Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor with KuppingerCole Analysts.
Today, we have an episode that Alexei Balaganski has suggested to me. And first of all, then I have to introduce you.
Welcome, Alexei Balaganski. Well, thanks, Matthias, for having me again. Great to be here. Great to have you. And you wanted me to do this episode. You wanted to do this because you think of a specific conversation that many organizations, many people are just leading right now. I've just been to a tech conference two weeks ago in Munich, and that it was really a hype topic that everybody was talking about. The topic was sovereignty, EU sovereignty, infrastructure on European soil.
You think, and that's the reason why we're together here, is that this overall sovereignty conversation has gone wrong. And where do you want to start to convince me, to explain this to me? Right.
Well, you know how I like the philosophical reins, if you will. Sometimes they are amusing, sometimes we can actually come to some interesting conclusions, and I hope we will in this one as well.
So yes, digital sovereignty, technology sovereignty, AI sovereignty, cloud sovereignty, any kind of that thing is now a huge buzzword here in Europe. Although, of course, it's definitely not limited just to Europe, because it is very relevant for every country of the world. I've been listening to all those conversations as well, but I cannot stop thinking about one experience I had a few months ago when I actually traveled to San Francisco and finally visited the famous Alcatraz prison. You've probably been there as well, at least you've seen the pictures.
You can walk around and you can actually visit the solitary confinement cells, which are extremely tiny, bare, dark, and well, you are supposed to be alone there all the time. And this actually suddenly gave me this feeling that this is exactly what many people think digital sovereignty is about. That you have maximum control, you have clearly defined boundaries which are impossible to break, you have zero dependency on the outside world, and it is kind of the logical extreme of what some, I would even say quite a few people think, is exactly what Europe should be looking for now.
And to be fair, I cannot completely disagree with that, because they have their point, it does actually address jurisdiction and compliance requirements, it does solve a lot of risks, so it's not coming out of thin air, but this is actually not the kind of Europe I would want to live in the future. Because I can tell you this feels exactly as it looks when you are staying for a long time in a solitary confinement cell.
Okay, that's an interesting perspective, first of all, to think of, it feels a bit like Brexit, just as you described it, but so really isolating each other from the former colleagues that you communicated with and made business with. But let's establish the baseline. When you say digital sovereignty, what do you actually mean? Because the term seems to mean something different to everybody.
For some, it seems to be liberty? Well, technology sovereignty has actually a very simple definition, you don't have to invent anything. It is an ability to continue operating whatever you were doing before, when something that you depend on suddenly becomes unavailable. It can be anything, it can be sanctions, a war, a natural catastrophe, export controls, just your supplier suddenly disappearing, any kind of reason. If you are prepared, if you can continue operating after that event, you are sovereign. If you stop operating, you are not sovereign.
I think it should be quite clear if you say, well, Europe is not sovereign at the moment and there is a lot of work to do to fix the situation. There are sort of two reasons to consider here. First of all, warranty is not about who are you buying from. It doesn't matter if it's your friend or foe, if it's a different country or your own compatriot, if it's an entity or a company or anything else, it doesn't matter who you're buying for. What matters is what happens when you cannot buy from them anymore. So this is not a procurement question. It's hedging your risks, your supply chain risks.
And the second point to think about is that nothing is truly sovereign. No product can be declared sovereign because it has to fulfill certain architectural requirements. It has to be designed and built from scratch to be sovereign.
Otherwise, you are just hiding dependencies or you are shifting those risks to somebody else. Stay Forever But as you've described it, first of all, what I take away with me from this explanation is that many are just thinking of sovereignty as something that it actually isn't. But what you describe sounds like business continuity to me. This is not what people typically right now associate with sovereignty, but this is being able to continue working and that is business continuity. Stay Forever That is exactly my point, if you will. There is nothing glamorous in the term sovereignty.
It's just continuity engineering and preparing for the worst-case scenario. Right. So to take the next step. So now that we have defined sovereignty, also from the technical definition perspective, how sovereign is Europe then today? Can I choose sovereign platforms? Stay Forever Well, again, of course, this discussion, whenever and whoever you are having it with, will inevitably evolve into a very different direction depending on how those people define sovereignty.
But I would say, to be completely blunt, Europe is not even remotely sovereign at the moment because it has so many unresolved dependencies on external parties. We can even name some very concrete numbers. For example, despite all the efforts of pushing the European sovereign clouds, we are still largely dependent on US-based hyperscalers. They probably have like three quarters of the entire cloud market in Europe. Or even more, probably around 80% of the entire corporate software spending goes to US vendors. Or the entire digital infrastructure is probably based on hardware produced in Asia.
