Data wasn’t leaked from a sovereign cloud. It leaked from a third-party vendor.
That single detail from the summer of 2026 cuts straight through the marketing noise surrounding digital independence. You can construct ultra-secure data centers on domestic soil, but sovereignty inevitably ends where the external supply chain begins. In Episode 14, Sarah and I examine the fractures across the European tech ecosystem: from Schwarz Digits selling XM Cyber’s intellectual property to Texas, to a bumpy week in Neckarsulm, the European Commission’s new SEAL benchmark, and the €30 billion race for AI Gigafactories.
The Landlord Model: When Schwarz Digits Bets on US Security
In mid-July, the European cloud sector saw a major shift: CrowdStrike signed a binding agreement to acquire the intellectual property—including over 45 patents and core source code—of XM Cyber. This was the cybersecurity firm acquired by the Schwarz Group in 2021 for roughly $700 million to serve as the defensive backbone of STACKIT.
The deal structure is revealing: customer contracts and operational revenue stay with Schwarz, while the underlying intellectual property moves to Texas. In return, CrowdStrike’s Falcon platform lands natively on STACKIT racks with telemetry processed inside Europe, joined by a similar deployment from Zscaler.
From a CFO perspective, the logic holds up: proprietary security research at that depth is brutally capital-intensive, the market leader scales better, and local server racks get filled. Yet from a pure sovereignty perspective, it redefines the mission. Schwarz is pivoting away from the ideal of „we build the entire stack“ toward the posture of an enterprise landlord: we own the real estate and the concrete; the interior furnishings are leased.
The fact that this deal coincided with Lidl notifying online shop customers about a data incident at an external IT provider, alongside an operational hiccup at STACKIT, highlights the vulnerability of the landlord posture: the foundation is local, but the entities walking the corridors introduce external exposure.
Europe Builds a Ruler: Measuring Sovereignty with SEAL
Until recently, „sovereign cloud“ was largely an unverified marketing claim. With the European Commission’s Cloud Sovereignty Framework, procurement teams now have an objective measuring stick:
- 8 core dimensions, evaluating legal jurisdiction, operational autonomy, and strategic control.
- Heavy supply chain weighting: The supply chain criteria carries the single largest weight at 20 percent.
- The SEAL Scale: Sovereignty Effectiveness Assurance Levels range from 0 to 4.
This framework directed real capital during the EU institutions‘ €180 million procurement round: STACKIT, Scaleway, and the consortium of Post Telecom, OVHcloud, and Clever Cloud all achieved SEAL-3.
Conversely, setups that merely place a local operating entity over a US hyperscaler stack capped out at SEAL-2. Corporate ownership within the EU is a prerequisite, but it is not sufficient on its own. Crucially, nobody reached SEAL-4. Level 4 mandates a verified, end-to-end European supply chain from the software layer down to the silicon. As long as every high-performance cloud stack relies on accelerators engineered in California and manufactured in Taiwan, SEAL-4 remains an unreachable standard. Sovereignty stops where semiconductor physics begins.
The Billionaire Test: Training Frontier AI in Europe
If a European enterprise or backer wants to train a proprietary large-scale foundation model strictly within European borders today, what are the actual options?
- The Academic Route: Applying for allocations through EuroHPC systems (such as JUPITER or Alice Recoque). Invaluable for public research, but you receive an compute allotment, not dedicated infrastructure you control.
- The Commercial Cloud: Providers like OVHcloud (noted as the sole European Challenger in Gartner’s Magic Quadrant for Cloud AI Infrastructure) and Scaleway offer viable platforms for inference and fine-tuning. However, provisioning tens of thousands of top-tier accelerators on a single low-latency fabric via credit card remains unavailable domestically.
- The AI Gigafactories: The EuroHPC tender launched on July 30 targets up to seven facilities across member states, backed by €10 billion in public funding and over €20 billion in anticipated private capital.
To access frontier training capacity at home, you do not simply purchase instances—you submit proposals to a public-private partnership.
The Operational Takeaway: Sovereignty as an Insurance Policy
Organizations are not adopting European cloud providers because of feature parity or lower pricing. They are purchasing operational insurance against the CLOUD Act, jurisdictional friction, and unpredictable foreign policy shifts.
For standard workloads—virtual machines, object storage, Kubernetes deployments, managed relational databases—European providers deliver stable, cost-efficient infrastructure. Roughly 70 percent of a conventional enterprise IT footprint could migrate today without operational roadblocks. The remaining 30 percent—deep SAP migrations, legacy enterprise ERP setups, and complex managed AI pipelines—presents the actual migration bottleneck.
The rational approach for IT leadership in 2026 is deliberate workload tiering: isolate regulated, sensitive datasets on SEAL-3 European infrastructure, while keeping general operational workloads where feature depth and tooling ecosystems provide the highest leverage.
Join the Discussion
If you oversee cloud architecture or procurement: has an objective sovereignty framework like SEAL influenced your vendor evaluations, or does ecosystem lock-in dictate the final choice? What remains anchored to foreign hyperscalers because a viable European alternative is still missing?
Send your migration notes and real-world experiences to: feedback@experten-system.de.
Sources & Further Reading
The Digital Omnibus & Regulation
- European Commission: Digital Omnibus Regulation proposal –
https://ec.europa.eu/commission/presscorner - Bird & Bird: Introduction to the European Commission’s Digital Omnibus Package –
https://www.twobirds.com/en/insights - White & Case: EU agrees Digital Omnibus deal to simplify AI rules (Regulation EU 2026/1744) –
https://www.whitecase.com/insight-our-thinking - Gleiss Lutz: The AI Act simplification proposal: The deadline shifts, article by article –
https://www.gleisslutz.com/de/aktuelles - Usercentrics: What the AI Act deal means for transparency and consent infrastructure (Article 50) –
https://usercentrics.com/knowledge-hub - EDRi (European Digital Rights): The Digital Omnibus is going on summer break. Your rights are not. –
https://edri.org/our-work - LYDnews: Digital Omnibus: Streit um Cookie-Einwilligung –
https://www.lydnews.com - Bitkom e.V.: Stellungnahme Digital Omnibus (GDPR) –
https://www.bitkom.org/Bitkom/Publikationen
Measuring Cloud Sovereignty & AI Gigafactories
- European Commission: Commission advances cloud sovereignty through strategic procurement (Cloud Sovereignty Framework & SEAL) –
https://digital-strategy.ec.europa.eu/en/news - European Commission (Tenders Electronic Daily): €180 million Sovereign Cloud Procurement award –
https://ted.europa.eu - EuroHPC Joint Undertaking: Launch of the AI Gigafactories call: Selection of consortia –
https://eurohpc-ju.europa.eu/participate/calls-tenders - Gartner / OVHcloud: Magic Quadrant for Cloud AI Infrastructure (July 2026) –
https://corporate.ovhcloud.com/en/newsroom
Schwarz Digits, STACKIT & XM Cyber
- CrowdStrike: CrowdStrike and Schwarz Digits expand strategic partnership –
https://www.crowdstrike.com/press-releases - Lebensmittel Zeitung: „Dämpfer für Digits“ (STACKIT-Disruption und Managementwechsel) –
https://www.lebensmittelzeitung.net/it-logistik - Borns IT- und Windows-Blog: „Verraten und verkauft?“ –
https://borncity.com/win - heise online: „Kundendaten bei Dienstleister abgeflossen: Datenschutzvorfall beim Lidl-Shop“ –
https://www.heise.de/security

Kommentar verfassen