Why the geographical choice of a cloud is no longer a sovereign strategy with AI (1/2)

Partager
Why the geographical choice of a cloud is no longer a sovereign strategy with AI (1/2)
10 experts in storage, safeguarding and law analyze the notion of data sovereignty. Leaders of the companies Cerabyte, euroNAS, Hill Dickinson, Keepit, Leil Storage, Nodeum, Scality, Tiger Technology, Veeam and WEKA

The challenge of data sovereignty is no longer limited to the question of where it is stored. With AI, companies must now know who controls them. 10 responsible for storage, safeguarding and law dissect the concept of digital sovereignty in terms of security. Decisive opinions that are necessary in the general debate.

10 experts from 3 data-related sectors, bringing together CEOs, technical directors, IT security managers and a business lawyer, provide their analysis on data sovereignty and its future evolution. Despite some differences, all agree on one point: sovereignty is no longer determined by geography. It now depends on operational control, legal jurisdiction and architectural independence.

 The residence trap

"It is dangerous to believe that the choice of a cloud region is enough to guarantee sovereignty," warns Aleksander Ragel, co-founder of Leil Storage. This warning, shared by the other stakeholders, confirms that organizations confuse data residence and data sovereignty, two concepts that actually designate fundamentally different realities.

"Residence is a matter of geography, while sovereignty concerns the laws that apply to your data," says Paul Speciale, marketing director at Scality.

Alexander Lefterov, founder and technical director of Tiger Technology, explains why this distinction is important. "Under the U.S. Cloud Act, U.S. authorities may force suppliers owned by U.S. entities to provide them with data stored in Frankfurt or Dublin without informing you. Sovereignty is about infrastructure control, not the physical location of servers. "

Sovereign data is often hosted in Frankfurt, London or in the "EU-West" cloud region

According to Edwin Weijdema, technical director and head of cybersecurity at Veeam, this misconception goes beyond simple physical location. "Many equate sovereignty to the residency of data, assuming that storing data in a specific country or region automatically guarantees compliance and control. In practice, residence is necessary but not sufficient. Sovereignty also depends on jurisdictional exposure, access and key management, operational control, as well as the ability to demonstrate end-to-end governance. "

For Kim Larsen, CISO at Keepit, "sovereignty cannot be resolved by building a new Microsoft, that is, by replacing one hyperscaler with another. That would be missing the essentials. Sovereignty is not a question of scale, but of control. "

"The question is no longer where my data is stored, but who can access it, who can influence it, what infrastructure it depends on, and how to preserve it independently in the event of a disruption," confirms Martin Kunze, founder and marketing director of Cerabyte.

In short, the message is clear. Data sovereignty is no longer a geographic-based purchasing decision. It became an architectural discipline articulated around control, independence and responsibility.

 Regulation redefines sovereignty

If operational control defines sovereignty within an organization, the external context is also changing. The era of a unique global approach to data governance is now giving way to an increasingly fragmented regulatory landscape.

"The EU has the GDPR and the Data Act in the making, China has its data security law, India has the DPDP law, and the United States has an increasingly fragmented landscape of privacy laws, both at the state and federal level," says Aleksander Ragel at Leil Storage. These regulations do not converge, they diverge, and each major trade tension accelerates this divergence. "

Kim Larsen of the company Keepit, abounds in this sense: "the emergence of data blocks, under the impetus of regulations such as the European Data Act, will profoundly reshape data flows. Organizations will face stricter constraints on where data is stored and how data flows across borders. "

Paul Speciale, at Scality, describes this evolution as an abandonment of global circulation without data restriction. “The old discourse on the free movement of data in vogue in the 2010s is replaced by a circulation with consents, contracts and conditions at each border. This means that organizations operating globally can no longer assume that a single cloud architecture is enough for the entire world. They will have to design architectures that promote regional autonomy while ensuring global governance, with several data plans, each in accordance with its local regime, unified by metadata and policies rather than replication. "

Digital sovereignty, an evolving concept

"Organizations should no longer consider sovereignty as a one-off exercise in compliance," insists Edwin Weijdema at Veeam. "Since regulation and the geopolitical context continue to evolve, organizations must consider sovereignty as a permanent discipline. Strategies must therefore be continuously reviewed and adapted to remain effective.”