And I mean, even if you kind of leave the technology aspect and start thinking about more political, 80% of all of our defense procurement comes outside from the EU as well. So I would probably not call it sovereign at all. And there are some other kind of less obvious considerations. For example, energy is the obvious concern. You know how the data centers in the US are struggling with getting enough electricity to power all the AI developments.
Well, Europe just doesn't have that supply. So we just cannot grow as fast as the US AI producers, even if we wanted to. So this is kind of not sabotage. This is not incompetence. This is just what happens when you never invested enough in all this in advance. And we have to change this trend radically. The typical answer that you get when people say, okay, let's move to sovereign, whatever that means, the most common answer you hear right now is just stop depending on American and Chinese technology, buy European instead. So what is wrong with that?
Well, first of all, this is actually not a security decision. It's a procurement preference. If you are making your decisions on where do you buy your tools from on political climate or cultural differences or just personal preferences, this has nothing to do with sovereignty, security or anything else. But even if you do somehow decide to do that, it doesn't actually solve your dependency on external parties. Because again, we still do not have enough hardware producers in Europe. We still have to buy chips in Asia. We still have to rely on American made AI models.
We still have tons of open source projects, which are difficult to pinpoint to a specific country, but they're definitely not EU resident by any stretch. And of course, we still have tons of foreign investment. Quite a few companies which are based in EU on paper are still owned by American investors. How do you consider them, for example? So this is like one of the aspects. Another one, you have to remember that we are just smaller and we are much more fragmented than the US. This is like physics, geography, you cannot escape that.
We are 27 countries as opposed to a single one in the West and a single very large one in the East. And we are still struggling internally on how to reconcile all of our EU-wide developments. If you are seriously considering ditching AWS in favor of some Dutch-based provider, whose entire hardware infrastructure is smaller than a single hyperscaler region, you are not getting anything in return.
You are, in fact, losing your resilience because you just what happens if that single data center burns down? There is no second one. There is no cross-regional resilience. So you cannot just compete with those countries by being sovereign. You have to start at the end. You have to get good, really good. And then you have to make sure that you can survive without the US and China.
Okay, so I take away that you cannot yet buy these solutions. So the other answer that typically can be heard is that Europe should build its own infrastructure, its own ecosystems, its own cloud, its own AI, its own stack, even maybe its own hardware. I think you are sympathetic to that in principle, but not in practice. Does that work? This is absolutely a great idea. And this is absolutely the right kind of thinking. But you have to temper your expectations very strongly. First of all, just to give you some background, I was born in the country which doesn't exist anymore, the Soviet Union.
So I experienced it firsthand as a child. What is it? What does it mean to be technologically sovereign to an extreme? But we do have other countries having the same struggle in the more recent years. To put it plainly, it is simply impossible for multiple reasons. First of all, it takes huge amounts of investments and decades of research, throwing a lot of resources, and just getting as good as your competitors. And as soon as you stop, you are lagging behind instantly. So you have to continue that investment cycle.
Second, you cannot just rebuild the entire stack from scratch. You will be still dependent on other parts of it. Even if you replay the software layer, you're still dependent on network, hardware, chips, intellectual property, you name it. There are so many different layers in the technological stack. It goes all the way down to, well, rare metals and stuff like that, which you can only get from China, for example.
Then, of course, there is a compatibility trap. As soon as you start reinventing the wheel from scratch, you are losing all those decades of investment into being able to use existing tools. Do you reinvent those tools? Do you make sure that you spend extra effort into making your tools compatible with those? Or do you build something completely different by design?
Again, we've seen it very clearly during the Cold War era. Turns out, it doesn't really work like that. And the biggest problem for the EU now, especially in the AI area, if you will, is that you cannot just push it by applying protection laws. Because protection removes the need to compete. And the need to compete and stay competitive is the only reason to make your products better than the competitors. As soon as you are limited to only EU-based solutions, regardless in which area, you are immediately starting to get less and pay more for that.
Because there will be absolutely no reason for those manufacturers or suppliers to offer you better products for less. So if the EU will actually continue pushing for the legislative solution instead of making something competitive, nobody wins in the end. Not the enterprises will pay more for less, not the actual products, because they will be less competitive, not more. And of course, you have to understand that protection is not a favor to the protected. Everybody is losing in that scenario. Right.
In the beginning, we've started with the definition and you said sovereignty, how we consider it, or the public typically considers it, is much closer to resilience. But in the end, sovereignty and resilience are just not the same thing. You've lost the ability to fail over to another country. When your system breaks down, you're losing resilience. So the question really is, can we dig deeper into the difference between sovereignty and resilience to make sure what your point is when we continue then?
Again, you are right in emphasizing that these are two different things. Unfortunately, a lot of people think that sovereignty is the solution for resilience.
