21.05.2026

7 Min. Read Time

One of the most-watched AI startups currently is building on a Chinese open-weight model. A German state administration saves more than €15 million annually by switching to open software. What connects both examples: Sovereignty doesn’t come from possession, but from control.

Key Takeaways

  • Sovereignty lies above the model: Data strategy, evaluation, integrations, and operations decide more than ownership of a base model.
  • Open source is not an exception: Linux, Kubernetes, Python, PyTorch, and TensorFlow make up large parts of the digital infrastructure.
  • Leadership must come closer to engineering: Those who only buy AI remain dependent. Those who understand it can consciously choose providers, layers, and operating models.

Related:Raw Materials Policy Becomes Tech Policy  /  Sovereignty Beats Price

The EU Package Creates Capacity, Sovereignty Emerges Elsewhere

On June 3, 2026, the EU Commission presented its European Tech Sovereignty Package: a Chips Act 2.0, a Cloud and AI Development Act, and its own open-source strategy. Billions for semiconductors, data centers, cloud, and open software to reduce Europe’s dependence on providers outside the Union, which, according to the Commission, exceeds 80 percent for key digital products and infrastructures. This is an important first step.

But anyone who takes sovereignty seriously must not view the package as pure purchasing policy. Money buys capacity, not control. It’s not enough to give a workforce new tools. They must learn to build added value, security, and control. That’s where it will be decided whether Europe only buys AI or truly masters it.

Those who only buy hardware create capacity. Those who train people create sovereignty. Those who build on open source create true independence.

Europe’s AI Debate is Focused on the Wrong Question

What is digital sovereignty in AI? Digital sovereignty in AI means being able to consciously control or delegate central layers of the AI stack: data, inference, post-training, evaluation, compliance, and operations. Sovereignty is not about owning everything, but about being able to control switching paths, risks, and value creation.

For months, there has been a debate about open source, hyperscaler dependencies, and the next big base model. Who is leading? OpenAI, Anthropic, Google, Chinese providers, or a European initiative like Mistral? The public discussion often seems like a technological horse race: Who wins, who prevails, who dominates the market?

Alexander Hendorf

Alexander Hendorf

AI & Open-Source Strategist, Board Member of the Python Software Association, and Head of the Open Source Working Group at the German AI Association

View Profile →

Strategically, this perspective leads nowhere. The crucial question is not: Who owns the best model? But: Which parts of the AI stack can we understand, control, and further develop ourselves?

Digital sovereignty in 2026 will no longer be achieved solely through ownership. It is created through capabilities: technical understanding, operational control, data competence, reliable evaluation procedures, secure integration architectures, and the ability to translate models into concrete work processes.

Those who view the debate merely as a provider competition easily end up in a spectator role. Perhaps one provider will win in the end, so the hope goes. Perhaps one will then simply have to follow suit. Perhaps the strategic decision will take care of itself. Really?

Those who wait and see will not build their own capabilities. And those who do not build capabilities will become dependent, regardless of which model ultimately delivers the best benchmarks or which provider wins the attention race.

The Real Value Lies Above the Model

Cursor is a good example of this. The US coding startup, valued at around €28 billion according to industry reports, operates its coding agent Composer based on Kimi K2.5, a Chinese open-weight model. What matters is not that Cursor owns the foundation. The value is created in the layers above: development environment, tool integration, post-training, evaluation, and consistent alignment with the use case of software development.

If even a hyped US AI startup derives its strength from pragmatically using existing model substance and mastering it better than others, Europe can learn from this.

How concretely this leverage also carries economic weight is shown by the public sector. Schleswig-Holstein has migrated its state administration to open software. According to the state chancellery, almost 44,000 email accounts have been moved to Open-Xchange, and around 80 percent of workstations use LibreOffice. The state quantifies the savings at more than €15 million in license costs, with €9 million in one-time investments in 2026.

Two very different worlds, the same pattern: Those who master open substance create value and room for maneuver.

