Cloud sovereignty: Why control matters more than location

Your data may be in Europe, but are you truly in control? Cloud sovereignty is changing how organizations approach resilience, risk and operational continuity.

Francisco Romero Gotor / September 21, 2026

For years, cloud strategy was driven by a clear objective: move faster. Cloud has delivered unprecedented speed, flexibility and access to innovation. Now, many organizations are asking a different question: how dependent are our most critical services on providers, technologies and operating models outside our direct control?

Geopolitical uncertainty, regulatory requirements and accelerating AI adoption are placing these dependencies under greater scrutiny. Cloud sovereignty therefore goes beyond data location. It is about retaining the ability to operate, make decisions and act when conditions change. 

 

Data residency is just the starting point

Discussions about cloud sovereignty often begin with where data is stored. Data residency matters, particularly for regulated or business-critical information, but location alone does not determine whether an organization is in control. 

Data may be stored in Europe while identity management, administrative access, encryption keys, logging and the cloud control plane remain tied to a single provider or jurisdiction. During a disruption, the immediate challenge may not be loss of data, but the inability to authenticate users, administer systems, make emergency changes or recover services quickly enough. 

This shifts the discussion from “Where is our data?” to more operational questions: 

  • Who can access and administer our critical services, identities and encryption keys? 
  • Could essential operations continue if access to a provider or control plane were restricted? 
  • Who has the authority to make emergency decisions? 
  • Have our recovery assumptions been tested in practice? 

These questions make sovereignty tangible by linking cloud architecture to continuity, governance and resilience. 

 

Cloud sovereignty is about managing dependencies

A sovereign cloud strategy does not require organizations to move away from public cloud. It requires them to make deliberate decisions about which dependencies are acceptable and which capabilities must remain under their control. 

Some dependencies are justified by the business value they provide. Others require stronger safeguards, alternative operating paths or direct organizational control. These choices should be made before a disruption exposes the consequences. 

A useful starting point is to ask: Which capabilities must remain under our control for critical operations to continue if a key cloud dependency becomes unavailable? 

The answer varies by organization and workload. The priority may be maintaining customer transactions, protecting industrial operations, delivering essential public services or preserving access to critical data and decision-making capabilities. 

Sovereignty cannot be solved with a generic architecture or provider label. It requires choices based on business criticality, acceptable risk and the consequences of losing control. 

 

Hybrid cloud is becoming an intentional operating model 

For many organizations, hybrid cloud is no longer an intermediate step on the way to public cloud. It is becoming a long-term approach to balancing innovation, control and resilience. 

Organizations want to retain the speed and innovation offered by hyperscalers while maintaining greater control over selected workloads, data flows and operational capabilities. The challenge is to do this without creating a fragmented environment that is costly and difficult to manage. 

When hybrid cloud is treated as a series of exceptions, complexity grows quickly. When it is supported by shared architecture, automation, governance and clear responsibilities, it can combine agility with greater resilience and control. 

The objective is not to make every workload portable. It is to identify where portability, alternative access paths or continuity arrangements provide meaningful business value. 

 

AI introduces a new layer of dependency

As organizations embed AI into customer service, software development, operations and decision-making, they introduce dependencies that extend beyond infrastructure and data. 

These may include models, development platforms, interfaces, identity services and governance controls. Organizations need to understand which capabilities they control and what would happen if access to a critical model, service or platform were restricted or withdrawn. 

The answer is not to slow AI adoption, but to match its speed with visibility, governance and deliberate choices about dependency. 

 

Cloud sovereignty must be proven in practice 

Policies and architecture diagrams describe readiness. Testing demonstrates it. 

Organizations can validate preparedness by mapping dependencies across critical services, testing identity recovery and emergency access, simulating disruption scenarios, validating achievable recovery objectives and clarifying decision rights. 

These exercises often expose operational and procedural dependencies that are easy to overlook: 

  • Does emergency access rely on the same service that has become unavailable? 
  • Can encryption keys still be accessed and administered? 
  • Are decision rights clear when normal approval processes cannot be followed? 
  • Do teams know which services should be restored first? 
  • Can readiness be demonstrated to auditors, regulators and customers? 
     

Sovereignty becomes meaningful when an organization can demonstrate that its critical services remain manageable and recoverable. 

 

From provider labels to evidence-based decisions

As interest in sovereign cloud grows, so does the number of services described as “sovereign”. Yet the term is used to describe very different levels of jurisdictional, technical and operational control. 

Rather than asking whether an entire provider is sovereign, organizations can make better decisions by evaluating two separate questions: 

  1. Does the service meet the sovereignty requirements of the workload Consider the required level of jurisdictional, technical and operational control.
  2. Does it provide the capabilities the business needs? Consider functionality, security, scalability, integration, operational maturity and support for innovation. 

Separating these questions avoids reducing the decision to a choice between control and capability. It also allows different sovereignty requirements to be applied to different workloads rather than expecting one provider or platform to meet every need. 

 

Turning sovereignty into an operating capability

At Vivicta, we see customers seeking to benefit from cloud and AI innovation while retaining control over the operations that matter most. The answer is rarely a single provider or technology decision. It starts with identifying critical services, making dependencies visible and determining which capabilities must remain controllable and recoverable. 

Vivicta helps customers translate sovereignty requirements into practical architectural, operational and governance decisions. This can include: 

  • defining sovereignty requirements based on critical services, risk scenarios and regulatory needs 
  • mapping dependencies across identity, access, encryption, platforms and operations 
  • testing recovery readiness and documenting the evidence 
  • designing sovereign and hybrid cloud patterns that balance control with innovation 
  • establishing clear governance, responsibilities and continuous assurance 
     

Organizations making the strongest progress are not trying to eliminate every dependency. They are making dependencies visible, assessing them deliberately and maintaining viable options if conditions change. 

A practical starting point is to identify your most critical business services and ask: What must remain under our control for these services to continue if our normal cloud operating model is disrupted? 

Let’s identify the cloud dependencies that matter most to your business and explore how to strengthen control and resilience without limiting cloud and AI innovation. 
 

Francisco Romero Gotor
Sovereign Cloud Service Owner, Vivicta

Francisco has had senior management responsibilities on value delivery to client from portfolio of applications and services across different areas of client organisation. His passion is to focus in quality, defined as fulfillment of our promises to client, and creation of business relevant excellent customer experiences from digital services.

Author

Francisco Romero Gotor

Sovereign Cloud Service Owner, Vivicta

Share on LinkedIn Share on Facebook Share on Threads