Whereas, of course, in reality, it cannot be further from truth. Again, we could talk about history and remember all those wonderful Soviet cars or the German turbines from the DDR. Those were truly sovereign solutions, but they weren't very good. But we can actually look at a very specific and way more recent example from last year in South Korea. They had a data center which was running the National Information Resources Service, basically the digital archive for the entire country.
It was extremely sovereign, not dependent on any kind of American hyperscaler run internally by the government, and it had a fire. And all the records were destroyed. And of course, there was no second data center. It was extremely sovereign, but it was very opposite of resilient. So one does not imply the other. Sovereignty without resilience is just a different form of fragility, if you will. So the biggest problem, I would say, is that a lot of vendors, especially the ones based in Europe, will just try to sell their solutions entirely on the claim of their sovereignty.
So they are based in the EU. Therefore, they are compliant, and compliance is the only thing you need.
Well, as you can see, it does not work like that. The question is, who is responsible for maintaining that resilience in the sovereign world? Should it be the customers, the vendors, the government, or a combination? I would say, first of all, we need to figure that out, share the responsibility of sovereignty, if you will. Without that, you cannot proceed. I think that that points already in the right direction. I can first of all tell you one thing that you definitely should not do. You should not wait for somebody to figure that out for them.
Because nobody will, or at least it will be way too late. Knowing the history of European bureaucracy, even if they come up with a good solution, it will be way too late for that.
So yes, you have to start today. And really, you have to architect your own sovereignty. There is no other way around it. So first of all, you have to understand what is it exactly that you are protecting. Not everything you own or operate needs the same sovereignty assurance. Some things are perfectly fine to fail, to ditch, and to replace with something else. Some are extremely critical and deserve a completely different level of resilience, protection, and even compliance. So first of all, you have to structure and classify your own problems, if you will.
Nobody can do it for you because nobody knows your problems better than you are. Then you have to decide where do you start focusing your efforts. Because again, you cannot do it in one step throughout the entire stack. You cannot replace hardware, and chips, and networks, and software, and services at the same time. You have to build your own sovereignty journey, if you will. So if it points to identity, focus on that. If it's more about cloud governance, do that. If it's all about software supply chain security, well, you know what to do.
And again, every company, every industry will probably have their own set of risks, challenges, and priorities. The third point is the same point we are making in almost every paper and podcast like this one. Stop trusting labels. Stop trusting where there's zero trust for anything like that. You have to look for specific capabilities. You have to search for specific frameworks that kind of help you to measure the real maturity, the real effectiveness of all the solutions you are offered.
And I would say, almost like a shameless plug for our analyst colleagues, they've done a lot of publications on that. And you are very welcome to visit our website and ask questions. Even talk to our new AI assistant who will point you to the right research.
Finally, you have to understand that sovereignty depends not on convenience. Sovereignty is nothing glamorous and something nice to have. Sovereignty means a lot of work, long time planning, and enough flexibility to be able to exit halfway, to abandon some development, to switch to a different standard, to adopt a new cloud infrastructure. Agility and flexibility should be your motto. Just like we have been talking about crypto agility before, sovereignty also depends on your agility.
So if we specifically focus on data, because for a lot of companies, digital sovereignty is primarily about data security and compliance. Again, cryptography is your best friend, probably. Because if your data is protected at any stage, if it's protected, trust, interacted, and in use while being processed, then location doesn't really matter. It will become more a decision from the performance or latency or cost perspective. Because again, if we forget the actual residence regulations for a second, it doesn't really matter where your data lives physically if nobody besides you can access it.
And I know that for some companies, this is a no-go because they would still have to fulfill the residence requirements. But again, the more flexible you are in knowing what you have and how you structure your data in your operations, the easier it becomes for you to find the right balance between flexibility, cost, latency, security, and resilience. And in the end, kind of reduce independence on self-privacy. So cryptography is the enabler for the portability of your data, which directly influences your sovereignty.
One other thing we still have to keep in mind is that even if you, for example, encrypt all your data, but this encryption happens in a centralized location and somebody takes it away from you, you are just as dead as a business. So one huge interesting development that's happening now is decentralization. Decentralization of data storage, encryption, backup, and security. If you know that you probably know what a RAID array is. When you spread your data on several disks and if one of those disks fail, you still have enough data to reconstruct it.
Well, there are the same approaches at the cloud level, for example. So you can store your data in a way that's distributed across multiple clouds. Some can be an American hyperscaler, some can be resident because they have to, in Europe, and some data still can even be on-prem. But all of those are distributed cryptographically in a way that if something goes down, you still have a reconstructed copy. And in the best case scenario, you don't even lose access. So you can just continue your business as usual.
That is something a lot of companies, I think, should be looking for because there are some interesting technology solutions for very political and compliant regulations. So crypto agility, I guess, is one of the things we should continue pushing because it's not just a solution for your security. It's also a solution for your resilience and sovereignty. Right.