Open source is not just free software. It is more comparable to free research. A result is available. The added value is created by understanding, applying, further developing, and translating it into real products, processes, and decisions.

Sovereign development means having a choice

Sovereignty doesn’t mean building everything yourself. It means being able to decide which layers you control yourself and which ones you deliberately delegate.

This distinction is crucial. A company can use a proprietary model and still act sovereignly if it has its data strategy, evaluation, integrations, and operational capabilities under control. Conversely, a company can use open source and still remain dependent if it doesn’t understand the technology and only consumes the next service provider.

In my view, six layers are decisive. For each, the same question applies: do you control it yourself, delegate it consciously, or operate it in a hybrid manner?

Layer Strategic Question
Data and Data Residency
In which country and under which legal jurisdiction do data physically reside
Which data leaves the company and who is allowed to use it?
Inference
The location where the AI request is actually processed
Does the request run on a US hyperscaler, in a European cloud, locally, or in a hybrid manner?
Post-Training How do I adapt a model to my terms, processes, and quality standards?
Evaluation How do I measure whether a model really works better, safer, or more economically?
Compliance and Audit Can I trace how decisions are made and what risks exist?
Operations What do I do if a central provider fails, increases prices, or changes its strategy?

Consuming Instead of Understanding is the Real Risk

Many organizations still treat AI like classical enterprise software: they buy a tool, connect an API, and expect the added value to arise almost automatically. That’s not how AI works.

AI is not a finished product that you install and then manage. AI is a capability that organizations must build. It involves data, processes, roles, decision-making paths, governance, and culture. Above all, however, it requires a different relationship with technology: less consumption, more understanding.

Additionally, the debate is too narrowly focused on large language models. AI is more than chatbots, copilots, and text generators. Deep learning has changed protein research with AlphaFold. Other AI methods are already creating measurable value in industry, medicine, logistics, and research. Anyone who only looks at AI through the lens of generative language models underestimates its economic and scientific breadth.

The real problem is therefore not just technological, but organizational. Many companies buy tools and expect competence to be delivered along with them. However, competence does not arise through procurement. It arises through working with the technology: through experiments, errors, pilot projects, and internal teams that understand what they are doing and why it works or fails.

This is exactly where AI collides with a procurement reflex that is still geared towards classical manufacturer logic: license, SLA, complete package. Open AI stacks need different operating models. They need service partners instead of mere license providers, engineering responsibility instead of pure contract transfer, internal competence instead of complete outsourcing.

The growing distance between decision-making and engineering is particularly risky. Strategic AI decisions are often made far away from the teams that will later work with the systems. At the same time, these teams often lack the space to test, learn, and develop solutions themselves.

Long-term competitive ability does not arise in presentations, roadmaps, or executive board templates. It arises where organizations practically master technology: in data flows, interfaces, evaluation loops, security mechanisms, and work processes. Anyone who only buys AI remains a user. Anyone who understands AI becomes capable of action.

Open Source is the Standard, Not the Exception

Open source has long been the standard in many digital infrastructures. Linux runs on the vast majority of all cloud servers, including those of the large hyperscalers. Kubernetes orchestrates the cloud. Python, PyTorch, and TensorFlow are the foundation on which AI models are trained worldwide, including those of proprietary US providers.

AWS, Microsoft, and Google themselves contribute massively to open-source projects and earn a significant portion of their revenue by professionally operating open software. Open source is therefore not the exotic special path. It is the invisible foundation on which the entire industry operates.

This does not mean that every company should train its own basic model. But every company should understand which layers are differentiating for its own business. Exactly there, capabilities must be built. Everything else can be consciously bought.

Anyone who masters open technologies can reduce license costs, facilitate provider changes, and build negotiation power. Anyone who is not bound to a single manufacturer can compare prices, change infrastructure, exchange components, and develop their own extensions.

The legal structure of many open-source licenses is particularly relevant. A license like MIT is irrevocable. No one comes along in the next price negotiation and demands a surcharge for license renewal. A provider can increase its prices, change its strategy, or disappear from the market. The open code remains usable, forkable, and developable.

