The European Sovereign Cloud Day – September 10, 2024, in Brussels

This year marked the second edition of The European Sovereign Cloud Day in Brussels. At this hybrid event, 100 in-person attendees and 350 online participants explored the current state of Cloud sovereignty. While the term "sovereign Cloud" has primarily been used as a catch-all phrase in recent years, we are now seeing the subject gain broader recognition. But is it truly a formal definition yet? No, and it is questionable whether it ever will be, as the term is likely too abstract for that.

In this article, Larik-Jan Verschuren, CTO at Fundaments, reflects on the event in Brussels and the insights he gathered regarding Cloud sovereignty.

Written by
Larik-Jan Verschuren
&
Posted on
07
-
10
-
2024
2024
Written by
Larik-Jan Verschuren
&
Posted on
07
-
10
-
2024
2024

What is Cloud sovereignty actually about?

In the discussions surrounding Cloud sovereignty, one central theme consistently emerged: protecting data in the Cloud and data processed from the Cloud. We see that several aspects of data are being examined through the lens of sovereignty principles:

Jurisdiction: The Cloud is everywhere and nowhere, so what about the legislation governing its operation? Which law applies when an incident occurs during Cloud usage? Does the provider's origin determine which laws apply, or is the location where data is stored and processed the deciding factor?

Regulation: We are all familiar with GDPR, which was imposed by Europe to protect its citizens. However, there are other laws in effect within Europe, such as the Data Act and the AI Act, which became active this summer. This new law outlines how to handle data used in training AI models.

Architecture: The chosen Cloud platform and the method of data storage are central to this and are fundamental principles when it comes to sovereignty. Ensuring data is stored securely through encryption is the current standard, but we must already look ahead. With the advent of quantum computing, breaking current encryption mechanisms will become easy, and we will need to look at solutions like data tokenization.

‍

ENISA: regulation and certification of Cloud services

In Brussels, various speakers addressed the aforementioned sovereignty principles. For instance, ENISA – the agency for certifying markets and standards – explained how they view Cloud sovereignty. The conclusion: a certification for a "sovereign Cloud" will never happen, but a working group from Spain, Portugal, and France is currently drafting a Cloud Scheme. This is intended to form the basis for a future EU Cloud Act. They expect to finalize this Cloud Scheme in 2025, though this depends on approval from all member states.

Additionally, ENISA is working on an EUCS: an EU Cybersecurity Certification Scheme designed to ensure the standardization and regulation of cyber resilience. This was adopted earlier this year and represents a milestone in certifying the digital market within the EU.

When looking at all certifications within Europe and the target domains of the Cloud, we see that a great deal of regulation applies:

‍

Developments among Cloud Providers regarding sovereign Cloud

In addition to the initiatives from the EU commissions, the day also covered market developments. How do Cloud Service Providers and Cloud Consultants view sovereignty in their service offerings?

Several providers shared their perspectives. For example, OVHcloud has positioned itself as the sovereign alternative to hyperscalers. Similar to Fundaments, they reason from a European sovereignty principle: they have structured their legal framework with entities that operate locally in every European country, combined with storage within the customer's home country. Furthermore, they adhere to the highest standards for data storage. Their service catalog offers over 100 services, presented in a menu similar to those of the major hyperscalers.

Other industry peers, such as Orange Sweden, define sovereignty through a regional lens: where data is stored, ensuring EU sovereignty by operating within European zones. This shows they approach the concept from an EU perspective rather than applying a national definition.

ITQ presented its ITQ Cloud platform, positioning the managed sovereign Cloud as an option alongside managed private or public Cloud and managed Software as a Service (SaaS) offerings. Sovereignty here translates to data regulation within the Cloud platform.

‍

Sovereignty in AI technology

Finally, during the event, NVIDIA showcased its capabilities for processing specific data within a regulated environment—in this case, the Indian government—using Retrieval Augmented Generation (RAG) AI on legal files. The result: a chatbot that makes legal documents accessible to judges, lawyers, and citizens in India's various languages. Extremely interesting. You can read more about this here: demoai.nic.in/scrag and blogs.nvidia.com/blog/what-is-sovereign-ai/

In conclusion: with all these technical developments, it is essential to maintain a balance between adopting new technology and protecting data through legislation, frameworks, and certifications. This all converges in the sovereignty of Cloud and data platforms. I am very curious to see how this balance evolves over the coming year. Regulating our data is certainly a good thing, as the ease with which we share and generate data as users demands regulation within the platforms provided, especially when it comes to business-critical data.

And speaking of data: now that the initial hype around Artificial Intelligence has subsided and organizations are thinking more deeply about how to truly deploy AI, the discussion is shifting to where data resides within an organization and how it is protected. To effectively implement AI, having a grip on data from all systems and (Cloud) platforms is crucial. Therefore, correctly collecting data in a data lake for statistical use—and as a next step, artificial intelligence and machine learning—is vital and usually the biggest challenge.

I will delve deeper into this in my next blog post: ‘The next stop in the organizational data journey: AI’.

‍

No items found.
No items found.
No items found.