 Tvrtko Fritz, CEO of euroNAS, highlights the dimension of the national interest. "Governments may introduce additional regulations governing where certain categories of data, intellectual property and critical commercial information may be stored, processed and accessed." He therefore advises organizations to "prepare for a future where digital sovereignty will be an integral part of IT strategy".

 Valery Guilleaume, CEO of Nodeum, suggests for his part "strict compliance with regional regulations governing storage, transfer and access to data". Therefore, if the regulation explains why sovereignty is changing, the court explains why the simple local storage of data is no longer sufficient.

 Why jurisdiction takes precedence over geography

The experts interviewed regret that "companies focus primarily on the place where data is stored, at the expense of the legal systems that govern their access.

As Aleksander Ragel explains, "legal jurisdiction will become more important in the future, a dimension that most companies still underestimate". "A petabyte of data stored in Frankfurt is of little importance if the parent company of the storage platform can be forced by a US federal court to hand over this data, regardless of its physical location. The Cloud Act has clearly established this, and we have not yet seen all the implications of this law materialize during its application."

Another major legal challenge could put these issues back in the spotlight. "We are probably heading towards a new "Schrems" moment, which will bring the question of American access laws back to the fore," says Kim Larsen, CSI at Keepit. "Even if the data is in Europe, it may be subject to a foreign jurisdiction depending on the provider. Organizations should therefore react by reducing their dependence on suppliers subject to conflicting laws, and by designing architectures where control, access and encryption remain firmly in their hands. "

 Paul Haswell, a partner at Hill Dickinson, believes that organizations should consider localization and jurisdiction as inseparable. "The place of data storage and the people who can access it cannot be dissociated; these two questions go hand in hand. Organizations will need easy and secure access to their data, and this access could depend on ensuring that the data is located and protected in their own jurisdiction. "

Organizations should therefore extend this reflection to the procurement process itself. "The location is visible on a map. While the legal scope remains invisible. And a foreign authority can constrain your supplier without informing you."

It therefore becomes important to consider the jurisdictional imprint of the supplier as a purchase criterion, and not as a reflection after the fact: "the place of registration of the parent company is just as important as the place where the data center is located. "

These reflections thus emphasize a change in the way sovereignty should be assessed. The location of the data remains important, but it is no longer sufficient on its own. Organizations must increasingly take into account the place where their data reside, but also who ultimately holds the legal authority to access it.

The challenge of sovereign AI

Experts are unanimous: the traditional notion of data sovereignty is outdated. The choice of where the data is stored remains important, but it is no longer enough. From now on, organizations will have to demonstrate who controls their data, who can access it, what legal frameworks apply and whether their infrastructure can operate independently of external jurisdictions.

In other words, sovereignty becomes an architectural choice rather than a supply process. It influences the way organizations design their storage platforms, manage their encryption keys, address resilience, and evaluate their technology providers.

This development should redefine procurement discussions in the coming months and years, as organizations transcend the geographic dimension to focus on operational independence, legal certainty and demonstrable control.

The next challenge for organizations will be to determine how these same principles apply to AI. Because if organizations are expected to retain sovereignty over their data, what happens when AI models are trained from them?

Shimon Ben-David, technical director at WEKA, summarizes: "Sovereign AI is often misinterpreted as an obligation to remove all AI workloads from the cloud and run everything on site. Because the future is hybrid. "

Continued in the second part of the article where experts examine why AI is becoming the next frontier in data sovereignty, and why organizations that quickly meet these challenges will be able to benefit from it beyond compliance.

Lire la suite

Face à la tempête cyber : Comment le CCB arme la Belgique contre les menaces étatiques et la cybercriminalité organisée

Face à la tempête cyber : Comment le CCB arme la Belgique contre les menaces étatiques et la cybercriminalité organisée

Menaces étatiques, professionnalisation de la cybercriminalité « as-a-service », essor de l'intelligence artificielle : le paysage de la sécurité numérique subit des mutations profondes. Au cœur de cet écosystème en proie à des enjeux géopolitiques et criminels majeurs, le Centre pour la Cybersécurité Belgique centralise les compétences techniques et

Par Boris Jancen