Of course, this does not replace professional operation. Open source does not mean: free and without responsibility. It means: accessible, shapeable, and controllable. Exactly from this arises freedom, but only for those who build the necessary skills.

Europe’s Opportunity Lies in the Value Creation of Open Models

Europe has better prerequisites than the debate often suggests. We have strong research, excellent developers, powerful communities, and a long tradition of open source. Many central open-source projects across infrastructure, data processing, and AI are now significantly driven by European developers. Their code runs in every hyperscaler stack without anyone talking about it.

Europe’s opportunity, therefore, does not solely lie in building the next big foundational model. This can be important, but it’s not the only path to sovereignty. The greater opportunity lies in seizing existing open technologies, mastering them professionally, and deploying them along a concrete value chain.

The decisive attitude is not catching up, but rather seizing.

Getting Started with Three Concrete Steps

If companies want to start tomorrow, three steps are crucial.

First: Layer check. Which of the six layers are differentiating for their own business: data, inference, post-training, evaluation, compliance, or operations? Capabilities are built there. Everything else is consciously purchased.

Second: Real pilot instead of tool procurement. An internal team needs a clearly defined use case, with their own hands and not through the next software license. A pilot where the team actually operates inference, post-training, and evaluation builds competence. Another license does not.

Third: Bringing decision-making and engineering together. Those who will operate the systems later should be involved early in the decision-making process. This shortens learning cycles, prevents misinvestments, and is the only form of governance that works in practice.

Frequently Asked Questions

Why does the debate about European AI models fall short?

The model question is only one aspect. Data strategy, evaluation, operations, integrations, and internal expertise are at least equally crucial for a company to act with sovereignty.

What role does Open Source play in digital sovereignty?

Open Source lowers entry barriers and provides choice. However, a company only becomes sovereign when it understands, operates, and consciously delegates the relevant layers.

Where should leaders start with AI sovereignty?

With a layer check, real internal pilots, and a closer connection between decision-making and engineering. Tool procurement does not replace competency development.

Read more on Digital Chiefs

Digital ChiefsSenior Tech Talent 2026: The New Interface ProfileDigital ChiefsTech Mandates on the Supervisory Board: NIS2, the EU AI Act, and the Skills GapDigital ChiefsRaw Materials Policy Becomes Tech Policy

More from the MBF Media Network

cloudmagazin
Platform Engineering is no longer just a DevEx project: business-critical infrastructure

mybusinessfuture
Process optimization without a permanent project: How medium-sized businesses stay agile

securitytoday
Adaptive MFA: Why the factory setting is not enough

Image source: AI-generated (May 2026), C2PA certificate embedded in the image

Share this article:

Also available in

More Articles

15.07.2026

Token-OPEX: Inference Controls, Not the Seat Budget

Angelika Beierlein

9 Min. read time Token costs aren’t a line item in SaaS contracts. They’re variable OPEX per workflow-and ...

Read Article
15.07.2026

Hardware Outperforms Software Deals – Rethinking Capital Expenditure Priorities

Benedikt Langer

9 Min. read time IBM reports a 7% decline in infrastructure for Q2, while distributed infrastructure ...

Read Article
13.07.2026

Sovereign AI: Responsibility Stays In-House

Eva Mickler

7 Min. Reading time Who brings an AI model into productive operation bears responsibility for its behavior, ...

Read Article
12.07.2026

Five Points Where Supply Chain Software Fails

Bernhard Liebl

6 Min. reading time Companies buy supply chain suites to combat master data chaos, media disruptions, ...

Read Article
12.07.2026

Managed Services: The Bill No One Is Footing

Angelika Beierlein

7 min read CIOs almost always compare managed services and in-house operations based solely on the nominal ...

Read Article
12.07.2026

When the factory hall and the data center become a network

Benedikt Langer

8 min read For decades, production was its own isolated world. Controls, sensors and machines ran on ...

Read Article
A magazine by Evernine Media GmbH