Identity Autonomy, Sovereignty & Cross-Border Collaboration
Combined Session
Thursday, May 21, 2026 11:00—12:00
Location: A 03-04
Log in to download presentations
Thursday, May 21, 2026 11:00—12:00
Location: A 03-04
Watch the video
Why Identity and Access Management Determines Digital Autonomy
Digital sovereignty is one of the most frequently used - and at the same time most hollowed-out - buzzwords of recent years. Hardly a keynote, strategy paper, or product pitch today goes without the term. In practice, however, digital sovereignty is often reduced to location arguments, certifications, or regulatory checkboxes. “Hosted in Europe,” “GDPR compliant,” or “Trusted Cloud” are sold as proof - while the real technical and organizational dependencies remain unchanged. In Identity & Access Management (IAM) in particular, this oversimplification is not only misleading, but dangerous.
This talk puts forward an uncomfortable thesis: digital sovereignty does not begin with data centers, but with identities. And anyone who does not control their identities is not sovereign - no matter how many certificates, compliance seals, or “Trusted Cloud” labels appear on the slides.
From Sovereignty to Autonomy – A Necessary Shift in Perspective
Digital sovereignty is often understood as a state: data resides in the “right” country, contracts are properly worded, regulatory requirements are met. But this perspective ignores a decisive factor: the ability to act. That is why it is more accurate to speak of digital autonomy - the ability of an organization to control, adapt, and, if necessary, decouple its core digital functions in a self-determined way.
Autonomy does not mean autarky. No enterprise will realistically forgo hyperscalers, SaaS platforms, or external identity providers anytime soon. But autonomy does mean understanding dependencies, entering them consciously, and being able to control them. This is precisely where Identity & Access Management (IAM) becomes a strategic key technology.
IAM as the Power Center of the Digital Organization
In many organizations, IAM is still viewed as necessary infrastructure: user management, single sign-on, a few policies, compliance reports for auditors. This view is not only outdated - it is dangerous. Modern IAM systems effectively define:
- who is allowed to access what,
- under which conditions,
- via which platforms,
- with which identities (human and non-human),
- and based on which external dependencies.
IAM is therefore no longer a downstream IT topic, but the power center of the digital organization. Those who lose control over identities - through external identity providers, proprietary access models, or deeply embedded platform dependencies - lose real steering capability.
Why Digital Sovereignty Without IAM Is an Illusion
Many current “sovereignty initiatives” fail due to a fundamental conceptual error: they focus on data, not on access. But data is worthless if access to it cannot be controlled autonomously. In practice, this means:
- Cloud workloads may be operated “in Europe” while identities are entirely dependent on U.S. platforms.
- Critical business processes are technically usable only as long as an external IAM service is available.
- Switching providers becomes practically impossible because identity models, roles, and policies are locked into proprietary implementations.
Digital sovereignty that ignores such dependencies is pure wishful thinking.
Put provocatively: many contemporary IAM strategies optimize for convenience and cost - and sell the resulting loss of control as “modernization.” Digital sovereignty then becomes a marketing phrase that glosses over missing exit strategies, implicit vendor lock-ins, and non-delegable core functions. For large enterprises with critical infrastructures, global value chains, and long-term liability risks, this is a dangerous trade-off - quite apart from personal (executive) liability under laws and regulations such as NIS2.
Who This Talk Is For - and Who It Is Not
This talk is deliberately not aimed at marketing departments or buzzword evangelists. It is aimed at:
- CIOs, CISOs, and enterprise architects,
- technical leaders,
- managers who bear responsibility for digital core processes.
It will not provide easy answers or “recommend tools.” Instead, it explains why IAM is the neuralgic point of digital autonomy, which misconceptions dominate today, and which strategic guardrails organizations must establish if they take digital sovereignty seriously.
The talk explicitly addresses the management perspective. Digital sovereignty is neither an end in itself nor an ideological project. It is a risk-management issue, a business-continuity issue, and increasingly a competitive factor. Organizations that can autonomously control their IAM capabilities respond faster to market changes, regulatory requirements, and technological disruption. They retain bargaining power vis-à-vis vendors and avoid strategic dead ends. Organizations without this autonomy, by contrast, implicitly shift central steering functions outward - often without ever making that decision explicitly.
In closing, the talk makes one thing clear: digital sovereignty in IAM is not a state that can be “achieved” and then checked off. It is a continuous design process that requires technical excellence, organizational clarity, and strategic courage. Those who reduce it to marketing will lose it. Those who take it seriously must be willing to ask uncomfortable questions - about architecture, governance, and the distribution of power in the digital space.
Precisely for this reason, now is the right time to remove digital sovereignty from the buzzword corner and anchor it where it belongs: at the core of modern IAM architectures.
Watch the video
Building up from last year’s instalment, join Asia Pacific Digital Identity (APDI) Consortium’s collaborative presentation that showcases the work on cross-border use cases that not only helps builds trust cross borders but also improves user experience and solves practical operational issues that have increasingly become relevant. Starting in the hospitality sector, APDI will continue to shape a collaborative ecosystem in the Asia-Pacific and beyond including alignment and inclusion with European frameworks.
Who Should Attend: This session will present a real use-case, focus on the use of standards, interoperability and user experience. It will showcase the required balance between commercial, legal and technical in building out cross-border ecosystems with relevant content for policy makers, technologists and business audiences.