«Data is stored in Europe» has become a routine promise from technology vendors. It matters, but it is not the same as European control.
The servers can stand in Frankfurt or Dublin while the service is owned, governed or operated from a country outside the EU. Critical parts of the supply chain can sit under another jurisdiction. And it can be hard to move data, change model or leave the vendor without rebuilding the whole solution.
EU sovereignty is therefore not only about where the data sits. It is about who controls the whole service.
From data residency to actual control
The European Commission describes technological sovereignty as Europe's ability to act independently in the digital world. That means control over key technologies, data and infrastructure – and less dependence on vendors outside the EU.
For an organisation, that means several questions have to be answered:
- Where is the data stored and processed?
- Who owns and operates the service?
- Which jurisdiction is the vendor subject to?
- Who has technical and administrative access?
- Which subprocessors does the solution depend on?
- Can we change model, cloud provider or platform?
- Can we take the data with us and carry on somewhere else?
If the only answer is that the data centre is in Europe, large parts of the picture are missing.
AI makes the question sharper
An ordinary cloud service tends to handle one bounded kind of data. An AI platform can be connected to large parts of the organisation at once.
It can draw on documents, routines, customer data, roles, access rules and information from line-of-business systems to answer employees and customers. Questions, answers, logs and sources can themselves hold information the organisation has to keep control of.
And an AI solution is made of several layers:
- the interface the employee or customer uses
- the knowledge base and the organisation's data
- access control and security rules
- the language models
- the infrastructure the models run on
- logging, monitoring and administration
It helps little that one of those layers is European if a critical part of the chain is controlled somewhere else.
Sovereignty has to be judged across the whole solution – not as a single setting at the cloud provider.
The EU has made sovereignty measurable
The European Commission's Cloud Sovereignty Framework makes the distinction concrete. It assesses cloud services against 48 criteria across eight areas:
- strategic sovereignty
- legal and jurisdictional control
- data and AI
- operations
- supply chain
- technological independence
- security and compliance
- environmental sustainability
The framework combines an overall sovereignty level, called SEAL, with a more detailed score. The point is to assess both whether a vendor clears certain minimum requirements, and how strong the overall sovereignty actually is.
In April 2026 the Commission used the framework in a procurement of sovereign cloud services worth up to 180 million euro over six years. Four vendors were awarded contracts.
That makes sovereignty more than a question of principle. It is becoming a concrete criterion in competition and in procurement.
Sovereignty is not isolation
European control does not mean an organisation has to turn its back on every innovation outside Europe.
It means the organisation itself decides which models and services it uses, on what terms and with which data. And that it can change that decision later.
Vendor independence is therefore a real part of sovereignty. If the whole solution is built around one model or one cloud provider, control sits with the vendor in practice. Switching becomes expensive, slow and risky.
A sovereign architecture should make it possible to use different models for different needs, replace components as the market changes, and keep the thing that matters most in-house: the data, the rules, the access and the organisation's own context.
What does this mean for Tindre?
Tindre is built with full EU sovereignty as the default.
That means data, operations and ownership are in Europe. The platform is at the same time model- and vendor-independent, so an organisation is not locked to one language model or one cloud provider.
The shared foundation – knowledge, standards, ownership and access – belongs to the organisation. The models can be swapped. The tools can change. The foundation stays.
When we use the term «full EU sovereignty», we are describing how Tindre is built and can be delivered. We are not claiming an official SEAL level. That assessment is made by the buyer in a specific procurement.
The most important question is not which label a vendor puts on its service. It is whether the organisation actually keeps control.
Read the European Commission's explanation of the Cloud Sovereignty Framework