Nvidia Buys Hugging Face for Over 11 Billion Euros
Eva Mickler
4 min read Nvidia is acquiring Hugging Face for around 11.1 billion euros; the contract was signed on ...
Many DACH corporations are caught between demands for digital sovereignty, plant-level OT, and global cloud standards. Treating on-premises IT as merely an infrastructure issue underestimates governance, operating models, and capex management. Decision-makers need an operating model that governs both and replaces ideological platform choices.
Key Takeaways
RelatedDigital Sovereignty 2026: Delos Cloud, Gaia-X, EU Data Act / Sovereign Cloud: Europe’s Path to Digital Sovereignty
Today’s CIOs and CDOs must govern three logics at once. Corporate platforms push for standardization, economies of scale, and global release cycles. Plant and site systems demand availability, deterministic latency, and tight coupling to machines, control systems, and shift handovers. Regulatory and contractual mandates on data residency, commissioned processing, and audit trails add further constraints. Yet none of this alone dictates an architecture.
The tension arises when any one of the three logics becomes the sole guiding principle. A blanket cloud-first mandate can plunge OT-near workloads into latency, maintenance, and release bottlenecks. A blanket on-premises mandate inflates costs for standard applications and undermines patch and identity discipline. Digital sovereignty, in an IT sense, is not a political statement. It is the ability to definitively control location, processing site, operator, and exit path.
In practice, this means data classes, processing locations, and operational responsibility must be defined before platform selection. Germany’s BSI C5 criteria catalog requires cloud providers to disclose court jurisdiction, data-processing sites, and statutory disclosure obligations in their system descriptions. The C5:2026 edition further sharpens technical implementation of sovereignty and tenant separation. At the same time, GDPR Chapter V (Articles 44 ff.) regulates third-country transfers of personal data. The EU Data Act (Regulation (EU) 2023/2854), effective from September 2025, adds cloud-switching rights and safeguards against unauthorized third-country access to non-personal data held in the EU. If these determinations are made only after cloud migration, rework costs and audit risks escalate-especially where production data, HR data, and supplier interfaces coexist in the same stack.
A robust operating model begins with workload classes, not providers. At least five classes make sense: enterprise-wide SaaS and collaboration services, core systems with high integration requirements, analytical and AI workloads, edge-proximate control and sensor workloads, and regulated or location-bound processing. Each class needs criteria for latency, data classification, change frequency, operator capability, and exit costs.
Cloud is suitable where elasticity, global identities, and standardized operations processes drive value. Edge and local compute power are appropriate where production cycles, offline capability, or tight OT coupling set the pace. Hybrid means the deliberate assignment of workloads to locations and operating models. Established reference models provide guidance: the functional hierarchy per ISA-95 (IEC 62264) separates physical process, control, manufacturing execution, and enterprise systems. The ISA/IEC 62443 series adds zones and conduits-security zones with comparable protection requirements and controlled communication paths between them.
Cleanly separating workload classes prevents two typical mistakes. First, migrating critical shop-floor systems solely because the corporate standard is cloud. Second, blocking straightforward standard workloads behind sovereignty arguments that don’t hold up technically or legally. The decisive question is: which control, which location, and which operator suit this class?
Without clear roles, hybrid collapses into shadow IT and duplicated effort. Corporate IT sets architectural principles, identity and security baselines, procurement frameworks, and platform standards. Regional IT translates corporate guidelines into country-specific compliance, contract realities, and operational conditions. The plant level owns OT proximity, shift operations, local disruptions, and the interface to maintenance and production.
The interface must be formalized. Change and release rights, incident ownership, and approval paths for OT-relevant changes belong in an operating model with clear escalation routes. Identities, network zones, and logging must not be reinvented at each site. At the same time, the plant needs decision-making leeway for time-critical systems that cannot follow the corporate release cadence.
Financially, capex and opex diverge along the same roles. Corporate platforms can often be budgeted as shared services. Site-proximate infrastructure and OT coupling remain largely investment-driven and require multi-year maintenance and modernization planning. Public company examples confirm the separation of control layers: Volkswagen is building a central platform for enterprise applications with the Group Private Cloud 2.0 based on T-Systems’ T Cloud Private, emphasizing, according to CIO Hauke Stars, the combination of partnerships and in-house infrastructure-explicitly ruling out cloud-only. At the same time, Volkswagen runs production-near workloads via the Digital Production Platform with AWS. Siemens describes the convergence of IT and OT at its Bad Neustadt engine plant as a site-proximate operating case with data-driven manufacturing. Without this separation of roles and budgets, shadow budgets and competing priorities arise between plant and headquarters.
