I thought I had a decent grip on my dependencies. My images are made on my own laptop, my dictation never leaves the machine, and the articles on this site are plain text files in a repository I also hold offline. That feels like control.
This morning I watched a webinar where two people put up a matrix with three questions per component. The first two got a nod from me. The third one stopped me, and when I sat down to fill it in for myself, my answer on the row that matters most was less reassuring than I expected.
Residency is not sovereignty
The speakers opened with a hearing in the French Senate on 10 June 2025. Anton Carniaux, director of public and legal affairs at Microsoft France, was asked under oath whether he could guarantee that French citizens’ data would never be handed to US authorities without French approval. His answer: “Non, je ne peux pas le garantir.”
The data was in Europe. That was never the issue. The US CLOUD Act applies to the company, not to the floor the disk is bolted to.
That is the distinction the whole session rests on. Residency answers where something sits. Sovereignty is about who controls the parts around it, and what is left of your operation when one of those parts changes hands, changes terms, or stops existing.
The speakers called sovereignty a dial rather than a switch. You are not sovereign or not sovereign. You are sovereign to a degree, and to a different degree per component. I wrote before about why the conversation on digital sovereignty stalls so often, and in hindsight this explains part of it: one side of the table is discussing a switch while the other is discussing a dial.
The matrix
Three layers against five components. The layers are data, operational and technological. The components are model provider, cloud and chips, orchestration, vector store and client systems.
Three questions per cell:
- Who owns it?
- Whose laws govern it?
- What happens if it disappears?
Anyone can answer the first two. They are usually written down in a procurement document already. The third is a different kind of question, because it does not ask for a fact but for a plan, and the answer is often that there is no plan.
My own stack, honestly filled in
I went through the rows for sparkone.nl. Not as a paper exercise, but because I wanted to know whether my sense of control would survive it.
| Component | Who owns it | What if it disappears |
|---|---|---|
| Language model (Anthropic) | US | Articles remain, working method stops |
| Image model (local, MLX) | Me, on my own hardware | Only gone if my laptop is gone |
| Hosting (Cloudflare Pages) | US | Site is static, moves in an afternoon |
| Scheduler (Cloudflare Worker) | US | Publishing becomes manual |
| Media (Cloudflare R2) | US | Images are also in the repository |
| Socials (Blotato) | US | Text is in the repository, scheduling is not |
| Code (GitHub) | Microsoft, US | Git is distributed, I hold it all locally |
| Vector store | I do not have one | Not applicable |
Two things stood out.
One row stays empty. I have no vector store, which means a framework built for company stacks leaves me with a spare component. An empty row is supposed to do that: show that you do not have something, rather than that you forgot to look.
The second one is less comfortable. On almost every row my answer to the third question is “that will be fine, it exists elsewhere too”. Except the first. If Anthropic vanished tomorrow, everything I have published stays up, and that is precisely the point: what disappears is not my work but my way of working. The output is portable, the process is not. That is a different kind of dependency from the question of where my files live, and it is the only row where I have no second option ready.
For image work it runs the other way. That happens on my own laptop, where the risk is not legal but physical. No vendor can take it away. A dead drive can.
What I take back to work
The five governance gates they showed next (see, constrain, interrupt, review, recover) are a second framework and deserve their own piece. One part belongs here, because it makes the third question concrete: a decision log per agent action, with fields for actor, input, action, result and escalation criterion.
That log is not interesting for what it contains. It is interesting because without it you cannot even answer “what if this disappears” for the work you handed off. You do not know what was done, so you do not know what you would be missing.
The escalation field in that log is where the line ends up between what the agent settles itself and what has to pass a person. Mine is not an amount but an action. I publish by hand, I let scheduling be automated, and that is written hard into my project instructions.
The caveat
The dial is an improvement, and it is also an invitation. While sovereignty was a switch, you had to explain why you left it off. Now that it is a dial, you can set it low and call that a conscious choice. Those words came up more than once in the webinar, and they are true, but they are also the exact phrasing that lets you close a trade-off you never actually made.
Liability does not move with the dependency. They illustrated that with a tribunal ruling against an airline whose chatbot invented a refund policy, which is the subject of part two. For me it translates into something smaller but not different in kind: my name sits under everything here, including the sentences a model helped write. That is not shared responsibility.
And then the uncomfortable part. This framework came out of a vendor webinar, and you can tell by where it lands. Fill in the matrix and you end up with a list of weak spots, and the logical next step is to buy something that covers them. That does not make the framework untrue, but it was designed by someone with an interest in the conclusion. The third question goes unasked precisely because the answer is uncomfortable, and a party that helps you ask it usually sells the answer too.
What I am doing
I am not turning the matrix into policy. What I am doing is adding the third question to the moment I let a new tool into my work: not just what it costs and where it runs, but what is left of my way of working when it is gone.
For the row that came out badly I have no fix, and I am not going to invent one to round the piece off neatly. What I can do is keep the distinction sharp: my output is portable and I intend to keep it that way, because everything is markdown in git and nothing is locked in a closed format. That is the half I hold. The other half is my own way of working, and for that I have no second option ready.
Frequently asked questions
Is this only relevant to large organisations?
No, but it fills in differently. An organisation uses the matrix to find contractual and legal risk. Someone working alone mostly finds habits welded to one supplier. Both are dependencies, but you repair them in different ways.
What is the difference between data residency and sovereignty?
Residency says where your data sits or is processed. Sovereignty is about who controls each component in the chain, under which legal system that happens, and whether you can keep working when something there changes. Data in Europe can still fall under foreign jurisdiction if the company providing the service is based there.
Does running locally make you sovereign?
You score higher on that component, but it moves the question rather than settling it. A model on your own laptop carries no vendor risk and does carry hardware risk. And the model itself was still trained by somebody else, on data you cannot see.
Do I need to watch the whole webinar for this?
The content starts around minute eleven; the first ten minutes are a sound check. Both frameworks were promised but had not been shared at the time of writing.
Sources
- Webinar “Sovereign AI in the enterprise: from data residency to operational control”, Freeday, 20 August 2026, with English captions — linkedin.com/events
- French Senate hearing, 10 June 2025, statement by Anton Carniaux (Microsoft France), accessed 20 August 2026 — theregister.com
- Moffatt v. Air Canada, British Columbia Civil Resolution Tribunal, accessed 20 August 2026 — bccrt.ca
- Transparency obligations under Article 50 of the AI Act, in force since 2 August 2026, accessed 20 August 2026 — digital-strategy.ec.europa.eu
- Stripe’s acquisition of OpenRouter, reported 16 August 2026, accessed 20 August 2026 — techcrunch.com
Checked on 20 August 2026. I did not watch the broadcast as video but read it: LinkedIn ships a caption file with it, and that file is the source for everything attributed to the speakers here. It is flagged as not automatically generated, yet it carries unmistakable machine errors, with company and personal names mangled throughout. I verified names separately rather than lifting them from the captions, and for the same reason I avoided direct quotes from the speakers. The hearing, the Air Canada case, the start date of Article 50 and the OpenRouter acquisition all check out. One thing does not: the speakers said the high-risk obligations take effect next year, while the Digital Omnibus package moved that deadline to 2 December 2027 and Article 50 was deliberately left out of that delay. The claim that 70 percent of models come from the United States I could not verify, since no source, methodology or definition was given, so that figure does not appear above.
