In times of hybrid warfare and digital industrial espionage, it is important to reduce dependence on foreign or at least non-European corporations and thus reduce corporate risk.
The internet has become a digital occupation zone.
Martin Andree, Founder of AMP Digital Ventures, Book author and Speaker at the iab Conference Day 2026 (Podcast Internetwold Austria). BDZV-Interview mit dem Medienwissenschaftler Martin Andree
This applies not only to the internet in the sense of (social) media, but also to the IT software industry as a whole.
- European companies and authorities are often dependent on a few US providers.
- Changes to terms and conditions or licensing models or measures resulting from political influence can have significant economic consequences.
- A short-term change is often hardly possible.
The examples listed below can be assigned to three categories:
- Political influence: ICC/Microsoft, CLOUD Act.
- Economic dependency: VMware/Broadcom, Oracle, SAP, or other proprietary platforms with high switching costs.
- Technological dependency: Cloud platforms (Azure, AWS, Google Cloud), office software, and collaboration services.
Click on a heading to read the details and conclusions.
Example VMware: Price increases of 500%, 1,000% or even 1,500%
The facts
- Following Broadcom’s acquisition of VMware at the end of 2023, Broadcom fundamentally changed its licensing model. This resulted in significant cost increases for numerous customers.
- In 2025, the German IT user association VOICE filed a complaint with the European Commission, citing “exorbitant price increases” and an exploitation of the dependency of many customers. CP
- The European cloud association CISPE reported price increases of up to 1,500% for individual cloud providers and called for intervention by the EU Commission. NetworkWorld
- There are documented individual cases in which companies reported cost increases of more than tenfold. Cloudmagazin
- The European Commission is currently investigating complaints from industry associations against Broadcom. These associations accuse the company of abusing its dominant market position following the VMware acquisition. Parallel to this, further competition law disputes are ongoing between Broadcom and the EU. Reuters
Conclusion
This is an example of Europe’s digital dependence on US technology companies.
The crucial point is the so-called vendor lock-in.
Many companies have been running their entire server infrastructure on VMware for years or even decades. While switching to a different virtualization platform (e.g., Hyper-V, Proxmox, or Nutanix) is possible, it often means:
- Migration of hundreds or thousands of virtual machines,
- Adaptation of backup, monitoring, and automation systems,
- Training of administrators,
- and often projects lasting months.
These switching costs give VMware and Broadcom a strong negotiating position. This is precisely what the antitrust complaints in Europe relate to.
Gartner predicts that by 2028, 70 percent of enterprise VMware customers will move 50 percent of their virtual workloads to alternatives.
These are reactive, not preventive, measures.
Example: Donald Trump indirectly caused revoke of access to Microsoft 365 email accounts.
The facts
- In February 2025, Trump signed an executive order imposing sanctions on the International Criminal Court (ICC) and, in particular, on individuals involved in investigations against US citizens (especially himself) or close allies (primarily Israel). This followed the ICC’s arrest warrants for Israeli Prime Minister Benjamin Netanyahu and former Defense Minister Yoav Gallant. Wikipedia
- Chief prosecutor Karim Khan was subsequently placed on the US sanctions list. This means, among other things, that US companies are generally prohibited from providing him with services unless exceptions apply.
- According to multiple reports, Microsoft then revoked Khan’s access to his official Microsoft email account. He was forced to switch to the Swiss provider Proton Mail. This was investigated by, among others, the Associated Press. Associated Press
- The ICC has decided to implement OpenDesk – an open-source office and collaboration platform developed by the German Center for Digital Sovereignty (ZenDiS). The goal is to reduce dependence on US cloud services. The Register
- However, this does not mean that the court will completely abandon Microsoft overnight. Such migrations typically take years for an international organization with many specialized applications.
Once again these are reactive, not preventive, measures.
Conclusion
This incident demonstrates that a non-European state can indirectly influence the digital infrastructure of European institutions or companies through its legislation. If a foreign government decides to impose sanctions on, for example, entire industries (steel industry, automotive industry, energy, oil), this can affect infrastructure such as power grids, refineries, or industrial companies, as well as government organizations (ministries, parliaments) and thus governments themselves.
