Early-bird Discount
expires in
Register Now

Agenda

Beyond the Buzzwords: Digital Sovereignty Is Not Marketing

Beyond the Buzzwords: Digital Sovereignty Is Not Marketing

Combined Session
Thursday, May 21, 2026 11:00—11:20
Location: A 03-04
Watch the video
Log in to download presentations

Why Identity and Access Management Determines Digital Autonomy

Digital sovereignty is one of the most frequently used - and at the same time most hollowed-out - buzzwords of recent years. Hardly a keynote, strategy paper, or product pitch today goes without the term. In practice, however, digital sovereignty is often reduced to location arguments, certifications, or regulatory checkboxes. “Hosted in Europe,” “GDPR compliant,” or “Trusted Cloud” are sold as proof - while the real technical and organizational dependencies remain unchanged. In Identity & Access Management (IAM) in particular, this oversimplification is not only misleading, but dangerous.

This talk puts forward an uncomfortable thesis: digital sovereignty does not begin with data centers, but with identities. And anyone who does not control their identities is not sovereign - no matter how many certificates, compliance seals, or “Trusted Cloud” labels appear on the slides.

From Sovereignty to Autonomy – A Necessary Shift in Perspective

Digital sovereignty is often understood as a state: data resides in the “right” country, contracts are properly worded, regulatory requirements are met. But this perspective ignores a decisive factor: the ability to act. That is why it is more accurate to speak of digital autonomy - the ability of an organization to control, adapt, and, if necessary, decouple its core digital functions in a self-determined way.

Autonomy does not mean autarky. No enterprise will realistically forgo hyperscalers, SaaS platforms, or external identity providers anytime soon. But autonomy does mean understanding dependencies, entering them consciously, and being able to control them. This is precisely where Identity & Access Management (IAM) becomes a strategic key technology.

IAM as the Power Center of the Digital Organization

In many organizations, IAM is still viewed as necessary infrastructure: user management, single sign-on, a few policies, compliance reports for auditors. This view is not only outdated - it is dangerous. Modern IAM systems effectively define:

  • who is allowed to access what,
  • under which conditions,
  • via which platforms,
  • with which identities (human and non-human),
  • and based on which external dependencies.

IAM is therefore no longer a downstream IT topic, but the power center of the digital organization. Those who lose control over identities - through external identity providers, proprietary access models, or deeply embedded platform dependencies - lose real steering capability.

Why Digital Sovereignty Without IAM Is an Illusion

Many current “sovereignty initiatives” fail due to a fundamental conceptual error: they focus on data, not on access. But data is worthless if access to it cannot be controlled autonomously. In practice, this means:

  • Cloud workloads may be operated “in Europe” while identities are entirely dependent on U.S. platforms.
  • Critical business processes are technically usable only as long as an external IAM service is available.
  • Switching providers becomes practically impossible because identity models, roles, and policies are locked into proprietary implementations.

Digital sovereignty that ignores such dependencies is pure wishful thinking.

Put provocatively: many contemporary IAM strategies optimize for convenience and cost - and sell the resulting loss of control as “modernization.” Digital sovereignty then becomes a marketing phrase that glosses over missing exit strategies, implicit vendor lock-ins, and non-delegable core functions. For large enterprises with critical infrastructures, global value chains, and long-term liability risks, this is a dangerous trade-off - quite apart from personal (executive) liability under laws and regulations such as NIS2.

Who This Talk Is For - and Who It Is Not

This talk is deliberately not aimed at marketing departments or buzzword evangelists. It is aimed at:

  • CIOs, CISOs, and enterprise architects,
  • technical leaders,
  • managers who bear responsibility for digital core processes.

It will not provide easy answers or “recommend tools.” Instead, it explains why IAM is the neuralgic point of digital autonomy, which misconceptions dominate today, and which strategic guardrails organizations must establish if they take digital sovereignty seriously.

The talk explicitly addresses the management perspective. Digital sovereignty is neither an end in itself nor an ideological project. It is a risk-management issue, a business-continuity issue, and increasingly a competitive factor. Organizations that can autonomously control their IAM capabilities respond faster to market changes, regulatory requirements, and technological disruption. They retain bargaining power vis-à-vis vendors and avoid strategic dead ends. Organizations without this autonomy, by contrast, implicitly shift central steering functions outward - often without ever making that decision explicitly.

In closing, the talk makes one thing clear: digital sovereignty in IAM is not a state that can be “achieved” and then checked off. It is a continuous design process that requires technical excellence, organizational clarity, and strategic courage. Those who reduce it to marketing will lose it. Those who take it seriously must be willing to ask uncomfortable questions - about architecture, governance, and the distribution of power in the digital space.

Precisely for this reason, now is the right time to remove digital sovereignty from the buzzword corner and anchor it where it belongs: at the core of modern IAM architectures.

Elmar Eperiesi-Beck
CEO / Managing Director
Bare.ID GmbH
Elmar Eperiesi-Beck is a seasoned deep-tech entrepreneur, investor, and executive with more than 20 years of experience building, scaling, and transforming technology-driven companies. He...
Nils Zenker
Digital Identity Specialist - Customer Relations
Bare.ID GmbH
Nils is a Digital Identity Specialist at Bare.ID, working closely with enterprise and mid-market clients across regulated industries including Public Sector, Finance, Healthcare, E-Commerce,...
Almost Ready for EIC 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.