The Germany setup carries typical procurement risks. Long lead times for servers, networking hardware, and OT equipment clash with tight maintenance windows in production. Master agreements with global hyperscalers and local hosting providers run in parallel, creating inconsistencies in SLAs, audit rights, and exit clauses. Staffing shortages in OT-adjacent operational roles amplify dependency on integrators and vendor support.
Operational risks mirror the architecture. Separate identities between IT and OT expand attack surfaces and complicate forensic traceability. Unclear data residency in backup, logging, and AI pipelines leads to later corrections. Patch backlogs accumulate at edge-adjacent systems when security updates aren’t aligned with production releases. Germany’s Federal Office for Information Security (BSI), in its ICS and OT recommendations, emphasizes that OT operates longer hours, has rare maintenance windows, and demands real-time performance-making it difficult to apply standard Office-IT protection measures. The BSI’s “Principles of OT Cybersecurity” (2024) targets decision-makers and calls for end-to-end control from planning to operations. ISA/IEC 62443 provides concrete baselines for segmentation and patch management in industrial automation and control systems through zones, conduits, and Technical Report 62443-2-3. The BSI’s IT-Grundschutz module IND.1 complements this with requirements for process control and automation technology.
Sourcing must therefore follow architecture, not the other way around. Multi-cloud driven solely by negotiation reflex inflates operating costs and governance complexity when workload classes and data flows aren’t predefined. Local colocation or sovereign hosting options only help if operational processes, key management, and recovery procedures are tested and budgeted. The CIO owns residual risks and exit readiness.
A practical decision tree starts with data and process classification. First, decision-makers must determine whether the workload processes personal, sensitive, or production-critical data and which residency and audit obligations apply. Next comes latency and availability: is a regional cloud zone sufficient? Is proximity to the plant or offline capability required? Then consider change frequency and integration density with MES (Manufacturing Execution System), SCADA (Supervisory Control and Data Acquisition), ERP, and identity services.
Only then does the location and operator decision follow. SaaS is permissible if data classification, contract terms, and exit provisions align. Private or virtual private cloud suits integrated core systems with stringent control demands. Edge and on-premises instances serve OT coupling, strict latency limits, or site-bound approvals. Hybrid emerges when local preprocessing and centralized analytics or training run in tandem with standardized interfaces.
The tree culminates in operational evidence. Who operates, who patches, who escalates, and how recovery is achieved within what timeframe must be answered before go-live. ISO 22301 on Business Continuity Management defines key metrics: RTO (Recovery Time Objective-the maximum tolerable downtime) and RPO (Recovery Point Objective-the maximum tolerable data loss). Without this proof, the architecture remains incomplete, even if the target platform is formally approved.
For CIOs and CDOs, the takeaway is clear: site IT becomes a control object defined by workload classes, role models, and decision trees. Cloud remains a tool. Sovereignty remains control. OT remains operational reality. Those who align these three layers in the operating model cut capex misallocation and build robust hybrid decisions for the Germany mode.
Data classes, processing locations, and operational responsibilities must be defined before platform selection. C5:2026 requires transparency regarding jurisdiction, data locations, and client separation. Chapter V of the GDPR governs third-country transfers, while the EU Data Act, effective since September 2025, introduces switching rights and protection against unauthorized third-country access. Retroactive corrections drive rework costs and audit risks once production, personnel, and supplier data reside in the same stack.
Extended lead times for servers, networking, and OT hardware clash with tight maintenance windows in production. Concurrent framework agreements with hyperscalers and local hosts create inconsistencies in SLAs, audit rights, and exit clauses. Staff shortages in OT-adjacent operational roles amplify dependency on integrators and vendor support. Sourcing follows architecture once workload classes and data flows are segmented.
Change and release rights, incident ownership, and approval paths for OT-relevant modifications belong in an operating model with clear escalation paths. Identities, network zones, and logging remain standardized across the enterprise. At the same time, the plant retains decision-making authority for time-critical systems outside the corporate release cadence. Capex and opex follow the same role logic, separating shared corporate services from investment-driven site infrastructure.
When operational evidence is missing before go-live. Who operates, who patches, who escalates, and how recovery is achieved must be answered definitively. ISO 22301 defines RTO as the maximum tolerable downtime and RPO as the maximum tolerable data loss. Without these targets and clear ownership paths, the architecture remains incomplete.
Read more on Digital Chiefs
Digital ChiefsToken-OPEX: Inference Controls, Not the Seat BudgetDigital ChiefsHardware Outperforms Software Deals – Rethinking Capital Expenditure PrioritiesDigital ChiefsThe Bill for Ten Years of Island SolutionsMore from the MBF Media Network
Image source: AI-generated (July 2026)