Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
⏱ 9 min Reading Time
61 percent of European CIOs plan to shift more workloads to local providers. With the production launch of Delos Cloud in early 2026, the EU Data Act, and Gaia-X as an interoperability framework, digital sovereignty is shifting from buzzword to concrete architectural decision. A roadmap for CIOs navigating the tension between innovation and control.
2024 was the year cloud dependence evolved from an IT concern into a strategic risk. The U.S. CLOUD Act, geopolitical tensions, and repeated legal challenges to the EU-U.S. Data Privacy Framework have accelerated the debate. What was once a compliance footnote now appears on supervisory board agendas.
The numbers tell a clear story: A Gartner study of 214 European CIOs reveals that 61% plan to shift workloads to local or regional providers. Fifty-three percent are actively planning to reduce reliance on global hyperscalers. Forty-four percent have already begun.
Behind these figures lies a tangible problem: Organizations running mission-critical IT on platforms subject to U.S. jurisdiction retain little control in a crisis – and that crisis is no longer theoretical.
61 % of European CIOs
plan, per Gartner, to shift more workloads to local or regional cloud providers – a clear signal against uncontrolled hyperscaler dependence.
In early 2026, Delos Cloud GmbH brought its second operations center online in the Leipzig region. With that, its georedundant infrastructure is fully operational for production use. Its promise: Microsoft Azure and Microsoft 365 delivered under German law, operated by security-vetted personnel, with telemetry data under BSI (Federal Office for Information Security) oversight.
“Europe’s cloud strategy must go beyond mere data localization. Real sovereignty means operational control, transparent supply chains, and the ability to switch providers.”
Gaia-X AISBL, Architecture Whitepaper 2025
Delos is a joint venture between Microsoft, SAP, and Arvato Systems. Its design aims to resolve a core dilemma: enterprises and public institutions want to harness a hyperscaler’s innovation power – without surrendering control over their data. According to Computerwoche, the premium over standard Azure ranges from 10 to 20 percent.
Critics like netzpolitik.org call this “label washing”: the underlying technology remains American; dependence on Microsoft’s product lifecycle persists; and no genuine exit scenario is built in. Sovereignty ends where Microsoft decides to deprecate a feature – or raise prices.
Those rejecting Delos must confront an uncomfortable truth: As of today, European cloud providers do not offer the full functional spectrum enterprises require for their digital infrastructure. OVHcloud, IONOS, and Open Telekom Cloud deliver solid IaaS services – but a complete ecosystem with productivity suites, AI services, and enterprise-grade integrations? That remains the exclusive domain of U.S. hyperscalers.
That’s precisely where Delos delivers strategic value – not as an end-state solution, but as a transitional model. Companies gain time to build out their multi-cloud strategy while meeting regulatory requirements today. The question isn’t “Delos or Europe?” but rather: “How quickly can European providers close the functionality gap?”
Gaia-X has had a rocky history. Launched in 2019 as a Franco-German flagship initiative for a European cloud infrastructure, it quickly became synonymous with overambitious industrial policy: too many stakeholders, too little concrete output, too much bureaucracy.
By 2026, the assessment is more nuanced. Gaia-X has shifted focus – away from building its own infrastructure, toward interoperability standards and trust frameworks. Its Gaia-X Digital Clearing Houses (GXDCH) certify cloud services against uniform criteria. Less flashy than a European “supercloud,” this approach is strategically smarter.
Because the real problem with cloud dependence isn’t infrastructure itself – it’s lock-in via proprietary APIs, data formats, and integrations. Building to Gaia-X standards lets organizations move workloads between providers without rewriting half their architecture each time. Sovereignty doesn’t emerge from owning hardware – it emerges from choice.
10-20 % premium
is what Delos Cloud costs versus standard Microsoft Azure – the price tag for German data residency and BSI-controlled telemetry.
Alongside strategic debates, the regulatory landscape is tightening. The EU Data Act, fully applicable since September 2025, obliges cloud providers to enable genuine portability. Switching charges must be transparently disclosed – and starting in 2027, they will be banned outright.
Simultaneously, NIS2 has raised cybersecurity requirements for critical infrastructure. Companies must demonstrate that their cloud service providers meet appropriate security standards. For CIOs, this means cloud provider selection is no longer just a technical decision – it’s a compliance obligation carrying personal liability for executives.