This doesn’t just apply to the USA, it can also apply to China.
Examples of preventive measures in the public service
Microsoft and the French Senate: During a hearing in 2025, a representative of Microsoft France stated, in response to a question, that he could not guarantee that a US company would never be required to disclose data under American law (such as the CLOUD Act) – even if the data was stored in Europe. This statement was frequently cited in the debate because it highlights the difference between data location and legal jurisdiction.
The same applies in reverse. An example is the TikTok data of American citizens, which is stored at Oracle in the USA, but TikTok naturally has unrestricted access to it. In this case, the USA is the “victim”.
France’s Health Data Hub: France initially stored sensitive health data on Microsoft Azure. After years of criticism regarding potential access caused by US law, the French government decided to migrate the platform to the French cloud provider Scaleway. The case is considered one of the most prominent examples of the attempt to put digital sovereignty into practice. Reuters
Schleswig-Holstein: The German state has decided to gradually migrate approximately 30,000 workplaces from Microsoft Office and Windows to LibreOffice, Linux, and other open-source solutions. This decision was explicitly justified on the rason of cost, transparency, and digital sovereignty. The case is being observed across Europe as a model project.
What does digital sovereignty mean in practice for an Austrian or European company?
Sovereignty means being able to switch at any time.
Sovereignty is not about using a particular technology, but about being able to make autonomous decisions and utilize alternatives.
Digital sovereignty means being able to switch at any time – because data is portable, standards remain open, and decisions are not forced by technical dependencies.
- Sovereignty means freedom of choice. Those who can switch providers, software, or platforms at any time are not permanently dependent on a single solution.
- Switching requires open standards. Data must be available in open, portable formats, interfaces must be accessible, and systems should be able to communicate with each other.
- Your own data remains the key. Digital sovereignty means retaining control over where data is stored, who can access it, and how it is used.
- Recognize and avoid dependencies. A convenient system can become a dependency in the long run if switching becomes too expensive, technically impossible, or organizationally too difficult.
- Sovereignty is also a question of the distribution of power. If users, companies, or states have no realistic alternative to a provider, they lose their room for maneuver.
- A good digital system binds users not through captivity, but through quality. People stay because the service is compelling, not because switching is made practically impossible.
Sovereignty requires a mix and does not mean isolation.
Digital sovereignty is often mistakenly equated with independence in the sense of “doing everything yourself” or isolation.
Digital sovereignty does not mean isolation, but the ability to act openly and networked – with a balanced mix of your own skills, trustworthy partners and interchangeable technologies.
- Sovereignty arises from diversity, not isolation. A sovereign system utilizes different providers, technologies, and partners to remain flexible and adaptable.
- A mix of solutions creates resilience. Those who are not dependent on a single technology or provider can respond better to changes, failures, or new requirements.
- Openness is an integral part of sovereignty. Exchange, cooperation, and international standards are necessary for digital systems to remain efficient and innovative.
- It’s not about developing everything in-house. Sovereignty means consciously deciding what you need to control yourself and where collaboration makes sense.
- Dependencies can be managed. Complete independence is hardly realistic in a networked world. The crucial factor is understanding critical dependencies and having alternatives.
- Sovereignty requires connectivity. A digital system that functions only in isolation loses value. True sovereignty lies in being able to interact with others without losing control over one’s own interests.
Sovereignty is a purchasing decision
Digital sovereignty doesn’t begin in operations, but rather with procurement. Every purchasing decision influences how freely an organization can operate tomorrow. Those who prioritize open standards, data portability, and fair switching options invest in long-term flexibility.
- Every procurement decision shapes future options. Whoever purchases a solution today also determines how easy it will be to switch tomorrow.
- Criteria such as openness, data sovereignty, and interoperability must be part of the selection process. It’s not just price, functionality, and ease of use that matter, but also long-term independence.
- Lock-in effects often arise from purchasing decisions. Proprietary formats, closed interfaces, or data that is difficult to transfer can make switching difficult later on.
- Sovereignty is either bought along with the product or bought away. A seemingly inexpensive solution can become costly in the long run if it creates dependencies.
