The idea of a completely sovereign information system is as appealing as it is challenging. In a globalized digital ecosystem, the real question is no longer about removing all dependencies.
With every technological crisis, digital sovereignty comes to the forefront. The dependence on American hyperscalers, the consequences of the acquisition of VMware by Broadcom, the rise of artificial intelligence and even geopolitical tensions remind us of the extent to which our digital infrastructures are based on largely globalized value chains. The temptation is then great to seek an entirely sovereign information system.
In search of impossible sovereignty?
Such an ambition is logically understandable. However, today it is largely out of reach, as has been the case recently recalled during a debate between experts. Processors, GPUs, operating systems or certain essential components remain dominated by a few non-European players. According to several converging estimates, an overwhelming portion of GPUs used for artificial intelligence remain produced by Nvidia today, illustrating the level of Europe’s dependence on this technological layer. This is, moreover, what was indicated a few months ago by Draghi report on the future of European competitiveness. Should we conclude that digital sovereignty is an illusion? Certainly not. But we probably need to change our perspective.
Moving away from a binary vision of sovereignty
Digital sovereignty cannot be decreed, it is built gradually. Because a sovereign organization is not one which does not depend on anyone: it is one which knows its dependencies, prioritizes them and retains the capacity to make them evolve. Rather than pitting totally sovereign infrastructures against infrastructures that are not, organizations must think in layers. Not all dependencies have the same strategic weight. Some can be reduced quickly; others will still require several years of industrial development.
This approach first requires knowing your information system precisely. Which applications are truly critical? Where is sensitive data located? Which suppliers have the main dependencies? This mapping work is now becoming a prerequisite for any credible strategy.
Some layers already offer solid European alternatives. The cloud, virtualization, OpenStack platforms or even certain collaborative suites gradually make it possible to diversify dependencies. Others remain much more complex. Semiconductors, artificial intelligence accelerators and operating systems remain, for the moment, largely dominated by a few global players.
The challenge is therefore not to eliminate all dependencies, but to prioritize them, understand them and reduce those that present the most risks for business continuity.
Reversibility becomes a principle of governance
This development also changes the way we design digital architectures. For a long time, organizations have prioritized performance or cost. From now on, the ability to regain freedom of choice becomes an equally determining criterion. The recent experience of VMware has reminded us that technological dependence can quickly become economic dependence when contractual conditions change suddenly (source: Reuters). Designing open architectures, favoring standards rather than proprietary technologies, anticipating migration scenarios and planning, from the outset, the conditions for exiting a supplier become essential principles. Reversibility no longer constitutes a simple contractual clause; it is an element of resilience.
Also note that this transformation is above all human. The technologies often already exist. What is most lacking are the skills to deploy, exploit and evolve them. Training teams, developing expertise in open technologies and supporting organizational changes are now conditions for success as important as the technological investments themselves.
From this perspective, sovereignty cannot be improvised, but is constructed using a methodical approach. Before any technological decision, organizations should carry out an audit of their digital dependencies, map their applications and critical data, then define a sovereignty trajectory adapted to their business challenges. It is only from this diagnosis that it becomes relevant to initiate technical transformations, by prioritizing the most sensitive assets and gradually organizing their evolution, within a realistic control trajectory.
Sovereignty based on trust
Ultimately, digital sovereignty is not limited to a location or the nationality of providers. It is based on the ability of organizations to maintain control of their choices over time.
This requires governance of dependencies, modular architectures, effective reversibility and a relationship of trust between organizations and their partners. This point is important. There is no universal recipe: each information system has its history, its constraints and its level of exposure.
In a context where geopolitical tensions are increasing and digital infrastructures are becoming strategic assets, sovereignty is no longer a promise of technological purity. It becomes a pragmatic approach to risk management, carried out over the long term. In reality, true sovereignty is undoubtedly not that which claims to eliminate all dependencies. It is the one that allows us to know them, to choose them when possible and never to endure them.