Prof. Dr. Luise Hölscher, newly appointed State Secretary at the Federal Ministry of Finance and Chair of the IT Planning Council, sent a clear signal: away from consensus-seeking among federal and state governments, toward operational implementation. The German Government Cloud is set to scale in 2026 – proving sovereign operating models work in practice.
Digital sovereignty cannot be achieved through a single migration project. It’s a continuous process demanding both strategic foresight and operational discipline. This five-step roadmap gives CIOs concrete orientation.
Step 1: Conduct data classification. Not all data carries equal sensitivity. CIOs should establish a three-tier model: public, business confidential, and regulatory critical. Only the third tier requires a sovereign cloud solution. Everything else can be distributed based on cost-benefit analysis.
Step 2: Audit lock-in across existing workloads. Where do proprietary dependencies lie? Which services rely on vendor-specific APIs with no portability? This audit forms the foundation of any exit strategy – and should be updated at least annually.
Step 3: Build a multi-cloud architecture. The target architecture deliberately distributes workloads: hyperscalers for AI services and global scale; sovereign providers for regulatory-critical data; open-source platforms like OpenStack or Kubernetes as a portability layer. Container orchestration with Kubernetes makes workloads fundamentally movable.
Step 4: Embed contractual exit clauses. The EU Data Act empowers CIOs – but enforcement lives in the contract. Maximum notice periods, defined data export formats, transition timelines, and cost transparency belong in every cloud agreement. Those who omit them today will pay dearly tomorrow.
Step 5: Implement continuous sovereignty monitoring. Regulatory requirements evolve, providers change terms, new options emerge. An annual cloud sovereignty review must become a fixed part of IT governance.
The question is no longer whether digital sovereignty matters – it already does. The question is whether CIOs will shape it proactively – or be driven reactively. Delos Cloud proves sovereign operating models are possible on hyperscaler foundations – even if they’re no silver bullet. Gaia-X provides the interoperability framework that reduces lock-in long-term. And regulatory pressure from the Data Act and NIS2 makes action non-negotiable.
CIOs who begin data classification now – and structure their multi-cloud strategy – gain a strategic edge. Those who wait until regulation forces what strategy should have delivered long ago will face costly catch-up.
The wise path lies in the middle: leverage hyperscaler innovation where it creates value; build sovereign alternatives where control is decisive; and secure contractual flexibility to hold open the options you’re planning for today – three years from now.
What exactly is Delos Cloud?
Delos Cloud is a joint venture of Microsoft, SAP, and Arvato Systems. It delivers Microsoft Azure and Microsoft 365 under German law. All customer data remains on German soil; telemetry data is overseen by the BSI (Federal Office for Information Security); and operations are conducted by security-vetted personnel adhering to German IT security standards.
How does Gaia-X differ from a standalone European cloud?
Gaia-X does not build its own cloud infrastructure. Instead, it defines interoperability standards and trust frameworks against which cloud services are certified. Its goal: make workloads portable across providers – and reduce lock-in.
Must all corporate data move to a sovereign cloud?
No. Classification is key: only regulatory-critical and highly sensitive data require a sovereign solution. Public and less-sensitive data may remain on global platforms, based on cost-benefit analysis.
What does migrating to a sovereign cloud cost?
Delos Cloud carries a 10-20% premium over standard Azure. Add migration costs, which vary depending on the complexity of your existing infrastructure. The EU Data Act caps switching charges – and bans them entirely from 2027 onward.
What role does NIS2 play in cloud strategy?
NIS2 tightens cybersecurity requirements for critical infrastructure. Companies must prove their cloud providers meet appropriate security standards. Executive leadership bears personal liability for compliance.
Control over three dimensions: where your data resides (data locality), who can access it (access sovereignty), and whether you can switch providers (portability). The EU Data Act – effective September 2025 – grants you legal levers for the first time.
As an infrastructure alternative to AWS/Azure, Gaia-X has failed. But as a framework for data sovereignty and interoperability, it delivers value: standardized labels, compliance checks, federated catalogs. Pragmatic recommendation: use Gaia-X certification as a procurement criterion – not as a platform.
Header Image Source: panumas nikhomkhai / Pexels