- Strategic procurement creates choices. Those who prioritize open standards, portability, and transparent contract terms early on maintain flexibility.
- Sovereignty doesn’t mean always choosing the supposedly most independent solution. The crucial factor is to consciously weigh the options: Which dependencies are acceptable? Where do we need control? Where can we purchase with confidence?
This is how I can help you
I will guide you from the initial analysis and strategic decision-making to the implementation of the projects to reach digital sovereignity.
My plan includes the following steps: Click on each step for more details.
Define vision, goals and requirements
- What does “digital sovereignty” mean specifically for the organization?
- Which data, applications, infrastructures, and processes require particular protection?
- Which dependencies should be reduced?
- What requirements exist regarding data protection, security, availability, and location?
Inventory of the current system landscape.
- Applications and IT infrastructure
- Cloud/on-premises deployment
- Data and data flows
- Suppliers and service providers
- Technologies and standards used
- Contracts, licenses, and terms
- Interfaces and dependencies
Analyze dependencies and lock-in risks.
- Vendor dependencies
- Proprietary data formats
- Proprietary interfaces/APIs
- Lack of alternative providers
- Cloud/hyperscaler dependencies
- Knowledge dependencies
- Switching or migration effort
Classify and prioritize risks
- Criticality of systems and data
- Failure risks or operational risks
- Security risks
- Data protection risks
- Geopolitical and legal risks
- Supplier and supply chain risks
- Lock-in risks
- Dependence on specific technologies or individuals
Assess the degree of sovereignty
- How dependent are we?
- How critical is this dependency?
- How well can we reduce it?
This allows us to create a kind of sovereignty heatmap.
Develop target architecture and target vision
- Which technologies and platforms should be used in the future?
- Where is cloud computing the right approach, and where is on-premises the better option?
- Which open standards should be used?
- Which data needs to be portable?
- Which interfaces need to be open or standardized?
- Which systems should be consolidated or replaced?
Develop strategy and courses of action
- Continue operating your existing solution
- Switching providers
- Open-source solution
- European/German/Austrian alternative
- In-house operation
- Multi-cloud
- Hybrid cloud
- Building your own expertise
Digital sovereignty does not automatically mean “open source” or “on-premises”. What matters is how dependent one is and how well one can maintain one’s ability to act..
Evaluate cost-effectiveness and effort
- Investment costs
- Operating costs
- Migration costs
- Personnel costs
- Training requirements
- Switching costs
- Long-term total cost of ownership
- Cost-benefit ratio to achieved sovereignty gains
Supplier/provider selection
Besides price and functionality, I would explicitly evaluate:
- Exit Strategy
- Data Portability
- Open Standards
- Interoperability
- Contract Terms
- Subcontractors
- Data Processing Location
- Legal Access Rights
- Provider’s Financial Stability
- Support and Expertise
- Switching Options to Other Providers
Securing contracts and exit strategies
This point is often underestimated when it comes to digital sovereignty.
For critical systems, the following should be clarified before procurement:
- Could we easily switch providers?
- How do we exit the solution?
- In what format will we receive our data back?
- Which data will be deleted and when?
- How long does a migration take?
- What are the costs associated with exiting?
- What support must the provider offer?
Create a roadmap and prioritize
Don’t tackle everything at the same time.
- Priority 1: Critical systems with high dependency
- Priority 2: High lock-in, medium criticality systems
- Priority 3: Long-term optimization
Implement projects and carry out migration
- Pilot project
- Proof of concept
- Migration
- Testing
- Operational handover
- Documentation
- Training
Establish governance and responsibilities
- Who is responsible for digital sovereignty?
- Who evaluates new technologies?
- Who approves new providers/cloud services?
- What architectural principles apply?
- What minimum requirements must procurements meet?
Continuous monitoring and regular reassessment
Digital sovereignty is not a one-off project. Providers, technologies, laws, and geopolitical frameworks are constantly changing.
Therefore, check regularly:
- Has our dependency changed?
- Have new lock-ins emerged?
- Are there better alternatives?
- Are our exit strategies still realistic?
- Have any contracts or providers changed?
Act preventively now, instead of reactively limiting harm !!!
Contact me!
