another. In the public sector, regulatory pressure is undoubtedly the dominant factor, as requirements relating to data protection, data localisation, IT security and compliance must be strictly adhered to. At the same time, geopolitical uncertainties act as a catalyst, as extraterritorial laws or political tensions can suddenly turn dependencies on global IT providers into strategic risks. In industries such as the automotive, manufacturing and finance sectors, we increasingly find that the desire for technological freedom of design takes centre stage – for example, to steer innovation in a more autonomous manner or to avoid proprietary lock-ins. Across the board, however, it is clear that digital sovereignty is now a strategic issue of resilience and future viability, not merely a technical or political one. 

 

As a first step, digital sovereignty means making existing dependencies visible. Where do you currently encounter the greatest ‘blind spots’ in IT architectures and service relationships?
The biggest blind spots arise where there is a lack of transparency regarding the origin, control and operational pathways of digital services. Many organisations do not have a complete overview of which subcontractors are involved in their service chains, which software components are actually being used, or how data flows between systems. In the public sector in particular, we frequently encounter unclear operational structures for cloud services, where responsibilities are difficult to assign. Added to this is the fact that a large proportion of existing IT landscapes are based on proprietary applications, the functioning and risks of which can only be understood to a limited extent due to a lack of source code transparency. This combination of technical complexity and a lack of insight is one of the key reasons why many organisations underestimate their level of dependency. 

 

The cloud remains the cornerstone of modern IT landscapes. In your view, how are sovereign cloud models changing the architectural and sourcing decisions of businesses and public sector organisations?
We are seeing a clear shift towards differentiated, multi-tiered cloud strategies. Rather than adopting a generic ‘cloud-first’ approach, customers now base their decisions much more on the criticality of their data when determining where and how workloads should be operated. Sensitive information or data requiring special protection is increasingly being transferred to sovereign operating models, either provided by European or German providers, or implemented in specialised hyperscaler models with EU-based operational structures. At the same time, standard public clouds retain an important role, though they are usually supplemented by additional security and control mechanisms. Multi-cloud architectures are becoming the norm, and the ability to exit is emerging as a fundamental requirement in sourcing. This is giving rise to hybrid, highly segmented architectures designed to combine regulatory security with technological innovation. 

Many providers position themselves as offering ‘sovereign’ solutions. How do you distinguish genuine characteristics of sovereignty from marketing promises, and what criteria should companies use to assess this?
The key benchmark is always actual control over data, processes and operational structures. A sovereign solution is characterised by the fact that it is clearly identifiable which jurisdiction it is subject to, which organisation is ultimately the operator, and which technical mechanisms give the customer actual control over their data. This includes ownership of key assets, transparent role and authorisation models, auditability of all operational processes, and a clear exit strategy. If, on the other hand, providers primarily cite geographical hosting locations or use sovereignty merely as a ‘marketing label’ without demonstrating these control points, it is more a matter of marketing. Companies should therefore consistently demand proof of how operator structures, responsibilities and technical controls actually function.

 

With regard to AI platforms, generative models and data rooms, entirely new dependencies are emerging. How must companies adapt their sovereignty strategy if AI becomes deeply embedded in core processes in the future?
As soon as AI becomes an integral part of value creation, the discussion on sovereignty also shifts. The actual dependencies will then arise less from infrastructure issues and more from models, training data, update mechanisms and access to specialised hardware. Companies should therefore expand their strategies to include the aspect of AI sovereignty. This involves maintaining clear control over models and data flows, ensuring transparency in training processes, exploring European or open-source models as alternatives, and establishing governance structures that regulate the management of AI risks in a traceable manner. Public authorities, in particular, are increasingly demanding AI solutions that are auditable, legally compliant and can be operated securely – even when the technology itself is highly dynamic. Those who take this perspective into account at an early stage reduce long-term dependencies and safeguard their ability to act. 

 

When you look at your clients: how can you tell whether a company genuinely wants to become more autonomous – rather than merely adopting the vocabulary of the political debate?
You can tell by the fact that the discussion translates into real action. Organisations that want to become more sovereign define responsibilities, establish governance structures, systematically classify their data and carry out risk analyses for their cloud and software supply chains. They invest in transparency regarding their architectures, strengthen their security mechanisms and establish processes that actually make it possible to switch providers. Companies, on the other hand, that merely include the term in strategic documents but neither adapt their architectures nor allocate budgets, are usually operating in a discursive rather than an operational mode. Sovereignty is therefore demonstrated not through wording, but through the consistency of technical and organisational decisions. 

What do all these developments mean for Materna? What do your clients expect from you in order to successfully build and operate robust IT ecosystems?
For Materna, this means a significant expansion of our role. We are increasingly sought after as a trusted partner who combines technological expertise, regulatory understanding and architectural foresight. Our clients expect us to support them holistically – from the development of a robust cloud and data architecture, through the implementation of governance models, to security, data management, AI strategies and open-source integration. This is not just about technical implementation, but increasingly also about empowering the organisation itself. Many clients wish to become more independent in the long term and need partners to help them build this autonomy in a structured way. This is precisely where we see our mission: to enable sovereignty not only technically, but also organisationally. 

 

If we fast-forward three years: how do you think digital sovereignty will develop? What progress do you expect – and what challenges will continue to face businesses and public authorities?
By 2029, digital sovereignty will be much more firmly established – both in procurement and regulatory requirements, and in architectural decisions. Sovereign cloud models will become more mature and functionally comprehensive, and European providers will gain in importance, even though the hyperscalers will remain leaders in many technological segments. At the same time, the need for evidence and certification will increase; stakeholders increasingly want to see how organisations actually implement sovereignty. The greatest challenge, however, will lie in the complexity of hybrid architectures. Businesses and public authorities must learn to balance regulatory compliance, the pace of innovation and economic efficiency. Those who commit to transparent and robust architectures at an early stage will have a clear long-term advantage – and this is precisely the trend we expect to see in the coming years.  

Timon Schmotz

Timon Schmotz (35) is a Business Development Manager at Materna, specialising in the public sector and KRITIS.