So if I got it right, so cryptography and distribution allows you to continue using existing infrastructure no matter where they are because you are mainly storing gibberish outside of your own country and you will decrypt it when you need it within your own boundaries, within your own legislation. So in the end, it's part of a risk-based roadmap approach plus the technologies that you just mentioned. Did I get that right?
Again, in reality, of course, it's a little bit more complicated than that. You have to consider other things as well. Zero trust, hybrid computing and cloud native and stuff. How do you move not just your data but your workloads as well? How do you extract your networking and data flows? How do you secure your access to that sensitive data? There is a lot of stuff to figure out, sure. I guess my biggest point would be you have to think in terms of, again, agility, abstraction, heterogeneity by default and making sure that you are in control of your own sovereignty.
Nobody, not even the EU government should prescribe you how to solve your sovereignty issues. If you know how to do it for yourself, only then you are truly sovereign, if you will, because nobody can tell you how to do your business. So sovereignty is a must. There is absolutely no discussion about that. My biggest complaint is that a lot of vendors are trying to sell sovereignty as a fun, glamorous way to solve your existing problems. And this is absolutely the opposite. Churchill used to say, I can only promise you blood, toil, tears and sweat.
And this is exactly what we are talking about when we are talking about sovereignty. Nobody can tell you it will be cheap or quick or even dignified. No. But you still have to do it. You have to be prepared for the worst case scenario, but you have to do it in a way that you don't end up paying more for less without a choice. So in the end, this is also, and you've mentioned that already, an individual journey for each organization, depending on what their target states towards sovereignty actually looks like.
So it's defining what you want to make sure that you embark on the right journey and start with the right, proper initial steps. So where to start with an assessment?
So again, first of all, you have to understand that nobody will do it for you. Not Europe, not the EU, not your government, definitely not a specific vendor who is trying to sell you something. It's your own challenge and nobody besides you should be in control of your sovereignty, if you will. So stop thinking European sovereignty, start thinking your own sovereignty. This is the only right way, if you will.
And yes, of course, feel free to reach out to people who know a little bit about specific technologies and benchmarks and frameworks. And I would say we and our colleagues at Kupfering and Co. do know a little bit about that, but again, never take anybody's opinion for granted. What we are telling you is not a gospel as well. You have to be in control of your own sovereignty.
We are happy to help, happy to guide you, but it's up to you to decide first of all, what should be the success measurement of your sovereignty program, and when do you want to reach it, and how much are you ready to sacrifice for that. Because again, it will be a lot of hard work for almost nothing, if nothing happens. But it will absolutely be your decision between survival or death, if something catastrophic does happen, like a war or a catastrophe, or just a sudden cut of ties between specific countries.
Again, everybody is the architect of their own livelihood, if you will. Right. So how do I get from war and catastrophe to our website? Not that easy, but for those who are members with Kupfering and Co., who have a subscription to have access to our research, I think you've mentioned that already. Our AI chatbot is the right place to ask these questions, and it will guide you through to the documents that are relevant here. But just to mention, for example, the works that Mike Small, our colleague, has made.
You, of course, have made. These are good starting points when it comes to understanding, for example, offerings of existing vendors, if you want to have that as part of the mix that you want to use towards your actual sovereignty. But the architecture, the way how to build such things, that is the more important part, I think. You've mentioned that questions are really highly welcome. This was more of an opinion piece, but actually not. So it's really a guidance towards starting on a sovereignty journey the right way.
If you have any questions, as usual, please leave your questions below this video on YouTube. We will read that, and we will get back to you, as we always do. If you have questions towards Alexei or myself or the colleagues, just drop us a note via mail. This is easy to find on our website, and we are happy to continue that discussion, because it will be a huge discussion. And this was one episode with not too much AI, which was also nice. So final words from you before we close down?
Well, the way I see it, if I left you with more questions after this episode than before, then my job is done. Now it's up to you to make the next step, to make probably the most important decision of your life, how to start your own journey towards your own sovereignty. And then we and all of our colleagues and all of the expert community we work together with are happy to support you with that.
Again, come to us with your right questions, and we will give you guidance. And then again, trust nobody, not even us.
And well, wish everybody a very sovereign success in the future. Right. So food for thought. That was what we have had today. And for me, it was also a change perspective towards sovereignty. So it's really not just changing your vendor for product, service, x, y, z. But it's really something that needs to be baked into your overall infrastructure strategy.
Thank you, Alexei, for being my guest today, for sharing your thoughts, for telling us about Alcatraz. I don't want to go there. And I'm looking forward to having you soon in another episode. And if you have questions, maybe such an episode might come faster, and then we can cover more of your individual questions.
Thank you, Alexei. Thank you.